Preserving Messages on a Device the Employee Owns
Work conversations migrate to personal phones without anyone deciding that they should. Whether those messages must be preserved turns on control rather than ownership, and the answer varies by circuit, by policy and by how the device came to be used for work.

The rule in short
Federal Rule of Civil Procedure 34 reaches material in a party's possession, custody, or control, which is the doorway through which employer obligations over an employee-owned phone are argued. Courts have divided between a legal right to obtain the data and a practical ability to obtain it. Written device policies, reimbursement arrangements and management software all shift the analysis, and collection raises privacy questions the rule does not resolve.
A dispute about a project frequently turns out to have been conducted in text messages. The relevant exchanges are not on any server the organization controls; they are on phones that employees bought, pay for, and use for everything else in their lives. Whether those messages have to be preserved, and by whom, is one of the least settled questions in the area.
Control, not ownership
Rule 34 requires production of designated items in the responding party's possession, custody, or control. Ownership of the hardware is not among the three. An organization that has never touched a device may still be required to produce what is on it, and an organization that issued a phone may find that it has no right to the personal account running on it.
Control is therefore the whole question, and it is answered by looking at the relationship between the organization and the data rather than the device. A written policy, a reimbursement arrangement, an enrollment in management software, or a contractual undertaking by the employee can each establish it. Silence on all four points usually means the organization has to ask rather than direct.
The consequence for preservation is immediate. If the messages are within control, the duty reaches them from the moment litigation is anticipated, and the failure to instruct the custodian is a failure of reasonable steps. If they are not, the organization's obligation is limited to what it can reasonably request, and the loss is attributed elsewhere.
How the circuits have divided
Two tests circulate. The narrower asks whether the party has a legal right to obtain the material on demand — a right arising from contract, policy or statute. The broader asks whether the party has the practical ability to obtain it, regardless of whether any enforceable right exists. The difference is not academic: an employer with no written policy but with a practice of asking employees for their messages, and being given them, satisfies the second test and fails the first.
| Arrangement | Typical indicator of control | Usual treatment |
|---|---|---|
| Organization-issued phone, work account only | Ownership and administrative rights | Within control |
| Personal phone, written policy granting access | Contractual right to obtain | Within control under either test |
| Personal phone enrolled in management software | Technical ability to collect or wipe | Usually within control |
| Personal phone, stipend paid, no policy | Practical ability only | Split; depends on the test applied |
| Personal phone of a former employee | Neither right nor ability | Ordinarily outside control |
A related split concerns whether an organization can be required to obtain material it has the right to request but has never held. Some courts have said that an unexercised right is still control and must be exercised; others have declined to order a party to make a demand on its own employee. The practical answer in either camp is that a documented request costs little and forecloses the argument.
Because the tests diverge, the same facts can produce different obligations in different districts. That instability argues for treating the messages as preservable and negotiating scope, rather than resolving the control question unilaterally and being wrong about it later. The negotiation is also the moment to raise the proportionality limits on what has to be kept.
What a device policy changes
A written policy does more than settle control. It tells employees in advance that work communications on a personal device may have to be produced, which removes the surprise that otherwise makes collection contentious. It can specify which applications are approved for work use, which pushes the conversation onto systems the organization can hold. And it can require the return or imaging of relevant data on separation.
The gap between a policy and its operation is where most argument occurs. A policy asserting a right of access that has never once been exercised, on a workforce that was never told about it, is a weaker foundation than a short rule that employees acknowledge at hire and that the organization has actually used. Courts look at the practice as well as the paper.
Policies also cut the other way. A policy that disclaims any right of access is evidence against control, but it does not prevent a court from finding practical ability, and it may look like an arrangement designed to keep records beyond reach. Where the organization has provided a retained messaging platform and told employees to use it, a policy disclaiming access to personal devices is easier to defend than one standing alone.
Whether or not the messages are within control, an organization that anticipates litigation can tell the employee in writing to stop deleting and to preserve the relevant threads. That instruction costs nothing, is easy to document, and is frequently the difference between a loss attributed to the organization and one attributed to an individual. It belongs in the hold notice sent to custodians rather than in a separate conversation.
Collecting from a device someone owns
Collection is where the privacy problem becomes concrete. A phone holds medical information, family photographs, financial records and the communications of people who are not parties to anything. Courts have managed this by scoping rather than by exempting: a protocol defines the applications, the counterparties and the date range, and a neutral examiner extracts only that.
Targeted extraction is technically straightforward for most messaging applications, and the resulting export carries the metadata that makes a message usable as evidence — the timestamps, the participants and the thread structure. Screenshots do not, which is why an instruction to employees to photograph their own conversations produces material that is contested on authentication grounds. The controlled route is described in the collection methods that leave the source unchanged.
Where deletion is alleged, the scope widens. A full image may be ordered so that deleted-message artifacts and system logs can be examined, usually with the image held by the examiner and only responsive material released to the parties. An order under Federal Rule of Evidence 502(d) is commonly entered at the same time so that inadvertent disclosure of privileged or personal material does not waive anything.
When the device cannot be reached
Some devices are simply unavailable. The employee has left, refuses, or has replaced the phone. The alternative is a subpoena to the individual under Rule 45, which reaches a non-party's documents and electronically stored information and is enforced against that person directly. It is slower, and it puts the organization in the position of watching rather than acting.
Replacement devices are their own category. A phone traded in during an upgrade is usually unrecoverable, but the content may survive in a backup held by the platform account, and that account is often reachable even when the hardware is not. Whether the backup is within anyone's control depends on whose account it is, which returns the analysis to the same question in a different location.
The organization's own exposure then depends on what it did while the device was still reachable. An instruction given and documented before separation, a request made and refused, or an offboarding process that captured work data all support the position that reasonable steps were taken. Nothing at all supports the argument that the loss should be treated under the measures the rule provides for lost electronic evidence.
Points to carry away
- Rule 34 turns on possession, custody, or control rather than on who owns the hardware.
- Circuits differ between a legal-right test and a practical-ability test for control.
- A written device policy giving the employer access rights strengthens the case for control.
- Mobile device management software is often treated as evidence of practical ability to obtain data.
- Collection from a personal device raises privacy issues that are handled by scoping, not by exemption.
- Where control is absent, a subpoena to the individual is the alternative route.
Questions readers ask
Can an employer be sanctioned for messages an employee deleted from a personal phone?
Only if the messages were within the employer's control and the employer failed to take reasonable steps. Where a policy gave the employer a right of access and it did nothing to exercise that right after a duty attached, courts have treated the resulting loss as the employer's. Where the device was genuinely outside any right of access and the employer instructed the employee to preserve, the analysis is more favorable. The instruction, and evidence that it was given, is what separates the two situations.
Does an employee have to hand over an entire phone?
Rarely, and courts have resisted requests framed that way. The usual approach is a targeted collection of defined applications, contacts and date ranges, conducted by a neutral examiner or under a protocol the parties agree on. Full forensic images of personal devices are ordered where targeted collection has failed or where deletion is alleged, and even then the image is normally held by the examiner with only responsive material released. Privacy is managed through the scope of the protocol rather than by an exemption.
What if the employee has left the organization?
Control over a former employee's personal device is difficult to establish, and most policies lapse on separation. The practical route is a subpoena to the individual under Rule 45, which reaches a non-party's documents and electronically stored information. That takes longer and is enforced against the individual rather than the organization. The organization is still expected to have asked before the person left, which is one reason offboarding is treated as a preservation checkpoint rather than a human resources formality.
Sources
- Federal Rule of Civil Procedure 34, Cornell LIIProduction reaches designated items in the responding party's possession, custody, or control.
- Federal Rule of Civil Procedure 45, Cornell LIIProvides the subpoena that reaches documents and electronically stored information held by a non-party.
- Federal Rule of Civil Procedure 26, Cornell LIIProportionality and the protective order provisions used to scope collection from a personal device.
- Federal Rule of Civil Procedure 37, Cornell LIIThe measures available where information that should have been preserved is lost.
- Federal Rule of Evidence 502, Cornell LIIA court order under subdivision (d) limits waiver where privileged or personal material is swept up.
- NIST SP 800-86, Guide to Integrating Forensic TechniquesFederal guidance on acquiring data from devices and verifying that the copy is unaltered.
Rapid Response Law is a publication, not a law firm. This article states general rules and cites its sources; it is not advice about any particular case, and the law differs by state and changes over time.
More in Evidence Preservation
When the Duty to Preserve Begins
The obligation to preserve evidence arises when litigation is reasonably anticipated rather than when a suit is filed. Federal Rule of Civil Procedure 37(e) presupposes that duty by asking whether information that should have been preserved was lost because reasonable steps were not taken. Anticipation is judged objectively on what an organization knew, and knowledge held by managers and counsel is generally attributed to the organization.
Collecting Data Without Altering It
An electronic record carries system-generated attributes that establish when it was created, who handled it, and where it sat. Ordinary copying overwrites several of them. Forensic imaging captures a bit-level duplicate and verifies it with a hash value; targeted collection captures defined items with their metadata intact; self-collection by custodians is the least reliable and the most commonly criticized. A chain-of-custody record documents each transfer.
Ending a Litigation Hold
A hold ends when the matter that created it is over and no other obligation covers the same material. That requires checking for appeals, related proceedings, regulatory retention periods and other holds on the same custodians before anything is released. The release itself is a written instruction reversing the original, and the record of what was held, collected and released is retained after the material itself is disposed of.


