
For general counsel, the relationship between privacy law and eDiscovery has never been more consequential. As data protection regulations tighten across jurisdictions and litigation volumes grow, the tension between an organization’s legal obligation to preserve and produce data and its equally binding obligation to minimize and protect that same data has become one of the defining compliance challenges of 2026.
This guide walks through the core concepts at this intersection, building from foundational principles to practical governance strategies. Whether you are navigating a cross-border dispute or building internal policies for the first time, understanding where these two disciplines meet and where they collide is essential for sound legal leadership.
At its core, the overlap between privacy law and eDiscovery arises from a fundamental tension: litigation requires the preservation and disclosure of data, while data protection law requires that personal data be collected minimally, stored securely, and deleted when no longer necessary.
eDiscovery is the process by which electronically stored information (ESI) is identified, preserved, collected, reviewed, and produced in the context of legal proceedings or regulatory investigations. Privacy law, on the other hand, establishes rights and obligations around how personal data is handled throughout its lifecycle. When litigation touches personal data, both legal frameworks apply simultaneously, and neither yields automatically to the other.
For example, an employment dispute may require a company to produce years of internal communications. Those communications almost certainly contain personal data belonging to employees, third parties, or customers. The company must satisfy its eDiscovery obligations to the court while simultaneously honoring its data protection obligations under applicable law. Navigating both at once is where general counsel earns their seat at the table.
The regulatory landscape directly shapes how eDiscovery must be conducted. Understanding which regulations apply and what they demand is the starting point for any compliant discovery process.
The General Data Protection Regulation remains one of the most consequential frameworks for GDPR eDiscovery. It imposes strict rules on data transfers outside the European Economic Area, requires a lawful basis for processing personal data, and grants individuals rights including access, rectification, and erasure. Each of these principles creates friction with traditional eDiscovery workflows.
For instance, transferring ESI from a European entity to US litigation counsel for review may constitute a cross-border data transfer under GDPR, requiring appropriate safeguards such as Standard Contractual Clauses. Failing to account for this step is one of the most common compliance failures in international litigation.
GDPR is not the only framework in play. General counsel operating across multiple jurisdictions must also account for:
Each of these regimes has its own definitions, lawful bases, and transfer restrictions. A discovery protocol built for US domestic litigation will rarely translate cleanly into a multi-jurisdictional matter.
Building on the regulatory overview above, one of the sharpest practical conflicts between privacy law and eDiscovery emerges around data retention. A litigation hold requires an organization to suspend its normal data deletion schedules to preserve potentially relevant ESI. Privacy law, however, generally prohibits retaining personal data beyond the period necessary for the original purpose.
These two obligations can pull in opposite directions. A routine data deletion that would satisfy a privacy policy may constitute spoliation if a litigation hold was already in place. Conversely, retaining data under a litigation hold beyond its lawful retention period may expose the organization to regulatory sanction.
The conflict becomes particularly acute when the litigation hold is broad or long-running. Consider a regulatory investigation that spans several years: data that would ordinarily have been deleted under a two-year retention schedule must now be preserved indefinitely, creating a growing pool of personal data held without a clear lawful basis under data protection law.
Effective general counsel resolve this tension by:
Cross-border litigation introduces a further layer of complexity. When a matter spans multiple jurisdictions, the legal requirements governing data collection, transfer, and production may conflict not just with each other but with the procedural rules of the forum court.
US federal courts, for example, operate under broad discovery obligations that assume relatively unrestricted access to ESI. European data protection authorities, by contrast, have historically viewed US-style discovery as incompatible with GDPR principles, particularly where it involves bulk transfers of personal data to foreign counsel or courts.
A privacy-compliant approach to cross-border eDiscovery typically involves several practical steps:
Engaging eDiscovery legal specialists who understand both the procedural demands of the forum court and the data protection requirements of the source jurisdiction is often the most effective way to manage this complexity.
With the mechanics of cross-border eDiscovery in view, it is worth examining where organizations most frequently go wrong. The failures at the intersection of privacy law and eDiscovery tend to cluster around a handful of recurring patterns.
Many legal teams still approach discovery as a litigation function and data protection as a compliance function, with little coordination between the two. This siloed approach means that privacy obligations are considered only after a discovery protocol has already been designed, forcing costly retrofits or creating gaps in legal compliance.
Data subject access requests (DSARs) do not pause because litigation is pending. An individual may submit a DSAR during an active matter, requesting access to or deletion of data that is subject to a litigation hold. General counsel must have a process for managing these competing obligations, including clear guidance on when a hold takes precedence and how to communicate that position to the data subject.
eDiscovery vendors process significant volumes of personal data on behalf of their clients. Under GDPR and equivalent regimes, this makes them data processors, and the organization remains accountable for their compliance. Failing to conduct proper due diligence on eDiscovery vendors, including reviewing their data processing agreements and security practices, is a compliance failure that regulators increasingly scrutinize.
Privacy counsel and data protection officers are often brought into a matter after the discovery protocol has been set. By that point, correcting course is significantly more difficult. Early engagement, ideally at the litigation hold stage, allows privacy considerations to be built into the process from the start rather than bolted on at the end.
The most effective response to the compliance challenges described above is not a series of ad hoc fixes but a unified governance framework that treats privacy law and eDiscovery as interconnected disciplines from the outset.
A well-designed framework addresses the full lifecycle of a matter, from the moment a litigation hold is triggered to the final release of preserved data. It assigns clear ownership, establishes documented processes, and ensures that both litigation and privacy counsel are engaged at each critical decision point.
Key components of a unified framework include:
For organizations operating across multiple jurisdictions, the framework should also include jurisdiction-specific annexes that address the particular requirements of each relevant data protection regime. A single global protocol will rarely be sufficient on its own.
Building this kind of integrated governance structure takes time and expertise. Organizations that invest in it early find themselves significantly better positioned when litigation arises, both in terms of legal compliance and operational efficiency. Those that do not tend to discover the gap at the worst possible moment.
The intersection of privacy law and eDiscovery demands professionals who understand both disciplines with genuine depth. Finding those individuals is genuinely difficult. The talent pool is narrow, the role requirements are highly specific, and the cost of a poor hire in a function this consequential is significant.
At Iceberg, we specialize in connecting organizations with elite eDiscovery and legal professionals who bring the precise expertise that matters at this intersection. We work with law firms, in-house legal teams, and legal technology companies across 23 countries to place professionals in roles including:
With a network of over 120,000 candidates and a track record of placing professionals who stay and grow in their roles, we understand what good looks like in this space. Our complimentary Vacancy Health Check is a practical starting point if your organization is struggling to fill a specialist legal or eDiscovery role, offering concrete recommendations rather than generic advice.
If you are ready to find the right legal talent for a complex, high-stakes function, get in touch with our team to discuss your requirements.





