Even U.S. government officials have used private email servers to avoid having to serve them up via requests.
And when that failed they destroyed the hard drive that contained the exchange server db. (See IRS scandal)
> There is no legitimate business reason for that policy.
So the policy is about limiting the chance of potentially very expensive lawsuits, and has no legitimate business reason? Choose one.
I wish people stopped overusing "Orwellian": the term is so overused that you could use it next to "agile" and I wouldn't notice.
"Orwellian" is an adjective describing a situation, idea, or societal condition that George Orwell identified as being destructive to the welfare of a free and open society. It denotes an attitude and a brutal policy of draconian control by propaganda, surveillance, disinformation, denial of truth (doublethink), and manipulation of the past, including the "unperson"—a person whose past existence is expunged from the public record and memory, practiced by modern repressive governments. Often, this includes the circumstances depicted in his novels, particularly Nineteen Eighty-Four[2] but political doublespeak is criticized throughout his work, such as in Politics and the English Language.
[1] https://en.wikipedia.org/wiki/Orwellian
I defend my use of the term. Disappearing the past absolutely is Orwellian. Down the memory hole!
Eric Schmidt’s retention policy was 72 hours.
More than likely Schmidt may have said something along the lines of deleting anything more than 3 days old because at the pace of his business, it's 'time out' and not relevant. But that's just a matter of his peculiar communications style. That the label has changed to 'archive' doesn't mean anything really from a corporate perceptive.
So yes, illegal to actually delete, and seemingly impractical to bump from one's inbox, but perhaps at 'Google Speed' there's some reason for it (and maybe there's a big caveat i.e. anything that's 'starred' or whatever doesn't get deleted, or, maybe anything older than 3 days that's opened or unopened gets deleted).
EDIT: For those who are wondering, here is a quick summary [1].
Eric Schmidt's emails are definitely kept around a very long time, for very legal reasons, and whatever he happens to do with his own personal 'inbox' is not relevant to the subject at hand, and amounts to a kind of personal email/habit choice.
To suggest '72 hours' in response to a discussion about legal discovery etc. is basically misleading in that regard.
[1] https://www.spamtitan.com/web-filtering/email-retention-laws...
Eric Schmidt is not deleting his emails after 72 hours for the reason you mentioned and certainly the company is not, which is the salient issue.
One could say 'oh that's just from his inbox' but that's pointless in the context of this conversation because we're talking about 'If the corporation has a copy or not' i.e. 'IT' etc..
Scmidt deleting maybe a local copy after 72 hours doesn't really have anything to do with anything other than his personal email habits.
[1] https://www.spamtitan.com/web-filtering/email-retention-laws...
>"Orwellian" is an adjective describing a situation, idea, or societal condition that George Orwell identified as being destructive to the welfare of a free and open society. It denotes an attitude and a brutal policy of draconian control by propaganda, surveillance, disinformation, denial of truth (doublethink), and manipulation of the past, including the "unperson"—a person whose past existence is expunged from the public record and memory, practiced by modern repressive governments.
https://en.wikipedia.org/wiki/Orwellian
Stop overusing terms you don't understand
Many business have auto-delete for the simple business purpose - when someone hacks your email (which will happen somewhere in a large business) - why do you need to keep all that crap around forever? And yes, people email payroll details, passwords, logins and the list goes on - stop with the preaching about how to email securely.
So you auto-delete, which reduces the blast radius. In most cases folks are not looking at emails past 3 years old.
You already completely answered the perfectly standard and reasonable business reason: "to limit legal exposure. "
In fact, this legitimate business reason is 100% the reason for the policy. Increasing legal exposure for no reason is a bad idea, for companies and for individuals.
This explanation was given to me by a corporate lawyer who was trying to figure out whether the same kind of expiration could be put on tickets in bug and project trackers, which would have been even more harmful to institutional memory than an email expiration policy.
Depending on context, these are either shared with the other person (and usually editable by them) or is accessible only by me.
Yes, it has: GDPR requires that you delete PII in reasonable time. I have a lot of customers contacting me by email for example, but also the JIRA notifications which all end up in emails with extensive PII. It must be deleted in a controlled way according to GDPR.
But you are correct that this excuse goes away with Google, since they don’t do support ;)