Ferron v. Search Cactus, L.L.C., No. 2:07-cv-327, 2008 WL 1902499 (S.D. Ohio Apr. 28, 2008)

Facts

  • John W. Ferron sued Search Cactus, L.L.C. under the Ohio Consumer Sales Practices Act (OCSPA), alleging deceptive email advertisements offering “free products” without adequate disclosure of conditions.
  • Central factual disputes included which emails Ferron received, whether the emails were unsolicited (a predicate for his OCSPA theory), and how Ferron interacted with defendants’ websites.
  • Defendants sought access to Ferron’s home and office computers to examine electronically stored information (ESI) showing email receipt and browsing activity; the computers were described as the only available documentary source for this evidence.
  • Relevant ESI was commingled on the same systems with Ferron’s personal financial information and attorney-client privileged client files.
  • The court had previously determined that inspection of Ferron’s hard drives was appropriate and directed the parties to develop an inspection protocol.
  • The parties could not agree on a protocol, citing risks of inadvertent destruction/omission of relevant data and inadvertent disclosure of confidential or privileged information.
  • The court noted indications Ferron had not satisfied his duty to preserve relevant ESI and had not otherwise produced the information sought.

Issues

  1. Under what conditions may a court order forensic inspection of a civil plaintiff’s computer systems where the systems contain unique, central ESI not otherwise produced?
  2. How should the court structure an inspection protocol to obtain relevant ESI while protecting confidential personal information and attorney-client privileged materials stored on the same drives?
  3. What role does an apparent failure to preserve ESI play in authorizing and shaping intrusive computer discovery?

Decision

  • The court ordered a forensic inspection of Ferron’s computer systems and imposed a detailed, staged protocol after the parties failed to agree on one.
  • The court permitted defendants’ forensic expert to access and mirror-image Ferron’s hard drives because the computers contained uniquely probative evidence and Ferron had not adequately preserved or produced it through ordinary discovery.
  • The court required procedures intended to reduce unnecessary exposure of Ferron’s confidential personal information while still allowing defendants meaningful access to relevant ESI.
  • The court directed the following protocol:
    • Plaintiff’s forensic expert was to mirror-image both systems’ hard drives and preserve the mirror images.
    • Plaintiff’s expert was to remove only Ferron’s confidential personal information from the preserved mirror images and disclose the removal protocol used.
    • Ferron was to provide defendants’ forensic expert access to the hard drives for defendants’ own mirror imaging.
    • Defendants’ imaging was expected to take approximately four to eight hours per system, with reasonable additional time if necessary.
  • Courts may order forensic inspection of a party’s computer systems when relevant ESI is uniquely located on those systems and cannot be reliably obtained through standard production.
  • A party’s apparent failure to preserve ESI in pending or reasonably anticipated litigation supports more direct and intrusive discovery measures to secure evidence.
  • When discoverable ESI is commingled with nondiscoverable confidential or privileged material, courts may manage discovery through staged imaging and filtering procedures designed to limit exposure while preserving evidence.
  • If parties cannot agree on an ESI inspection protocol, a court has discretion to impose technical, step-by-step procedures (including expert roles, deadlines, and imaging parameters) to balance relevance, preservation needs, and confidentiality.

Conclusion

The court compelled a structured forensic inspection of the plaintiff’s computers because the devices contained the only documentary evidence on key disputed facts and the plaintiff had not adequately preserved or produced the ESI, while using a staged protocol to reduce disclosure of confidential personal information and manage privilege concerns.