ComplyChat Start free

Guide · Work messaging

Message archiving for compliance

Search for message archiving and almost everything you find is written for banks and brokers, whose regulators require them to record and keep their staff's communications. Schools, charities and care providers have no rule headed "archive your messages", but they have several duties that assume the messages exist and can be found: subject access requests, Freedom of Information, safeguarding records, the regulator's inspection, a tribunal. This guide explains why an organisation outside financial services archives messages, the difference between gathering messages after the fact and recording them as they are sent, and how the Microsoft 365 retention model most of these organisations already own keeps and deletes them.

By ComplyChatPublished 12 minute read

A records officer at a multi-academy trust’s central office wheels a trolley of archive boxes along a bright corridor, morning light through tall windows
01

What message archiving is, and who is required to do it

In short

A message archive is a complete, unaltered, searchable copy of an organisation's business messages, kept for a set period under a retention policy and then deleted, with the ability to hold it longer when a dispute or request requires.

Financial firms have explicit recording rules. Schools, charities and care providers do not, but their duties on access requests, Freedom of Information, safeguarding and care records mean that a message which records a decision about a person is a record, and has to be findable for as long as that record is kept.

Message archiving is the practice of capturing an organisation's business communication, email, chat, SMS messages and sometimes voice, and storing the message content with its metadata so that they can be searched, produced and eventually deleted according to a policy. A good archive has four properties: it is complete, so nothing that should be in it is missing; it has integrity, so a message cannot be quietly changed or removed; it is governed, so it keeps each message for the right period and no longer; and it is searchable, so that a request can be answered within its deadline.

For some organisations archiving is an explicit regulatory requirement. In the UK, the Financial Conduct Authority's rules on recording telephone conversations and electronic communications (SYSC 10A in its Handbook) require in-scope firms to "take all reasonable steps to record telephone conversations, and keep a copy of electronic communications" relating to certain investment activities; in the United States the SEC and FINRA impose their own books-and-records rules. Those obligations are specialist, carry their own retention periods and supervision duties, and they are the reason most archiving software is built for regulated industries and bought by compliance officers in financial services. This guide does not cover them. If your organisation is a regulated financial firm, take advice from your compliance function.

Everyone else archives for a different reason. A school, a charity or a care provider is not told to record its staff's communications. It is told to keep accurate records of the things it does, to hand people their personal data when they ask, to produce information on request if it is a public authority, and to delete what it no longer needs. The archive is how those duties are met for the part of the organisation's work that now happens in messages.

02

Why schools, charities and care providers keep messages

The regulatory compliance reasons that make a message worth keeping, and worth deleting on time, come from several directions at once:

  • Subject access requests. Article 15 of the UK GDPR entitles a person to their personal data, and the ICO's right of access guidance makes clear that this includes information held in emails and messages. The organisation normally has one month to respond, and a message it cannot search is one it cannot answer for. Our guide to subject access requests and WhatsApp messages covers messages on staff phones.
  • Freedom of Information. Maintained schools, academies and other public authorities must answer requests for recorded information, usually within 20 working days. The ICO's guidance on non-corporate channels says official business in private messaging accounts can be held on the authority's behalf, and that where staff use instant messaging, "auto-delete options should be in line with the retention policies of your official systems".
  • Records management for public authorities. The section 46 code of practice gives public authorities good practice on "keeping, managing and destroying your information". It applies to every public authority covered by the Freedom of Information Act, including schools.
  • Safeguarding. Keeping children safe in education 2026 (KCSIE 2026) and Working Together to Safeguard Children 2026 expect concerns, discussions and decisions to be recorded. A concern first raised in a message is part of that record.
  • Care records. Regulation 17 of the 2014 Regulated Activities Regulations requires a care provider to keep "an accurate, complete and contemporaneous record" for each person. A decision about a resident taken in a message between the manager and a senior carer belongs in it.
  • Charity governance. Trustees must be able to show how decisions were made and how they exercised oversight, and a serious incident report to the Charity Commission often turns on what was known and when.
  • Disputes. In a grievance, an employment tribunal or a civil claim, relevant messages are documents that may have to be disclosed, including those that do not help the organisation.
  • Storage limitation. UK GDPR Article 5(1)(e) requires personal data to be kept "for no longer than is necessary". An archive that keeps everything forever is not compliant either; retention periods and deletion are half the job.

None of these duties says which app to use. All of them assume that when someone asks, the organisation can find what was said, show it was not altered, and explain why it still holds it, or why it no longer does.

03

Two ways to get a message into an archive: afterwards, or at source

Every archiving solution has to answer one practical question: how does the message reach the archive? There are two broad answers, and most of the difference in completeness, cost and trust follows from which one a product uses.

Capture after the fact gathers messages from where they already are. For email that is usually straightforward, because the organisation runs the mail system and can journal or retain every message in it. For text messages and messaging apps on phones it is harder. The methods used include capture agents on company-managed mobile devices, network-based text message archiving that specialist providers offer for company-issued numbers, and, at the informal end, exports and screenshots made by the member of staff when asked. The weaknesses grow the further the method is from the organisation's control:

  • Completeness. A message deleted before the capture ran, or sent from a device the capture does not cover, is not in the archive, and nobody can tell that it is missing.
  • Personal phones. Capture tools generally need a managed device. On a personal phone the organisation can ask, not require, and a bring-your-own-device policy has limits a capture agent cannot get past.
  • Integrity. An export made by a member of staff, perhaps the subject of the complaint, carries no independent evidence that it is complete or unaltered.
  • People outside the organisation. The parent, the volunteer or the agency carer at the other end of the conversation is not on any device the organisation manages.

Recording at source means the service the conversation happens in writes each message into the record as it is sent, on the server, not on the handset. Nothing has to be gathered later, a message deleted from a phone is still in the record, and the organisation's copy does not depend on anyone's device. The limitation is equally plain: it only covers conversations held in that service. It cannot reach a conversation that took place somewhere else, which is why an organisation that records at source still needs a policy that tells people where work conversations belong.

For organisations outside financial services, the realistic route to a complete archive is usually the second one: move the conversations that matter to systems that record them at source, and stop relying on capture from phones the organisation does not own.

04

The Microsoft 365 retention model

Most schools, charities and care providers already have an archiving and retention system and may not think of it as one. Microsoft 365, a cloud-based archive in all but name through Microsoft Purview data lifecycle management, lets an administrator keep and delete email, files and Teams messages under rules the organisation sets. Microsoft's overview of retention policies and labels is the primary source.

In summary, a retention setting can keep content for a period, delete it after a period, or keep it and then delete it, which is what most retention schedules call for. People keep working as normal, and a copy of anything edited or deleted within the period is kept in a location most users cannot see. A retention policy applies to a whole location, such as every mailbox or all Teams chats, and a label to an individual item, although Teams messages can only be governed by policy. Where settings overlap, "retention always takes precedence over permanent deletion, and the longest retention period wins"; an eDiscovery hold suspends deletion while a request or dispute is live, and Preservation Lock can stop anyone, administrators included, from weakening a policy.

Two things the model does not do on its own. It keeps what reaches Microsoft 365: messages in a consumer app on a personal phone never arrive, and no retention policy can reach them. And it does not decide the periods for you. The retention schedule, for schools the IRMS toolkit or the Department for Education's record-keeping guidance, for care providers the NHS Records Management Code of Practice that many adopt, is still the organisation's to write; our data retention policy guide covers how. Check which Purview features your licence includes before you plan around them.

In a charity’s converted-warehouse head office, a compliance officer walks down an open steel staircase carrying a closed laptop, colleagues at desks on the floor below
05

What a defensible message archive has to show

Whether the archive is Microsoft 365, a specialist product or a combination, the test is what it can demonstrate when a request, an inspection or a claim arrives. Archiving best practices come down to questions worth being able to answer before that happens:

  1. Which communication channels are in scope, and which are not? Email, Teams, text messages from organisation phones, any other messaging service. The list of channels that are not archived matters as much as the list that are.
  2. How long is each kept, and why? A retention period for each type of message, tied to the record it belongs to, and set out in the retention schedule.
  3. How is deletion done and evidenced? Automatic deletion at the end of the period, and a record that it happened, so storage limitation is met as well as retention.
  4. How is a hold applied? Who can suspend deletion for a live request, complaint or claim, and how quickly.
  5. Who can search it, and is their access recorded? Access to archived messages is access to personal data, some of it special category. It should be limited to named roles, and the searches themselves logged.
  6. Can you export a conversation with its context? The message content with its metadata: who sent each message, when, and to whom, in a form a requester, a tribunal or an inspector can read.
  7. Have people been told? Staff, volunteers and anyone else in the conversation should know from the privacy information you give them that work messages are kept, for how long and why. Keeping messages openly is both the lawful position and the one that survives scrutiny.
A retention schedule row for messages – fictional example

Record: messages recording a safeguarding concern or decision about a pupil · Channels: staff messaging service, email · Retention: as the child protection file, then reviewed · Deletion: by retention policy, logged · Hold: DSL or data protection lead may apply · Access: DSL, deputy DSLs, data protection lead; searches logged · Not in scope: personal messaging apps, which staff are told not to use for this.

The row names the record the messages belong to, not the app, and says plainly which channels are outside the archive.

06

The conversations the archive was never going to see

Most organisations that have thought about archiving have their email and their Teams chats covered. The gap is elsewhere. It is the senior leadership group on personal phones where the decision to exclude a pupil was discussed on a Sunday. It is the night staff's group where a fall was first reported. It is the volunteers' chat where a concern about a coach surfaced. It is the parent who texts the teacher whose number they have. None of those people is doing anything unusual, and none of those conversations will ever reach a retention policy, because they happen in apps the organisation does not run, often with people who have no account on its systems.

When the subject access request, the Freedom of Information request or the tribunal arrives, the archive is complete for everything except the conversations that mattered most, and that is where the compliance risk sits.

ComplyChat is built to close that particular gap by recording at source. Messages in a ComplyChat channel are recorded on the server as they are sent, not gathered from handsets afterwards. Everyone added to a channel is told it is on the record and can object or leave. A mobile number verified by SMS is an identity, so bank staff, volunteers, parents and families can be in a channel without an account on your systems. On paid plans, once your tenant is connected, the lasting record files into a restricted SharePoint document library in your own Microsoft 365, where a Microsoft Purview retention policy you apply to it governs how long it is kept, and holds and eDiscovery searches run inside your own tenant. It is not a capture tool for other apps, it does not archive email, and it is not built for the recording rules that apply to financial firms. ComplyChat Free is one private group, direct messages, up to 25 staff and three calendar months of recent history, with no Microsoft 365 archive, so it cannot meet a retention duty.

A question for the next leadership or board meeting: if your archive were asked tomorrow for every message about one named child, resident or member of staff, which conversations would it return, and which would you know were missing?

07

Official guidance and your next step

For data protection, start with the ICO's right of access guidance and its guidance on storage limitation. The Data (Use and Access) Act 2025 has amended UK GDPR and the Data Protection Act 2018, and its last data protection provisions came into force on 19 June 2026, so check the date on any ICO page you rely on. Public authorities should read the section 46 code of practice; schools the Department for Education's record keeping and management guidance; care providers the Records Management Code of Practice. Microsoft documents its retention model on Microsoft Learn. Quotations are from those pages as published on 25 September 2026.

This guide is general information for UK schools, charities and care providers, not legal advice, and it does not cover the recording obligations of regulated financial firms.

One step to take this month: list every channel your staff and volunteers use for work conversations, and mark each one "archived under our retention schedule" or "not archived". The second list is where your next access request will run into trouble.

Why we publish this

We build ComplyChat so that the work conversations an archive usually misses, the ones with people who have no work account, are recorded as they happen and, on paid plans, file into the organisation's own Microsoft 365. Most of what an organisation needs to archive well it already owns; we would rather you used it fully than bought a product for a problem you do not have.

Explore Free · How it works · Compare plans

Sources

Every document this guide quotes or links to, in the order it first cites them.

  1. Right of access guidance ico.org.uk
  2. Guidance on non-corporate channels ico.org.uk
  3. Section 46 code of practice ico.org.uk
  4. Overview of retention policies and labels learn.microsoft.com
  5. Storage limitation ico.org.uk
  6. Record keeping and management guidance gov.uk
  7. Records Management Code of Practice digital.nhs.uk