Email Retention Policy: Federal Minimums, Legal Holds, and Privacy Caps

The legal requirements for an email retention policy come from a stack of overlapping federal rules that each set a minimum keep-time for a particular kind of record, together with privacy laws that limit how long you may hold personal data and court rules that punish destruction of evidence once litigation is on the horizon. No single statute covers every email. Instead, a given message may sit under two or three retention floors at once, depending on whether it touches taxes, payroll, healthcare, securities business, or a pending dispute. A defensible policy sorts email into categories, assigns each category the longest applicable period, and pairs the schedule with a working legal hold process.

Federal Minimums by Content Type

The floors below are the ones most policies have to account for. Which ones apply to you depends on your industry and the content of the message, not the sender’s job title.

Sarbanes-Oxley: The Anti-Destruction Rule

Under 18 U.S.C. ยง 1519, anyone who destroys, alters, or falsifies records to obstruct a federal investigation faces fines and up to 20 years in prison.1Office of the Law Revision Counsel. 18 U.S. Code 1519 – Destruction, Alteration, or Falsification of Records in Federal Investigations and Bankruptcy The statute reaches any “record, document, or tangible object,” and courts have consistently treated email as within that scope. Deleting a message that could be relevant to a federal inquiry is not a policy problem. It is a potential felony.

SEC Rule 17a-4: Broker-Dealers

Broker-dealers must preserve certain records for at least six years, with the first two years in an easily accessible location.2eCFR. 17 CFR 240.17a-4 – Records to Be Preserved by Certain Exchange Members, Brokers and Dealers A separate provision requires copies of all business-related communications, including emails, to be preserved for at least three years, again with the first two years readily accessible.3FINRA. SEA Rule 17a-4 and Related Interpretations

HIPAA: Healthcare Compliance Documentation

Organizations handling protected health information must retain compliance-related documentation for six years from the date it was created or last in effect, whichever is later.4eCFR. 45 CFR 164.530 – Administrative Requirements That covers policies, procedures, written communications required under the Privacy Rule, and documentation of actions or designations. Emails memorializing any of those activities fall within the six-year window. Many healthcare organizations simply default to six years for all email touching patient information rather than trying to separate compliance documentation from clinical correspondence in real time.

IRS Records

The IRS requires taxpayers to keep records sufficient to support a return for as long as they are relevant to tax administration.5Office of the Law Revision Counsel. 26 U.S. Code 6001 – Notice or Regulations Requiring Records, Statements, and Special Returns The retention floor tracks the situation:

  • Standard returns: three years after filing.
  • Underreported income exceeding 25% of gross income: six years.
  • Employment tax records: at least four years after the tax is due or paid, whichever is later.
  • Unfiled or fraudulent returns: indefinitely.

Any email documenting revenue, expenses, payroll, or deductions should follow the longest applicable period.6Internal Revenue Service. How Long Should I Keep Records? Format does not matter; if the information is material to a return, electronic records carry the same obligations as paper.

FLSA and EEOC: Employment Records

The Fair Labor Standards Act requires employers to preserve payroll records for at least three years from the last date of entry.7eCFR. 29 CFR 516.5 – Records to Be Preserved 3 Years Records used to compute wages, such as time cards and schedules, must be kept for two years.8U.S. Department of Labor. Fact Sheet #21 – Recordkeeping Requirements Under the Fair Labor Standards Act (FLSA)

EEOC regulations require all personnel and employment records to be preserved for one year from the date of creation or the relevant personnel action, whichever is later. When an employee is involuntarily terminated, that employee’s records must be kept for one year from the termination date.9eCFR. 29 CFR 1602.14 – Preservation of Records Made or Kept If an EEOC charge is filed, the obligation extends until the charge reaches final disposition. Under the Age Discrimination in Employment Act, payroll records specifically must be kept for three years.10U.S. Equal Employment Opportunity Commission. Recordkeeping Requirements Emails discussing hiring, termination, performance, or compensation live inside these rules.

Privacy Laws That Cap Retention

The rules above set floors. A newer wave of privacy laws sets ceilings, and the two directions genuinely pull against each other.

The EU’s General Data Protection Regulation requires that personal data be stored “no longer than is necessary for the purposes for which the personal data are processed,” and gives individuals the right to demand erasure. If your organization handles data belonging to EU residents, emails containing personal information cannot sit in an archive indefinitely without a documented justification.

The California Consumer Privacy Act follows similar logic, prohibiting businesses from retaining personal information longer than reasonably necessary for the business purpose that justified collecting it. Several other states have enacted comparable laws. A retention rule of “keep everything for ten years just to be safe” may satisfy recordkeeping mandates while violating data minimization obligations. The way through is a policy that assigns different periods to different categories, so personal data does not outlive its purpose while regulated records survive their mandatory window.

What the Policy Has to Contain

The working part of any retention policy is a category schedule. Each category gets a retention period driven by the longest applicable legal requirement. The categories vary by organization, but most policies address at least these:

  • Tax and financial records: seven years covers the IRS’s six-year lookback for unreported income plus a buffer, and aligns with SEC requirements for broker-dealers.
  • Employment and HR records: four years after separation exceeds the FLSA’s three-year payroll floor and the EEOC’s one-year general rule while leaving room for potential discrimination claims. Some organizations extend to seven years to account for state statutes of limitations.
  • Healthcare compliance records: six years from creation or last effective date, matching HIPAA.
  • Contracts and legal correspondence: the life of the agreement plus the applicable statute of limitations for breach claims, typically four to six years depending on the jurisdiction.
  • General business correspondence: one to three years, depending on ongoing operational value.
  • Transitory messages: meeting invitations, automated notifications, and personal messages can be deleted within 30 to 90 days.

The policy should specify what counts as part of the “email” for retention purposes. Attachments must be archived with the original message. Metadata, including sender identity, timestamps, and routing information, provides context that often matters as much as the body text. Stripping metadata during archiving can make the record useless for litigation or audit.

Ownership and scope matter as much as the schedule. Each category needs a designated department: finance for tax correspondence, HR for personnel emails, legal for anything under hold. And the policy has to cover everyone who sends or receives business communications, across every system in use. A schedule that governs the corporate inbox while ignoring a shared drive full of exported email folders defeats itself.

Off-Channel Communications Are Now Squarely In Scope

A retention policy that only covers traditional email has a gap regulators are actively targeting. The SEC has been pursuing firms whose employees conduct business through personal text messages, WhatsApp, Signal, and similar platforms that the firm’s archive never captures. In January 2025, the SEC announced settlements with twelve firms totaling $63.1 million in penalties for failing to preserve these communications, with individual penalties reaching $12 million for a single firm group.11U.S. Securities and Exchange Commission. Twelve Firms to Pay More Than $63 Million Combined to Settle SEC Charges for Widespread Recordkeeping Failures Earlier enforcement waves involved even larger aggregate amounts.

The lesson reaches beyond financial services. If employees discuss business on personal devices, those messages may be subject to the same preservation obligations as formal email. A policy should either prohibit off-channel business communications, require they be forwarded into the archive, or deploy technology that captures them automatically. FINRA has emphasized that compliance and supervisory systems must account for off-channel communications as part of standard recordkeeping oversight.12FINRA. SEC Off-Channel Communications Settlements – SRO Collateral Consequences

Storage Format Rules

For firms subject to SEC Rule 17a-4, archived electronic records must be stored in a non-rewritable, non-erasable format, commonly called “write once, read many” (WORM) storage, or alternatively in a system that maintains a complete audit trail of any changes.13U.S. Securities and Exchange Commission. Amendments to Electronic Recordkeeping Requirements for Broker-Dealers The requirement exists to prevent quiet alteration of an archived email. Organizations outside SEC jurisdiction often adopt WORM or audit-trail storage anyway because it makes the archive defensible in court.

Legal Holds Override the Schedule

A legal hold suspends your retention policy. When litigation is reasonably anticipated, the organization must stop routine deletion of anything potentially relevant and affirmatively preserve it.14United States District Court for the District of Nebraska. Litigation Holds – Ten Tips in Ten Minutes The automated purge that ordinarily protects you becomes a liability the moment a hold should have been in place.

When the Duty Triggers

The duty does not wait for a filed lawsuit. It attaches when you know or should know that litigation is reasonably likely. Common triggers include a demand letter, a regulatory investigation notice, a formal complaint from a customer threatening legal action, or internal discussions about initiating a claim. Vague rumors do not trigger the duty. A credible, specific threat does. Courts ask whether a reasonable organization in your position would have anticipated litigation at that point.

Implementing the Hold

Implementation starts with identifying the custodians who possess relevant information and the scope of data to preserve. Scope is typically defined by date range, keywords, and custodians. A hold might cover all emails sent or received by three managers during a particular quarter that mention a specific project or client. Defining scope carefully prevents under-preservation, which risks sanctions, and over-preservation, which buries the legal team in irrelevant data and inflates review costs.

Each custodian should receive a written hold notice explaining what to preserve and why. Track who received the notice and who acknowledged it. That audit trail matters if the opposing party later accuses you of destroying evidence, because you can show the right people were told to preserve the right data at the right time. The hold stays active until legal counsel formally releases it, which may not happen until years after the dispute resolves.

What Happens When Emails Are Destroyed

Spoliation is the legal term for destroying or failing to preserve evidence you had a duty to keep. In email, that usually means relevant messages were purged by automated systems after a hold should have been in place, or an employee deleted messages knowing they were relevant. Federal Rule of Civil Procedure 37(e) sets the sanctions framework. When electronically stored information that should have been preserved is lost because a party failed to take reasonable steps to preserve it, and the information cannot be recovered through other discovery, the court has two tiers of response:15Legal Information Institute. Federal Rules of Civil Procedure Rule 37 – Failure to Make Disclosures or to Cooperate in Discovery

  • Prejudice without intent: if the opposing party was prejudiced by the loss, the court can order measures to cure that prejudice, but nothing more severe than necessary.
  • Intent to deprive: if the court finds you deliberately destroyed evidence to keep the other side from using it, sanctions escalate. The court can instruct the jury to presume the destroyed emails were unfavorable to you, dismiss the case entirely, or enter default judgment.

Rule 37(e) has a built-in protection. If you took reasonable steps to preserve electronic evidence, courts cannot impose sanctions even if some data was still lost. A documented retention policy and a working legal hold process are the practical shape of that protection. “Reasonable steps” does not require perfection. It requires a written policy, holds implemented when triggered, the right custodians notified, and follow-through documented. Organizations that can show that good-faith effort stand in a far stronger position than those explaining, after the fact, why they had no preservation process at all.