Email Retention Policy: How Long to Keep Email and How to Enforce It

Guides › Email Retention Policy: How Long to Keep Email and How to Enforce It · 3 min read 6 sections
1

Retention is a decision, not a default

"Keep everything forever" is not a retention policy — it is the absence of one, and it usually happens by accident because deleting anything feels riskier than keeping it. In practice, keeping everything indefinitely has real costs (storage, search performance, and broader exposure if you are ever required to search or produce mail in litigation) and real regulatory risk under privacy law, which generally expects data to be kept no longer than necessary for the purpose it was collected for.

A retention policy is simply a documented, deliberate answer to "how long do we keep this category of mail, and what happens to it after that."

2

What drives the retention period

The right retention period is rarely one number for the whole organisation. It usually comes from several, sometimes conflicting, sources:

  • Legal or regulatory minimums. Some industries and jurisdictions set a minimum retention period for specific categories of business record — tax, financial, or sector-specific correspondence often has to be kept for a set number of years regardless of internal preference.
  • Privacy law minimisation. Regulations such as GDPR generally expect you not to keep personal data longer than necessary, which pulls in the opposite direction from "just in case." See the GDPR subject access request guide for the related search/export obligation.
  • Storage cost and search performance. Larger archives cost more to store and are slower to search meaningfully; this is a legitimate factor even though it should not override a legal minimum.
  • Litigation and dispute risk. Mail that could be relevant to an ongoing or reasonably anticipated dispute generally should not be deleted under routine policy — see the note on legal hold below.
3

Writing a policy you can actually follow

A retention policy that is too complicated to enforce is worse than a simple one that is actually followed. A workable structure:

  1. Categorise, not case-by-case. Group mail into a small number of categories (general correspondence, financial records, HR, legal) rather than trying to decide message by message.
  2. Set one retention period per category, based on the longest legitimate requirement that applies to it.
  3. Document the reasoning, not just the number — this matters if the policy is ever reviewed or challenged, and it stops the number silently drifting over time as people forget why it was chosen.
  4. Decide what "expire" means — permanently deleted, or moved to cheaper cold storage with a longer eventual deletion date.
4

Enforcing retention technically

A policy written in a document and never applied technically is not really a policy — it is a good intention. Retention needs to be enforced somewhere it will actually run without someone remembering to do it manually:

  • In the archive
  • In the mailbox platform, if you are relying on mailbox-level retention (Microsoft 365 retention labels, for example) rather than a separate archive.
  • Not just "someone deletes old folders occasionally" — this is inconsistent, undocumented, and gives you no evidence the policy was actually followed if ever asked.
5

Retention and legal hold can conflict — know which wins

Routine retention and litigation hold are opposite instructions, and the second one has to be able to override the first. If mail is or may become relevant to a legal dispute, regulatory inquiry, or investigation, normal expiry needs to be suspended for that mail specifically — deleting it on schedule while it is under hold can be a serious problem in its own right, independent of what the underlying dispute is about.

Whatever archive or retention tool you use, confirm it actually supports a hold that overrides expiry, rather than assuming "we just won't delete anything" is a substitute — that quietly turns into "we never delete anything," which is the outcome the policy was meant to avoid.

6

How Hexamail Can Help

Hexamail Vault enforces retention through rule-based expiry policies applied to the archive independent of live mailboxes, so a documented policy is actually carried out rather than relying on manual cleanup. For a formal, named legal hold that freezes deletion regardless of policy, review this against your specific compliance requirement before relying on any SMB-scale archive.