- Keeping everything forever is expensive and risky; deleting too soon can be worse.
- Here is a practical, category-based framework for how long to keep business email.
Few Nepali businesses have a written email retention policy — most either keep everything indefinitely by default or lose data accidentally with no policy at all. Both extremes carry real costs. A short, deliberate policy fixes both.
Why Retention Policy Matters
- Legal exposure: tax authorities and courts can request historical financial correspondence — missing records create real problems.
- Storage cost: unlimited retention on paid platforms is not actually unlimited storage cost.
- Discovery risk: old, forgotten emails can resurface in disputes; a defined policy with documented deletion is a legitimate defense.
A Practical Category Framework
| Category | Suggested retention |
|---|---|
| Financial records, invoices, tax correspondence | 7 years |
| Contracts and legal correspondence | Life of contract + 5–7 years |
| HR records (hiring, termination) | 5–7 years post-employment |
| General internal correspondence | 1–2 years |
| Marketing and newsletters | 6–12 months |
Adjust categories to match your industry's actual legal requirements — consult a Nepali accountant or lawyer for finance and compliance-specific minimums.
Implementing the Policy
- Document it in writing and share it with all staff.
- Use platform retention/archiving rules (Google Vault, similar tools) to automate enforcement rather than relying on manual deletion.
- Ensure automated deletion excludes anything under legal hold.
- Review the policy annually as the business and regulations evolve.
What "Legal Hold" Means and Why It Overrides the Schedule
A legal hold is a deliberate suspension of normal deletion rules for specific correspondence relevant to an actual or reasonably anticipated dispute, audit or investigation — even if the standard retention schedule would otherwise call for deleting it. Automated retention tools that lack a legal-hold exception risk deleting exactly the evidence a business needs during a dispute, purely because a scheduled deletion job ran on time. Any automated enforcement of the category framework above should include a manual override mechanism, checked before enabling automatic deletion, for the (hopefully rare) case where specific correspondence needs to survive past its normal category's schedule.
Retention Policy Is Not the Same Thing as Backups
These two get treated as one topic and they are not. A backup exists to restore data after accidental loss — a deleted mailbox, a corrupted server, a fat-fingered bulk-delete — and typically covers a short rolling window (days to a few weeks) before older backup copies themselves age out. A retention policy exists for a different reason entirely: deciding, deliberately, how long specific categories of business correspondence should exist at all, for legal and operational reasons, independent of whether anything ever gets accidentally deleted. The two can work against each other if nobody notices: a company with a strict 1-year retention policy on general correspondence but backups quietly retained for 5 years has, in practice, no real retention policy at all, because the "deleted" emails are still fully recoverable from backup. Any organization implementing the category framework above should confirm with their hosting or email provider exactly how long backup copies persist after a message is deleted through the retention schedule, and align the two deliberately rather than assuming deletion in one system means deletion everywhere.
Frequently Asked Questions
Is it safer to just keep everything forever?
Not necessarily — unmanaged retention increases legal discovery exposure and storage cost without a corresponding benefit.
Do I need a lawyer to write this policy?
For general correspondence, this framework is a solid starting point. For finance and HR specifics, brief legal review is worthwhile.
Should this policy apply to WhatsApp or other messaging platforms used for business too?
In principle yes — if business-relevant communication happens outside email, the same retention logic and legal-hold awareness should extend there, though the practical tooling to enforce it varies by platform.
Need archiving tools alongside your email hosting? See our business email plans or ask our team.
Communicating the Policy to Staff Clearly
A retention policy that exists only as a document nobody has read provides little real protection. A short, plain-language summary shared during onboarding and revisited annually — covering what gets kept, for how long, and why — ensures staff understand the reasoning well enough to flag edge cases (an email that seems like it should be kept longer than its category suggests) rather than deleting or retaining purely by habit.