How legal hold works

Legal hold preserves a user's backup data for a legal matter, independently of how that user configures their own backups. It is available on CrashPlan Enterprise plans.

This article explains what a legal hold does to a custodian's devices and data, and what changes when a hold ends. To set one up, follow the three steps in Set up a legal hold below. Legal hold is one part of the wider eDiscovery process, which is covered in the eDiscovery integration guide.

Components of a legal hold

A legal hold is built from three things:

  • A preservation policy defines which files to preserve and how long to keep them.
  • A matter applies one preservation policy to a group of users.
  • A custodian is a user in a matter.

Adding a custodian to a matter creates a new backup set on each of that custodian's devices. The preservation policy controls that backup set, and the custodian cannot see it or change it in the CrashPlan app.

Each matter creates its own backup set. A custodian on three matters has three legal hold backup sets, and each one preserves files according to its own preservation policy.

Set up a legal hold

Setting up a legal hold takes three steps. The Org Legal Admin or Cross Org Legal Admin role is required throughout.

  1. Create a legal hold preservation policy, which defines what to preserve and for how long. One policy can be applied to many matters.
  2. Create a legal hold matter and add custodians, which applies the policy to the users whose data the matter covers.
  3. Collect files from a legal hold when the matter requires the preserved data.

What a legal hold changes on a custodian's devices

Each of the following results from the preservation policy controlling the legal hold backup set instead of the custodian.

  • More files and folders are backed up than the custodian selected, because the preservation policy chooses the selection for the legal hold backup set.
  • The legal hold backup set backs up to every destination the custodian's organization offers, whether or not the custodian selected those destinations for their own backups.
  • Backups can take longer and use more bandwidth, because an additional backup set is running to additional destinations.
  • Version retention follows the preservation policy, whose frequency and version retention settings take precedence while the hold is active.
  • The custodian keeps their current encryption key option and keeps their archive, because archives under preservation stay in place. Changing the encryption key option and deleting an archive are unavailable to them.
  • A file that one matter's policy excludes is still preserved if another matter's policy includes it, because each matter's backup set applies its own policy.

Retention while a custodian is on hold

While a custodian is on legal hold, the preservation policy's frequency and version retention settings take precedence over the settings on that custodian's other backup sets. This is what allows a matter to keep material the custodian's ordinary policy would remove. For example, a preservation policy can keep deleted files indefinitely while the custodian's standard policy purges them after 90 days.

When a custodian is released, their original retention settings resume. Versions kept only because the preservation policy required them become subject to the custodian's ordinary retention again.

This means that ending a hold affects more than the files the hold alone was preserving. For the full effect, see Release custodians and close a matter.

The legal hold lifecycle

  • Adding a custodian to a matter sets their status to Active. A legal hold backup set is created on each of their devices and begins backing up.
  • Releasing a custodian sets their status to Released. The legal hold backup set is removed, and the preserved data remains until the next archive maintenance.
  • Closing a matter releases every custodian in it, with the same effect on each of them.
  • Reactivating a custodian or a matter returns the status to Active. The preserved data is retained if archive maintenance has not yet run. Otherwise the preservation policy's selection is backed up again from scratch.

Releasing a custodian or closing a matter permanently deletes preserved data. Reactivating recovers it only until the next archive maintenance.

Both procedures, and what to check before running them, are covered in Release custodians and close a matter.

What custodians can observe

Custodians are not notified that they are on a legal hold, and the legal hold backup set does not appear in the CrashPlan app. The effects of the hold are still observable:

  • More files and folders appear in the backup selection.
  • Backups use more bandwidth, and the custodian's own backup sets can progress more slowly.
  • Files backed up by a legal hold backup set are available in the custodian's own restore view in the CrashPlan app, even though the set itself is not shown.
  • After a release, files that were preserved only by the hold leave that restore view once archive maintenance runs.

Help desk staff receiving a report of slower backups, an expanded selection, or an unavailable encryption key upgrade can check whether the user is a custodian on an active matter.

Custodians and user accounts

A legal hold preserves data for an active user, so a custodian remains an active user for as long as the matter is open. Attempting to deactivate a custodian reports that the user is on legal hold and blocks the user instead. The deactivation is retained and completes on its own once the user is released from every matter, whether it came from the CrashPlan console or from a provisioning provider. A hold therefore cannot be lost by deactivating someone covered by it.

Blocking a user prevents them from signing in to the CrashPlan app and the console. Their archives are unchanged and their devices continue to back up, so blocking removes access without affecting preservation. See Block, deauthorize, and deactivate users and devices.

Because custodians remain active users with active devices, each one continues to consume a user subscription for as long as the matter is open. This includes blocked custodians and people who have left the organization. See User subscriptions for CrashPlan.

A user who was deactivated before the matter existed cannot be added as a custodian. Deactivating a user moves their archives to cold storage, and reactivating the user moves any unexpired archives back so their data can be preserved. Archives that pass the organization's cold storage retention period are permanently deleted and cannot be placed on legal hold.

Before you rely on a legal hold

Three conditions determine whether a hold will preserve and deliver what a matter needs. Check them before adding custodians.

  • Custodians must be active users. Only active users can be added to a matter, and a custodian stays active for as long as the matter is open. See Custodians and user accounts.
  • Collection is unavailable for custodians using an advanced encryption key option. Administrators cannot access data protected by an Archive key password or Custom key, so a custodian using either has their data preserved but cannot have files collected through the console. Organizations with Compliance Settings activated require these options, so their users are affected as well.
  • Moving a custodian between organizations affects their archives later. Archives on destinations the new organization does not offer remain available for as long as the custodian is on hold. They move to cold storage when the custodian is released or the matter is closed, and are then retained for the organization's cold storage period.

Global exclusions apply to every preservation policy, so files matching them are not preserved. See Best practices for legal hold file selections and exclusions.

More about legal hold

Was this article helpful?
0 out of 0 found this helpful