
[EDRM Editor’s Note: The opinions and positions are those of Michael D. Berman.]
While U.S.A. v. Chu, 2026 WL 2742739 (S.D.N.Y. Sep. 16, 2026), does not break new ground, it is an important reminder of, among other things, the importance of information governance in connection with assertions of privacy or privilege when an employee uses business devices for personal communications.
Mr. Chu’s corporate electronic devices and iCloud accounts were seized pursuant to a search warrant. He was formerly the CEO of Tricolor Holdings, Inc. He asserted attorney-client privilege and work product protection to the materials. The government argued that Chu “had no reasonable expectation of privacy” in his use of Tricolor electronic devices, accounts, or systems. It also made a waiver argument as to other ESI that is not addressed here.
Applying those principles, the Chu court first looked to the Tricolor Handbook. Tricolor had a limited personal use policy and its handbook added: “Users have no legitimate expectation of privacy in regard to their use of the Tricolor Auto Group, LLC systems.” The handbook gave Tricolor a right of review—however, it was limited to specific reasons.
Michael D. Berman, Owner, E-Discovery LLC.
Mr. Chu asserted privilege as to 1,355 documents. The Chu court looked at precedent and also to Tricolor’s information governance policies and their implications. Id. at *2. It wrote:
Before the widespread use of electronic devices, the Supreme Court addressed an employee’s reasonable expectation of privacy in personal documents kept in the employer’s space within the employer’s office. In O’Connor v Ortega, 480 U.S. 709 (1987), the Court concluded that the head of a hospital’s professional education department had a reasonable expectation of privacy in personal papers he kept in a desk and file cabinets used exclusively by him. The Court, in part, relied on the absence of a company policy prohibiting the storage of personal property in desks or file cabinets, although it noted that “the absence of such a policy does not create an expectation of privacy where it would not otherwise exist.” Id. at 719.
The Chu court also looked to more recent precedent, including In re Asia Global Crossing, LTD, 322 B.R. 247, 257–58 (Bankr. S.D.N.Y. 2005), to identify the “factors [that] have been applied to claims of privilege in [personal] communications stored or transmitted on an employer’s system….” Those factors are:
(1) does the corporation maintain a policy banning personal or other objectionable use, (2) does the company monitor the use of the employee’s computer or e-mail, (3) do third parties have a right of access to the computer or e-mails, and (4) did the corporation notify the employee, or was the employee aware, of the use and monitoring policies?
Applying those principles, the Chu court first looked to the Tricolor Handbook. Tricolor had a limited personal use policy and its handbook added: “Users have no legitimate expectation of privacy in regard to their use of the Tricolor Auto Group, LLC systems.” The handbook gave Tricolor a right of review—however, it was limited to specific reasons. Additional facts are set out below, as the court applied those factors.
THE FIRST FACTOR: “As to the first Asia Global inquiry, Tricolor does not have a policy banning personal use of its systems. To the contrary, it generally permits personal usage, albeit with the limited exception that it must not ‘hinder performance of job duties or violate any other Company policy.’ The Court concludes that Chu’s use of the Tricolor computer systems to communicate with lawyers on personal matters was not a violation of the Tricolor policy.” Thus, that factor weighed in favor of Mr. Chu.
THE SECOND FACTOR: “As to the second Asia Global inquiry, there is no evidence in the record of Tricolor actually monitoring employees’ use of its systems. Some courts have found that where a company warns employees of its right to monitor employee systems but does not do so, employees may assume system is secure in using the system for personal matters…. But these cases are factually dissimilar. Rather than a broad and generalized right to monitor, Tricolor’s policy lists specific reasons why it may ‘obtain communications within the systems without notice to users,’ including ‘but are not limited to; maintaining the system; preventing or investigating allegations of system abuse or misuse; assuring compliance with software copyright laws; complying with legal and regulatory requests for information; and ensuring that Company operations continue appropriately during an employee’s absence.’ … Here the policy was explicit and fulsome, and this Court similarly concludes that it tilts the factor against Chu.”
THE THIRD FACTOR: “The third factor focuses on whether third parties have a right to access the Tricolor systems. While there is no evidence of such right of access granted to a third party… [i]f the policy states that materials could be turned over to regulators, the third factor may be fulfilled…. Here, Tricolor disclosed that it may access the system to comply with ‘legal and regulatory requests for information.’” On the facts presented, Tricolor’s access to Mr. Chu’s communications were to comply with a grand jury request. “Chu was the CEO of a corporation that obtained large loans from heavily regulated financial institutions and offered asset-back securities to investors. He would have had a heightened awareness that his communications on Tricolor systems could wind up in the hands of a prosecutor or regulator.”
THE FOURTH FACTOR: “The fourth factor focuses on the individual’s knowledge of the company’s monitoring or access policies.” Mr. Chu had signed an employment agreement stating that he would follow all applicable company policies. “The Court concludes that the Handbook was applicable to Chu, and he knew or was willfully blind to its contents…. The fourth factor — whether the corporation notified the employee, or the employee aware, of the use and monitoring policies — weighs against the reasonable expectation privacy in communications on the Tricolor system.”
ADDITIONAL CONSIDERATIONS: Mr. Chu raised an additional argument. During a 2023 internal review, “he secured an agreement limiting the scope of the investigators’ search, lest his privileged communications be compromised.” That argument failed, with the court writing:
The incident cuts both ways. It shows a willingness on the part of Tricolor, of which he was CEO, to accommodate his reasonable privacy requests. But it also shows that Chu knew his personal emails on the Tricolor system could be the subject of an internal investigation and that investigators needed the prior authorization of the Tricolor Audit Committee before sharing their proposed search terms and custodians with him…. He could request a limitation on the scope of search, which was granted by Tricolor in this instance, but he had no right to such a limitation.
In concluding that Mr. Chu had not shown a reasonable expectation to privacy in the communications on the company system, the court wrote: “Finally, the plain text of the Tricolor Handbook also undermines Chu’s privilege assertion: ‘Users have no legitimate expectation of privacy in regard to their use of the Tricolor Auto Group, LLC systems.’”
The Chu court also addressed waiver by turning a Tricolor laptop over to an investigative firm that had been retained by counsel to a Special Committee. Id. at *4-5.
I have suggested that Bad Things Can Happen When Company Officers Use Their Private Email Accounts for Work (May 20, 2024). Chu presents the opposite situation—use of company systems for private communications. Information Governance–Employee’s Use of Employer’s Email for Privileged Communications (Jul. 10, 2026); Use of Personal Email by Government Personnel (Aug. 26, 2026).
My personal opinion is that, in the real world, as a practical matter, employees are going to use business devices for some personal communications. An employee sitting in the middle of a meeting that is running late, is likely to text their spouse or partner on a business cell phone: “Hey, can you pick up the child today—I’m running late?”
A middle-of-the-road policy is to permit employees to use business devices for non-privileged and non-confidential personal communications, provided, however, that privileged or confidential communications, such as personal, legal, accounting, pastoral, or medical communications are not permitted. Similarly, spousal communications are permitted on routine matters, but there would be no spousal privilege.
Assisted by GAI and LLM Technologies per EDRM’s GAI and LLM Policy.

