Email Retention Policy: Legal Requirements and Setup Guide

Email Retention Policy Legal Requirements

An email retention policy is a documented organizational policy that defines how long different categories of business email must be kept, in what format they must be stored, and when they must be permanently deleted. It is driven by regulatory obligations including GDPR, HMRC requirements, and sector-specific rules from the FCA, HIPAA, and SEC, and covers legal hold procedures as well as destruction schedules.

If your solicitors have ever told you that you should have kept emails from a project that ended several years ago, you have experienced the most common consequence of not having a documented email retention policy. The same risk applies in reverse: organizations that keep every email indefinitely, believing this is the safe approach, are creating a GDPR data minimization violation rather than solving one. A properly structured policy addresses both what must be kept and precisely when it must be deleted.

What Is an Email Retention Policy?

An email retention policy is a formal documented framework that defines how long each category of business email must be kept, in what format it must be stored, who is responsible for compliance, and when it must be permanently deleted.

A complete policy covers retention periods by email category, storage platform requirements, access controls during the retention period, legal hold procedures that override normal deletion schedules when litigation arises, and destruction procedures at the end of each retention period. Roles and responsibilities must be defined across IT, legal, compliance, and HR.

Why a policy rather than just retaining everything indefinitely? GDPR’s data minimization requirement makes indefinite retention a compliance risk in its own right. What you must delete is as important as what you must keep.

For how email retention connects to email security more broadly, see The Complete Guide to Email Security.

Why Do Businesses Legally Need an Email Retention Policy?

Business emails are legally considered business records in most jurisdictions, subject to the same retention obligations as physical documents.

Regulatory obligations are consistently significant:

  • Financial records: HMRC requires 6 years for most business records. Companies Act 2006 requires 6 years for private company accounting records
  • Regulated financial communications: FCA SYSC 9 requires 5-7 years for regulated UK firms. SEC Rule 17a-4 and FINRA require 3-7 years for broker-dealer communications in the US
  • Legal correspondence: SRA guidance requires 7 years after matter closure for UK solicitors
  • Healthcare: HIPAA requires 6 years for PHI documentation. NHS Records Management Code specifies 8-30 years depending on clinical record category
  • Employment: employee-related email is typically retained for employment duration plus 6 years to cover potential tribunal claims

Without a documented retention policy, organisations face serious litigation risk if required email records cannot be produced, and regulatory enforcement risk if they cannot demonstrate a compliant programme during audit.

How Long Should You Keep Emails Under UK and US Law?

No single universal email retention period applies across all organisations. The right period depends on the email type, the industry, and the applicable jurisdiction.

Email CategoryUK Retention PeriodUK Legal BasisUS Retention PeriodUS Legal Basis
Financial and accounting records6 yearsHMRC; Companies Act 20067 yearsIRS recommendation
HR and employment recordsDuration plus 6 yearsEmployment tribunal limitation periodDuration plus 7 yearsFLSA, ADEA requirements
Legal correspondence7 years after matter closureSRA record-keeping guidance7 years (varies by matter)State bar guidance
Regulated financial communications5-7 yearsFCA SYSC 93-7 yearsSEC Rule 17a-4; FINRA
Healthcare/PHI communications8-30 years (varies by record type)NHS Records Management Code6 years from creation or last effective dateHIPAA Security Rule
General business correspondence6-7 years (recommended baseline)HMRC, Companies Act alignment7 years (recommended baseline)IRS, state limitation periods

Without specific regulatory guidance requiring a different period, 7 years for most general business email provides practical coverage against the most common UK and US requirements.

What Is GDPR Email Retention and What Does It Require?

GDPR creates two simultaneous email retention obligations that pull in opposite directions, and most organisations only acknowledge one of them. GDPR Article 5(1)(e) requires that personal data is not kept longer than necessary. GDPR Article 6(1)(c) simultaneously permits retention where required for a legal obligation.

The misconception that indefinite retention is the conservative compliant approach is one of the most consequential misunderstandings in data protection practice.

Organizations that keep all email indefinitely are not playing it safe. They are creating a data minimisation violation for every data subject whose personal data is retained beyond its justified period without documented basis. Three specific problems follow that competitors who focus only on “keep your emails” consistently ignore.

First, indefinite retention is a direct GDPR Article 5(1)(e) violation for personal data held beyond its justified period. Second, it expands the eDiscovery burden dramatically: more historical data means more expensive and time-consuming searches in litigation proceedings. Third, accumulating years of undeleted sensitive data creates a progressively more valuable attacker target. A breach of an email archive containing 15 years of business communications is far more damaging than one containing only the required 7 years.

GDPR requires each retention category to be connected to a specific lawful basis under Article 6 or Article 9 and documented explicitly. When that basis ends, deletion is required and not optional. UK ICO guidance expects documented retention schedules to be technically implemented, not merely described in a policy document.

What Is Email Archiving Compliance and How Is It Different From Backup?

Email archiving compliance is the practice of storing email in a format that preserves integrity, ensures accessibility, and meets regulatory requirements throughout the specified retention period. The critical distinction most organisations miss is that backup and archiving serve completely different purposes.

CriteriaEmail BackupEmail Archiving
Primary PurposeDisaster recovery and business continuityCompliance, legal hold, and eDiscovery
Retention PeriodRolling cycle, typically 30-90 days, overwrittenFixed compliance periods, years to decades
SearchabilityNot searchable across backup setsFully indexed for full-text search
Integrity ProtectionNone, backups can be overwritten without auditTamper-evident, hash verification, audit trail
Legal Hold CapabilityNoYes: specific custodians or topics can be held
eDiscovery ReadinessPoor: expensive reconstruction requiredRapid search, filter, and legal production export

What Is eDiscovery and Why Does Email Retention Matter for It?

eDiscovery is the process of identifying, collecting, preserving, reviewing, and producing electronically stored information (ESI) in response to litigation or regulatory investigation. Email is the primary eDiscovery data type in most legal proceedings.

Microsoft Purview eDiscovery and Google Vault both provide legal hold, search, and export capability for their respective platforms, but they only work effectively when email is properly retained and indexed in the archive from the outset.

The prerequisite that competitor content almost never frames correctly: confirmed legal hold capability is what makes automated email deletion legally safe.

When litigation is anticipated or commenced, all relevant email must immediately go on legal hold, suspending the automated deletion schedule for those custodians or topics. If automated deletion removes email that should have been preserved for foreseeable litigation, the organization risks spoliation sanctions: courts can instruct juries to assume deleted evidence would have been unfavorable to the deleting party.

The correct implementation sequence is: confirm legal hold capability functions correctly first, then activate automated deletion. Not the reverse.

Organizations that activate automated deletion without verifying that their legal hold actually suspends it for specific custodians are creating a legal liability while believing they are creating legal compliance.

Before any email retention policy moves from documentation to technical enforcement, IT and legal must jointly verify that a specific custodian’s email can be placed on hold, that the hold prevents deletion, and that deletion resumes correctly when the hold is lifted.

What Is a PST File and Is It Suitable for Email Retention?

A PST (Personal Storage Table) file is a Microsoft Outlook data file that stores email messages, contacts, and calendar items locally on a user’s computer. PST files have no place in a compliant email retention programme.

PST files create a specific GDPR compliance liability that most organisations are sitting on without realizing it, and it must be addressed before any email retention policy can be fully implemented.

Organizations using Outlook for more than a few years typically have large volumes of PST files on user computers, file servers, and decommissioned machines, containing years of personal data, client communications, and financial information that exists entirely outside centralized control:

  • PST files cannot be subject to automated deletion schedules because their locations are often unknown
  • They cannot be placed on legal hold centrally
  • They cannot be audited for unauthorized access
  • They cannot be searched at scale for eDiscovery
  • They are prone to corruption at large file sizes

Every PST file containing personal data whose retention period has expired represents an ongoing GDPR Article 5(1)(e) violation. Most retention policy guides list PST migration as a setup step without explaining that it is often the most significant pre-existing compliance gap in the organization. A PST inventory and migration programme is a prerequisite for full policy implementation, not an optional enhancement.

What Is Cloud Email Archiving and How Does It Work?

Cloud-based email archiving automatically captures every email through journal rules that forward copies to the archiving platform, indexes each email for full-text search, and stores it with integrity hash verification proving it has not been modified after capture. Legal hold functionality preserves specific emails indefinitely when litigation is flagged.

Leading platforms include Microsoft Exchange Online Archiving and Microsoft Purview for Microsoft 365 environments, Google Vault for Google Workspace, and Mimecast Cloud Archive and Barracuda Cloud Archiving Service for organizations requiring advanced features or greater control. For platform-specific setup, see Email Security for Microsoft 365: Complete Setup Guide and Google Workspace Email Security: Setup and Best Practices.

When selecting a cloud archiving provider, prioritise ISO 27001, SOC 2 Type II certifications, GDPR compliance documentation, and UK data residency options for organisations with data localisation requirements.

How Do You Set Up an Email Retention Policy Step by Step?

Setting up a compliant email retention policy requires completing these steps in sequence. Steps 1 to 3 must be completed before any technical configuration begins.

Step 1: Map all retention obligations by sector, jurisdiction, and data type across all applicable regulatory requirements.

Step 2: Categorise email types (financial, legal, HR, operational, customer correspondence) and assign retention periods to each based on your obligations mapping.

Step 3: Document the formal email retention policy covering periods, storage requirements, legal hold procedures, deletion processes, and team responsibilities.

Step 4: Select a compliant cloud email archiving platform appropriate for your email environment and regulatory context.

Step 5: Configure journal rules to automatically capture all inbound and outbound email to the archive from day one.

Step 6: Inventory and migrate legacy PST files to the compliant archive before activating any automated deletion.

Step 7: Set automated deletion schedules in the archiving platform aligned to documented retention periods.

Step 8: Test legal hold capability jointly with your legal and IT teams before activating automated deletion.

Step 9: Train IT, legal, HR, and compliance teams on their roles and legal hold activation procedures.

Step 10: Review the policy annually against regulatory changes and business workflow changes.

Cyber Security Solutions Ltd can support this process from obligation mapping through to compliant cloud archiving implementation and legal hold testing.

Conclusion

A compliant email retention policy addresses what you must keep, how you must store it, and when you must delete it. All three obligations apply simultaneously. The PST file backlog and the legal hold prerequisite are the two elements most organisations discover too late. Visit cybersecuritysolutionsltd.com for expert guidance on building a retention policy that meets your regulatory obligations and connects to compliant cloud archiving that makes eDiscovery and legal hold straightforward.

FAQs

HMRC requires 6 years for most business records. FCA SYSC 9 requires 5-7 years for regulated communications. SRA guidance requires 7 years after matter closure. Employment records need duration plus 6 years. A practical baseline of 7 years covers most general business email across the most common UK retention requirements.

Yes. GDPR Article 5(1)(e) requires personal data is not kept longer than necessary. Email containing personal data must be actively deleted when its justified retention period expires. Indefinite retention without documented justification is a data minimisation violation. Keeping and deleting are equal obligations under GDPR, not alternatives.

Backup creates rolling recovery copies that are overwritten and not searchable. Archiving creates permanent, indexed, tamper-evident copies retained for the compliance period, with full-text search, legal hold capability, and audit trail functionality. Backup serves system recovery. Archiving serves regulatory compliance, legal evidence, and eDiscovery response.

A legal hold suspends automated deletion for specific custodians or content indefinitely until lifted. When litigation is anticipated or commenced, all relevant email must be placed on legal hold immediately. Legal hold capability must be tested and confirmed before automated deletion schedules are activated in your archiving platform.

No. PST files stored locally have no central management, cannot be placed on legal hold, cannot be searched at scale, have no integrity verification or audit trail, and cannot be subject to automated deletion schedules. Personal data in PST files held beyond its retention period is an ongoing GDPR Article 5(1)(e) violation.

Look for ISO 27001, SOC 2 Type II, GDPR compliance documentation, and UK data residency options for data localisation requirements. Financial services firms should verify that the platform meets FCA SYSC 9 recordkeeping requirements. These certifications confirm the provider can support your specific regulatory compliance obligations.

Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *