iceberg logo
iceberg logo

Where Privacy Law and eDiscovery Overlap: A Guide for GCs

Leather-bound legal brief and padlock-secured laptop on a dark conference table, city lights glowing through floor-to-ceiling windows.

For general counsel, the relationship between privacy law and eDiscovery has never been more consequential. As data protection regulations tighten across jurisdictions and litigation volumes grow, the tension between an organization’s legal obligation to preserve and produce data and its equally binding obligation to minimize and protect that same data has become one of the defining compliance challenges of 2026.

This guide walks through the core concepts at this intersection, building from foundational principles to practical governance strategies. Whether you are navigating a cross-border dispute or building internal policies for the first time, understanding where these two disciplines meet and where they collide is essential for sound legal leadership.

What is the overlap between privacy law and eDiscovery?

At its core, the overlap between privacy law and eDiscovery arises from a fundamental tension: litigation requires the preservation and disclosure of data, while data protection law requires that personal data be collected minimally, stored securely, and deleted when no longer necessary.

eDiscovery is the process by which electronically stored information (ESI) is identified, preserved, collected, reviewed, and produced in the context of legal proceedings or regulatory investigations. Privacy law, on the other hand, establishes rights and obligations around how personal data is handled throughout its lifecycle. When litigation touches personal data, both legal frameworks apply simultaneously, and neither yields automatically to the other.

For example, an employment dispute may require a company to produce years of internal communications. Those communications almost certainly contain personal data belonging to employees, third parties, or customers. The company must satisfy its eDiscovery obligations to the court while simultaneously honoring its data protection obligations under applicable law. Navigating both at once is where general counsel earns their seat at the table.

How key privacy regulations shape eDiscovery obligations

The regulatory landscape directly shapes how eDiscovery must be conducted. Understanding which regulations apply and what they demand is the starting point for any compliant discovery process.

GDPR and eDiscovery in European contexts

The General Data Protection Regulation remains one of the most consequential frameworks for GDPR eDiscovery. It imposes strict rules on data transfers outside the European Economic Area, requires a lawful basis for processing personal data, and grants individuals rights including access, rectification, and erasure. Each of these principles creates friction with traditional eDiscovery workflows.

For instance, transferring ESI from a European entity to US litigation counsel for review may constitute a cross-border data transfer under GDPR, requiring appropriate safeguards such as Standard Contractual Clauses. Failing to account for this step is one of the most common compliance failures in international litigation.

Other data protection laws GCs must track

GDPR is not the only framework in play. General counsel operating across multiple jurisdictions must also account for:

  • UK GDPR, which mirrors the EU regulation post-Brexit but operates under a separate supervisory authority
  • CCPA and CPRA in California, which grant consumers rights over their personal information that can complicate discovery involving customer data
  • PDPA frameworks across Southeast Asia, including Singapore and Thailand, which impose varying restrictions on data access and transfer
  • Brazil’s LGPD, which follows a GDPR-adjacent model and applies to any processing of Brazilian residents’ data

Each of these regimes has its own definitions, lawful bases, and transfer restrictions. A discovery protocol built for US domestic litigation will rarely translate cleanly into a multi-jurisdictional matter.

Where litigation holds and data retention limits conflict

Building on the regulatory overview above, one of the sharpest practical conflicts between privacy law and eDiscovery emerges around data retention. A litigation hold requires an organization to suspend its normal data deletion schedules to preserve potentially relevant ESI. Privacy law, however, generally prohibits retaining personal data beyond the period necessary for the original purpose.

These two obligations can pull in opposite directions. A routine data deletion that would satisfy a privacy policy may constitute spoliation if a litigation hold was already in place. Conversely, retaining data under a litigation hold beyond its lawful retention period may expose the organization to regulatory sanction.

The conflict becomes particularly acute when the litigation hold is broad or long-running. Consider a regulatory investigation that spans several years: data that would ordinarily have been deleted under a two-year retention schedule must now be preserved indefinitely, creating a growing pool of personal data held without a clear lawful basis under data protection law.

Effective general counsel resolve this tension by:

  • Issuing targeted litigation holds that are as narrow as the matter permits, rather than defaulting to broad, organization-wide holds
  • Documenting the legal basis for continued retention during the hold period
  • Building a defined release process so that data is deleted promptly when the hold is lifted
  • Engaging data protection counsel alongside litigation counsel at the outset of any matter that touches personal data

Applying privacy-compliant eDiscovery in cross-border matters

Cross-border litigation introduces a further layer of complexity. When a matter spans multiple jurisdictions, the legal requirements governing data collection, transfer, and production may conflict not just with each other but with the procedural rules of the forum court.

US federal courts, for example, operate under broad discovery obligations that assume relatively unrestricted access to ESI. European data protection authorities, by contrast, have historically viewed US-style discovery as incompatible with GDPR principles, particularly where it involves bulk transfers of personal data to foreign counsel or courts.

A privacy-compliant approach to cross-border eDiscovery typically involves several practical steps:

  1. Data mapping before collection: Identify where relevant data sits, what categories of personal data it contains, and which jurisdictions’ laws apply before any collection begins.
  2. Proportionality review: Apply proportionality principles early to limit the scope of collection to what is genuinely necessary for the matter.
  3. Transfer mechanism selection: Determine the appropriate legal mechanism for any cross-border data transfer, whether Standard Contractual Clauses, a derogation under Article 49 GDPR, or an equivalent instrument under the applicable national law.
  4. Redaction and anonymization: Where possible, redact personal data that is not directly relevant to the matter before production, reducing the volume of personal data disclosed.
  5. Regulatory notification: In some jurisdictions, notifying the relevant data protection authority before transferring data in response to foreign legal proceedings is required or strongly advisable.

Engaging eDiscovery legal specialists who understand both the procedural demands of the forum court and the data protection requirements of the source jurisdiction is often the most effective way to manage this complexity.

Common compliance failures GCs face at the intersection

With the mechanics of cross-border eDiscovery in view, it is worth examining where organizations most frequently go wrong. The failures at the intersection of privacy law and eDiscovery tend to cluster around a handful of recurring patterns.

Treating eDiscovery as a purely procedural exercise

Many legal teams still approach discovery as a litigation function and data protection as a compliance function, with little coordination between the two. This siloed approach means that privacy obligations are considered only after a discovery protocol has already been designed, forcing costly retrofits or creating gaps in legal compliance.

Underestimating the reach of data subject rights

Data subject access requests (DSARs) do not pause because litigation is pending. An individual may submit a DSAR during an active matter, requesting access to or deletion of data that is subject to a litigation hold. General counsel must have a process for managing these competing obligations, including clear guidance on when a hold takes precedence and how to communicate that position to the data subject.

Inadequate vendor due diligence

eDiscovery vendors process significant volumes of personal data on behalf of their clients. Under GDPR and equivalent regimes, this makes them data processors, and the organization remains accountable for their compliance. Failing to conduct proper due diligence on eDiscovery vendors, including reviewing their data processing agreements and security practices, is a compliance failure that regulators increasingly scrutinize.

Late engagement of data protection expertise

Privacy counsel and data protection officers are often brought into a matter after the discovery protocol has been set. By that point, correcting course is significantly more difficult. Early engagement, ideally at the litigation hold stage, allows privacy considerations to be built into the process from the start rather than bolted on at the end.

Build a unified privacy and eDiscovery governance framework

The most effective response to the compliance challenges described above is not a series of ad hoc fixes but a unified governance framework that treats privacy law and eDiscovery as interconnected disciplines from the outset.

A well-designed framework addresses the full lifecycle of a matter, from the moment a litigation hold is triggered to the final release of preserved data. It assigns clear ownership, establishes documented processes, and ensures that both litigation and privacy counsel are engaged at each critical decision point.

Key components of a unified framework include:

  • A data map that is litigation-ready: Knowing where personal data sits, who controls it, and which laws govern it before a matter arises dramatically reduces response time and compliance risk when litigation does occur.
  • Standardized litigation hold procedures with privacy checkpoints: Hold notices should include a privacy review step that identifies the categories of personal data affected and the applicable legal framework before collection begins.
  • Cross-functional governance: Legal, compliance, IT, and privacy functions should operate under a shared protocol for responding to litigation that touches personal data, rather than coordinating informally on a matter-by-matter basis.
  • Vendor management standards: Approved eDiscovery vendors should be pre-vetted for data protection compliance, with data processing agreements in place before any matter requires their engagement.
  • Training for legal and compliance teams: The individuals issuing holds, overseeing collections, and reviewing ESI need a working understanding of both eDiscovery obligations and the privacy principles that constrain them.

For organizations operating across multiple jurisdictions, the framework should also include jurisdiction-specific annexes that address the particular requirements of each relevant data protection regime. A single global protocol will rarely be sufficient on its own.

Building this kind of integrated governance structure takes time and expertise. Organizations that invest in it early find themselves significantly better positioned when litigation arises, both in terms of legal compliance and operational efficiency. Those that do not tend to discover the gap at the worst possible moment.

How Iceberg supports your eDiscovery and privacy legal hiring

The intersection of privacy law and eDiscovery demands professionals who understand both disciplines with genuine depth. Finding those individuals is genuinely difficult. The talent pool is narrow, the role requirements are highly specific, and the cost of a poor hire in a function this consequential is significant.

At Iceberg, we specialize in connecting organizations with elite eDiscovery and legal professionals who bring the precise expertise that matters at this intersection. We work with law firms, in-house legal teams, and legal technology companies across 23 countries to place professionals in roles including:

  • eDiscovery counsel and project managers
  • Data privacy attorneys and DPOs
  • Legal technologists with eDiscovery platform expertise
  • Senior legal appointments requiring cross-functional privacy and litigation knowledge

With a network of over 120,000 candidates and a track record of placing professionals who stay and grow in their roles, we understand what good looks like in this space. Our complimentary Vacancy Health Check is a practical starting point if your organization is struggling to fill a specialist legal or eDiscovery role, offering concrete recommendations rather than generic advice.

If you are ready to find the right legal talent for a complex, high-stakes function, get in touch with our team to discuss your requirements.

Share this post

Related Posts

JOIN OUR NETWORK

Tap Into Our Global Talent Pool

When you partner with Iceberg, you gain access to an unmatched network of 120,000 candidates and 66,000 LinkedIn followers. Our passion for networking allows us to source and place exceptional talent faster than anyone else. Join our community and gain a competitive edge in hiring.
Pin
Pin
Pin
Pin
Pin
Pin