Skip to content
Live13+ production solutions40+ clients deployeddirect + partner
Glossary · Compliance & Data

What is Message Archiving & Legal Hold?

The records discipline for business communications — retaining messages to a regulatory schedule, preserving them beyond deletion under legal hold, and auditing access.

Also known as

message archivinglegal holdcommunications retentionsupervisory reviewrecords retention
Definition

Message Archiving & Legal Hold — explained.

Message archiving is the systematic retention of business communications as records: messages captured to an organisation-governed archive, kept for a defined retention schedule, searchable for supervisory review and dispute resolution, and disposed of when the schedule expires. Legal hold is the override: when litigation or investigation is reasonably anticipated, affected records are preserved beyond their normal schedule until the hold is released — deleting them after a hold attaches can constitute spoliation with serious legal consequences. For messaging specifically, the obligations are sector-shaped. Financial-services regulators worldwide require firms to retain and supervise business communications on any channel staff actually use — enforcement against firms whose staff conducted business over personal consumer apps has produced fines in the billions cumulatively, which is why 'channel capture' has become a board-level topic. Government bodies operate under public-records law; healthcare providers under clinical-records regulation; and privacy regimes such as GDPR and PDPL add data-subject rights and minimisation duties that shape how archives must be governed. The design question for an [end-to-end encrypted](/glossary/end-to-end-encryption) platform is where the archive sits and who holds it: the credible enterprise answer is an organisation-held archive — inside the operator's perimeter, governed by its policy, with supervisory access itself audited and archiving policy-visible to staff — rather than either a vendor-accessible backdoor or no archive at all. Retention schedules, review workflows, hold procedures, and export formats are mapped from the operator's actual regulatory framework during scoping, which is how Zeour engineers the archive in each NOVARYX deployment.

Why it matters

Why operators care about message archiving & legal hold.

The most expensive messaging failure of the last decade was not a breach — it was regulated staff doing official business on personal apps with no archive. If official communications happen on a channel, that channel must produce records; a platform that cannot archive is a platform your compliance team cannot approve.

What to look for in a vendor

Buyer's checklist

  • Organisation-held archive inside your perimeter — not vendor-accessible storage
  • Retention schedules configurable to your regulatory framework
  • Legal hold that preserves records beyond deletion and disappearing-message policies
  • Supervisory review workflows with audited access to the archive itself
  • Export in formats your legal and eDiscovery tooling accepts
  • Policy-visible archiving — staff know official channels are records
Related terms

Adjacent definitions to read next.

Secure Enterprise Messaging

Secure Communications

Organisation-governed instant messaging for official business — encrypted, directory-controlled, policy-managed, and archived to the organisation's regulatory obligations.

End-to-End Encryption (E2EE)

Secure Communications

An encryption model where content is encrypted on the sender's device and decrypted only on the recipient's — every system in between, including the server, handles ciphertext only.

GDPR

Compliance & Data

The EU's data-protection regulation — establishes consent, purpose-limitation, residency, breach-notification, and the data-subject rights regime.

PDPL

Compliance & Data

Personal Data Protection Law — the data-protection regime in Saudi Arabia (and equivalents in the UAE and several Gulf states).

CCPA / CPRA

Compliance & Data

California's data-protection law — and the CPRA amendment in force since 2023 — establishing data-subject rights for California residents.

Cyber Essentials

Compliance & Data

The UK NCSC's baseline cybersecurity certification — a five-control posture (firewalls, secure config, access control, malware, patches) increasingly required for UK government contracts.

Data Subject Access Request (DSAR)

Compliance & Data

The data-subject's right to request a copy of all personal data an operator holds about them, plus deletion, correction and processing-restriction rights — under GDPR, PDPL and equivalent laws.

Explicit Consent

Compliance & Data

Consent that is specific, informed, unambiguous and given by a clear affirmative action — separate tickboxes per purpose, not bundled — required under GDPR, PDPL and equivalent laws.

Want to discuss message archiving & legal hold for your operation?

Talk to a Zeour engineer.

A 30-minute scoping call to walk your operational profile against where message archiving & legal hold actually sits in your stack, then a fixed-fee Discovery price by the end of the call.