What is Message Archiving & Legal Hold?
The records discipline for business communications — retaining messages to a regulatory schedule, preserving them beyond deletion under legal hold, and auditing access.
Also known as
Message Archiving & Legal Hold — explained.
Message archiving is the systematic retention of business communications as records: messages captured to an organisation-governed archive, kept for a defined retention schedule, searchable for supervisory review and dispute resolution, and disposed of when the schedule expires. Legal hold is the override: when litigation or investigation is reasonably anticipated, affected records are preserved beyond their normal schedule until the hold is released — deleting them after a hold attaches can constitute spoliation with serious legal consequences. For messaging specifically, the obligations are sector-shaped. Financial-services regulators worldwide require firms to retain and supervise business communications on any channel staff actually use — enforcement against firms whose staff conducted business over personal consumer apps has produced fines in the billions cumulatively, which is why 'channel capture' has become a board-level topic. Government bodies operate under public-records law; healthcare providers under clinical-records regulation; and privacy regimes such as GDPR and PDPL add data-subject rights and minimisation duties that shape how archives must be governed. The design question for an [end-to-end encrypted](/glossary/end-to-end-encryption) platform is where the archive sits and who holds it: the credible enterprise answer is an organisation-held archive — inside the operator's perimeter, governed by its policy, with supervisory access itself audited and archiving policy-visible to staff — rather than either a vendor-accessible backdoor or no archive at all. Retention schedules, review workflows, hold procedures, and export formats are mapped from the operator's actual regulatory framework during scoping, which is how Zeour engineers the archive in each NOVARYX deployment.
Why operators care about message archiving & legal hold.
The most expensive messaging failure of the last decade was not a breach — it was regulated staff doing official business on personal apps with no archive. If official communications happen on a channel, that channel must produce records; a platform that cannot archive is a platform your compliance team cannot approve.
Buyer's checklist
- Organisation-held archive inside your perimeter — not vendor-accessible storage
- Retention schedules configurable to your regulatory framework
- Legal hold that preserves records beyond deletion and disappearing-message policies
- Supervisory review workflows with audited access to the archive itself
- Export in formats your legal and eDiscovery tooling accepts
- Policy-visible archiving — staff know official channels are records
Zeour solutions that operate on this layer.
Verticals where message archiving & legal hold is operationally critical.
Blog posts that go deeper on message archiving & legal hold.
Adjacent definitions to read next.
Secure Enterprise Messaging
Secure CommunicationsOrganisation-governed instant messaging for official business — encrypted, directory-controlled, policy-managed, and archived to the organisation's regulatory obligations.
End-to-End Encryption (E2EE)
Secure CommunicationsAn encryption model where content is encrypted on the sender's device and decrypted only on the recipient's — every system in between, including the server, handles ciphertext only.
GDPR
Compliance & DataThe EU's data-protection regulation — establishes consent, purpose-limitation, residency, breach-notification, and the data-subject rights regime.
PDPL
Compliance & DataPersonal Data Protection Law — the data-protection regime in Saudi Arabia (and equivalents in the UAE and several Gulf states).
CCPA / CPRA
Compliance & DataCalifornia's data-protection law — and the CPRA amendment in force since 2023 — establishing data-subject rights for California residents.
Cyber Essentials
Compliance & DataThe UK NCSC's baseline cybersecurity certification — a five-control posture (firewalls, secure config, access control, malware, patches) increasingly required for UK government contracts.
Data Subject Access Request (DSAR)
Compliance & DataThe data-subject's right to request a copy of all personal data an operator holds about them, plus deletion, correction and processing-restriction rights — under GDPR, PDPL and equivalent laws.
Explicit Consent
Compliance & DataConsent that is specific, informed, unambiguous and given by a clear affirmative action — separate tickboxes per purpose, not bundled — required under GDPR, PDPL and equivalent laws.
Talk to a Zeour engineer.
A 30-minute scoping call to walk your operational profile against where message archiving & legal hold actually sits in your stack, then a fixed-fee Discovery price by the end of the call.