Custodian: the practical definition
Why custodians matter
People are a useful route into evidence. They know what happened, whom they communicated with, which systems they used and where they stored information. A custodian list therefore helps structure identification, preservation, interviews and collection. But it is a starting point, not a complete map of the evidence.
A custodian is not the same as a data source
A person may use many sources: Exchange, Teams, OneDrive, a laptop, a phone, a shared drive, a CRM and specialist applications. Conversely, an important database or shared mailbox may have no single meaningful custodian. Modern eDiscovery needs both custodian mapping and system mapping.
How custodians are identified
Potential custodians can emerge from pleadings, allegations, organisation charts, interviews, email participants, project records, contracts and early data analysis. Teams should ask who made decisions, who communicated them, who implemented them and who maintained the relevant systems or records.
Custodian interviews
A good interview is factual and practical. What was the person’s role? Which devices and accounts did they use? Did they work from home? Which collaboration tools, messaging apps, shared folders or business systems were relevant? Did they keep local copies? Did they change roles or devices? The aim is to understand information behaviour, not simply complete a form.
Custodian questionnaires
Questionnaires can collect consistent information across a larger population and help prioritise interviews. They work best when questions are clear and tailored to the organisation. Long generic forms often produce poor answers because custodians do not recognise technical terminology or cannot remember every system name.
Custodians and legal hold
Legal hold notices are commonly sent to custodians who may possess relevant information. Acknowledgement, reminders and follow-up help demonstrate that preservation has been communicated and monitored. Technical preservation may still be necessary because relying only on individual behaviour can be risky.
Custodian collection
Collection decisions should reflect the sources actually used by the custodian. “Collect John’s email” may be inadequate if the important conversation occurred in Teams and the relevant documents were stored in SharePoint. The collection plan should connect each custodian to specific sources and time periods.
Departed employees and changing roles
Former employees can present practical difficulties: devices may have been reissued, accounts disabled, mailboxes archived or cloud data deleted according to policy. Employees who changed departments may also have data spread across systems.
Non-custodial data
Some of the most important evidence may sit outside personal accounts: shared drives, finance systems, transaction databases, ticketing systems, collaboration channels, CCTV, logs or enterprise archives. Calling everything “custodian data” can obscure this distinction.
Common misconceptions
The most senior person is not automatically the most important custodian. The person named in a complaint is not necessarily the only one. Every custodian does not require every source to be collected. Identifying a custodian does not mean all of that person’s data is relevant.
Custodian maps
A useful custodian map records role, relationship to issues, relevant dates, known sources, preservation status, interview status, collection status and notes about risk. It becomes a living project tool rather than a static list of names.
Privacy and proportionality
Custodian data can contain substantial personal and irrelevant material. Scope should therefore be tied to legitimate discovery needs. Targeted dates, sources and methods can reduce unnecessary intrusion while preserving what the matter reasonably requires.
The key lesson
Custodians matter because people create and use information, but modern evidence lives in systems. Effective eDiscovery connects the two: who knew or did something, and where the digital traces of that activity are likely to exist.
Practitioner takeaways
- Define the question before choosing the technology or workflow.
- Make assumptions visible and revisit them as the evidence develops.
- Use proportionate methods, but validate important exclusions and reductions.
- Track cost, time, quality and risk together; improving one can affect the others.
- Document material decisions so the process remains explainable and defensible.
Related eDiscovery Certification Council Knowledge Hub reading
Authoritative reference points
This is a vendor-neutral professional reference from the eDiscovery Certification Council Knowledge Hub. Jurisdiction-specific legal requirements should be checked against the current applicable rules and authoritative guidance.