GDPR Email Archiving: Retention, Access, and Deletion You Can Explain
GDPR does not require a brand-name archive. It requires a place mail actually lives, a way to find a person’s data, and a way to delete or export it. On-premise options versus leaving everything in Microsoft 365.
GDPR is a process, not a SKU
You need: a lawful basis and schedule for keeping mail, a way to find a data subject’s messages (SAR), a way to export them in a reasonable format, and a way to erase what you should not keep. An archive that cannot delete is as wrong as a mailbox that cannot find.
This is not legal advice. It is the infrastructure conversation that legal then blesses. Related: legal discovery, on-prem comparison.
Why “we have backups” fails
Backups are rolling and slow to search. Users delete from live mail. Cloud tenants apply their own retention. An archive with MIME-faithful storage, search, export, and expiry is the usual engineering answer. Redaction of exports (Hexamail Flow on this site) is a neighbouring job, not a substitute for the store.
On-prem vs Microsoft holding the record
Purview can support GDPR if configured and licensed. On-prem (Vault, MailStore, Cryoserver) supports GDPR-style control when the organisation refuses to make Microsoft the only copy. Data residency is a policy choice; the software must match it.
Hexamail Vault
Verbatim MIME, full-text index, rule-based include/exclude, retention expiry, EML/zip export, web search, data on your disks (Windows or Linux). Pair with a written retention schedule or you have only bought a bigger disk.
app cta