Neither Google Workspace nor Microsoft 365 (Outlook) was built as a compliance archive, and both make that clear the moment you actually need to produce seven years of correspondence for a regulator, a court, or a departing partner's replacement. Google Vault and Microsoft Purview each offer retention holds; neither gives a 30-person firm a genuinely audit-ready archive out of the box. The difference is in where each one quietly runs out of road.
Picture the scenario: a former client lodges a complaint with the Law Society two years after their matter closed, and asks for every email exchanged with the handling solicitor. The solicitor left the firm eighteen months ago. Their mailbox was reassigned, then archived to a PST that lives on an IT contractor's external drive somewhere. Someone has to find it, open it in Outlook, and hope the file isn't corrupted. This is not a hypothetical — it's the single most common way small professional services firms discover their email retention has a hole in it.
What the retention rules actually require
In Australia, law firms face retention obligations that vary by state but commonly run 7 years from matter closure (see NSW Law Society Rule 1.15 as one reference point), and longer for trust account records. Accountants and financial advisers fall under the Corporations Act 2001 (Cth), which requires 7 years of financial record retention, plus AML/CTF Act obligations for reporting entities. In the UK, SRA Standards and Regulations require solicitors to retain client files for at least 6 years, and FCA-regulated advisers face similar minimums under COBS record-keeping rules. In the US, FINRA Rule 4511 and SEC 17a-4 impose retention and, critically, tamper-evidence requirements on broker-dealers and advisers.
The common thread: it's not just "keep the emails somewhere." Regulators and courts expect you to produce a complete, unaltered record on request — including sent mail, not just received — within a reasonable timeframe. A PST file nobody can locate, or a mailbox that was deleted when an employee's licence lapsed, doesn't meet that bar, regardless of what your retention policy document says.
What most small firms actually do
Most firms under 50 people do one of three things: rely on the mailbox itself as the archive (fine until someone leaves or a license is removed), export periodically to PST or MBOX files sitting on a shared drive (fine until someone needs to search across five years of them), or trust that "it's all in the cloud, so it's covered" (not what either vendor's terms actually promise). All three work adequately right up until there's a departure, a device wipe, or a subject access request that requires searching mail nobody has opened in three years. That's usually the point at which someone discovers a gap.
Where Google Workspace and Outlook diverge
Google Vault, included with Workspace Business Plus and Enterprise tiers, applies retention rules and litigation holds across Gmail, Drive, and Chat, and its search is genuinely fast. The catch: Vault retains what existed in the account at the time the rule applied — it doesn't independently capture a tamper-evident copy at the moment of send/receive. If a user deletes and then the account is later suspended before the hold caught it, or if you're on a lower Workspace tier without Vault at all, there's a gap. Vault also doesn't preserve full email headers and metadata in a form easily portable to a third-party review platform — exports come out as MBOX, which is workable but requires additional tooling to make searchable at scale.
Microsoft Purview (formerly the Compliance Center) does something similar for Microsoft 365 mailboxes, and its retention policies are arguably more granular — down to specific labels and per-folder rules. But Purview's full compliance features, including In-Place eDiscovery holds that survive mailbox deletion, sit behind E3/E5 licensing that most 20-person firms haven't bought; the standard Business Premium tier gives you considerably less. And like Vault, Purview retains what's in the mailbox — it's a retention layer over live data, not an independent capture stream, which matters if an admin account is compromised or a hold is misconfigured.
Neither platform, in short, gives you continuous, independent, tamper-evident capture as a default. Both require you to actively configure the right tier, the right policy, and the right holds — and to keep checking that configuration as staff and licensing change.
What good looks like
An audit-ready archive has a few characteristics regardless of which mail platform sits underneath it. It captures every message — sent and received — continuously, at the point of transmission, independent of mailbox retention settings or license status. It's tamper-evident: once archived, a message can't be quietly edited or deleted by an admin, a departing employee, or an attacker. It preserves full metadata — headers, timestamps, attachments — not just message bodies. It's searchable across the whole retention period in one place, not scattered across PST files and two different vendor consoles. And it survives platform changes: if the firm migrates from Google to Microsoft or vice versa, the archive doesn't reset to zero.
This is the gap both native tools leave. Vault and Purview are retention features bolted onto a live mailbox system; a proper archive is a separate, independent system of record. AutoArchive Mail captures every message continuously as it's sent and received, across both Google Workspace and Microsoft 365, storing it in a tamper-evident archive that's fully searchable regardless of what happens to the original mailbox — so a license change, a deleted account, or a platform migration doesn't create a hole in seven years of records.
The practical path forward
Start today: check which Workspace or Microsoft 365 tier you're actually on, and confirm whether Vault or Purview compliance features are included or an add-on. Most firms assume they have retention holds configured when they don't. Next, audit departed staff from the last three years — are their mailboxes and any exported PSTs still accessible and searchable? If you can't answer that in under ten minutes, that's your gap.
For firms under 10 people with under 3 years of retention exposure, careful use of native retention labels plus a disciplined PST export process can be adequate — it's manual, but manageable at that scale. Past 10 people, or once you're carrying multi-year retention obligations under bar rules, AML regulations, or ASIC/FCA requirements, the manual process becomes the risk. That's the point to look at independent archiving — Start Free Trial is a reasonable way to see what continuous capture looks like against your actual mailboxes before committing. If you're also holding data subject to GDPR or an equivalent privacy regime, loop in your solicitor on retention versus deletion obligations — those two requirements sometimes pull in different directions, and that's a legal judgment call, not a technical one.
One limitation
This comparison covers email specifically. Both Vault and Purview also touch Drive, Teams, and Chat records, which have their own retention questions this article doesn't address — if your firm's compliance exposure extends to chat platforms or shared drives, that needs separate treatment.
Ready to automate your email archiving?
AutoArchive Mail captures every email automatically — incoming and outgoing — with clean filenames and full .MSG preservation. 14-day free trial, no credit card required.
Start Free Trial See How It Works