Skip to content

Home Topics Email Compliance Data retention and DSARs

Email Compliance · Data retention and DSARs

Email data retention examples: what good and bad look like

Short answer

A good email data retention implementation follows these steps: Classify data: consent records, engagement logs, message content; Set retention periods per class and automate deletion. A bad one typically deleting consent records that you need to defend a complaint.

Data retention policy defines how long mailbox data and marketing records are kept and when they are deleted. DSARs (data subject access requests) require producing or erasing a person's data on request.

What good looks like#

  • Done: Classify data: consent records, engagement logs, message content.
  • Done: Set retention periods per class and automate deletion.
  • Done: Build a DSAR process that can search and export across ESP, CRM, and mailbox.
  • Done: Log every deletion and export for accountability.

What bad looks like#

  • Seen in audits: Deleting consent records that you need to defend a complaint.
  • Seen in audits: No process for AI tools that have processed mailbox content.

How to move from bad to good#

Work through the good list in order and re-verify after each change. Most teams find one or two items from the bad list already present; fixing those usually produces the largest improvement.

Frequently asked questions#

How long can I keep unsubscribed contacts?

Keep the suppression record indefinitely (email only) so you never re-mail them; delete profile data per your retention schedule.

Keep reading on Data retention and DSARs