Email Retention Policy for a Small Business: How Long to Keep What
How to write an email retention policy for a small business: typical retention periods by type, what to keep, how to delete, legal holds, and a short template.
Keeping every email forever feels safe until a subject-access request, a lawsuit, or a breach turns ten years of inboxes into a liability. Deleting aggressively feels tidy until the tax office asks for a 2021 invoice thread. A retention policy is the middle path: a short written rule for how long each kind of email is kept and what happens then. This is general guidance for small businesses, not legal advice; confirm periods with your accountant or lawyer for your country.
Quick answer
Write a one-page policy that sorts email into a handful of categories, gives each a retention period based on the longest legal or business need, names who is responsible, describes how deletion happens, and includes a legal-hold clause that suspends deletion when a dispute is likely. Apply it with mailbox folders and a yearly cleanup rather than complex software.
Why a small business needs one
- Data-protection laws (GDPR in the EU and UK, and similar rules elsewhere) require that personal data is not kept longer than necessary. "Forever" is not a defensible period.
- Tax and company law set minimum periods for financial records, and emails that evidence a transaction count as records.
- A breach exposes everything you kept. Less data retained is less harm when a mailbox is compromised.
- Litigation and disputes go better when you can say what you keep, for how long, and prove you followed the rule.
Typical categories and periods
Exact numbers depend on jurisdiction and sector; these are common starting points to check with your adviser.
- Financial and tax records (invoices, receipts, payment confirmations, VAT or sales-tax correspondence): commonly 6 to 7 years from the end of the financial year, and 10 years in some countries.
- Contracts and their negotiation history: the life of the contract plus the limitation period for claims, often 6 years or more.
- Employment records (offers, reviews, disciplinary, leaver correspondence): usually several years after employment ends; check local employment law.
- Customer support conversations: 1 to 3 years, or as long as the customer relationship plus a margin.
- Marketing and general correspondence with no legal weight: 1 year or less.
- Recruitment emails for unsuccessful candidates: months rather than years, because they contain personal data with no continuing purpose.
Writing the policy in six steps
- List the kinds of email your business actually sends and receives. Five to eight categories is enough.
- For each, write down the longest period any law, contract, or business need requires. That is the retention period.
- Name an owner: usually the founder or office manager.
- Decide the mechanism. For a small team, that is a folder structure (Finance, Contracts, Clients, General) plus an annual cleanup date where anything past its period is deleted or archived offline.
- Add a legal-hold clause: when a dispute, investigation, or regulator enquiry is reasonably anticipated, deletion of related email stops immediately and the owner records the hold.
- Add the leaver rule: a former employee's mailbox is retained for a defined period (90 days to a year is common) before deletion, and its business-relevant content is moved to the successor first.
Applying it without special software
- Set up the folders in each mailbox on day one, and teach the habit of filing rather than leaving everything in the inbox.
- Use your mail client's archive-to-local-file feature for records past their active period but within their legal period. Store the archive on backed-up company storage, not a personal laptop.
- Put the annual cleanup in the calendar and do it in an hour: sort by date in each folder, delete or archive by period, empty the bin.
- Keep mailbox size manageable. OquMail's free plan gives each mailbox 5 GB, which for most small businesses covers several years of mail, but the policy is what keeps that from filling with a decade of newsletters.
Mistakes to avoid
- A policy with periods nobody enforces. Regulators and courts look at what you did, not what you wrote.
- Deleting during a dispute. Once litigation is foreseeable, destroying relevant email can be treated as spoliation.
- Forgetting Sent and Deleted folders, and mail apps that keep local copies after server deletion.
- Applying one period to everything. Seven years for recruitment rejections is a data-protection problem; one year for tax records is a tax problem.
Common questions
Do we need an archiving product?
Not at a small size. Folders, an offline archive file, and a calendar reminder implement the policy. Consider a product when regulation requires tamper-proof archives, as in some financial and legal sectors.
What about emails containing customer personal data that we need for tax?
The legal obligation to keep the record wins for the retention period, and that obligation is itself the lawful basis for keeping it. Once the period ends, delete.
Can we just export everything and delete the mailboxes?
An export is still retained data and still subject to the same periods and access requests. It changes where the data lives, not whether you hold it.
Free business email on your own domain
OquMail gives you up to 15 mailboxes on your domain — free — with guided SPF/DKIM/DMARC, webmail, IMAP/SMTP for any mail app, and a send API. Most teams are live in under fifteen minutes. Start at oqumail.com.
Get started free