TwistedHelixis Posted May 23, 2019 Posted May 23, 2019 If Google Vault email retention has been set to forever and someone deleted an email last year and also deleted the email from their bin, would that email still be retained in Vault? The Google blurb says that it only retains deleted emails for 1 month, but wanted to check.
ChrisMiles Posted May 23, 2019 Posted May 23, 2019 Deleted emails in the vault are kept for 25 days unless covered by a retention or hold so if your mail retention is set to forever then it should stay in the vault for forever. 1
TwistedHelixis Posted May 23, 2019 Author Posted May 23, 2019 So what effect does fault have on emails if the retention is set to 1 year? Does it go in to the users inbox and delete all emails over 1 year old, or does it only effect emails that have been deleted from the bin?
TwistedHelixis Posted May 23, 2019 Author Posted May 23, 2019 Just read this Set retention rules to control how long data is retained before being removed from user accounts and deleted from Google systems. So it will go in to an account and delete the data that is older than xxx
ChrisMiles Posted May 23, 2019 Posted May 23, 2019 Vault will purge data from user accounts that falls outside the configured retention period. So if you set it to 1 year, emails older than this will be removed from your whole domain. See about retention here: https://support.google.com/vault/answer/2990828?hl=en 1
Ditto Posted May 23, 2019 Posted May 23, 2019 Perhaps like others, we had retention at forever, but this was set pre-GDPR. Post GDPR, I think it is nigh on impossible to justify. The issue I see is how do you separate emails that might have 40 year retention recommendation (see other recent thread http://www.edugeek.net/forums/data-protection-information-handling/206718-irms-toolkit-schools-updated.html) from those that might 3 to 6 years? I believe even if you delete from email accounts, the vault will still be holding on to them. And then let's suppose we do identify what we want to remove from the vault - is that an easy thing to do?
TwistedHelixis Posted May 23, 2019 Author Posted May 23, 2019 Are files and documents that are in Vault still under GDPR control, I seem to remember backups being exempt from some aspects.
TwistedHelixis Posted May 23, 2019 Author Posted May 23, 2019 (edited) This is the issue as I see it. We need to retain one type of email or document for 1 year and another type for 10 years. We can't set a retention period of less then 10 years as the system would go in and delete any emails or files we need to keep for 10 years. So we have to set the retention to 10 years. Then the school doing what they should do, manually delete the emails or documents that need to be removed after one year, except Vault has been set to keep all emails and documents for 10 years, so those documents that have been deleted after one year will still be kept for 10 years , it's a catch 22. UPDATE: Just posted this as a new question - http://www.edugeek.net/forums/data-protection-information-handling/206886-google-vault-retention-catch-22-a.html#post1769107 Edited May 23, 2019 by TwistedHelixis
ZeroHour Posted May 23, 2019 Posted May 23, 2019 Are files and documents that are in Vault still under GDPR control, I seem to remember backups being exempt from some aspects. If it exists I would expect them to be covered by GDPR and SAR. It sounds like you need something like o365 sensitivity categories, it allows you to tag things as keep for x time and others get removed although I have not looked into it in anger.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now