File formats

How Long Should You Keep Email

Storage is cheap and storage is not the cost. Everything kept is everything that can be asked for.

6 min read

How long you should keep email is decided by three clocks that rarely agree. Mail accumulates unless somebody stops it. That means having no retention policy is itself a policy. The policy is keep everything forever. Most organisations are running that one without ever having agreed to it.

Which would be fine if keeping things carried no cost. It carries several. None of them is the one people expect.

Three Clocks That Decide How Long to Keep Email

Any given message sits under at least three periods at once and they rarely agree.

  1. The minimum How long you must keep itTax rules, sector regulation, contracts. Also the window in which a dispute could still be raised. This one says keep
  2. The useful period How long anybody needs itUsually far shorter than people assume. Most mail is never opened again after a fortnight
  3. The maximum How long you may keep itData protection rules expect personal data to be held no longer than necessary. This one says delete
The first and the third genuinely conflict. No technical setting resolves that, because it is a judgement somebody has to make and write down.

The conflict is the reason nothing gets decided. One set of obligations says keep and another says remove, so the safest looking move is to do neither and leave everything where it is. That is a decision with consequences rather than a way of avoiding one.

What Keeping Every Email Forever Actually Costs

Storage is cheap and storage is not the cost.

The costWhat it looks like
DiscoveryEverything kept is everything that can be asked for. Somebody has to read it
A breachTwenty years of mail leaks rather than two
Access requestsSomebody can ask what you hold about them. More held, more work
Finding anythingSearch quality falls as the pile grows
MigrationEvery future move carries the whole accumulation

Only the last two are technical. The first three are the reasons organisations with lawyers involved tend to keep less rather than more.

A mailbox is mostly other people. Their addresses, what they said, what somebody said about them, attachments they sent. That is what turns retention from a housekeeping preference into a question somebody may have the right to ask about.

Read next What Deleting Mail Does And What It Leaves Behind Why the copies a policy forgets are the ones that still hold everything.

The Layers an Email Retention Policy Has to Reach

A retention rule that covers only the mail server describes something narrower than what exists.

Usually Covered

  • The live mailbox
  • Server side archiving
  • Deleted items retention

Usually Forgotten

  • Backups, which hold everything deleted
  • Exports somebody made once
  • Old mailboxes of people who left
  • Mail on laptops nobody has collected
The right column is where most old mail actually lives. A rule naming only the mail platform can be followed perfectly while the organisation still holds everything it said it had removed.

A personal store on a laptop is the classic gap. Somebody exported a PST in 2018 to get under a quota. The file sat in a documents folder, outside every policy anybody has written. Nothing is wrong with the file. Nobody knows it exists.

The One Rule That Overrides Every Retention Policy

Where litigation or an investigation is anticipated, ordinary retention stops applying.

A legal hold is an instruction to preserve. It overrides deletion including the automatic kind nobody thinks about. That last part catches people, because an automatic rule quietly removing mail on a schedule is still deletion.

Deleting during a hold is a separate matter from whatever was deleted. It is treated as its own problem and a serious one. Where one might apply, suspend the schedule and ask somebody qualified rather than reasoning it out.

The Case Everybody Actually Faces

Retention stops being abstract the week somebody leaves. Their mailbox is still there and nobody has decided what happens to it.

The usual outcome is that it stays, forever, because deleting it feels risky and keeping it feels free. Four years later the organisation holds forty mailboxes belonging to people it no longer employs.

What is worth keeping

The business record
contracts and quotes
project correspondence
decisions and approvals
anything a client
  might ask about

These belong to the organisation and somebody will want them. Extracting them is a job with an end.

What rarely is

Everything around it
internal chat
newsletters
lunch arrangements
their personal mail
  that arrived at work

Held indefinitely, this is the harder half to justify and the half that grows every year.

Almost nobody separates these, so the whole mailbox is kept on the strength of the left column. The right column comes along for the ride and outlives everybody's memory of why.

Redirecting the address is a different decision. Forwarding a leaver's mail to a colleague means somebody is reading correspondence addressed to a person who has gone, including anything personal that still arrives. Common practice. It deserves a written rule and a time limit. It rarely gets either.

Building an Email Retention Policy You Can Defend

  1. Write it down. An unwritten policy cannot be shown to anybody and cannot be followed consistently. This step alone puts an organisation ahead of most.
  2. Use few categories. Three or four. Contracts and finance. Project correspondence. General mail. Anything under a hold. Twenty categories is a policy nobody will apply.
  3. Have somebody senior agree the periods. Not the mail administrator. The decision weighs legal exposure against operational need, which is not a technical judgement.
  4. Include the forgotten layers. Backups, exports, leavers, laptops. A policy that names only the server is describing a fraction of what exists.
  5. Apply it to what you already hold. A policy that starts from today leaves the accumulation untouched, which is the part that carries the risk.
  6. Keep evidence that it runs. Defensible means a reasonable rule, followed, that somebody can explain afterwards. The explaining is most of it.

None of this is advice about your obligations. Retention periods differ by country, by industry and by contract. A rule that fits one organisation is wrong for the next. What is general is the shape of the question. What the answer is belongs to somebody who knows your situation.

Where a policy finally exists and the old accumulation has to be dealt with, the first job is finding out what is in it. Our file viewers open an old store in a browser tab so a forgotten export can be assessed before anybody decides what happens to it.

General principles checked against the referenced articles in August 2026. Retention rules differ by country, by industry and by contract, so nothing here is advice about any particular obligation.

Questions People Ask

6 questions, answered in full below.

How long should a company keep email?

There is no single number and anybody offering one is guessing. Different categories of mail attract different periods. Those periods come from tax rules, from sector regulation, from contracts. Also from how long a dispute might still be raised. The work is deciding the categories.

Is keeping everything the safe option?

It removes one risk and creates another. Nothing is missing when somebody asks for it. Everything is discoverable when somebody else does. A mailbox full of other people

What is a legal hold?

An instruction to stop deleting, issued once a dispute or an investigation looks likely. It overrides ordinary retention entirely, including automatic deletion nobody thinks about. Removing anything while one is in force is a serious matter separate from whatever was removed.

Do backups count?

They hold the data, so in practice they are part of the answer. A message deleted from a mailbox and still sitting in an archive has not gone anywhere. Any retention plan that ignores backups describes something other than what exists.

Who should decide this?

Not whoever administers the mail system. It needs somebody who can weigh the legal side against the operational one. The technical side then implements it. Retention set by default because nobody chose is the position most organisations are actually in.

What is the simplest defensible position?

A written policy. A small number of categories. Periods somebody senior agreed. Evidence that it is applied. Defensible does not mean perfect. It means an ordinary rule, applied the same way each time, that stands up to being explained.

Sources

Where the figures and behaviour described above were checked.

  1. Data retention Wikipedia
  2. Legal hold Wikipedia
  3. Records management Wikipedia