A partner deletes an email in 2023 because it looks embarrassing in hindsight — a terse reply to a client, a throwaway comment on a matter that later goes sideways. Three years later, that matter turns into a dispute, opposing counsel serves a discovery request, and the email turns up anyway. Not from the mailbox it was deleted from, but from a backup snapshot, a synced phone, or the recipient's own inbox, which was never touched. Deleting an email from one place almost never deletes it from every place — and firms that assume otherwise are making decisions on a false premise.
Why "deleted" doesn't mean gone
Modern email systems are built for redundancy, not disappearance. When someone deletes a message in Outlook or Gmail, it typically moves to a Deleted Items or Trash folder, then sits in a recoverable state for 30 days or more before permanent purge — and even after that, Microsoft 365 and Google Workspace retain litigation-hold and backup copies that admins can pull back. Mobile devices sync independently; a message deleted on a desktop client may still exist on a phone that hasn't synced since. And critically, every email has at least one other copy by design — sitting in the recipient's mailbox, on their device, in their backups, entirely outside your firm's control.
For litigation purposes, this matters enormously. Under the Federal Court of Australia's Practice Note GPN-DISC and equivalent discovery rules in the UK (Civil Procedure Rule 31) and the US (FRCP 34), a party's duty to preserve relevant documents attaches once litigation is reasonably anticipated — not once proceedings are filed. Deleting a relevant email after that point, even inadvertently, can constitute spoliation. Courts have sanctioned parties for exactly this: assuming a deleted email was gone, only for it to resurface from a backup tape or the other side's production, at which point the deletion itself becomes the story.
What most small firms actually do
Most firms under 20 people have no real retention schedule — they have habits. Emails sit in individual mailboxes until someone runs out of storage quota, at which point they get archived to a PST file, moved to a shared drive, or just deleted to free up space. Nobody applies a consistent rule about what gets kept, for how long, or why. This works fine until it doesn't: a staff member leaves and their mailbox gets wiped before anyone checks whether it held relevant client correspondence, or a regulator asks for "all correspondence relating to this file" and the honest answer is "some of it, from whoever still has it."
What good looks like
A defensible position isn't "we never delete anything" — that's not realistic and not required. It's having a documented, consistently applied retention schedule, and an archive that can prove what was kept, for how long, and that it wasn't altered afterwards. Four things matter in practice.
Continuous capture. Every message — sent and received — gets archived as it happens, not swept up later from whatever mailboxes still have it. Sent mail matters as much as received mail; it's usually the firm's own correspondence that gets requested.
Tamper-evident storage. The archive needs to demonstrate that messages haven't been edited or backdated after the fact. This is what separates an archive from a folder of exported emails — a regulator or opposing counsel can ask you to prove integrity, not just produce a copy.
Full metadata preservation. Headers, timestamps, attachments, and thread context need to survive intact. A message stripped of its metadata is far weaker as evidence and harder to authenticate.
Fast, complete retrieval. When a request comes in — from a regulator, a court, or your own risk team — you need to search and produce relevant correspondence within days, not weeks of manually trawling PST files and asking staff to check their phones.
This is the gap AutoArchive Mail is built to close: it captures every message continuously as it's sent or received, stores it in a tamper-evident format with full metadata intact, and makes the whole archive searchable, so retrieval is a query rather than a forensic exercise.
The practical path forward
Start with what you can do this week. Check whether your current email platform has litigation hold or retention policies enabled — Microsoft 365 and Google Workspace both offer this, but it's usually off by default. Write down, even briefly, what your firm currently does with old email — the honest version, not the policy you meant to write. That document alone is useful if a regulator ever asks.
Next, decide on retention periods by matter type, based on the rules that actually apply to your practice — 7 years for most Australian financial and legal records under the Corporations Act and state bar rules, longer for specific categories like trust account records. Then put continuous, automated capture in place rather than relying on manual archiving, since manual processes are the ones that lapse when someone's busy or leaves. You can Start Free Trial to see what continuous capture looks like without committing to a full migration first. If your firm has been through a regulatory inquiry, a major client dispute, or a messy staff departure in the last few years, it's worth having a solicitor review your retention position specifically — general guidance won't cover firm-specific exposure.
One limitation
This article covers email retention and discoverability generally — it doesn't address jurisdiction-specific privilege rules, which determine whether a discovered email can actually be used even once it's found. That's a legal question specific to your matter, not an archiving one, and it needs a lawyer's judgment, not a policy.
Ready to automate your email archiving?
AutoArchive Mail captures every email automatically — incoming and outgoing — with clean filenames and full .MSG preservation. 14-day free trial, no credit card required.
Start Free Trial See How It Works