You Don't Need a Regulator to Lose a Case Over Deleted Messages

You Don't Need a Regulator to Lose a Case Over Deleted Messages

On May 26, 2026, Vice Chancellor J. Travis Laster granted spoliation sanctions in In re World Wrestling Entertainment, Inc. Merger Litigation, Consol. C.A. No. 2023-1166-JTL (Del. Ch.), after WWE's controlling stockholder and several senior officers used Signal with short auto-delete timers and let the messages disappear. They had already received litigation hold notices. The Court found the destruction at minimum reckless, found plaintiffs prejudiced, and shifted the burden of proof to defendants by presuming a limited set of facts in plaintiffs' favor, rebuttable only by clear and convincing evidence.

No securities recordkeeping rule appears anywhere in that outcome. No SEC exam, no FINRA cycle exam, no Exchange Act Rule 17a-4. An entertainment company lost control of the evidentiary record in a merger fight because senior people talked on an app that erased itself.

That's the answer to the question executives at non-regulated companies keep asking: if we aren't a bank, why archive employee messages?

The exposure has a different name outside financial services

Broker-dealers and RIAs talk about off-channel communications because the SEC and FINRA made it a line item with a dollar figure attached. Everyone else has the same underlying problem filed under different headings: spoliation, trade secret loss, knowledge transfer, discovery cost.

Laster's reasoning in WWE is worth reading closely, because it generalizes. Burden-shifting matters most when evidence is in equipoise. If the parties who created the evidentiary vacuum are the ones who benefit from it, the incentive structure is broken. So the Court put the consequence on the people who ran the auto-delete timers. Notably, the presumptions reached only the two culpable fiduciaries. Non-spoliating defendants stayed free to rebut at trial, which is a reminder that this lands on individuals, not just entity balance sheets.

For a company with no registration and no examiner, the federal analogue is FRCP 37(e)(2). Courts can impose sanctions, including adverse-inference instructions and default judgment, where electronically stored information that should have been preserved is lost because a party didn't take reasonable steps. That rule doesn't care what industry you're in and it doesn't age the way a sweep does.

A litigation hold is not a preservation system

The Albertsons sanctions are the sharpest available counterexample to the "we have a policy" defense. The company issued litigation holds that specifically reminded custodians to disable auto-delete settings on their phones. It still faced sanctions. Instructions to humans about settings on devices those humans control are not a record, and courts have started saying so.

The direction of travel in recent ESI case law suggests an affirmative duty to understand and police the communication tools employees actually use, not just the ones IT provisioned. Commentators reading these cases point to technical controls: MDM, periodic audits of how people actually communicate, and capture at the source. That's a meaningfully higher bar than a signed acknowledgment in an onboarding packet.

The pressure isn't only from private plaintiffs. On January 26, 2024, DOJ and FTC jointly updated their standard preservation and voluntary access letters to warn that failure to preserve ephemeral messages can lead to civil spoliation sanctions or obstruction charges. In April 2024 the FTC moved on the point directly, accusing senior Amazon executives including Jeff Bezos of using Signal's disappearing messages while an FTC antitrust investigation was underway. The court ordered a Rule 30(b)(6) deposition on the issue, and the matter is set for trial in March 2027. Amazon isn't a broker-dealer.

The IP problem nobody puts in a risk register

Litigation risk is the one that generates headlines. The quieter loss is institutional.

Product roadmap debates, pricing decisions, the reasoning behind an architecture choice, the reason a deal was structured the way it was: these get argued out in iMessage and WhatsApp threads, then summarized into a decision doc that captures the conclusion and none of the reasoning. When the person who made the call leaves and takes their phone with them, what's left is the conclusion without its evidence.

Trade secret protection makes this concrete. Establishing a trade secret claim generally requires showing reasonable measures to keep the information secret. A company that can't produce where sensitive technical information traveled, who received it, or when it left the building has a harder time making that showing. The same gap that hurts you in a preservation fight hurts you in the case where you're the plaintiff.

Customer relationships carry a version of it too. An account manager's two years of texts with a client is the relationship's actual history: what was promised, what was escalated, what the client said they cared about. When that account manager resigns, the CRM has the meeting notes and the chat history is gone. The replacement rebuilds from scratch while the client wonders why they're re-explaining themselves.

What regulated firms figured out first

The finance-sector enforcement record is useful here mainly as a preview. In January 2026 FINRA fined Benjamin F. Edwards & Co. $750,000 after representatives ran at least 3,560 business texts, including customer investment directives, through apps the firm could neither supervise nor preserve. In June 2025, Velox Clearing paid $1.3 million to FINRA and $500,000 to the SEC following a routine cycle exam.

What those matters demonstrate isn't that finance is special. It's that when someone with subpoena power actually goes looking, the gap between "we have a policy prohibiting business use of personal messaging" and "here is the record" turns out to be wide at almost every firm examined. Regulated firms got audited into discovering this. Unregulated ones tend to discover it during their first serious piece of litigation, when opposing counsel asks for the text messages and the answer has to be that they're gone.

The mechanics of the fix are the same either way: capture iMessage, SMS, and WhatsApp from the devices people actually use, into an archive the company controls, with retention set by policy rather than by whoever configured their disappearing-message timer.

Questions worth asking before the hold notice goes out

  • Where do your executives and deal teams actually make decisions? If the honest answer includes a personal-device app, that's the scope.
  • Are auto-delete settings enabled anywhere in the organization? On whose devices, at what interval, and who confirmed it?
  • If a preservation duty attached tomorrow, what would you be able to collect from personal devices, and how long would it take?
  • When someone resigns, what happens to their client-facing message history? Who has to ask them for it, and what's the leverage if they say no?
  • Can you demonstrate reasonable measures to protect confidential technical information that circulates in chat?

None of these require a regulator to become urgent. WWE didn't have one.

What to do with this

The framing that tends to land with executives outside financial services isn't compliance. It's control of your own record. A message archive is the only version of your company's decision-making that survives a resignation, a device wipe, or a litigation hold that somebody quietly ignored.

Firms we work with generally start by mapping which communication channels carry business content, then capturing the ones that carry the most before writing more policy about the rest. Policy first, capture later is the sequence that produced the Albertsons result.

This post discusses litigation and regulatory matters for general informational purposes and isn't legal advice. Preservation obligations turn on facts and jurisdiction, so work through your specific exposure with counsel.