- Why getting this wrong carries real consequences
- Step 1: Work out which emails are actually legal records
- Step 2: Check whether a dispute or investigation is on the horizon
- Step 3: Address privacy obligations for personal information in emails
- Step 4: Build a simple, written email retention framework
- How Artificer Legal can help you get this right
- The one thing to carry away from this
The company has just wrapped up a long project, the team inbox is overflowing, and someone has raised the idea of doing a mass clean-up. It sounds straightforward — until your IT manager asks whether there is a policy, your accountant mentions that some of those threads might be financial records, and your HR adviser points out that a former employee's performance emails are probably in there somewhere. Suddenly, "delete everything older than two years" feels a lot less simple.
Why getting this wrong carries real consequences
Emails are not just messages. In most businesses, the inbox quietly accumulates contracts, invoices, pay queries, supplier negotiations, customer complaints, and instructions that carry legal weight. Deleting the wrong email at the wrong time can leave a business unable to explain a transaction to the ATO, unable to defend an unfair dismissal claim, or — in the worst case — facing allegations that evidence was destroyed ahead of a dispute.
The exposure is not theoretical. The Corporations Act 2001 (Cth), the Fair Work Act 2009 (Cth), the Privacy Act 1988 (Cth), and tax law each impose distinct obligations that can reach into your inbox. A court or regulator is unlikely to accept "we didn't know" as a defence when an obligation was clearly on the books.
There is also a tension that sits at the heart of the issue: privacy law says you should not hold personal information longer than you need it, while other laws say you must keep certain records for years. Threading that needle requires a deliberate framework, not good intentions.
Step 1: Work out which emails are actually legal records
Before anything is deleted, someone needs to ask whether the email is the only copy of a record that the business is legally obliged to keep.
The most common obligations that pull business emails into the "must retain" category are:
- Corporate financial records — under s 286 of the Corporations Act 2001 (Cth), a company must keep written financial records that correctly record and explain its transactions for at least seven years after the transactions are completed. Emails containing contracts, purchase approvals, payment authorisations, and invoices commonly fall within this obligation.
- Tax records — the ATO generally requires businesses to keep records for five years from when the record was prepared or the transaction completed, whichever is later. For assets subject to capital gains, the period can extend beyond that. Email threads that substantiate income, deductions, payroll, or superannuation contributions fall within this net.
- Employment records — under s 535 of the Fair Work Act 2009 (Cth), employers must make and keep prescribed employee records for seven years. Those records include pay rates, hours worked, leave, and other conditions of employment. Emails discussing rosters, pay adjustments, leave approvals, warnings, or termination are likely to form part of that record.
- Consumer correspondence — emails about warranty claims, refunds, product defects, and complaints may need to be retained long enough to manage any claim under the Australian Consumer Law (Schedule 2 of the Competition and Consumer Act 2010 (Cth)).
If any category applies to an email, the record should be saved to a dedicated system — a document management platform, HRIS, or finance system — before the email is removed from the inbox. The inbox should not be the only place a legal record lives.
What is generally safe to delete are genuinely low-value messages: vendor newsletters, automated system alerts, internal scheduling notes, and promotional emails that do not contain anything of legal significance. The test is whether the email records or evidences a transaction, commitment, decision, or obligation.
Step 2: Check whether a dispute or investigation is on the horizon
Even if an email would otherwise be outside a mandatory retention window, it must be preserved if the business has reasonable grounds to anticipate a legal dispute or regulatory inquiry.
Once a client threatens legal action, an employee lodges a formal complaint, a regulator requests documents, or an audit is announced, a business is under a practical and legal obligation to suspend deletion of any potentially relevant material. Deleting emails in this context risks a finding that evidence was destroyed — a serious problem in any litigation or regulatory proceeding.
Practically, this means:
- Identifying the categories of emails likely to be relevant (timeframe, participants, topics).
- Suspending any automated deletion rules that touch those categories.
- Communicating clearly to staff that a hold is in place and what it covers.
- Keeping the hold in place until the matter is fully resolved.
This kind of arrangement is often called a litigation hold. It does not need to be elaborate — a written instruction to relevant staff, with a clear scope, is usually enough to start. The key is that it happens quickly, before anything is lost.
Step 3: Address privacy obligations for personal information in emails
Business emails frequently contain personal information: customer names, contact details, health information, financial information, and staff data. If your business is an APP entity under the Privacy Act 1988 (Cth) — broadly, this covers businesses with an annual turnover above $3 million, health service providers, businesses that trade in personal information, and others — the Australian Privacy Principles (APPs) impose two competing obligations.
Under APP 11, an APP entity must take reasonable steps to protect personal information it holds from misuse, interference, and loss, and must take reasonable steps to destroy or de-identify personal information that it no longer needs for any purpose for which it may lawfully be used or disclosed.
This creates a floor and a ceiling for email retention:
- Floor — if another law requires you to keep a record that contains personal information, you must keep it for the prescribed period.
- Ceiling — once that period ends (or no mandatory period applies), continuing to hold personal information indefinitely exposes you to a potential breach of APP 11. You are expected to destroy it or de-identify it.
For emails that contain personal information but are not subject to any mandatory retention period, the practical obligation is to delete them once you no longer have a genuine business need for them. "We might need it one day" is not sufficient.
Businesses below the $3 million turnover threshold — and not otherwise captured — fall within the small business exemption in s 6D of the Privacy Act 1988 (Cth). That said, even exempt businesses should treat email deletion consistently, since personal information mismanaged in an inbox can create reputational and commercial risk beyond the Privacy Act.
Step 4: Build a simple, written email retention framework
A clear, consistent policy protects the business in two ways: it reduces the risk of accidental deletion of records you must keep, and it gives you a defensible basis for explaining your process to a regulator, court, or counterparty.
A workable framework does not need to be long. It should cover:
- Categories and timeframes — what types of emails are records, what retention period applies, and what triggers the clock (for example, "contract end date plus seven years" or "employee exit date plus seven years").
- Archiving versus deletion — whether emails will be exported to a records system, archived in-platform, or deleted outright, and who has the authority to approve each.
- Litigation hold procedure — who has the power to activate a hold, how staff are notified, and how the hold is lifted.
- Secure deletion — when deletion is lawful, how it is carried out (including Trash purges and shared mailbox copies) and whether a log of bulk deletions is maintained.
- Staff training — at onboarding and periodically, so that everyone understands what they are expected to do.
The framework should be written down. An unwritten policy that exists only in someone's head will not help when you are trying to demonstrate that your business acted reasonably.
How Artificer Legal can help you get this right
Email retention sits at the intersection of corporate law, tax law, employment law, and privacy — and for most small-to-medium businesses, the problem is not identifying that a framework is needed, but working out exactly what it must say and how it connects to the business's existing obligations.
When a client brings this situation to Artificer Legal, our practitioners typically:
- Map the specific record-keeping obligations that apply to the business based on its size, industry, and structure.
- Identify where existing contracts, client agreements, or professional standards impose additional retention or disposal requirements beyond the statutory minimums.
- Draft an email retention and disposal policy that sets out categories, timeframes, hold procedures, and deletion methods in plain language suitable for the whole team.
- Review or draft connected documents — including an employment agreement or HR policy covering information management obligations, and a privacy policy that accurately describes how the business handles personal information derived from email.
- Advise on the interplay between mandatory retention and privacy law obligations where the two create tension for a particular category of data.
If a dispute has already arisen and the business is concerned about emails that may have been deleted, we can advise on the legal position and what steps should be taken.
The one thing to carry away from this
The most common mistake is not deleting emails that should have been kept — it is treating email as a temporary communication tool rather than as a business record system. The inbox accumulates legal obligations by default. A business that consciously separates "records" from "inbox messages" — saving critical documents to purpose-built systems before managing email storage separately — reduces both its compliance risk and its exposure if a dispute arises.
To summarise the key points: Australian businesses can lawfully delete work emails, but the conditions matter. Companies must keep financial records for at least seven years under s 286 of the Corporations Act 2001 (Cth), employee records for seven years under s 535 of the Fair Work Act 2009 (Cth), and tax records generally for five years from the date the record was prepared or the transaction completed. APP entities under the Privacy Act 1988 (Cth) must destroy or de-identify personal information they no longer need, subject to any mandatory retention obligation. Once a dispute or investigation is anticipated, deletion must stop until the matter resolves. A written framework — covering categories, timeframes, holds, and deletion methods — is the practical foundation for managing all of these obligations without creating new ones.