
Guides
US email retention rules: what to keep, what to delete, and for how long
US email retention rules for business: IRS, FLSA, HIPAA and SEC schedules, legal hold duties, deletion calendars, plus PIPEDA-safe sharing with Vancouver teams.
What to take away
- No single federal law sets one email retention period. Obligations come from tax, employment, industry and litigation rules that stack on each other.
- Common floors inside email retention requirements3 years for payroll records under the FLSA, 4 years for employment tax records under IRS rules, 6 years for HIPAA compliance documentation.
- A legal hold overrides every deletion schedule. Once litigation is reasonably anticipated, automated purging must stop for the affected custodians.
- Keep your email retention policy short and defensible. Long retention raises discovery cost and breach exposure without adding legal protection.
- Cross-border teams need a written transfer plan, not just a shared drive, when email leaves Canada for a US provider.
Where US email retention rules actually come from
No federal statute sets a single deletion year for business email. Instead, obligations arrive from four directions, and the tightest deadline controls.
Tax rules come first. The IRS says to keep records supporting a return for 3 years from the filing date or 2 years from payment, whichever is later, matching the assessment window in IRC 6501(a). Employment tax records run longer, 4 years after the tax is due or paid.
Employment rules follow. The FLSA requires payroll records for 3 years and supporting documents such as time cards for 2 years under 29 CFR 516.5 and 516.6.
Industry rules add years on top. Health care providers keep HIPAA compliance documentation for 6 years under 45 CFR 164.316(b)(2)(i). Broker-dealers keep most records 6 years and correspondence 3 years under SEC Rule 17a-4 and FINRA Rule 4511.
Litigation rules set the floor that matters most. FRCP 37(e), amended December 1, 2015, governs sanctions for lost electronically stored information. Zubulake v. UBS Warburg, decided in 2003 and 2004, established that the duty to preserve attaches once litigation is reasonably anticipated.
A retention schedule you can put in the policy
A retention schedule
| Record type | Keep for | Authority |
|---|---|---|
| Tax return supporting records | 3 years from filing | IRC 6501(a), IRS guidance |
| Employment tax records | 4 years after due or paid | IRS |
| Payroll and hours records | 3 years | 29 CFR 516.5 |
| Time cards and supporting data | 2 years | 29 CFR 516.6 |
| HIPAA compliance documentation | 6 years | 45 CFR 164.316(b)(2)(i) |
| Broker-dealer correspondence | 3 years, first 2 accessible | SEC Rule 17a-4(b)(4) |
| Broker-dealer other records | 6 years | FINRA Rule 4511 |
| Records under legal hold | Until released | FRCP 37(e) |
Add owner and review date columns in your own version. A schedule nobody audits is a schedule nobody follows.
US Email Retention Schedule
Record type
- Tax return supporting records
- 3 years from filing
- Employment tax records
- 4 years after due
- Payroll and hours records
- 3 years
- Time cards and supporting data
- 2 years
- HIPAA compliance documentation
- 6 years
- Broker-dealer correspondence
- 3 years, first 2 accessible
- Broker-dealer other records
- 6 years
- Records under legal hold
- Until released
Keep for
- Tax return supporting records
- IRC 6501(a)
- Employment tax records
- IRS
- Payroll and hours records
- 29 CFR 516.5
- Time cards and supporting data
- 29 CFR 516.6
- HIPAA compliance documentation
- 45 CFR 164.316(b)(2)(i)
- Broker-dealer correspondence
- SEC Rule 17a-4(b)(4)
- Broker-dealer other records
- FINRA Rule 4511
- Records under legal hold
- FRCP 37(e)
Authority
- Tax return supporting records
- Employment tax records
- Payroll and hours records
- Time cards and supporting data
- HIPAA compliance documentation
- Broker-dealer correspondence
- Broker-dealer other records
- Records under legal hold
A business email archiving system with retention rules and audit trail features can prove what existed on a given date, how document management systems handle retention. That evidence matters more than the number of years you chose.
Legal hold: when deletion has to stop
- Issue a written hold notice the day litigation, a subpoena or a government inquiry becomes reasonably likely.
- Suspend automated deletion for named custodians and for shared mailboxes they used.
- Copy relevant mail to a separate preservation store with read-only access.
- Track acknowledgments and reissue the hold quarterly until counsel releases it.
- Record the release date, then let normal retention resume.
Do not treat keeping everything forever as a substitute. Courts and regulators treat it as a cost and privacy problem, and state privacy laws increasingly limit it.
Legal Hold Procedure
- Issue written hold notice when litigation likely
- Suspend automated deletion for custodians
- Copy relevant mail to read-only preservation store
- Track acknowledgments and reissue quarterly
- Record release date and resume normal retention
A retention policy is only as strong as its deletion log. If you cannot show when a message was destroyed, and under which rule, you have an archive rather than a policy.
Deletion and disposal obligations
Retention is half the job. Several rules also require destruction. The FTC Disposal Rule at 16 CFR 682 requires reasonable measures when disposing of consumer report information. The FTC Safeguards Rule, with an effective date of May 13, 2024, requires a written information security program for covered financial institutions.
Deletion and Disposal Obligations
- FTC Disposal Rulereasonable measures for consumer report info
- FTC Safeguards Rulewritten information security program
- CCPA/CPRAdisclose retention periods at collection
- State laws (CO, VA, CT)match disclosures to system
- Name each copy location and purge cycle
California's CCPA, amended by the CPRA effective January 1, 2023, requires businesses to disclose retention periods at collection. State email data retention laws in Colorado, Virginia and Connecticut do the same. Those disclosures must match what your email system actually does.
The FTC guide on protecting personal information recommends safeguards for stored records, protecting personal information guide. Archived mail is stored personal information.
Deleting a message from an inbox is not deletion. Copies sit in backups, journaling mailboxes, eDiscovery holds, phones and third-party archives. A defensible policy names each location and its purge cycle.
Cross-border teams and PIPEDA-safe movement
Canadian businesses do not follow US retention rules, but their US clients often demand US-style archives. That creates a transfer question.
PIPEDA Principle 4.5 requires organizations to destroy, erase or anonymize personal information once it is no longer needed. Moving email to a US provider for processing is permitted, and the Canadian organization stays accountable for it. The Office of the Privacy Commissioner sets out consent and accountability duties in its PIPEDA overview from the OPC.
Vancouver teams serving US clients should document the transfer, name the US processor, and tell individuals that their information may be handled in the United States. For teams moving files to US clients, the same logic covers attachments, contracts and design files, not only inbox mail.
Sharing less is also a retention control
Every attachment you send creates another copy outside your archive. Sending a link keeps one authoritative version with one retention clock.
Teams that compare file sharing alternatives by job, rather than by brand, usually find that own-server options such as Nextcloud and managed transfer tools solve different problems. Versioned repositories handle documents. Managed transfer handles large media.
Fewer copies mean fewer places to search during discovery and fewer places a breach can start.







