Skip to content

Legal holds

A legal hold, or litigation hold, keeps data from being destroyed while a case, a regulator's request or an internal investigation needs it. While a hold covers something, nobody can destroy it: not the user, not a delegate, not an administrator, and not the server's own clean-up.

The people it covers aren't told, and their mail works as before. What they delete disappears from their view as usual, but is kept.

Holds are under Management › Compliance › Legal holds. Server administrators and server-level compliance officers see and place them; see Who can place holds.

Legal holds: an active hold on a domain from January, what it covers and keeps now, and a released one below

What a hold keeps

Everything in the accounts it covers: mail, calendar events, contacts, files and filter scripts.

  • Anything deleted is kept in the archive, with no expiry. That includes deletions from any app or protocol, emptying Trash, removing a folder with its mail, and the server emptying Trash and Junk on its schedule. It happens even if undelete is switched off.
  • Items already in the archive when the hold is placed are kept too. Something deleted yesterday and still restorable stays.
  • A held archived item can't be deleted for good. Restoring it is still allowed, since that destroys nothing.
  • A held account can't be destroyed. Deleting it removes the login, so the person disappears and can't sign in, and offboarding goes ahead. Its data is kept as a deleted account with no expiry, and its addresses stay reserved. Destroy now refuses it.

A hold keeps messages, not their history: flags and folders aren't recorded as they change. Mail refused before delivery, or discarded by a filter, was never stored, so it can't be held.

Held items don't count against anyone's quota, so a person who deletes mail to make room still gains the room. They do take space on the server. Each hold shows how much.

Placing a hold

Place a hold… asks for:

  • Case name, and an optional Reference (a matter or ticket number) and Description.
  • What it covers: people, groups, domains, tenants, or every account on the server.
  • Dates, optional. Leave both empty to hold everything.
  • A reason, which goes into the audit log.

Placing a hold on two people, from July, with a reference and a reason

Who a hold covers

Domains, groups and tenants count as they are now, not as they were when the hold was placed:

  • an account added to a held domain, group or tenant later is held too;
  • an account moved out of one stays held: the hold names it from then on;
  • an account counts as in a domain if any of its addresses are there.

Dates

With dates, only what falls in the range is held. The dates are whole UTC days.

Kind Which date counts
Mail When it arrived
Calendar events When they start, with a day's leeway for time zones. Repeating events are held whole.
Contacts, files, filter scripts None: held whole

Without an end date, mail still to come is held too. Outside the range, things behave as if there were no hold: undelete's rules, then gone.

Arrival dates on imported mail

A mail app that imports old mail can set when it arrived, but only on a new message, never on one already stored.

Changing a hold

A hold can only grow. Widen… can add accounts, groups, domains or tenants, or move the dates outward. Nothing can be taken out and the range can't be narrowed, since that would free what the hold kept. To hold less, release the hold and place a new one.

Each change needs a reason and is recorded.

What a hold keeps now

Each hold on the page shows how many accounts it covers (deleted ones it keeps included), how many deleted items it's keeping, and their size.

A person's page under Management › Directory › Accounts says which holds cover them. Only those who can see holds see this.

Exporting what a hold keeps

Export… on an active hold collects what it keeps into one ZIP file, for counsel, a regulator or a review tool. Give a reason, and pick people if you want only some of those it covers; leave it empty for all of them. The server builds the file in the background, so you can leave the page. The hold's card lists its exports, newest first, and shows Ready with a Download button when one is done.

A legal hold with three finished exports, each with its reason, item count, size, SHA-256 and a Download button

Each person gets a folder named by their address:

Path What
mail/<folder>/ Their mail, as .eml files, under the folder it's in
calendar/<calendar>/ Events, as .ics
contacts/<address book>/ Contacts, as .vcf
files/ Their files, as stored
archived/<kind>/ What they deleted that the hold keeps

Beside the folders, manifest.csv has a line for every file: its path, account, kind, folder, date, whether it was deleted, size and SHA-256. manifest.sha256 is the manifest's own SHA-256, so a copy can be checked against the original later.

What goes in follows the hold:

  • People it doesn't cover are left out, even if you pick them.
  • Its dates apply as they do to what it keeps: mail by the day it arrived, events by the day they start. Contacts and files have no date, so all of them go in.
  • Deleted accounts it keeps are included.
  • Deleted items another hold keeps are left out unless this hold's dates cover them too.

Things to know:

  • Only the person who started an export can download it. The file is theirs.
  • The file doesn't last. It's kept as long as an upload: an hour, unless Expire after under Settings › Mail & apps › JMAP limits says otherwise. The export's record, with its SHA-256, stays on the hold's card. Start a new one if the file has gone.
  • One export holds up to 2 GB. A bigger one fails and says so; export a few people at a time.
  • Each export is recorded in the audit log, with who started it and why.

Releasing a hold

Release… asks you to type the case name and give a reason. Then:

  • What only this hold kept gets its normal deadline back, but never less than 30 days from the release. A release made by mistake can be undone within those 30 days by placing a new hold.
  • Anything another hold covers stays held.
  • Deleted accounts it kept are destroyed 30 days later, not before.

A released hold stays on the page, read-only, with who released it, when and why. It can't be put back; place a new one instead.

Who can place holds

Server-level administrators and compliance officers. The Administrator and server-level Compliance Officer roles have all four:

Permission Lets you
See legal holds See holds, and which holds cover an account
Place legal holds Place one
Widen or release legal holds Widen or release one
Export held data Export what a hold keeps

Nobody in a tenant can have them, whatever their role says, tenant administrators and a tenant's compliance officer included, since a hold may concern the tenant's own administrator.

Every hold's placing, widening and release is in the audit log, with its reason. Audit records about a held account aren't removed by the log's retention while it's held.

Holds and locked accounts

A locked account and a hold do different things. A lock stops the owner signing in; a hold stops anything being destroyed. A delegate with Full access to a locked, held account can still delete mail from view, but the hold keeps it in the archive.