
eDiscovery document review is the stage where people, sometimes aided by software, read the collected email, chat and files and decide what is responsive, what is privileged and what must be redacted before production. Done well, it produces a defensible set of documents, a privilege log that holds up, and a clear record of how decisions were made.
This guide explains how a review is organized, from first-level review through privilege review and quality control, and what the federal rules say about privilege logs, clawbacks and FRE 502(d) orders. If you need a workspace and reviewers now, our document review and secure hosting team hosts data and staffs counsel-directed review as part of our eDiscovery and litigation support practice.
Key takeaways
- A typical review runs in layers: first-level coding, second-level and privilege review, then quality control before production.
- A written review protocol approved by counsel is the single best control on consistency and cost.
- FRCP 26(b)(5)(A) requires withheld documents to be described well enough for the other side to assess the privilege claim.
- As amended effective December 1, 2025, Rule 26(f)(3)(D) asks parties to plan privilege log timing and method at the start of the case.
- A FRE 502(d) order limits the damage of an inadvertent production, but it does not replace a careful privilege review.
Where this guidance comes from. This article draws on the text and committee notes of Federal Rules of Civil Procedure 16, 26, 34 and 45 and Federal Rule of Evidence 502, the EDRM model’s description of review and production, and the Rio Tinto v. Vale opinion on technology-assisted review. We add the practical lessons our veteran-led forensics and litigation support team applies when we host data and support review for counsel. This is general information, not legal advice; confirm specifics with counsel.
What eDiscovery document review covers
The EDRM model, a widely used reference framework, describes review as evaluating documents for relevance, responsiveness, privilege, confidentiality, privacy and issue significance. Production is the next step: delivering documents in agreed, defensible or appropriate formats. EDRM stresses that its model is a conceptual view, not a literal or linear workflow, and in practice review often loops back to collection when new custodians or date ranges emerge.
Review sits after preservation, collection and processing. If those earlier steps are sloppy, review inherits the problems. Our guide to forensic data preservation and legal holds covers the front end, and our explainer on eDiscovery vs digital forensics shows where forensic work ends and review begins.
How an eDiscovery document review is organized
Most reviews follow the same sequence, even if the names vary by team.
- Process and cull. Collected data is processed, deduplicated and filtered by custodian, date range and agreed search terms so reviewers see less noise.
- Write and approve the protocol. Counsel sets definitions for responsiveness, privilege, confidentiality and issue tags, with examples and an escalation path.
- First-level review. Reviewers code each document under the protocol.
- Second-level and privilege review. More experienced reviewers check escalations and every document flagged as potentially privileged.
- Quality control. Samples and targeted searches check coding consistency before anything leaves the building.
- Produce and log. Responsive, non-privileged documents are produced in the agreed form, and withheld documents go on the privilege log.
- Close out. Final exports are reconciled and the workspace is archived or deleted as counsel directs.
First-level review
First-level reviewers work through batches of documents and apply tags: responsive or not, key issues, confidentiality level and a flag for anything that looks privileged. Their job is consistency; close calls go up the escalation path.
Batching by email thread or near-duplicate cluster lets a reviewer code related material together, which reduces conflicting calls on the same conversation.
Second-level and privilege review
Second-level reviewers handle escalations and recheck the documents most likely to cause trouble: anything flagged privileged, highly confidential or central to the case. For each potentially privileged document they confirm the basis, decide whether to withhold it entirely, redact part of it or produce it, and capture the details the privilege log will need.
Common privilege traps include email chains where one message is privileged and the rest are not, attachments to privileged emails, communications that include third parties, and in-house counsel acting in a business rather than legal role. These are counsel’s calls, and the protocol should say when to escalate them.
Quality control
Quality control catches errors before they become productions. Typical checks include sampling first-level coding, searching responsive sets for attorney names and law firm domains that should have been flagged, comparing coding across near-duplicates and thread members, and confirming that redactions were burned in on the production images.
QC results should feed back into the protocol: if one tag keeps producing errors, the fix is clearer guidance and targeted re-review.
Writing an eDiscovery document review protocol
The review protocol is the instruction manual for every reviewer. A vague protocol produces inconsistent coding, more QC rework and weaker privilege logs. A strong one usually covers:
- Case background and the requests or subpoena being answered.
- Responsiveness definitions with concrete examples of what is in and out.
- Privilege and work-product guidance, including a list of attorneys, firms and domains.
- Confidentiality tiers that match the protective order.
- Issue tags tied to the claims and defenses.
- Redaction categories, such as personal data or trade secrets.
- How to handle families, threads, foreign language and unreadable files.
- The escalation path and turnaround expectations.
Need a review team that works from your protocol? We host the data, staff licensed attorney reviewers under counsel’s direction and run privilege QC. Request document review online with your data volume and deadline, or book a consultation online to talk through scope.
Privilege logs under FRCP 26(b)(5)
Federal Rule of Civil Procedure 26(b)(5)(A) says that when a party withholds otherwise discoverable information as privileged or as trial-preparation material, it must expressly make the claim and describe the nature of what is withheld in a manner that, without revealing the privileged information, will enable other parties to assess the claim. That description is what practitioners call the privilege log.
The rule does not dictate a single format. The 1993 committee note says details like time, persons and general subject matter may fit when only a few items are withheld, but may be unduly burdensome when voluminous documents are withheld, particularly if the items can be described by categories. Subpoena recipients face a parallel duty under Rule 45(e)(2).
The rules changed effective December 1, 2025. Rule 26(f)(3)(D) now asks the parties to address the timing and method for complying with Rule 26(b)(5)(A) in their discovery plan, and Rule 16(b)(3)(B)(iv) lets the court put that in the scheduling order. The 2025 committee note warns that compliance can involve very large burdens, that no one-size-fits-all approach works, and that a privilege log produced near the close of discovery can create serious problems. It suggests rolling logs instead.
For reviewers, the lesson is to capture log fields during privilege review, not after.
Clawbacks and FRE 502(d) orders
Even careful reviews miss things. Rule 26(b)(5)(B) gives a clawback procedure: a party that produced privileged information may notify the receiving party, which must then promptly return, sequester or destroy it, must not use it until the claim is resolved, and may present it to the court under seal.
Federal Rule of Evidence 502(b) says an inadvertent disclosure in a federal proceeding is not a waiver if the holder took reasonable steps to prevent it and promptly took reasonable steps to fix it. Your QC records are part of the evidence that reasonable steps were taken.
Rule 502(d) goes further. A federal court may order that privilege is not waived by disclosure connected with the litigation, and that order also controls in any other federal or state proceeding. Under 502(e), an agreement between the parties binds only them unless a court order incorporates it. The advisory committee’s 2007 explanatory note says the rule responds to complaints that the cost of protecting against waiver had become prohibitive, a concern it called especially troubling in electronic discovery.
Whether to seek a 502(d) order is counsel’s decision. It reduces the risk of a mistake but does not remove the need for privilege review, because a clawed-back document has still been seen by the other side.
Technology-assisted review basics
Technology-assisted review, or TAR, uses machine learning to rank documents by likely responsiveness based on coding decisions made by experienced reviewers. Reviewers then focus on the highest-ranked documents, and the team uses statistical sampling to judge when enough of the responsive material has been found.
Courts accept it. In Rio Tinto v. Vale (S.D.N.Y. 2015), the court wrote that it is now black letter law that where the producing party wants to use TAR for document review, courts will permit it, and that it is inappropriate to hold TAR to a higher standard than keywords or manual review. The opinion traced that development to the Da Silva Moore decision three years earlier.
TAR is not automatic savings. It works best on large, text-rich sets and needs a plan for training, disclosure to the other side if required, and validation. Privileged documents still need human review. No honest provider promises a fixed accuracy rate in advance.
What drives eDiscovery document review cost
The right budget depends on your data, so here is what moves it. Rule 26(b)(1) frames discovery around proportionality, weighing burden and expense against likely benefit, and the same factors shape a review budget.
| Cost driver | Why it matters | How to keep it in check |
|---|---|---|
| Volume that reaches review | Hosting and reviewer hours both scale with documents in the workspace | Cull by custodian, date range and deduplication before loading for review |
| Quality of the review protocol | Vague definitions cause inconsistent coding and rework in QC | Written definitions, examples and an escalation path approved by counsel |
| Privilege density | Privilege review and logging take more senior time per document | Identify attorney names and law firm domains early; agree on log format at the Rule 26(f) conference |
| Redactions | Each redaction must be applied, checked and logged | Define redaction categories up front and batch similar documents |
| Deadline pressure | Compressed schedules mean more reviewers and more QC | Negotiate rolling productions and a realistic schedule early |
| Analytics or TAR | Design, tool use and validation are separate work | Decide early whether TAR fits and how it will be validated |
| Matter closeout | Data left in an active workspace keeps accruing hosting charges | Plan the final export and documented deletion or archive |
Forum matters too. Arizona and other state courts have their own disclosure rules that differ in detail from the federal rules, so confirm the governing requirements with counsel before you set the review plan.
How to choose an eDiscovery document review provider
- Who performs attorney review, and are reviewers licensed attorneys with conflicts checks done before they see data?
- Will the provider follow your written protocol and escalate close calls instead of deciding them?
- How are QC sampling and error rates reported to counsel?
- Can the platform produce in the form required by your ESI agreement or by Rule 34, and build privilege log exports from review coding?
- How are user roles controlled when co-counsel, experts or clients need access?
- What happens at closeout, and will you receive written confirmation of return or deletion?
For examples of the data types that often end up in review, see our pages on Slack and Teams message forensics and corporate email investigation.
How Honeybadger supports eDiscovery document review
Honeybadger Solutions is a veteran-led, service-disabled veteran-owned small business based in Casa Grande, Arizona, delivering litigation support nationwide. Our document review service keeps one rule front and center: attorney review is performed by licensed attorneys, and legal calls on responsiveness, privilege and redaction stay with the counsel who represents the client.
- Managed review hosting. A secure workspace with search, tagging, saved searches and self-service exports, with five named users included. A premium review environment is available for larger or more complex matters.
- ECA staging and archive tiers. Cull and size data before review, or park a dormant matter in an inactive archive.
- First-level attorney review. Licensed attorneys code under a protocol approved by counsel, after staffing and conflicts checks.
- Senior review and privilege QC. Experienced reviewers check privilege calls, escalations and QC samples.
- Privilege logs, redactions and closeout. We build privilege log exports, apply redactions counsel approves, reconcile counts and document the return or deletion of all data.
- Analytics and TAR. Quoted separately, designed with counsel, with validation results reported as they are.
If preservation is not yet in place, our legal hold and data mapping service handles hold notices, custodian interviews and data mapping before review begins. Tell us the data volume, the deadline and how many people need access, and request service online or book a consultation with the buttons below.
Why the online intake is faster than a phone call. The request takes about two minutes. Picking the service routes it straight to the specialist team that handles that type of case, so there is no phone tag and no waiting for a call-back to explain it all again. For anything happening right now, use the urgent intake form.
Frequently asked questions
What is the difference between first-level review and privilege review?
First-level review codes each document for responsiveness, key issues and possible privilege under the review protocol. Privilege review is a second, more experienced pass over documents flagged as potentially privileged, where reviewers confirm the call, choose withhold, redact or produce, and capture the information needed for the privilege log.
What does FRCP 26(b)(5) require for a privilege log?
Rule 26(b)(5)(A) requires a party withholding otherwise discoverable information as privileged to expressly make the claim and describe what is withheld in a way that lets other parties assess the claim without revealing the privileged content. The rule does not prescribe one log format, and the 1993 committee note recognizes that voluminous items may be described by categories.
What is a FRE 502(d) order and why do reviewers care?
Federal Rule of Evidence 502(d) lets a federal court order that privilege is not waived by disclosure connected with the case, and that protection carries into other federal and state proceedings. It lowers the stakes of an inadvertent production but does not replace privilege review.
Is technology-assisted review accepted by courts?
In Rio Tinto v. Vale (S.D.N.Y. 2015), the court wrote that it is now black letter law that courts will permit a producing party to use TAR, and that TAR should not be held to a higher standard than keywords or manual review.
What drives the cost of eDiscovery document review?
The biggest drivers are the volume of data that reaches reviewers, how well it was culled first, the share of documents needing privilege review or redaction, the clarity of the review protocol, and the deadline. Hosting volume and user seats also matter.
Who makes the final privilege calls in an outsourced review?
Counsel does. A review provider can host data, staff reviewers under counsel’s protocol, run quality control and build the privilege log export, but the attorney of record decides what is privileged, approves redactions and signs off on the log before it is served.
Sources and further reading
- Federal Rule of Civil Procedure 26 (LII) — privilege logs, clawbacks, proportionality and the 2025 amendment notes.
- Federal Rule of Civil Procedure 16 (LII) — scheduling orders addressing privilege log timing and FRE 502.
- Federal Rule of Civil Procedure 34 (LII) — form of producing electronically stored information.
- Federal Rule of Civil Procedure 45 (LII) — privilege claims by subpoena recipients.
- Federal Rule of Evidence 502 and explanatory note (LII) — inadvertent disclosure, 502(d) orders and review cost.
- U.S. Courts: Federal Rules of Civil Procedure — official current rules.
- EDRM Model — definitions of review and production.
- Rio Tinto plc v. Vale S.A., 306 F.R.D. 125 (S.D.N.Y. 2015) — court acceptance of TAR.
Written and reviewed by the Honeybadger Solutions security and investigations team, a veteran-led Arizona firm (Arizona DPS private investigation agency license No. 1759795). Facts checked against the cited sources on October 2, 2026. This article is general information, not legal advice.
Browse by topic
Security guard services  · Private investigations  · Cybersecurity  · Digital forensics  · Financial fraud investigation  · Executive protection  · All articles