Retention policies
Keep your organisation's mail as long as the law says, and delete it when its time is up: finance's for ten years, everybody's for two, with a preview before anything changes.
Some mail has to be kept for years: company records under the German HGB and tax code as GoBD reads them, typically six or ten years, or a financial firm’s five to seven. Other mail should not be kept longer than it is needed, which is what the GDPR asks. Retention policies do both, for everybody or for the groups, domains or people you name.
A policy says:
- whose mail: everybody’s; the members of one or more groups (and of groups inside them); everybody whose address is at one of your domains; or people you name;
- which mail: all of it, mail received, or mail sent;
- for how long, from the day each message arrived;
- what its time means:
- keep it until then: nobody can delete it for good before its time. If the person deletes it, it disappears from their mail but is kept out of sight, the way a legal hold keeps mail. When its time comes, it goes.
- delete it then: it is deleted when its time comes.
- keep it, then delete it: both.
- archive it then: it is moved from the person’s Inbox and Sent to their Archive folder, so it stays theirs to search but is out of the way. Mail they filed in a folder of their own stays where they put it, and nothing is taken out of Trash or Junk.
- keep it, then archive it: both.
A legal hold always wins over a deletion, and so does a policy that keeps the same mail for longer.
Set up policies
On the console, open Settings and find Retention. Write one policy to a line: a name, a colon, whose mail, a semicolon, which mail, a semicolon, and what its time means.
Finance: finance@example.com; all; keep 10y then delete
Everybody: everybody; received; delete after 2y
Legal: legal@example.com; sent; keep 7y
Branch: domain branch.example.com; received; archive after 1y
Board: people chair@example.com, cfo@example.com; all; keep 10y then archive
| Part | What to write |
|---|---|
| The name | Anything that tells people what the policy is for. |
| Whose mail | everybody; groups’ addresses separated by commas; domain and one or more of your domains; or people and their addresses. |
| Which mail | all, received (everything except sent mail and drafts), or sent. |
| What its time means | keep 10y, delete after 2y, archive after 1y, keep 7y then delete or keep 7y then archive. Write years with y and days with d, from 1 day to 100 years. |
Before you save, choose Preview. For each policy it shows how many people it applies to, how many of their messages it covers today, and how many the next nightly run would delete. Nothing changes until you choose Save, and Undo puts the policies back as they were.
From the command line:
vsx admin retention add Finance --groups finance@example.com --keep 10y --then-delete
vsx admin retention add Everybody --what received --delete-after 2y
vsx admin retention preview
vsx admin retention show
vsx admin retention remove Everybody
When things happen
- Keeping starts as soon as you save: from then on, what a policy keeps cannot be deleted for good before its time.
- Deleting happens once a day, overnight. The oldest mail goes first. Shortening a policy never deletes anything straight away; the next nightly run deletes what the new time allows. Preview first to see how much that is. The preview leaves out mail a legal hold or a discovery case keeps, and says how much that is separately.
- Archiving happens once a day too, the same way.
- A person who joins a group is given its policies within the hour.
Each night’s deletions and archiving are in the audit log: one line for each policy, saying how many messages it deleted or archived. The log never says what the messages were.
Mail kept by a policy counts toward the person’s storage, the same as mail kept by a legal hold.
Who can change them
The organisation’s administrators set the policies and preview them. An auditor can read them. Every change is in the audit log, with the policies before and after.
Something unclear or out of date on this page? Tell us.