
Government Investigations: Public Records Acts and Government-Issued Phones
When a government investigation involves mobile communications, data security compliance becomes the central challenge for agencies trying to fulfill their legal obligations without exposing sensitive information. Text messages, once considered informal and fleeting, now sit at the heart of public records law, FOIA disputes, and accountability debates nationwide.
Data Security Compliance: What Counts as a Public Record on Your Phone?
The short answer is: more than most people expect. Under both federal and state law, a communication qualifies as a public record based on its content, not the device it lives on. If a government employee uses a personal mobile phone to discuss official business, those texts are still subject to disclosure. Courts across the country have consistently upheld this standard.

Here is what typically determines whether a message qualifies as a public record:
Content and purpose. Messages tied to official government functions, decisions, or transactions are public records.
Device ownership is irrelevant. Personal phones used for public business are still subject to records laws.
Custodial responsibility. State law often designates employees who retain public information on personal devices as "temporary custodians."
Scope of employment: A message qualifies if the employee created it within the scope of their official role.
How FOIA and State Records Acts Apply to Text Messages
Fulfilling a public records request for text messages is not as simple as forwarding a thread.
At the federal level, the Freedom of Information Act and the Federal Records Act require agencies to preserve and produce communications related to official business, including mobile messages. At the state level, Sunshine Laws, Open Records Acts, and Public Information Acts fill in the gaps, and timelines can be tight. Some states require responses within just five business days.
The legal obligation breaks down into three core actions:
Preservation. Messages must be retained in their original format. Deleting them after a request is filed can constitute spoliation or trigger criminal penalties.
Search. Employees must conduct a thorough and documented search across all relevant devices, including personal phones.
Production. Records must be disclosed unless a specific legal exemption applies, and agencies must justify any withholding.
Mobile carriers retain deleted messages for a limited period only. Without a proper message preservation system already in place, agencies risk being unable to comply even when they want to.
Balancing Transparency and Official Security in Data Security Compliance
Government agencies handle sensitive data, including law enforcement tactics, protected personal information, national security details, and privileged communications. Not everything on a government phone can or should be disclosed.
Administrators design policies governing agency mobile devices with this tension in mind. The goal is not to make every message public. Instead, it ensures the agency preserves, searches, and produces the right messages when legally required, without exposing unrelated private content or classified material.
Key distinctions agencies rely on:
Scope-based filtering: Personal content on a government employee's device that has no connection to official duties is generally not subject to disclosure.
Exemptions: FOIA and state equivalents include carved-out exemptions for law enforcement sensitive information, deliberative processes, and privileged communications.
Targeted collection: Rather than extracting entire device contents, agencies can scope a request to specific custodians, date ranges, and communication types.

The Operational Challenge of Producing Mobile Evidence
Even when agencies understand their obligations, executing them is another matter entirely.
Courts and regulators rarely accept manual methods, such as screenshots or self-reported exports, as defensible. Furthermore, employers often manage geographically dispersed employees, making physical collection impossible. Devices range from agency-issued iPhones to employee-owned Android phones. Data may span SMS, iMessage, WhatsApp, and other messaging platforms. Each layer adds complexity to an already time-sensitive process.
Agencies face these recurring obstacles:
Inconsistent preservation across departments and personnel
Over-collection that exposes unrelated personal data
No centralized audit trail to document what was collected and how
Difficulty scaling collections when multiple custodians are involved
How Purpose-Built Collection Tools Support Compliance
Pivotal Mobile eDiscovery (PME) is built specifically for legal and compliance workflows. Our platform enables government entities, law firms, and corporate legal teams to collect mobile communications remotely, defensibly, and at scale. Rather than seizing devices or relying on carrier exports, PME allows custodians to participate in the collection process from wherever they are, minimizing disruption and protecting personal privacy.
Every collection through PME follows documented, repeatable workflows with clear chain-of-custody, audit trails, and cryptographic hashing to ensure evidentiary integrity. Targeted acquisition by custodian, date range, and data type means agencies collect only what is legally relevant, reducing over-collection risk while satisfying public records obligations.
When a FOIA request or state records demand arrives, having a defensible collection process already in place is what separates a compliant response from a compliance failure. Want to see how targeted mobile data collection can support your agency's records obligations? Request a demo today.
FAQ
What happens if a government employee deletes text messages after a public records request is filed?
Deleting records after a request has been filed, or after a preservation obligation has been triggered, can result in serious legal consequences, including spoliation claims, court sanctions, or even criminal penalties depending on the jurisdiction. Agencies and individual employees may both face liability.
How does PME help government agencies respond to public records requests for mobile communications?
PME enables targeted, remote mobile data collection with full chain-of-custody documentation, audit trails, and defensible workflows designed to meet legal and regulatory scrutiny. This allows agencies to produce relevant text messages and mobile communications accurately and efficiently while minimizing privacy risk and avoiding over-collection of unrelated personal data.