Email retention schedule card showing IRS, FLSA and HIPAA deadlines. US email retention rules: what to keep, what to delete, and for how long
Image: Productivity Software Reviews

Guides

US email retention rules: what to keep, what to delete, and for how long

US email retention rules for business: IRS, FLSA, HIPAA and SEC schedules, legal hold duties, deletion calendars, plus PIPEDA-safe sharing with Vancouver teams.

What to take away

  • No single federal law sets one email retention period. Obligations come from tax, employment, industry and litigation rules that stack on each other.
  • Common floors inside email retention requirements3 years for payroll records under the FLSA, 4 years for employment tax records under IRS rules, 6 years for HIPAA compliance documentation.
  • A legal hold overrides every deletion schedule. Once litigation is reasonably anticipated, automated purging must stop for the affected custodians.
  • Keep your email retention policy short and defensible. Long retention raises discovery cost and breach exposure without adding legal protection.
  • Cross-border teams need a written transfer plan, not just a shared drive, when email leaves Canada for a US provider.

Where US email retention rules actually come from

No federal statute sets a single deletion year for business email. Instead, obligations arrive from four directions, and the tightest deadline controls.

Tax rules come first. The IRS says to keep records supporting a return for 3 years from the filing date or 2 years from payment, whichever is later, matching the assessment window in IRC 6501(a). Employment tax records run longer, 4 years after the tax is due or paid.

Employment rules follow. The FLSA requires payroll records for 3 years and supporting documents such as time cards for 2 years under 29 CFR 516.5 and 516.6.

Industry rules add years on top. Health care providers keep HIPAA compliance documentation for 6 years under 45 CFR 164.316(b)(2)(i). Broker-dealers keep most records 6 years and correspondence 3 years under SEC Rule 17a-4 and FINRA Rule 4511.

Litigation rules set the floor that matters most. FRCP 37(e), amended December 1, 2015, governs sanctions for lost electronically stored information. Zubulake v. UBS Warburg, decided in 2003 and 2004, established that the duty to preserve attaches once litigation is reasonably anticipated.

A retention schedule you can put in the policy

A retention schedule

Record typeKeep forAuthority
Tax return supporting records3 years from filingIRC 6501(a), IRS guidance
Employment tax records4 years after due or paidIRS
Payroll and hours records3 years29 CFR 516.5
Time cards and supporting data2 years29 CFR 516.6
HIPAA compliance documentation6 years45 CFR 164.316(b)(2)(i)
Broker-dealer correspondence3 years, first 2 accessibleSEC Rule 17a-4(b)(4)
Broker-dealer other records6 yearsFINRA Rule 4511
Records under legal holdUntil releasedFRCP 37(e)

Add owner and review date columns in your own version. A schedule nobody audits is a schedule nobody follows.

US Email Retention Schedule

Record type

Tax return supporting records
3 years from filing
Employment tax records
4 years after due
Payroll and hours records
3 years
Time cards and supporting data
2 years
HIPAA compliance documentation
6 years
Broker-dealer correspondence
3 years, first 2 accessible
Broker-dealer other records
6 years
Records under legal hold
Until released

Keep for

Tax return supporting records
IRC 6501(a)
Employment tax records
IRS
Payroll and hours records
29 CFR 516.5
Time cards and supporting data
29 CFR 516.6
HIPAA compliance documentation
45 CFR 164.316(b)(2)(i)
Broker-dealer correspondence
SEC Rule 17a-4(b)(4)
Broker-dealer other records
FINRA Rule 4511
Records under legal hold
FRCP 37(e)

Authority

Tax return supporting records
Employment tax records
Payroll and hours records
Time cards and supporting data
HIPAA compliance documentation
Broker-dealer correspondence
Broker-dealer other records
Records under legal hold

A business email archiving system with retention rules and audit trail features can prove what existed on a given date, how document management systems handle retention. That evidence matters more than the number of years you chose.

Legal hold: when deletion has to stop

  1. Issue a written hold notice the day litigation, a subpoena or a government inquiry becomes reasonably likely.
  2. Suspend automated deletion for named custodians and for shared mailboxes they used.
  3. Copy relevant mail to a separate preservation store with read-only access.
  4. Track acknowledgments and reissue the hold quarterly until counsel releases it.
  5. Record the release date, then let normal retention resume.

Do not treat keeping everything forever as a substitute. Courts and regulators treat it as a cost and privacy problem, and state privacy laws increasingly limit it.

Legal Hold Procedure

  1. Issue written hold notice when litigation likely
  2. Suspend automated deletion for custodians
  3. Copy relevant mail to read-only preservation store
  4. Track acknowledgments and reissue quarterly
  5. Record release date and resume normal retention

A retention policy is only as strong as its deletion log. If you cannot show when a message was destroyed, and under which rule, you have an archive rather than a policy.

Deletion and disposal obligations

Retention is half the job. Several rules also require destruction. The FTC Disposal Rule at 16 CFR 682 requires reasonable measures when disposing of consumer report information. The FTC Safeguards Rule, with an effective date of May 13, 2024, requires a written information security program for covered financial institutions.

Deletion and Disposal Obligations

  • FTC Disposal Rulereasonable measures for consumer report info
  • FTC Safeguards Rulewritten information security program
  • CCPA/CPRAdisclose retention periods at collection
  • State laws (CO, VA, CT)match disclosures to system
  • Name each copy location and purge cycle

California's CCPA, amended by the CPRA effective January 1, 2023, requires businesses to disclose retention periods at collection. State email data retention laws in Colorado, Virginia and Connecticut do the same. Those disclosures must match what your email system actually does.

The FTC guide on protecting personal information recommends safeguards for stored records, protecting personal information guide. Archived mail is stored personal information.

Deleting a message from an inbox is not deletion. Copies sit in backups, journaling mailboxes, eDiscovery holds, phones and third-party archives. A defensible policy names each location and its purge cycle.

Cross-border teams and PIPEDA-safe movement

Canadian businesses do not follow US retention rules, but their US clients often demand US-style archives. That creates a transfer question.

PIPEDA Principle 4.5 requires organizations to destroy, erase or anonymize personal information once it is no longer needed. Moving email to a US provider for processing is permitted, and the Canadian organization stays accountable for it. The Office of the Privacy Commissioner sets out consent and accountability duties in its PIPEDA overview from the OPC.

Vancouver teams serving US clients should document the transfer, name the US processor, and tell individuals that their information may be handled in the United States. For teams moving files to US clients, the same logic covers attachments, contracts and design files, not only inbox mail.

Sharing less is also a retention control

Every attachment you send creates another copy outside your archive. Sending a link keeps one authoritative version with one retention clock.

Teams that compare file sharing alternatives by job, rather than by brand, usually find that own-server options such as Nextcloud and managed transfer tools solve different problems. Versioned repositories handle documents. Managed transfer handles large media.

Fewer copies mean fewer places to search during discovery and fewer places a breach can start.

Common questions

How long should a US business keep email?
There is no single number. Use the longest period that applies to the record underneath: 3 years for payroll, 4 years for employment tax records, 6 years for HIPAA documentation or broker-dealer files.
Can we delete email on a fixed schedule?
Yes, if the schedule is written, applied consistently to every custodian, and suspended when a legal hold applies. Selective deletion by one employee before litigation is the pattern that draws sanctions.
Does an email archive satisfy retention requirements?
It helps. An email compliance policy still needs named owners, review dates and purge cycles. An archive with audit logs shows what existed and when it was removed.
What about email sent to clients in Canada?
PIPEDA follows the personal information, not the server location. Canadian clients must be told about cross-border processing, and the Canadian business remains accountable for that data.

More in Guides

Latest from Reporting Desk