American discovery is the broadest in the world. Under the Federal Rules of Civil Procedure, electronically stored information has been squarely discoverable since the 2006 amendments, and a party must produce ESI on any nonprivileged matter relevant to a claim or defense. Most of the rest of the world starts from a different premise: disclosure, privacy, and data-protection obligations are generally stricter outside the United States, and when the evidence sits abroad, that difference is not a nuance — it adds an entire layer of legal complexity to the collection itself.
The producing party’s dilemma is structural. A US court can order production of data held overseas; the jurisdiction where the data lives may treat the transfer of personal data beyond its borders as a criminally and administratively punishable act. Counsel who treat cross-border forensic collection as a logistics exercise — send the examiner, image the device, ship the image — discover the conflict at the worst possible moment: after the collection has already happened.
The discipline that works is the reverse. Map the legal layer first, and design the collection so it is lawful in every jurisdiction the data touches.
§ 01 · Why the regimes genuinely conflict
Start with the disclosure rules themselves. The FRCP organizes discovery around relevance. England’s Civil Procedure Rules establish a far narrower scope: under CPR Part 31.6, a party discloses the documents on which it relies and those that adversely affect or support a party’s case — relevance is not the test. Continental civil-law systems narrow disclosure further still and channel international evidence requests through treaty machinery. Misunderstanding runs in both directions: US courts, lawyers, and parties routinely misread non-US law, and the reverse is equally true. For a company operating on both sides, guessing wrong in either direction means exposure to sanctions and fines.
Now layer data protection on top. Under the EU General Data Protection Regulation (Regulation (EU) 2016/679), personal data may be transferred to a third country only through the mechanisms its Chapter V provides — an adequacy decision, appropriate safeguards, or narrow derogations. In Schrems II (Case C-311/18, Data Protection Commissioner v. Facebook Ireland Ltd. and Maximillian Schrems, CJEU July 16, 2020), the Court of Justice invalidated the EU–US Privacy Shield and demanded case-by-case scrutiny of transfers made under standard contractual clauses. And forensic collection is personal-data-intensive by nature: custodian mailboxes, laptops, and handheld devices carry not only the custodian’s personal data but third parties’ — which is exactly what these statutes protect.
§ 02 · The treaty layer and its limits
The Hague Convention of 18 March 1970 on the Taking of Evidence Abroad in Civil or Commercial Matters is the treaty mechanism through which international discovery requests are channeled in much of continental Europe; it regulates the transfer of evidence located abroad through national legal proceedings. But the Convention does not dissolve the conflict for US litigants. In Société Nationale Industrielle Aérospatiale v. United States District Court, 482 U.S. 522 (1987), the Supreme Court held that the Convention is neither the exclusive nor necessarily the first resort: American courts may order discovery of foreign-held evidence directly under the Federal Rules, subject to a comity analysis. The lesson: a producing party can face a US production order on one side and a foreign data-protection or disclosure regime on the other, with no treaty automatically reconciling the two. The reconciliation has to be engineered into the discovery protocol.
The hard part of cross-border collection is not imaging the device. It is making the transfer lawful in every jurisdiction the data touches.
§ 03 · Designing the protocol
The elements of a defensible cross-border protocol are knowable in advance. (1) Map the legal layer before the technical plan: for every data source, identify where the data resides, who the custodians are, which data-protection and disclosure regimes apply, and what mechanism will authorize the transfer. (2) Narrow before anything moves: agree on categories of ESI, date ranges, custodians, and search terms — the scoping discipline international arbitration protocols already demand — so the volume of personal data crossing a border is the minimum the dispute requires. (3) Write the data-privacy obligations into the discovery protocol and the protective order expressly, rather than assuming a US confidentiality order satisfies foreign law. (4) Where feasible, process and review in-country, so only responsive, filtered material is ever transferred. (5) Use the analytical frameworks that exist: The Sedona Conference’s Working Group 6 published its Framework for Analysis of Cross-Border Discovery Conflicts and its International Overview of Discovery, Data Privacy & Disclosure Requirements precisely to help practitioners navigate the competing currents of international data privacy and e-discovery.
§ 04 · What this means for selecting the neutral
Counsel selecting a forensic neutral or special master for a cross-border matter should test the candidate on the legal-authorization layer, not just the laboratory. Can the candidate walk through a GDPR transfer analysis? Explain what changed after Schrems II? Say when the Hague Evidence Convention route is worth its delays, and when the Aérospatiale comity factors will carry the day? A neutral who is technically excellent but blind to that layer can put a matter sideways before the first device is imaged.
Authorization first; collection second. A forensic image acquired in violation of the law of the place it came from is not evidence — it is a liability.
Draws on Daniel's eDiscovery Dispute Resolution (2024) and his cross-border e-discovery writing.