Paid search in litigation
Retaining a PPC Expert Witness

When a PPC Expert Is Worth Retaining

The paid-search disputes an account examination moves, and the ones it does not move at any level of effort

Start from the fact in dispute, not from the claim

The triage question is not whether the matter involves paid search. It is whether the fact the case turns on is a fact about a record.

Write the disputed fact in one sentence, with no legal conclusion in it. Spend continued for eleven weeks after the instruction to pause. The competitor's brand name appeared in the headline of a served ad. The agency invoiced media cost that appears in no platform export. Those are facts about a record, and a record either contains them or does not. Run the same exercise on another matter and you get the agency should have restructured the account sooner, or the fund should not have been charged for that. Those are characterizations, decided by the contract and the finder of fact rather than by an export.

What follows sorts a dispute into those piles, and names the ones that belong in neither.

Disputes the account record largely settles

These are the fact patterns where an examination earns its cost, because the answer is written down with a timestamp.

  • Spend after a documented directive. Campaign and budget change history carries the user email, old value, new value and time, and daily cost by campaign sits alongside it. Matching that to a written instruction is arithmetic.
  • Targeting configured outside the intended area. Google's default advanced location option reaches people in, regularly in, or who have shown interest in the targeted places; the alternative reaches presence only. The setting is binary, its change history is visible, and the geographic performance report shows where clicks landed. One of the cleanest findings available.
  • Conversion measurement that never worked. Whether a conversion action existed at all, when it was created, whether the tag was detected, whether it was included in the reported conversions column, and whether an automated bidding strategy optimized toward an action that recorded nothing for the whole engagement. That last combination is close to self-proving.
  • A competitor's mark in served creative. The US cases have settled on a line between the keyword and the ad: buying a competitor's mark as a keyword is, standing alone, not infringement, and the Second Circuit affirmed judgment for the keyword buyer on that basis in 1-800 Contacts, Inc. v. JAND, Inc., No. 22-1634 (2d Cir. Oct. 8, 2024), holding that the similarity comparison is what appears in the advertisement rather than the keyword purchased. Whether the mark appeared in headlines, descriptions, display URLs, sitelinks or callouts is a records question, and dynamic keyword insertion frequently put it there without anyone drafting it.
  • Reconciliation. Platform cost against invoiced cost, per month and per campaign. Where an agency bought media as principal and resold it, there may be no platform export in the client's name at all, and that absence is itself the finding.

Disputes where the account is only half the record

Here an examination is worth commissioning, but only if counsel understands from the start that the account will not close it alone.

Invalid traffic. Google reports a count of clicks it filtered before billing and issues credits; Microsoft classifies clicks and bills only standard-quality ones. Neither gives an advertiser a click-level ledger tying a filtered click to an address, device or source, and neither publishes its operational definition — a paradox stated on the record by the court-appointed independent expert in the first major click-fraud class action and unresolved since. The vocabulary that survives cross-examination belongs to the Media Rating Council, which splits invalid traffic into general invalid traffic, catchable by list-based filtration, and sophisticated invalid traffic, which requires advanced analytics, multi-point corroboration and significant human intervention. Those definitions are published in the MRC's Invalid Traffic Detection and Filtration Standards Addendum, updated June 25, 2020. What the case needs is the advertiser's own web server and CDN logs, the one dataset the client controls end to end.

Attribution and affiliate disputes. The finding lives in click-level and conversion-level records — timestamp, referrer, affiliate identifier, sub-identifier, landing page, order value — not in the network's summary report. Reconstructing the click-to-conversion path per transaction either works or it does not, and that depends on whether raw logs were kept.

Undisclosed markup. If media ran in the agency's own account under a non-disclosed model, the client's platform record may not exist at all, and proving a margin requires the agency's own platform and billing records. That is a discovery problem before it is an analysis problem, and retaining an analyst before the production arrives buys very little.

Disputes that turn on the contract, where no expert settles it

This is the section that matters most, because it is the one that saves a client money.

If the dispute is about what the engagement required, an examination will not resolve it. There is no tort of returning an ad account in poor condition; claims of that shape are pleaded as breach of a transition or deliverables clause, and the clause decides them. Whether a franchisor's in-house digital team's cost is an administrative expense properly charged to a system advertising fund, or overhead the franchisor should bear, is contract interpretation — the disclosure regime requires the split to be disclosed precisely because it is contested. Whether a client approved a budget increase is not in the change history either; change history records the email that made the edit, not consent, and approval lives in email, meeting notes and signed authorizations.

And if the theory is that the manager fell below professional standards, there is no published standard of care for paid-search management to measure against, so an opinion built that way rests on a document that does not exist. What can be built instead, in descending order of durability: the contract and scope of work; the platform's published documentation for the relevant dates; the platform's in-product warnings and recommendations, which carry timestamps and show the manager was told inside his own interface; and the account's internal inconsistency, where the same manager applied a practice in one campaign and not in the identical campaign beside it. That last needs no external benchmark, which is why it holds up.

None of that is legal advice, and Bill Hartzer is not an attorney. It is a statement about what an examination can supply to counsel deciding where to spend.

When the evidence is on the other side and nobody preserved it

Some claims require a record only the counterparty ever held, and that nobody preserved. If the mechanism has to be shown from traffic-level logs and those logs are gone, aggregate reporting does not rebuild them. Aggregates show that something happened, not how.

The stack a paid-search hold has to reach is wider than the ad account, and a demand naming only the Google Ads account misses most of it: the manager account layer and its link history, platform billing separately from agency invoices, tag manager containers with their version history — often the only record of when a conversion tag was changed or removed — analytics properties and their retention settings, call tracking and lead capture, the customer relationship system, the reporting tooling, the messaging traffic where directives live, the contract stack, and the landing pages, which change without leaving a platform trace.

The uncomfortable version is worth saying plainly. If the necessary logs were never kept, the window has closed, and the counterparty's production will not contain them, an examination cannot manufacture the finding. That is a decision to make before commissioning the work rather than after reading it in a limitations section. Preservation failure does cut both ways, and destruction is itself provable — but that is a discovery argument, not an analysis.

When the analysis costs more than the amount in issue

The most frequent honest answer is proportionality, and it is the one least often given.

The effort scales with scope, and the scope variables are knowable before anything is commissioned: how many accounts and platforms; how long a period, and whether it sits inside the retention windows; whether direct access exists or every record arrives through production and has to be normalized first; whether reconciliation against billing, invoices and the client's own order data is included; and whether the deliverable is a conversation with counsel, a memorandum, or a signed report with exhibits. Each of those moves the work by a multiple, not a margin.

Set that against the sum in issue. A single account, a three-month period, and a disputed amount that a full examination and written report would consume a meaningful share of is not a matter to send to an expert on a full scope. Sometimes the right answer is narrow: an assessment of what records exist, who holds them and what windows apply, or a consulting-only read of one question with no report. Sometimes it is none of it.

The window, and why the timing question comes before the merits

Retention is the one place where waiting changes what is possible, so here are the figures once. Google Ads change history is two years in the web interface and thirty days through the API's field-level change resource; hourly, daily and weekly reporting data is held 37 months effective June 1, 2026, with monthly and coarser aggregates held eleven years; Microsoft Advertising's change history report is six months. Sources: Google Ads Help, About change history, and the Google Ads Data Retention Policy, both read August 14, 2026; Google Ads API documentation, read the same day; Microsoft Learn, Reporting Data Retention Time Periods, read the same day.

Two things follow that are not obvious. The windows run from the date of examination, not the date of the conduct, so they keep moving while a matter is assessed. And a preservation demand does not extend them — nothing about serving one changes a platform's retention schedule, or an analytics retention setting, which remains a dropdown the account's administrators control and which deletes affected data on its next monthly cycle once shortened.

That is not a reason to hurry a decision. It is a reason to sequence it: whether the record still exists is cheap to answer, and worth answering before what the record would prove.

Claims that sound like data questions and are not

Four theories arrive regularly, sound quantitative, and do not survive the record.

  • "Cost per click rose, so the bids were mismanaged." Cost per click is an auction outcome and moves when competitors move. Attributing an increase to the other side requires ruling out the auction, and share-of-voice reporting is the only native tool for that — while never disclosing what a competitor bid or spent.
  • "Revenue fell after the handover, and that difference is the damages." A before-and-after delta has to survive seasonality, competitive entry, the advertiser's own pricing and site changes, and platform product changes. It also has to survive a check that the measurement did not change: if a conversion action was redefined, or attribution moved from last click to data-driven when the rules-based models were retired in 2023, the two periods are different instruments and part of the delta is an artifact.
  • "The industry average conversion rate is higher than what this account achieved." Published benchmarks come from vendors selling advertising services, drawn from convenience samples of their own customer base. They describe a heterogeneous pool of other advertisers, not what this advertiser could have achieved in its own auctions.
  • "The detection tool found twenty percent invalid traffic, so twenty percent of the spend was stolen." The vendor measures after the click lands, under its own definitions; the platform filters before billing, under definitions it does not publish. Google's own documentation lists filtered invalid clicks as a reason its click count is lower than a third-party tool's, which means the two are partly different populations and cannot simply be differenced.

One theory runs the other way. "Nobody ever put their trademark in one of these ads" sounds like a question of testimony and is in fact a records question — dynamic keyword insertion, ad customizers, automatically created assets and sitelink text can all place a competitor's mark into served creative without anyone drafting it. Google's Trademarks policy restricts marks in ad text while expressly not restricting them as keywords, so the two surfaces are examined separately.

What a first conversation should establish

Triage is quick if the right things are asked. Which platforms carried spend, over what dates. Who created each account, and which manager account holds ownership now. Whether anyone still has administrative access, and on which side. Whether anything has been exported already, by whom, in what format. Whether the client's own web server logs, tag manager version history and order records still exist for the period. And the one sentence describing the disputed fact.

Those answers usually decide the retention question without any analysis, and they surface what has to happen first regardless of who is retained: preserving and exporting while access exists.

When the answer is a different expert

Three questions come up constantly in paid-search matters and belong to other disciplines. Saying so early avoids paying twice. Whether consumers were confused is a survey question, and clickthrough rate is not a proxy for it in either direction. Quantifying lost profits is forensic accounting or economics — the paid-search contribution is the predicate, not the number, and an expert who supplies both invites an attack on qualification. Organic search and rankings are a separate field with separate evidence.

What is left over — what ran, what it cost, what was configured, what changed and when, what the platform recorded and never recorded — is where a paid-search examination is the right instrument, and worth what it costs.

Frequently Asked Questions

When is a PPC expert witness not worth retaining?

When the dispute turns on what the agreement required rather than on what the account did; when the sum in issue is smaller than a full examination and written report would reasonably consume; and when the record that would show the mechanism was never preserved and its window has closed. A fourth case is worth naming: if the theory is that the manager fell below professional standards, there is no published standard of care in paid search to measure against, so the opinion would rest on a document nobody can produce. Say that early and spend the money elsewhere.

Can an expert prove click fraud from a Google Ads account alone?

Not on its own. Google reports a count of clicks it filtered before billing and issues credits, but no advertiser receives a click-level ledger tying a filtered click to an address, device or source, and no platform publishes its operational definition of an invalid click. What can be examined independently is the advertiser's own web server and CDN logs — addresses, user agents, timing, session behavior — which is why a hold on those logs matters more than the platform report. A third-party vendor's percentage measures a different population at a different point and cannot simply be differenced against the platform's count.

The dispute is really about what the contract said. Does an expert help at all?

Sometimes, in a supporting role, and it should be scoped that way. An examination can establish what the money actually bought — what ran, where, at what cost, on whose budget, and whether platform cost reconciles to the invoices — which gives counsel facts to argue the clause against. What it cannot do is interpret the clause, decide whether a charge was permissible, or establish that a client approved a change, since change history records the email that made an edit and not consent. If the whole case is the clause, the examination is an accessory rather than the engine.

How small is too small for a paid-search examination?

There is no threshold figure, but there is a test. Scope drives effort: the number of accounts and platforms, the length of the period, whether direct access exists or everything arrives through production and needs normalizing, whether reconciliation against billing and the client's own order data is included, and whether the deliverable is a conversation, a memorandum or a signed report. If the disputed amount would be consumed by a meaningful share of that work, the proportionate answer is a narrow one — a records-and-windows assessment, or a consulting-only look at a single question — or none at all.

What if the other side holds the account and never preserved anything?

Then the analysis question becomes a discovery question, and the sequencing matters. Establish who holds the manager account and whether administrative access still exists on your client's side, because either party to a manager link can sever it and the severed side sees nothing afterward. Preserve and export whatever your client can still reach. Then ask what the counterparty's production would have to contain for the theory to work. If the answer is traffic-level logs that were never kept and whose window has passed, no examination reconstructs them from aggregate reporting.

Can an expert say the agency fell below the standard of care in PPC?

Not from a published standard, because none exists for paid-search management. What can be established is narrower and sturdier: what the contract and scope of work required; what the platform's own dated documentation said at the time; what the platform's in-product warnings and recommendations told the manager, in the manager's own interface, and how long the condition persisted; and where the account contradicts itself, applying a practice in one campaign and not in the identical campaign beside it. Internal inconsistency is the strongest of those, because it needs no external benchmark.

Does retaining someone early actually change anything?

It changes what is still available, which is the only thing that cannot be recovered later. Platform windows run from the date of examination — two years for Google Ads change history in the interface, thirty days for the API's field-level record, six months for Microsoft's change history report — and a preservation demand does not extend any of them. Analytics retention is a setting a party controls and deletes on its own schedule once shortened. Communications, invoices and contracts survive being late. The granular platform record does not.
Keep reading

The pages behind this guide

Every dispute and every kind of record named here has its own page, with the retention window quoted, the date it was read, and the row that names what the data will not establish.

Top