Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Mike Lewis on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Legal Question about email retention

Status
Not open for further replies.
Nov 1, 2005
7
US
My company is about 80 users strong. As you know, users come and go, but there emails tend to stay. I have been trying to research certain policies, and have not found much on what I am looking for, could any of you please help point me in the right direction.

The issue is, how long do I keep the old users emails? How long do I allow the current users to keep there emails before I get ride of them or back them up?

Your help would be appreciated

Blackhawh4evr
 
That's several issues...

Right: backup. Each and every day my friend.
Get rid of them: don't. Let the users do that.
How long do I keep them? See above.
Legal / email retention: You'd need to do journalling or get an archiving program to make it tamper proof.
 
You said: How long do I keep them? See above.

This was a comment about old users, they are no longer with the company.
 
old users? i exmerge them. but if you have archiving it doesn't matter.
 
I keep them forever or until management says it's definately safe to delete (written order).
 
If you're a financial institution, you're required by Sarbanes-Oxley to retain all email coming into your org or going out - FOR LIFE.

If you're a healthcare provider, HIPPA requires the same - FOR LIFE.

That pertains to ALL EMAIL - personal, business or otherwise.

Penalties include jailtime for IT staff.

If you're not either of those two, it depends on business. I have one client who's business doesn't get payment for services until 3 years after the original work begins - so retention for longer times is important. Most of the ~7000 seats we manage are for law firms, who intentionally purge mail over 30 days old when possible.

Pat Richard, MCSE(2) MCSA:Messaging, CNA(2)
 
Sarbanes-Oxley applies to publicly held companies.
HIPPA Applies to Healthcare providers.
The FDA has rules that impact pharmacudical and medical device manufacturers.
For the financial industry, there are a myriad of rules by different agencies.

All of them require some form of control and auditing measures. Probably the most severe is the FDA which require cradle to grave documentation for drugs or medical devices.
 
The above is assuming you are in the US or any other country that applies that ridiculous law.

We keep or delete what we want and when we want, period.

Marc
[sub]If 'something' 'somewhere' gives 'some' error, expect random guesses or no replies at all.
Free Tip: The F1 Key does NOT destroy your PC!
[/sub]
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top