
Share
A company in a class action spent hundreds of hours trying to produce its own documents. It even hired an outside eDiscovery vendor to help, but the effort still fell short.
The documents were not missing. They were hyperlinked, stored in the cloud, and shared as links inside emails. By the time the team went looking, many of those links no longer resolved to anything.
This happened in In re StubHub Refund Litigation, in the Northern District of California. The parties had agreed to produce hyperlinked files as attachments, but the court later found that impossible to fulfill most of the time. A federal court accepted that an agreed requirement could not be met, despite real effort and real cost.
Today, data lives in links, shared drives, and chat threads that change by the hour. This blog covers the distinctions every legal team needs. Then it goes further, into where those distinctions break down and what that means for your case.
Start with the version most practitioners agree on. Three terms describe three distinct acts, each with its own trigger, owner, and failure mode.
A legal hold is a notice. It tells custodians to stop deleting relevant information, and it marks where the preservation process begins. Venio's guide to ESI and legal holds covers the mechanics of issuing one correctly.
Preservation is the duty behind that notice, the obligation to keep relevant information intact once litigation is reasonably anticipated. Ensuring proper collection, preservation, and safeguarding of that information starts with understanding this distinction clearly.
Collection is the affirmative act of gathering preserved data for review, moving it into a place that is secure and defensible. It is a separate step, not an automatic outcome of the first two.

This model is accurate, and it is also where most articles stop. The trouble starts once you apply it to how data actually lives and moves today.
The clean three-step model carries a hidden assumption. It assumes that data holds still long enough for each step to finish before the next begins. That assumption came from a world where files were static and preservation was mostly a filing problem.
Modern data breaks the assumption in two separate ways. The workflow itself collapses, as preservation and collection stop being distinct stages. The data also moves, so what you preserved may no longer be what you need. Legal data preservation now has to account for both.
Start with the workflow problem. Consider in-place preservation, where tools like Microsoft 365 lock data down where it already lives. That single action performs both preservation and the earliest step of collection at once.
The old boundary between the two stages quietly softens as a result. This is not a flaw by itself, since the right data preservation methods depend on the source. But it changes how legal teams must think, because what you preserve now shapes what you can later collect.
Here is the risk most generic guides miss entirely. You can preserve something and still not have the evidence a case actually needs.

Modern attachments are the clearest example of this problem. A modern attachment is a link, not a file, which is why people also call it a cloud attachment or a pointer. When you preserve the email, you preserve the link, but you do not automatically preserve the document that link points to, since it lives somewhere else entirely. That document usually sits in a shared drive, where it can be edited or deleted after the message is sent. The link may still work, but it can resolve to a different version than the one that mattered.
Microsoft's own documentation confirms this risk directly. In a standard eDiscovery search, only the cloud attachment link is returned, not the content of the shared document itself. By default, cloud attachment collection also captures the current version of a file, not the version that existed when it was originally shared. So the file you finally collect may not match what was actually shared.
The courts are still working through this problem case by case. In StubHub, the producing party could not reassemble linked files as attachments, and the court accepted that as impossible in most instances. Other cases have gone differently on similar facts.
In Nichols v. Noom, a New York federal court declined to treat hyperlinked files as attachments under the parties' own ESI protocol. The lesson is not one single rule for every matter. Treatment often turns on the specific ESI protocol the parties negotiate, and the law is still catching up to the technology.
There is even debate over the underlying preservation duty itself. Some practitioners argue there is no automatic duty to keep the as-sent version of every linked file by default. This is contested ground rather than settled law, so it deserves a real conversation with counsel instead of an assumption made either way.
Do not assume a preserved link equals preserved evidence. Confirm which linked files matter, whether the target document still exists, and which version you are actually holding. Building that verification step into your hold process is what separates a defensible preservation record from a hopeful one.
Venio's legal hold best practices guide walks through how to make those checks routine rather than reactive.
Most preservation happens because of a legal duty, not because a court ordered it. The two are easy to confuse, but the duty is self-executing and needs no judge to trigger it. A preservation order is different, because a judge directs specific parties to preserve specific information.
Courts issue them when preservation is disputed or genuinely at risk. An order raises the stakes, since violating it can expose a party to contempt on top of Rule 37(e) sanctions. Understanding preservation order legal exposure matters most once a court has entered the dispute.
Most organizations never receive one. But the duty applies to everyone, every time litigation becomes reasonably anticipated. That is why legal data preservation done correctly by default remains the only safe posture.
Most guidance warns about preserving too little, and almost nobody warns about preserving too much. Over-preservation carries real costs, because you hold data longer than necessary and expand the volume that needs review. It also raises storage and security exposure, and can conflict with privacy rules on holding personal data.
The Federal Rules point toward balance rather than hoarding. Rule 26(b)(1) ties discovery to proportionality, not to preserving every version of every document. The goal is to preserve the right things defensibly, and no more than the matter requires.

If the data has changed this much, your evaluation criteria for legal hold software needs to change with it. A modern process needs more than notice tracking alone.
Start with the fundamentals every one of the legal hold tools on the market should offer, then look closely at how each handles modern, cloud-based sources.
Most top legal hold software vendors can check the first item on that list today. Far fewer can prove that what they preserved is what a team can actually produce months later.
Venio's legal hold module builds notice tracking, in-place preservation, and audit trails into one connected workflow, so preservation and collection never fall out of sync. See how it compares to other legal hold software vendors before you choose one.
Come back to the three terms, since they still matter and every legal team still needs them. A legal hold starts the process, while preservation protects the evidence and collection prepares it for discovery. The real test is no longer whether a team can name these three steps correctly.
It is whether what was preserved is what a team can actually produce. In a world of links and living documents, that outcome is not automatic. It takes a process built for how data behaves now, not how it behaved a decade ago.
When you preserve something, can you prove you captured what mattered, at the version that actually mattered to the case? That is the question a court will ask. See how Venio helps legal teams manage legal holds, preservation, and collection together for modern data.
Contact us today to see how Venio keeps every version of your evidence defensible, from the first hold notice through final production.
A legal hold is the notice that tells custodians to preserve relevant data. Preservation is the underlying duty to keep that data intact and unaltered. The hold starts the process, and preservation is the outcome a court actually measures.
A preservation order is a court directive requiring specific parties to preserve specific information. Its purpose is to remove doubt and enforce preservation with judicial authority behind it. Violating one can add contempt exposure on top of sanctions available under Rule 37(e).
Collection means gathering preserved data without altering it, protecting metadata, and documenting every step to maintain chain of custody. For cloud and chat data, it also means capturing the correct version of a file, not just the current one.
Not necessarily. A modern attachment is a link rather than a file, so preserving the message only preserves the link itself. The document it points to can still change or disappear unless it is preserved directly.
The best method depends on where the data actually lives. Some systems support in-place holds, while others need targeted exports before retention rules purge the data. In every case, the goal stays the same: suspend routine deletion and keep the right version intact.
Consider it once data volume and complexity outgrow manual tracking through spreadsheets and email chains. Cloud platforms, chat tools, and frequent litigation are all strong signals worth acting on. The goal is one connected, defensible process across every modern data source.