Google Workspace retention policies — What should I set?

You should set retention in Google Workspace by mapping each record type to a legal or operational need, enforce those rules with Google Vault, and appoint one policy owner to maintain them; start with a clear rule per record class and review it every 12 months.

Retention left at ‘forever’ because no one owns records — designate an owner and map files

Problem: many organisations keep everything indefinitely because no one has responsibility for deciding what stays or goes. The diagnosis is simple: without a named owner you get a default of inertia — users save to Drive, Gmail threads accumulate, and the admin console collects “data because it might be useful.” That behaviour increases storage costs, extends eDiscovery searches and raises ICO risk if personal data is kept without a lawful reason.

Recommended action: assign a retention policy owner (one person or a small group) and run a short mapping exercise. Break your data into three practical classes — financial/HR records, client project records, and routine operational emails — and set a retention baseline for each. Use Google Vault to implement rules for Gmail, Drive and Shared Drives so deletion is automated rather than manual.

  • Start with a one-day workshop to map record types and legal drivers (HMRC, employment law).
  • Create a retention table: record type → legal basis → minimum retention → disposal trigger.
  • Document policy ownership and a 12-month review cadence.

If you want a ready link for help with the technical side of policies and migration, our Google Workspace support and migration help page explains how to apply rules without disrupting users.

Users deleting critical data by habit — implement holds and educate key teams

Problem: teams delete emails or tidy Drives to free space, then discover later they need those messages for a dispute or an audit. Diagnosis: retention relying on user behaviour fails because users lack context and will delete the wrong records. The immediate risk is losing evidence you legally should have kept, or conversely keeping everything because you’re afraid of accidental deletions.

Recommended action: use preservation holds in Google Vault for sensitive classes (HR, contracts, financial data). Holds stop deletions while a matter is live; retention rules then govern final disposal. Your steps are straightforward: identify teams that regularly delete (finance, HR, legal), enable holds for their mailboxes and Drives during active matters, and pair that with short training sessions explaining why certain folders are off-limits for deletion.

  1. Apply a targeted hold to user accounts or organisational units when a matter arises.
  2. Set retention rules that supersede user deletion where required.
  3. Train two champions in each team to spot records that must be preserved.

This combination reduces operational disruption while preventing accidental loss. From our experience, Google Workspace works better than most UK businesses assume — the sticking points are usually one legacy Outlook plugin or a “we have always used Outlook” reflex rather than any real functional gap. Migration from Microsoft 365 is a genuine option for the right business, not a downgrade.

Labels, retention rules and audit trails tangled — simplify by converting labels into rules

Problem: labels are used as an improvised retention system (label = keep), but labels are user-controlled and inconsistent. Diagnosis: labels are great for filing, poor for enforced retention because users can remove or misapply them. That creates holes in legal defensibility and makes audits slow and expensive.

Recommended action: translate label intent into enforceable retention rules and keep labels for human navigation only. Adopt a simple two-layer approach: retention rules set the legal lifecycle; labels remain for people to find documents. Ensure every retention rule has an audit trail: who created it, when it was last reviewed, and the legal justification.

Practical checklist to convert labels into rules:

  • Export a label inventory and sample documents for each label.
  • Map each label to a retention rule or archive action in Vault.
  • Remove retention reliance on labels; keep labels as metadata only.

Where retention rules are complex (e.g. mixed-content Shared Drives), test on a small unit and record the results. Keep a simple register of active rules and review it annually so changes in regulation or business practice are captured.

Related reading

FAQ

How long should I keep payroll and PAYE records in Google Workspace?

Keep payroll and PAYE records for at least 6 years to meet HMRC expectations; store them in a secure, retained Drive folder or as mail archives with a Vault rule tied to that period.

Can I rely on user deletion policies rather than Vault holds?

No — user deletion is unreliable for legal or regulatory records; use Vault holds for matters that require preservation and set retention rules to enforce final disposal.

Will retention rules affect shared cloud drives used by project teams?

Yes — retention rules can target Shared Drives and will apply regardless of individual user actions, so map Shared Drives to record types before applying rules to avoid over-retention or accidental deletion.

How often should retention policies be reviewed?

Review retention rules at least once every 12 months and immediately after any legal, tax or contractual change affecting record-keeping to ensure rules remain defensible.