Compliance
How long should a business keep email?
Six years? Ten? Forever? Ask three people how long a business must keep its email and you'll get three confident, different answers — because the honest answer is: it depends on what the email is, not that it's an email. Here's how to think about retention periods without a law degree, and how to set a policy you can actually enforce.
Retention rules follow the document, not the medium
Almost no law says "keep email for N years." What laws regulate are business records: invoices, contracts, orders, delivery notes, business letters. When those records happen to be emails — and today, most of them are — the email inherits the retention period of the document it contains.
That's why a newsletter subscription confirmation and a price agreement sitting in the same inbox can have completely different retention requirements. The newsletter is noise; the price agreement is a business record that a tax authority or court may want to see years later.
Commonly cited timeframes
As orientation — not as your policy — these are the ballpark figures that come up again and again for business correspondence and accounting-relevant records:
| Context | Commonly cited periods |
|---|---|
| Germany (HGB/AO) | 6 years for commercial letters, up to 10 for accounting-relevant records — with GoBD principles requiring unalterable storage |
| United Kingdom | 6 years is the common reference point for company and tax records |
| United States | Varies widely; 7 years is a frequent internal default, with sector rules (e.g. finance, healthcare) going further |
| Contract-related mail | Often kept for the life of the contract plus the limitation period for claims |
The pattern across jurisdictions: relevant business email is measured in years — commonly somewhere between five and ten — while the tools most companies rely on measure retention in weeks. A default Microsoft 365 tenant makes deleted mail unrecoverable after roughly two weeks, and backup rotations rarely reach past a few months. That mismatch, not the exact number of years, is the real finding.
Why "we'll sort the important ones" doesn't work
The tempting policy is selective: keep the business-relevant mail, delete the rest. In practice it fails twice. First, classification: nobody reliably decides, email by email, what will matter in year seven — the throwaway reply confirming a delivery date is the record. Second, enforcement: a policy executed by humans clicking "move to folder" is a policy that stops working every vacation, resignation, and busy week.
Which is why enforceable email retention policies in the real world look like this:
- Archive everything automatically. Every message, captured on send/receive, no human in the loop. Storage is cheap; reconstructing a missing email is not.
- Keep it as long as your longest obligation. If some of your records need 10 years, retaining everything for 10 years is simpler and safer than per-message sorting.
- Make it tamper-proof. Several frameworks (Germany's GoBD principles among them) expect records to be stored so they can't be quietly altered — which rules out PST folders and ordinary mailboxes.
- Write the one-page email retention policy. A short document stating what's archived, for how long, and who can access it. If an auditor ever asks, this plus a working archive is a strong answer.
The part people forget: leavers
Retention obligations don't end when an employee resigns — but in Microsoft 365, their mailbox typically does, 30 days after the account is deleted. Any retention policy worth the name has to survive offboarding, which is exactly where archive-on-arrival beats every export-on-departure routine.
If your business runs on Microsoft 365, mailvault365 implements this policy in about five minutes: every mailbox archived continuously, storage that supports unalterable-retention requirements, and full-text search when someone actually needs that email from year seven. 14 days free, no credit card.