← Back to Blogs & Insights

Mobile devices can contain some of the most relevant evidence in a modern case: SMS and MMS, iMessage, WhatsApp, Signal, Teams, Slack, email, photos, videos, browser activity, application data, location artifacts and cloud-synchronized content. They can also contain deeply personal information that has nothing to do with the matter. That tension makes collection scope one of the most important decisions in mobile eDiscovery.

Full-device collection

A broad forensic acquisition is appropriate when the investigative question cannot be answered reliably through a narrow collection, when deleted or system-level artifacts are relevant, or when the device itself is a primary evidence source. Depending on the device, operating system, security state and forensic tool, the available acquisition may be logical, file-system, full file-system or another supported method.

Full acquisition can provide valuable context, but it can also increase privacy exposure and review volume. Counsel and the forensic examiner should understand why the broader scope is necessary and how irrelevant personal information will be protected.

Targeted collection

For many civil matters, the requirement may be narrower: collect messages with specific participants, content from defined applications, a date range, selected photos, or a combination of relevant sources. A targeted workflow can reduce unnecessary collection while still preserving the communications needed for review.

Targeting should not be confused with simply taking screenshots or asking the custodian to forward selected messages. A defensible targeted collection should use repeatable tools and document the device, collection date, selected sources, filters, export format and validation results.

Conversation data should remain conversational

SMS, MMS and chat applications are not ordinary documents. Converting relevant conversations to a review format such as RSMF can preserve participants, timestamps, message order and supported attachments in a form designed for modern review platforms. Relativity supports RSMF workflows for multiple short-message sources, including mobile data processed from supported Cellebrite UFDR packages.

Key scoping questions

  • Which applications and account identities are relevant?
  • Are deleted messages or device-level artifacts potentially important?
  • What date range is proportional to the matter?
  • Are specific participants or conversations known?
  • Does the review platform need native exports, reports, RSMF, or a combination?
  • How will personal and privileged information be minimized or segregated?

Practical takeaway

The best collection is not automatically the largest collection. The defensible approach is the collection method that is technically sufficient for the investigative questions, documented well enough to be explained later, and appropriately scoped for privacy and proportionality. Digital Shield can perform both broad forensic acquisitions and targeted mobile collections depending on the needs of the matter.

Digital Shield collection support: We assist law firms, corporations, government agencies and investigative teams with remote and onsite collections, forensic preservation, cloud data, mobile devices, collaboration platforms, custom conversions and litigation-ready reporting.

Technical references

Platform capabilities and interfaces change. These official resources provide current technical context for the topics discussed above.

NIST: Digital Evidence PreservationRelativity: Cellebrite short message conversionRelativity Short Message Format