Offboarding without an email retention policy creates two failures: deleting mail that the business still needs, or leaving accounts open indefinitely. This page helps you draft a practical retention policy—ownership, periods by role, access during the offboarding window, and an audit trail—while making clear that legal obligations vary by jurisdiction.
Departure triggers the same mailbox decisions whether someone is permanent staff or seasonal—without a written rule, ops improvises under pressure.
Customer threads, project handoffs, and vendor contacts live in the mailbox. Delete too early and the next owner starts blind.
Leaving accounts active “just in case” keeps licenses billed and extends login risk long after the last day worked.
Without a policy, forwards and shared access linger. Former employees or unmanaged delegates may still receive operational mail.
High-turnover teams should align this policy with the Seasonal employee email lifecycle model so offboarding rules match how seats are created and archived across seasons.
Two different questions drive mailbox decisions—do not collapse them into one vague “keep everything” rule.
How long does operations need this mailbox so work can continue? Who inherits customer threads, approvals, and project context?
Measured in weeks or months for handoff—not statutory years. Archive, delegate, or export when access must stop but history still matters.
What must be preserved for litigation holds, industry rules, or privacy law—and who confirms it?
This page does not state jurisdiction-specific periods. Your counsel or DPO fills those in; ops executes the technical state (hold, export, archive, delete).
Primary reference: Microsoft’s remove-former-employee overview separates blocking sign-in, saving mailbox content, forwarding, and eventual deletion—each step maps to a different retention need. learn.microsoft.com · Verified: 2026-07-22
Every offboarded account needs a named business owner before IT changes access.
Manager or successor who approves exports, forwarding duration, archive vs delete, and restore requests. They answer “who still needs this mail?”
Email or IT admin who runs disable, archive, export, and delete actions on written approval—not as the sole retention decision-maker.
For execution steps after ownership is set, see Archive employee email without deleting data.
Tier roles by data sensitivity and rehire likelihood—then let legal counsel validate periods for your jurisdictions.
Shift schedules, store comms, limited customer contact. Often archive-friendly when seasonal rehire is common; shorter business continuity window.
Active accounts, quotes, and contracts in mail. Longer continuity period; export or delegate before access ends; legal review before delete.
Finance, HR, legal, or exec roles. May trigger holds, extended retention, or separate eDiscovery—never guess periods; document counsel sign-off.
Use the fill-in retention table in the policy template below—do not copy statutory numbers from vendor docs or this page without local review.
The days between notice and last login are when credentials and forwards are most often misconfigured.
Block sign-in promptly
On last day or earlier if policy requires. Reset password and sign out sessions per vendor guidance.
Review delegates & forwards
Document any temporary forward with an end date and approving manager. Remove stale mobile device access.
Log every admin action
Who disabled access, who approved export, timestamp, and ticket or HR case reference—for audit and privacy requests.
Microsoft’s offboarding sequence starts with blocking sign-in before saving or forwarding mailbox content. Remove a former employee — Overview · Verified: 2026-07-22
Pick one primary end state per mailbox—mixing indefinite forward + active seat is the usual failure mode.
Rehire possible or history needed?
→ Archive
Access stops; mailbox history kept for controlled restore. See Archive employee email without deleting data.
Legal or compliance needs a copy?
→ Export / hold
Separate from archive. Hold blocks delete; export satisfies many continuity handoffs.
Short-term coverage for one successor?
→ Delegate or time-boxed forward
Document end date and owner. Not a substitute for archive when rehire is likely.
No rehire, hold cleared, policy allows removal?
→ Delete
Permanent. Confirm business owner and legal/privacy sign-off first.
If the person may return, plan restore through Reactivate a former employee email account securely instead of leaving the seat active.
Retention decisions should be reconstructable months later—for audits, disputes, and privacy requests.
Retention must align with how you describe data processing to employees and regulators. Cross-check vendor subprocessors and your published notices.
See the SmtpMan Privacy Policy for how SmtpMan handles account data—not a substitute for your organization’s employee-facing privacy documentation.
Copy this starter into your internal wiki or HR packet. Fill blanks with counsel-approved values for your locations.
Employee offboarding email retention policy template
Internal use · Fill-in fields · Not legal advice
Document control
Per-departure ownership (complete for each offboard)
Retention period by role (fill in with counsel-approved values)
| Role tier | Business continuity period | Legal retention period (if applicable) | Default end state |
|---|---|---|---|
| Standard frontline / ops | ____ days / months | ____ (counsel) | Archive / Delete |
| Customer-facing / revenue | ____ days / months | ____ (counsel) | Export / Archive |
| Privileged / regulated | ____ days / months | ____ (counsel) | Hold / Export |
Do not treat vendor default recovery windows as your statutory retention period without local legal review.
Approval signature block
Business approver
Name: ________________
Title: ________________
Signature: ________________
Date: ________________
Technical executor
Name: ________________
Action taken: ________________
Ticket / case ref: ________________
Date completed: ________________
Jurisdiction disclaimer
This template is operational guidance only. Not legal advice. Retention periods, employee privacy rights, and sector-specific rules vary by country, state, and industry. Have qualified legal or privacy counsel review before adoption.
Offboarding checklist (run per departure)
Escalate before you delete—not after someone asks where the mail went.
Retention basics
There is no universal period. Your policy should define retention by role and risk tier, then have legal or privacy counsel confirm what applies in your jurisdictions. Use the fill-in table above—not statutory numbers from this page.
Name a business owner—typically the departing employee's manager or a designated successor—who can approve access, export, or deletion. IT or email admin executes changes but should not be the sole decision-maker for retention.
Archive & access
Archive addresses access and seat cost—it is not a substitute for legal holds, eDiscovery, or jurisdiction-specific retention rules. Separate business continuity needs from legal retention and document both in policy.
Forwarding can help continuity short term but creates ongoing access paths that need review. Document an end date, approving manager, and privacy implications. Prefer archive when rehire is possible—see Archive employee email without deleting data.
Put the policy into practice
Once ownership and periods are defined, execute archive-first offboarding without destroying history.