Setting up eDiscovery and Retention

Organizations which use emails as their primary mode of communication for their business should be cautious about accidental data loss and regulatory compliance laws. Zoho Mail's eDiscovery portal allows admins to retain emails and recover them at any point in time.

Steps to enable eDiscovery

Follow the below instructions to setup eDiscovery for your organization:

  1. Log in to your Admin account at https://ediscovery.zoho.com.
  2. Alternatively, you can log in to Zoho Mail Admin Console and select eDiscovery on the left pane. The eDiscovery portal welcomes you with a small intro to email retention and eDiscovery.
  3. Enable eDiscovery for Mail, Cliq and WorkDrive and click Next. A pop-up message confirms that you have successfully enabled eDiscovery for your organization.
    enable eDiscovery

Note:

eDiscovery for Cliq and WorkDrive will be available only for organizations that are part of the Zoho WorkPlace plan. For details reach out to support@zohomail.com.

Defining retention period

Almost every governmental regulation requires "records" to be captured, managed, retained for specific periods of time, and made available to the governmental agency when asked. These records can include hard copy content, email, voicemail, instant messages, and social media.

The considerations for establishing and maintaining your organization’s retention policy remain the same; they are: business needs, legal requirements, organizational culture, approaches to retention policies, litigation holds, automation, and implementation.

Steps to define a default retention policy

  1. Once you enable eDiscovery, the next step is to choose the Default retention period. The default retention policy determines the period for which the users' data would be retained.
  2. Select the retention period for Mail, Cliq and WorkDrive based on your organization's requirements. You can either define a specific number of days or choose Retain forever.
  3. Click Next.

Note:

  • eDiscovery for Cliq and WorkDrive will be available only for organizations that are part of the Zoho WorkPlace plan. For details reach out to support@zohomail.com.
  • Default Retention Period can be overwritten by Custom Retention Policies which allow for certain data of specific users or a certain type of data to be retained for a different retention period for a specific need. Refer Customizing retention policy for more details.

Defining retention rule

The retention rule acts as an email filter for emails to be allowed into the eDiscovery service for archival. It provides you with the option to choose the types of emails that you want to retain in the eDiscovery portal such as sent emails or received emails or retain only a specific sub-set of sent/ received emails and so on.

Define the appropriate Retention Rule to ensure you retain the required emails while not filling up your user's storage with unnecessary emails. This rule gets saved as EDISCOVERY_FILTER and will be applied to your entire organization. Admins can create custom email filters for specific users based on their organization's requirements.

Steps to define a default retention rule

  1. Once you define the retention period, you can go ahead and define the Default retention rule.
  2. Choose from the granular options available and set the ingestion rule for the eDiscovery portal.
  3. Click the Next button.

  • Retain all emails
  • Retain based on the conditions such as
  • Retain all sent emails Retain all sent emails - outside the organization
  • Retain emails sent - only within the organization
  • Alternatively, you can specify selected domains and choose to retain the emails that are sent only to those domains.
  • Retain all received emails
  • Retain all received emails - from external organization accounts
  • Retain emails received - only within the organization
  • Alternatively, you can specify selected domains and choose to retain the emails that are received from those domains.
  • Retain all deleted and/or spam emails.

Note:

The allocated user storage is used by the User's mailbox + eDiscovery + Backup. Therefore it is recommended to refine what you retain and for how long depending on your organization's needs.

Selecting user accounts

Once you define the retention period and retention rule, you must select the users for whom email retention should begin.

Steps to enable user accounts for eDiscovery

  1. Enter a user's name in the search bar to select specific users to enable retention.
  2. Alternatively, select the checkbox on the header and click on Select all users to enable retention for all the user accounts.
  3. Click the Retention drop-down.
  4. Select Enable retention and click Finish.

Once you enable the retention, the emails that get delivered to these user accounts will be retained in the eDiscovery portal, based on the retention rules. The retention period will be based on the default retention rule applied to the accounts. The sync to the eDiscovery portal may take a while, after which you will be able to search/ view/ export the retained emails from the portal.

Customizing retention policy

Based on your organization's requirements, you can configure different retention policies for emails and chat conversations. By clicking on the Retention tab, admins can view the set default retention policy and the list of custom retention policies. Organizations that are part of the Zoho Workplace plan will be able to configure separate retention policies for Mail and Cliq data. Navigate to the corresponding sections to learn more:

Custom retention policy for emails

Below the default retention policy, you will find an option to create a new custom retention policy. In case there are any special or custom requirements that need certain emails, based on custodians or certain conditional criteria, to be retained for a different period of time, the administrators can define custom retention policies. Custom retention policies can be defined based on various parameters.

Note:

Emails that are beyond the set retention period will be automatically cleaned up or purged, once in every 10 days.

To define new custom policies, follow the below steps:​​

  1. Log in to Zoho Mail Admin Console and select eDiscovery on the left pane.
  2. Navigate to the Mail tab under Retention.
  3. Click the Create custom retention policy button and provide a Name for the custom policy.
    custom retention policy
  4. Select the desired mailbox category:
    • All accounts - All user accounts and shared mailboxes will be included.
    • Specific user accounts - Admin can select one or more user mailboxes in the User mailboxes field.
    • Specific shared mailboxes - Admin can select one or more shared mailboxes in the Shared mailboxes field.
  5. Click the drop-down and select a predefined retention duration or Custom range.
  6. Select the start and end dates if you chose custom range.
  7. In the Condition query, provide the conditions based on which you want to define the custom policy for email retention from the granular options provided:
    • Contains - contains text/ email address in the entire email
    • Subject - subject contains the selected term
    • Content - email content contains
    • From - from email address contains
    • To - To email address contains
    • Cc - Cc email address contains
    • Bcc - Bcc email address contains
    • Reply To - Reply to email address contains
    • Has attachment - Only the emails with attachment
    • Attachment name - Attachment content contains
    • Attachment content - Attachment content contains
    • Only outgoing emails - Include only outgoing emails
  8. Select whether you want to retain the emails marked as spam.
  9. Choose Only deleted emails to retain only the emails deleted from the mailbox that match the entered condition query.
  10. Choose Retain forever or enter the number of days to retain the emails that match the conditions.
  11. Click Preview results to check whether the condition query provides the expected results.
    save custom policy
  12. Click Save retention to save the custom retention policy.
    preview results

You can create and save multiple retention policies for different purposes. Mostly each custom retention policy will differ based on periods of retention and the conditions required for retention.

Note:

When an email matches multiple custom retention policies, emails are always retained as required by the retention policy with the longest retention period. Email that are on hold are retained till the hold is removed.

Cliq custom retention policy

There can be situations where you are required to retain a certain set of Cliq messages for a different duration as per the unique requirements of your organization. Custom retention policies for Cliq conversations can be configured based on various parameters. The custom retention policy will take precedence over the default retention policy for those messages that satisfy a custom policy.

Note:

Deleted messages which are expired beyond the retention period will be automatically cleaned up or purged, once a week.

To define new custom policies, follow the below steps:​​

  1. Log in to Zoho Mail Admin Console and select eDiscovery on the left pane.
  2. Navigate to the Cliq tab under Retention.
  3. Click the Create custom retention policy button and provide a Name for the custom policy.
    Cliq Custom Retention Policy
  4. Select one or more condition queries from the available list:
    • File name
    • File type
    • Link
    • Content
  5. Select the preferred Chat type to be retained as per the custom policy:
    • Direct message - The personal chat messages within the organization.
    • Group chat - Filters group chats within the organization.
    • Private channel - Search messages shared in personal channels.
    • Organization channel - Conversations in channels used across the organization get saved.
    • External channel - Conversations in channels which include external members (users outside the organization).
    • Team channel - Conversations within the team channels get saved.
    • Chat thread - Filters the inline chat threads in all conversations.
    • Bot - Filters only the chat messages initiated by bots.
    • Entity chat - Includes chat messages initiated from other Zoho apps. 
  6. If required, select Only messages with files and Only messages with links checkboxes.
  7. Enter the desired retention period or choose Retain forever.
  8. Click Preview results or Save.
    Preview Custom Retention Policy

The chat messages that match the filter conditions will be retained as per the custom retention period.

Email Filters for eDiscovery

Every organization's need for data retention varies according to the industry and its business needs. Some may require storing all emails of the entire organization for compliance purposes, while others may choose to store certain VIP mailboxes or certain client communication emails which were sent to or received from outside the organization.

As an administrator, you will know your organization's goals for retention and can determine what needs to be retained in eDiscovery. In order to control what gets stored/retained you can create an eDiscovery Email Filter. You can do this in the following ways:

  1. While enabling eDiscovery, you can select the filter criteria by which only a subset of emails get retained. This filter (EDISCOVERY_FILTER) is a default email filter and it is applied to all user mailboxes.
  2. To have more fine-grained or granular control on specific filters on certain mailboxes, say group mailboxes or emails from a certain department, etc. you can create custom Email Filters.

Steps to add eDiscovery Email Filters (Custom Email Filter)

  1. Navigate to Email Filters under Retention Policies.
  2. Click Add Filter and provide a Filter Name.
    eDiscovery email filter
  3. Select either All emails or Emails based on conditions below.
  4. If you select All emails, mention the users and click Save.
  5. In case you select Emails based on the conditions below, specify all the conditions:
    • All sent emails (emails sent only within the organization or emails sent outside the organization)
    • All received emails (emails received from within the organization or received from outside the organization)
    • Mention specific domain(s) under the All sent emails and All received emails category.
    • Deleted emails
    • Exclude spam emails
  6. Add the user mailboxes for whom the custom filter must be applied.
    save email filter
  7. Add the shared mailbox addresses to which you want to apply the filter and click Save.
  8. Navigate to the Associated users or Associated shared mailboxes tabs to add or delete the mailboxes.

Once the filter is saved, the new custom filter will appear under the list view. Click on the filter name to view its details or edit permissions, if required.

Still can't find what you're looking for?

Write to us: support@zohomail.com