ATTORNEY ON CALL · 24/7
212 300 5196
FROM THE DEFENSE DESK / SEC ENFORCEMENT
2 AUG 2026 · UPDATED 20 AUG 2026 · 15 MIN READ · BY TODD A. SPODEK
THE BRIEF · FILED UNDER: SEC ENFORCEMENT
DOCKET NO. 700 · THE DEFENSE DESK

Document Preservation After an SEC Subpoena.

★★★★★1,100+ FIVE-STAR GOOGLE REVIEWS
SUPER LAWYERS · 2020-25AVVO · “SUPERB”SECOND GENERATION · SINCE 1976
AS SEEN ON NETFLIX · CNN · FOX NEWS · NY POST

Receiving an SEC subpoena unmistakably triggers an immediate obligation to preserve potentially responsive documents and data. This includes everything from computer files and cloud storage to hard-copy files and server backups. At this point, routine document deletion policies should be suspended; and, if necessary, the company’s IT staff should be engaged to suspend the automatic deletion of emails and documents as well.

Knowingly destroying documents with the intent to impede, obstruct, or influence the investigation after the obligation to preserve attaches can create exposure for an organization beyond the scope of the underlying securities investigation. This means that even if the underlying investigation doesn’t lead to an enforcement action, the organization could still face allegations of document spoliation, which can carry its own set of penalties.

The obligation to preserve potentially responsive information can also arise before a subpoena from the SEC. If an investigation has become reasonably foreseeable, you must preserve all potentially relevant documents, data, and other records immediately, even if you have not yet received an SEC subpoena. Once you have an SEC subpoena in hand, your organization’s obligation to preserve responsive information has definitively attached.

A formal investigation order allows the SEC’s authorized staff to issue subpoenas with the full power of the federal courts. If authorized, your counsel can request a copy of the SEC’s formal investigation order directly from the agency.

The formal investigation order identifies the SEC staff members who are authorized to issue subpoenas, and it also broadly describes the type of violations of federal law that are at issue. This information will help your counsel better understand the scope of the SEC’s investigation, and it will help your counsel develop an effective defense strategy going forward as well.

As a first step in the SEC’s enforcement process, the SEC’s formal investigation order is not the final word. The preliminary theory discussed in the SEC’s formal investigation order can and often does differ from whatever enforcement action the SEC eventually decides to pursue.

How should an SEC legal hold be managed?

Once your company or organization decides what it is required to preserve, next it needs to put together a comprehensive preservation plan. The preservation plan should identify:

  • Relevant individuals (i.e., the “custodians” whose information must be preserved);
  • Relevant information systems;
  • Relevant devices;
  • Relevant date ranges;
  • Relevant data owners; and,
  • Relevant third parties (e.g., external data backup vendors);

Then, your counsel can work with those custodians, data owners, and third parties to execute an effective legal hold. This is a multi-step process involving several distinct tasks. The steps described below may be appropriate, and preservation efforts should be documented to the extent possible.

The steps for executing a corporate or organizational legal hold are as follows:

  • Interview custodians;
  • Create data map;
  • Serve legal hold notice to custodians;
  • Collect written acknowledgments;
  • Send legal hold reminders;
  • Monitor compliance with legal hold;
  • Release legal hold; and,

The following is a more-detailed description of the steps described above.

  • Interview custodian. Interview each identified custodian about the devices, accounts, and other systems he or she uses to generate or store information that may be subject to the SEC’s legal hold. During the interview, your counsel should also identify whether the custodian has a practice of deleting information on a schedule or basis that does not conform to the organization’s corporate document retention policy.
  • Create data map. Interview data owners (i.e., company or organizational personnel who know where data reside), and interview the relevant third parties (i.e., the external data backup vendors). Use these interviews to develop a data map that connects each custodian and business function to the relevant information systems, and that connects each information system to the relevant data owner or third party.
  • Serve legal hold notice to custodians. Serve a legal hold notice to each identified custodian, and, if necessary, serve a copy of the legal hold notice to the relevant IT personnel as well. The legal hold notice should include an explanation of the custodian’s document preservation duties, and it should provide specific instructions for preserving any documents, data, or other information that may be relevant to the SEC’s investigation.
  • Collect written acknowledgments. Require each identified custodian to acknowledge receipt of the legal hold notice. Require each custodian to sign a written acknowledgment confirming his or her receipt of the legal hold notice, and to acknowledge that he or she understands his or her duties under the legal hold.
  • Send legal hold reminders. Send legal hold reminders to each identified custodian periodically. These reminders should serve both to remind custodians of their ongoing preservation duties, and to serve as an opportunity for custodians to report any new systems or devices (i.e., mobile phones, laptops, computers) that they use; or, any changes to their positions or roles that may require adding or removing custodians from the SEC’s legal hold.
  • Monitor compliance with legal hold. Your counsel should periodically monitor custodians’ and others’ compliance with the legal hold. This includes ensuring that automatic deletion is suspended, that custodians are complying with the legal hold, and that custodians’ data are being backed up by the company’s or organization’s IT personnel (i.e., to a backup server) or by the relevant third party.
  • Release legal hold. Do not release the legal hold (i.e., resume the destruction of documents in accordance with the organization’s corporate document retention policy) without counsel’s approval. This includes not removing custodians or devices from the legal hold. Once the SEC’s investigation is concluded, your counsel will determine whether your company’s or organization’s obligation to preserve potentially responsive documents and data remains, and, if not, your counsel will authorize releasing the legal hold.

Even if your company or organization has a document retention policy, this policy is not sufficient to meet your legal preservation obligation. In addition, your legal preservation obligation is not limited to your company’s or organization’s document retention policy either. Your legal preservation obligation is focused on the SEC’s investigation and any reasonably anticipated litigation or other applicable preservation obligation. It includes everything, from all relevant departments and personnel to all potentially relevant devices and data storage, that could possibly contain potentially responsive documents or data. As a result, an effective legal hold should reach any and all custodians who possess documents or data subject to preservation.

Which devices, accounts, and providers must an SEC hold cover?

Once your company or organization’s counsel has worked with its IT personnel (i.e., the relevant third party) to disable any automatic deletion for email, instant messaging, messaging apps, and other forms of cloud storage, your company or organization will need to identify and secure all relevant devices, accounts, and providers. This includes all pertinent devices and accounts that are owned, leased, or used by custodians of responsive documents, data, and other information. Some examples include:

  • Computers (i.e., desktops, laptops, tablets);
  • Smartphones, smartwatches, and other mobile devices (including those personally owned by custodians);
  • Email accounts (including those personally owned by custodians);
  • Instant messaging accounts, messaging apps, and other similar cloud storage;
  • Social media accounts;
  • Ephemeral messaging accounts;
  • Departed employee devices and accounts;
  • Third-party providers; and,
  • Personal accounts.

Although most corporate and organizational document retention policies exempt personal accounts and personal devices, this is not a true exemption. If documents, data, or other information that are responsive to the SEC’s subpoena are stored on a custodian’s personally owned device, account, or similar cloud storage, the custodian must preserve those documents, data, and other information as well. This is true regardless of whether the custodian’s personally owned device, account, or similar cloud storage is used primarily for personal use.

Along with disabling automatic deletion for email, messaging apps, and cloud storage, your company or organization’s counsel will also work with its IT personnel (i.e., the relevant third party) to suspend automatic deletion for any devices, accounts, or other sources of information that utilize “ephemeral messaging.” These apps generally use a “vanishing mode” that makes messages disappear automatically after they are read or after a set amount of time has passed. This type of automatic deletion can threaten the preservation of responsive communications, and, as a result, suspending it is necessary for ensuring an effective legal hold.

Similarly, if any responsive documents, data, or other information can be found in the social-media accounts of any of the identified custodians, those documents, data, and other information must be preserved as well. This includes responsive social-media content posted by a custodian, and it includes responsive content posted by others which falls within the custodian’s control.

If an identified custodian is an employee who is about to leave your company or organization, you will want to ensure that any responsive documents, data, or other information on that employee’s personal device, account, or similar cloud storage are properly preserved before the employee’s access to your company’s or organization’s networks terminates.

Finally, although your company or organization’s personnel are the custodians of the vast majority of potentially responsive documents, data, and other information, third-party providers may also have responsive information in their possession. This includes relevant information held in your company’s or organization’s backup systems, if those systems are managed by a third party.

Individuals must preserve all responsive documents, data, and other information contained in their personal email and instant messaging accounts as well. Although individuals’ communications in these accounts are private, all communications involving business-related matters may be subject to the SEC’s subpoena.

How should metadata, linked files, backups, and archives be preserved?

If your company or organization identifies documents, data, or other information that appear responsive to the SEC’s subpoena, then you need to ensure that these items are adequately preserved in their original, native forms. This includes, for example, the ability to see when a file was modified, who modified the file, and from where the file was accessed. Preservation of information is not just limited to preserving the information’s content; but rather, it involves preservation of the information’s metadata as well.

If the identified responsive information is available in native format, your company or organization’s counsel should preserve it in native format. This is important, as converting the information into another format (e.g., converting an electronic file into PDF) can cause some of the information’s metadata to be changed or even permanently removed.

In addition to preserving native files, your company or organization must also preserve all responsive attachments and documents that are linked within those files. If the identified responsive information is an email or similar communication, all attachments that are responsive to the SEC’s subpoena must be preserved as well. This includes both the communication and the attachment itself.

Similarly, if the identified responsive information contains a hyperlink that points to a responsive document, data, or other information, you must preserve the linked document, data, or other information as well. For example, if a responsive document has a hyperlink that points to a responsive Instagram post, that Instagram post must be preserved as well.

In addition to preserving documents, data, and other information, if any identified responsive information contains “reactions,” “edits,” or “replies” that are responsive to the SEC’s subpoena, those reactions, edits, and replies must be preserved as well.

Backups and archives present unique preservation challenges. Generally, if documents, data, or other information in a computer or organizational backup are redundant with information stored on another active source, the backup information will not need to be preserved. However, this is not always the case. If a computer or organizational backup contains potentially responsive documents, data, or other information that are not stored on any other source, then that backup medium containing the responsive documents, data, or other information must be preserved. Similarly, if the backup medium containing information that is not stored on another source will be recycled, then the responsive documents, data, or other information that are contained on that backup medium must be transferred and then preserved.

Similarly, if a computer or organizational legacy system contains potentially responsive documents, data, or other information, then the information in that legacy system must be preserved. If the information in the legacy system can no longer be accessed due to changes in the system’s technology or accessibility, then it must be adequately documented as being inaccessible. Documentation of inaccessible data will be key to ensuring that it is not presumed to be absent from the organization’s production to the SEC.

Finally, if an employee or third party is departing your company or organization, you will want to determine whether any potentially responsive documents, data, or other information are contained on the employee’s or third party’s storage medium before it is wiped or reused. If responsive documents, data, or other information are contained on that storage medium, then it must be preserved as well.

Spodek Law Group, led by managing partner Todd Spodek, defends clients in federal criminal and white collar matters.

What is the difference between preservation and document production?

While related, preservation is different from document production. As explained above, preservation refers to the process of taking steps to ensure that potentially responsive documents, data, and other information are not deleted, overwritten, lost, or otherwise made unavailable. Once an information source is identified as potentially responsive, it must be preserved, a process known as “collection.” This includes everything from which file is collected from where, who collects it, and how it is stored. This process should be documented in a collection log.

After a successful collection, your company or organization’s counsel must ensure that the collected information is properly processed. Processing involves extraction, indexing, and normalization, all of which are necessary steps in making the collected materials ready for review.

Once the collected materials are processed, they will then be reviewed for responsiveness, privilege, confidentiality, and other concerns. Then, your counsel will select the materials that are responsive to the SEC’s subpoena to produce.

Similar to the collection process, the materials that are selected for production must be properly produced. This includes producing them in the required or negotiated format and transmitting them to the SEC in the time frame requested.

Your company or organization’s counsel will need to make critical decisions throughout the preservation and production process. These decisions must be properly documented so that if challenged in court, your company or organization can present documentation showing that it took reasonable steps to meet its preservation and production obligations. Documentation should be thorough, and should include the factual and legal basis for including or excluding any information in the production.

Similarly, while broad subpoena language can present challenges, it can also mean that there are documents and other information that are responsive to the SEC’s subpoena that the SEC has not specifically identified. In this scenario, you will want to rely on your counsel’s experience in dealing with the SEC to ensure that no responsive information is overlooked.

Broadly speaking, if your company or organization receives an SEC subpoena, there are five main stages of document preservation, collection, and production.

  • Preservation: Protect responsive information from deletion, alteration, or loss.
  • Collection: Transfer the preserved information from its native location to a known and secure location.
  • Processing: Extract, index, and normalize the information for effective review and search.
  • Review: Analyze the processed information to identify responsive materials.
  • Production: Deliver the relevant and responsive materials to the SEC in the required format.

How should privilege be protected during an SEC production?

When your company’s or organization’s counsel produces materials responsive to the SEC’s subpoena, he or she will also prepare a “privilege log” that lists each document, data, or other item withheld from production and the asserted protection.

Generally, you need to take proactive steps to avoid a waiver of privilege in federal proceedings. Under Federal Rule of Evidence 502(b), you can avoid a waiver if:

  • You took reasonable steps to prevent the accidental or inadvertent disclosure of privileged or work product information;
  • You promptly took reasonable steps to rectify the disclosure; and,
  • The disclosure does not unreasonably prejudice the party receiving the information.

Another form of protection is available under Rule 502(d). Under a Rule 502(d) court order, protection against waiver is effective beyond the parties who received the court order, and any clawback agreement executed between the parties will also be enforceable beyond the parties. In contrast, agreements executed under Rule 502(e) are binding only upon their signing parties, unless they are incorporated into a court order under Rule 502(d).

Similar to a privilege log, clawback agreements also need to be properly executed to prevent claims of inadvertent waiver. These agreements should address not only the requirement to return or delete the privileged or work product information, but also its use, and the consequences of a violation of the agreement’s terms.

When individuals receive a compelling subpoena, their legal counsel must carefully review the documents and information that are subject to preservation. For large document populations, the process of identifying responsive and privileged documents can take several weeks. If some of the documents or information are only potentially privileged, this may lead to federal litigation to enforce an SEC subpoena.

When individuals testify under compulsion in federal proceedings, it is possible to invoke the Fifth Amendment right against self-incrimination on a question-by-question basis. This gives you the opportunity to work with your counsel to avoid potentially self-incriminating testimony.

What happens if responsive SEC subpoena data is lost?

If you fail to preserve documents, data, or other information that you identify as potentially responsive to the SEC’s subpoena, then you could face criminal obstruction charges under 18 U.S.C. § 1519. To meet this statute’s intent requirement, however, the person who is accused of destroying information must have acted knowingly and with the specific intent to “impede or obstruct” an investigation. As a result, if documents were deleted routinely without the required intent, this fact alone should not establish criminal obstruction.

When dealing with civil spoliation issues, courts rely on Federal Rule of Civil Procedure 37(e) to ensure preservation. Generally, Rule 37(e) allows “adverse-inference sanctions” only upon a finding that ESI was lost as a result of the “intent to deprive another party of the information’s use in the litigation.” Negligence is generally not sufficient to meet this high standard, and evidence of lost ESI that falls short of evidence that would support adverse-inference sanctions can support “curative measures” if it “prejudices” the opposing party.

Outside of legal ramifications, missing deadlines and delivering evasive productions can damage your counsel’s credibility with SEC staff. This is particularly important during a document preservation process, as the SEC staff will either rely on the production as sufficient, or they will seek further information about potential additional documents and other information.

The SEC may also share investigative information with the DOJ, the FBI, the IRS, state attorneys general, and other regulators. SEC staff may also refer evidence to the DOJ when they are unable to pursue a civil case, in which case this evidence could lead to a criminal case.

The SEC’s authority to seek civil money penalties, disgorgement of “ill-gotten” profits, industry bars, and other types of civil remedies can be very significant. Generally, these remedies apply to civil cases involving substantial or intentional misconduct, but they can also include unintentional misconduct in some cases as well.

Contact a Federal Criminal Defense Attorney

Nothing here is legal advice, and the details of your case matter. Todd Spodek and Spodek Law Group take federal criminal and white collar cases nationwide, from offices in New York, Brooklyn, Queens and Los Angeles. You can reach the firm at 212-300-5196.

LEGAL INFORMATION, NOT LEGAL ADVICE · STATUTES CHANGE - VERIFY CURRENT LAW · ATTORNEY ADVERTISING
THE AUTHOR'S RECORD · PRIOR RESULTS DO NOT GUARANTEE A SIMILAR OUTCOME
Acquitted.
$26M MONEY LAUNDERING
Dismissed.
RICO · 10-YEAR MINIMUM FACED
Six months.
$12M PONZI · YEARS ASKED
ALL RESULTS →
★★★★★VERIFIED CLIENT · FEDERAL CASE · 2022 · VIA GOOGLE REVIEWS
"By the time our free consultation was over, we left at ease."
1,100+ FIVE-STAR GOOGLE REVIEWS →
RISK FREE · CONFIDENTIAL · 24/7

Reading is good. Calling is better.

Answered within 24 hours, guaranteed. Some stories are better told out loud -

212 300 5196
AFTER YOU REACH OUT
01A person answers - not a service. Day or night. 02Free, confidential consultation - ask us anything, regardless of how long it takes. 03Strategy starts the same day - and you hold the senior partner's cell number.
★★★★★1,100+ FIVE-STAR GOOGLE REVIEWS
READ THEM →
INTAKE · PRIVILEGED & CONFIDENTIAL
24/7
01
02
03
04
05
ANSWERED WITHIN 24 HOURS, GUARANTEED OR CALL 212 300 5196
EVERYTHING YOU SHARE IS PROTECTED BY ATTORNEY-CLIENT PRIVILEGE FROM THE FIRST WORD.