• forkDestroyer@infosec.pub
    link
    fedilink
    English
    arrow-up
    3
    ·
    15 hours ago

    My company locks it down and deletes email older than 3 months but default unless you request a special group asking for longer storage.

    • jj4211@lemmy.world
      link
      fedilink
      English
      arrow-up
      10
      ·
      15 hours ago

      Ah yes, the “it’s not evidence tampering if we just delete the stuff as a matter of course” policy.

      • forkDestroyer@infosec.pub
        link
        fedilink
        English
        arrow-up
        3
        ·
        11 hours ago

        Which makes no sense to me because I could swear there’s a legal retention policy that supercedes this.

        • jj4211@lemmy.world
          link
          fedilink
          English
          arrow-up
          1
          ·
          5 hours ago

          I presume longer retention policies apply to specific data rather than arbitrary communications. The place I worked with a 90 day deletion was maniacal about adhering to the letter of the law and they didn’t seem broadly concerned about any data that was solely in email.

          Well until they went to sue someone else, then they’d grab and freeze all email boxes that ever communicated with the defendant and instruct all parties to immediately forward any email from that party to legal and ignore it.

        • Buddahriffic@lemmy.world
          link
          fedilink
          English
          arrow-up
          4
          ·
          11 hours ago

          Likely the penalty for not retaining the data is less severe than any penalty for getting caught with evidence of illegal actions, so it’s the default action to reduce risk when you’re doing illegal shit.