Regulators and courts are cracking down on businesses and their employees’ use of “ephemeral” messaging—e.g., WeChat, Slack, Signal, WhatsApp, Snapchat—to conduct business activities. The SEC and CFTC have levied billions of dollars in fines against financial institutions that failed to preserve ephemeral messaging communications. In 2021, the FTC obtained spoliation sanctions related to the use of Signal communications, and more recently the agency said it may refer cases to DOJ for potential criminal prosecution when documents are not preserved. In January 2024, the FTC and DOJ announced a hard line: Document preservation obligations require preservation of data from ephemeral messaging platforms and a failure to do so will be treated as spoliation or even criminal obstruction of justice. That is unsurprising given DOJ’s view that “ephemeral messaging applications” are “designed to hide evidence.” Indeed, the FTC has said that complying with document preservation obligations may require “stopping use of certain applications altogether.” Moreover, several courts have imposed hefty discovery sanctions in civil litigation, including dismissal of claims, for failing to identify and preserve ephemeral messaging data.
Given this environment, it is self-evident why companies need to mitigate the risks of ephemeral messaging. But that begs the question of how to mitigate, a question this article will attempt to answer, at least in part.
First, though, what is “ephemeral messaging”? Ephemeral messaging generally refers to communications applications that allow for end-to-end encryption, disappearing messages, or short-term auto-delete capabilities. Because auto-deletion is a hallmark feature of these applications, their use makes it all but certain that some data will be destroyed, perhaps without anyone even pressing a “Delete” key. A party may be found to have intentionally spoliated evidence in bad faith simply because employees used ephemeral messaging tools. However, employees at all levels, including C-suite executives and supervisory compliance personnel—including those charged with enforcing firm policies prohibiting the use of “off-channel” communications platforms—continue to use ephemeral messaging both for personal reasons and to engage in business-related activities. The fact that employees may use these platforms for personal use also invites new risk for businesses that rely on “bring your own device” (BYOD) policies.
Facing the risk of stiff civil penalties or even criminal prosecution, what can businesses do to get out in front of the ephemeral messaging enforcement tidal wave?
Assess the Risk. Businesses should assess the scope of ephemeral messaging use within their organizations to better understand the risks. This might take the form of an annual assessment, surveying employees for information on whether they use the applications (in their personal life or for business-related communications) and whether customers have communicated or requested communications on ephemeral messaging platforms. With this assessment, organizations can revisit their policies and procedures and consider new or revised practices.
Evaluate Policies and Procedures. Policies and procedures must be clearly articulated and disseminated across the organization, consistent with practical considerations and the organization’s appetite for risk. For example, an organization could prohibit employees from communicating about business other than by firm email or firm-specified applications or devices, or it could permit use of certain ephemeral platforms under circumstances that are warranted based on business needs and risk profile. If off-channel communications are permitted, the relevant policy should articulate the rationale and justification—DOJ prosecutors, for example, will weigh these explanations in considering how to proceed against a company that has lost relevant data. One specific consideration might be to revisit policies related to business-related communications, including BYOD policies. BYOD policies grew in popularity as firms confronted the significant investment needed to supply employees with mobile devices, but the substantial civil and criminal risks presented by these policies may warrant a second look at the cost of that upfront investment. BYOD policies limit organizational control and oversight, and the organization may not have access to the data at all. Organizations may be stymied, especially in internal investigations, if they need to quickly preserve communications or data located on an uncooperative employee’s personal device. By contrast, if the firm owns the device and controls the software and applications that run on it, there are technological solutions to eliminate these risks. This is particularly important for highly regulated industries, such as financial services, where the relevant statutes and regulations impose clear directives for firms to maintain business-related records and require firms to implement policies to ensure recordkeeping occurs.
Implementation and Training. Policies are important but only a starting point – companies must implement and train employees on the policies. As the settled regulatory actions show, the mere existence of a policy accompanied by rote annual training is unlikely to affect employee conduct or satisfy a firm’s preservation obligations in the eyes of conspiracy-minded regulators. Rather, supervisory personnel and company leadership must foster a culture of compliance by following these policies and enforcing them in meaningful ways. This might include quarterly training sessions and employee attestations, as well as actively monitoring employees’ business communications and doling out appropriate penalties for violations of the policies. Both SEC and DOJ have rewarded firms that proactively identify and punish individuals who violate these policies.
Data Preservation. Organizations must act swiftly to preserve data. A party’s obligation to preserve potential evidence (separate from regulatory requirements) arises when the party knows or should have known that information is relevant to litigation or a government investigation (e.g., upon receipt of a subpoena). But knowing when to preserve is only a first step. The organization must understand its technology and how to counteract features, such as auto-delete functions, that would thwart document preservation. This means specifically providing for the preservation of text messages and ephemeral messages as part of a litigation hold and taking steps to disable any deletion features. It also means continued monitoring for compliance with the hold.
Ephemeral messaging applications are here to stay, and regulators are increasingly aware of potential pitfalls and the leverage that may be gained through company missteps. If businesses are not proactive in understanding how ephemeral messaging affects their organizations and implementing strategies to manage its usage, they may well find themselves in the uncomfortable position of defending their actions before a court or a regulator.
This client update may be reproduced, in whole or in part, with the prior permission of Thompson Hine LLP and acknowledgement of its source and copyright. This publication is intended to inform clients about legal matters of current interest. It is not intended as legal advice. Readers should not act upon the information contained in it without professional counsel.
This document may be considered attorney advertising in some jurisdictions.
© 2024 THOMPSON HINE LLP. ALL RIGHTS RESERVED.
