The first question is not what happened, it is which record would show it
An attorney who arrives at an online advertising expert witness usually arrives with a business problem, not a data problem: money was spent, results were promised, something went wrong, and nobody on the file can read the reports. The productive first move is not to argue about the numbers. It is to identify the channel, because that decides three things governing all that follows — what record exists, who holds it, how long it survives.
The channels behave differently. In paid search the advertiser sees almost everything in aggregate and almost nothing per click after ninety days. In display and programmatic the record is fragmented across six intermediaries and no single party holds it end to end. In paid social the advertiser's own export is close to complete while the public archive is nearly useless for commercial ads. In affiliate marketing the decisive artifact is a click log the network holds and rarely surfaces. In email, the metric most people reach for stopped meaning what they think it means in 2021. In e-commerce, four systems count the same order four ways.
A dispute described as being about "digital advertising" is not yet described. A useful description names the channel, the period, the party that held the account, and the representation or obligation said to have been breached. From there the evidence question becomes tractable.
Who holds it: four routes, and one of them is nowhere
Advertising evidence comes by one of four routes, and knowing which applies before a request is drafted saves motion practice.
Party production. The advertiser's own account exports, its agency's reporting, web server logs, order and payment records, contracts and internal correspondence. This is the bulk of what a case runs on. Where an agency ran the account, the account and its history are usually reachable by a Rule 34 request or a contract audit right — and access to the account is often worth more than the reports the agency chose to send.
A platform's self-service export. Google Ads, Google Analytics, Search Console, Meta Ads Manager and Amazon Ads all generate exports from within the account, without process, by anyone with credentials. Because the account holder generates them, they are the fastest route to the underlying data and the one most often overlooked while a subpoena is being negotiated.
Third-party process. A subpoena to a platform, network, demand-side platform or verification vendor. Slow, contested and of uncertain scope: the Stored Communications Act restricts what a provider may divulge about the contents of communications, and courts have divided on its reach over non-content business records. Plan on the party's own export as the primary route, with process reserved for what the account structurally cannot show.
Nowhere. Some questions have no record. A competitor's spend on ordinary commercial advertising is not public. An impression the advertiser did not itself log has no advertiser-side artifact. A search term below a volume threshold was never reported and cannot be recovered. Identifying this fourth category early is worth more to counsel than any analysis of the first three.
The retention clocks, in one place
Most of this evidence is deleted on schedules the advertiser cannot pause, whether or not litigation is pending. In rough order of urgency:
- Click-level data (Google Ads
click_view, keyed on the GCLID): requestable back 90 days, one day at a time. Nothing restores it. - Google Ads change history: two years in the interface; the API's
change_eventresource, 30 days. - Google Ads filtered-click reporting: the invalid clicks column in the campaigns table covers roughly the last 60 days.
- Google Analytics 4: user-level and event-level retention is settable to 2 or 14 months on the free product, with 26, 38 and 50 months on the paid tier, and expired data "is deleted automatically on a monthly basis." Google signals data is capped at 26 months regardless.
- Search Console: 16 months, rolling.
- Meta Ads Insights API: since 12 January 2026, 37 months for aggregate totals, 13 for unique-count and hourly breakdowns, 6 for frequency breakdowns.
- Amazon Ads Reporting API: requests may reach back 95 days but data is returned for roughly the last 65, in windows of 31 days at most.
- Amazon Marketing Cloud: a 25-month ad traffic lookback since November 2025, up from 13 — and an expansion does not resurrect data that already aged out.
Set against a dispute surfacing months after the conduct, most of the granular record is gone before counsel is retained. That is not a merits finding in anyone's favor. It is a fact about the infrastructure, and it cuts equally against both sides.
A litigation hold here is an export protocol, not an instruction not to delete
Preservation here is unusual, and the ordinary instinct is wrong. Rule 37(e) asks whether a party failed to take reasonable steps to preserve electronically stored information, and it was drafted against an assumption that a custodian can stop deletion. Here the custodian cannot. Nothing in Google Analytics, Google Ads, Search Console, Meta Ads Manager or Amazon Ads exposes a control that suspends retention. The only act within a party's power is copying the data out before it expires.
So a hold here is a protocol. Export every ad account at the finest granularity still offered, dated. Pull click-level data immediately. Capture change history from the interface rather than the API, because that window is two years against thirty days. Raise analytics retention to the licensed maximum and enable the durable export — it will not backfill, so it preserves everything from that day forward and nothing before. Suspend the destructive changes a party does control: data-deletion requests, property deletion, account cancellation, and changes to the retention setting itself, each of which is logged. And record, for every extract, the account identifier, the query or interface path, the date range, the attribution setting, the reporting identity, the time zone, the currency and the moment of extraction.
Brown v. Tellermate Holdings, No. 2:11-cv-1122 (S.D. Ohio, 1 July 2014), is the closest analogy. A party asserted it did not control data held in a third-party hosted sales database; the magistrate judge rejected that, finding that employees with credentials could retrieve it, that nothing was done to preserve it after a preservation letter, and that counsel never asked the vendor about its backup retention. Sanctions were preclusion and fee-shifting, not default. It is one magistrate judge's decision, persuasive and binding nowhere, and it is the right frame because the failure it punishes is a failure to copy out rather than a failure to refrain from deleting.
Whether the number in the interface was counted or estimated
An expert asked on the stand where a figure came from should be able to say whether it was counted or estimated. Across large parts of these interfaces, the platform does not break that out.
Google states that modeled conversions "use data that doesn't identify individual users to estimate conversions that Google is unable to observe directly," that modeled and observed conversions appear in the same Conversions column, and that the modeling "determines whether a Google ad interaction led to the online conversion. It doesn't determine whether or not a conversion happened." Meta told developers in January 2021 that "statistical modeling will be used for certain attribution windows and/or metrics." Google Analytics models the conduct of users who declined analytics cookies from the conduct of those who accepted, subject to eligibility thresholds — a property below them simply has a gap.
None of that is an observation of a person doing a thing. These are outputs of proprietary models, produced by the party whose delivery is being measured, from inputs unavailable for inspection. An expert cannot validate or reproduce them. What an expert can do is identify where modeling is present — the data-quality indicator, the modeling effective date, the irreconcilability between a standard report and the raw event export, which excludes modeled data — and quantify the gap rather than smooth it.
The same discipline applies generally: a platform-reported number is the seller's report of its own delivery. It may still be the best evidence available, but it is not an independent measurement.
The rebuttal posture, which is more common than the literature suggests
A substantial share of the work in this field is not building an affirmative case. It is reading a report that already exists and looks wrong, and saying precisely where and why. That engagement has a different shape and should be scoped as one.
The recurring defects are specific and checkable. A time series drawn across a reporting-policy change, so that the chart measures the platform's disclosure rules rather than the advertiser's conduct — Google's search terms restrictions of 2020 to 2022 and Meta's January 2021 attribution change both produce this. A conversion figure treated as counted when the platform's documentation says it is partly estimated. A filtered-click number offered as a fraud measurement. An industry-wide waste percentage applied to one account, substituting aggregate prevalence for individual causation. Two non-reconciling extracts treated as evidence of bad faith when the platforms' own documentation predicts the discrepancy. A viewability rate quoted without saying which standard produced it.
A rebuttal report that does that work well is narrow and unglamorous. It need not establish an alternative theory of the case and should resist the temptation to try. Its function is to identify where the opposing analysis outruns its own evidence, using the platforms' documentation as the authority — which is usually more persuasive than a competing opinion, because it is not an opinion.
What none of this record establishes
An advertising expert witness who says every question is answerable is the expert the other side wants on the stand. Four limits belong in any engagement, either side of the caption.
Delivery is not receipt, receipt is not perception, and perception is not persuasion. An impression log shows a server responded. A viewable impression shows pixels occupied a viewport for a defined interval. Neither shows a human looked, and no record described here shows anyone was persuaded to do anything.
Absence of data is not absence of the event. Given the windows above, the ordinary case is that the granular record was deleted by the platform on schedule before anyone looked. "It could not be found" and "it did not happen" are different statements, and a report conflating them can be impeached with the platform's own documentation.
Records establish sequence, not cause. Every record described here is observational. Establishing that a campaign caused a business outcome requires an experimental design that, in the ordinary commercial case, nobody ran — which is why the causation question and the measurement question have to be separated early, and why a damages model built on platform-reported conversions inherits every uncertainty above.
No advertising record identifies a natural person. A user in these systems is a platform-defined construct, and the same activity yields materially different user counts under settings a party can toggle at will. An IP address is not a person, a device fingerprint is probabilistic, and cross-device gaps are structural.
Naming those limits first is not a concession. It is the reason the rest of the analysis is worth anything.
Frequently Asked Questions
The campaign ran across search, social and display at once. Which channel is the dispute in?
Ask which representation or obligation is said to have been breached, and then follow it to the record that would show it. A promise about cost per acquisition points at conversion tracking and attribution settings. An allegation of wasted spend on worthless inventory points at programmatic log-level data and placement reports. A claim about competitor conduct points at search terms and click-level data. A cross-channel budget dispute usually resolves into a billing and change-history question. Most matters described as cross-channel turn on one or two records, and identifying them narrows discovery substantially.What should be exported first when an advertising dispute is anticipated?
Click-level data, because Google'sclick_view resource reaches back only 90 days and nothing restores it. Then account change history from the platform interface rather than the API, since the interface window is far wider. Then a full export of every ad account at the finest granularity still available, the web server logs for the landing pages, and analytics explorations that will be relied on before the retention window rolls. Raise analytics retention to the licensed maximum and enable the durable warehouse export immediately, understanding it preserves data from that day forward and does not backfill.Can a platform be ordered to preserve advertising data?
A litigation hold binds parties, not Google or Meta. None of these platforms exposes a control that suspends retention, and their deletion runs on published schedules regardless of whether litigation is pending. Rule 37(e) asks whether a party failed to take reasonable steps to preserve; here the only reasonable step available is early export. That is why the failure that gets sanctioned in this area is a failure to copy the data out, and why a preservation letter that says nothing more than "do not delete" accomplishes very little on this material.Is a platform's own performance report an independent measurement?
No. It is the seller's report of its own delivery, produced under definitions the seller chose and can change. Meta published corrections in November and December 2016 disclosing that several of its metrics had been materially misstated for months. Google reports modeled and observed conversions in the same column without breaking them out. None of that establishes that any particular number is wrong — but it means the figure should be characterized in a report as a party's claim about its own product, with its definition, its date and its known limitations stated, rather than as a measurement.The granular data has already expired. Is there anything left to do?
Often, yes. Aggregate campaign and keyword statistics generally survive far longer than the forensic layers, billing records and invoices are retained on ordinary business-record schedules, and change history reaches back two years in the interface. Agency-side reporting, warehouse copies, scheduled email reports, screenshots taken contemporaneously and exports made for other purposes frequently preserve what the platform no longer holds — as secondary artifacts requiring authentication. The web server logs and order records on the advertiser's own systems are also unaffected by platform retention. What the expert must then do is state plainly which questions the surviving record can and cannot reach.When is a rebuttal engagement the right one?
When a report already exists and the defects are in its use of the evidence rather than in its conclusions. The recurring ones are checkable against platform documentation: a time series drawn across a reporting-policy change; modeled figures treated as counted; a filtered-click number offered as a fraud measurement; an industry-wide loss percentage applied to one account; two non-reconciling extracts presented as evidence of bad faith. A rebuttal of that kind is narrow by design and does not require an alternative theory of the case, which usually makes it faster and less expensive than an affirmative report.Published