# Data retention in Proton Mail

**URL:** https://discuss.privacyguides.net/t/data-retention-in-proton-mail/34302
**Category:** General
**Created:** 2025-12-30T15:50:30Z
**Posts:** 7

## Post 1 by @ph00lt0 — 2025-12-30T15:50:30Z

Proton Mail adds data retention policies for organizations (first only visionary)

> **[Data retention for organizations | Proton](https://proton.me/support/retention-policies-organization)**
>
> Find out how to use data retention rules in Proton Mail so your organization controls how long to keep emails and when to auto-delete them.

---

## Post 2 by @anonymous520 — 2025-12-30T16:03:46Z

Surprised they didn’t already have this. I would assume most business customers would want this.

---

## Post 3 by @anon57862721 — 2025-12-30T16:05:09Z

They are slow to provide things people need. To do it right with all the right privacy and security, it also times time to develop. Plus, they may not have the resources and manpower of the big tech so that’s another constraint. Even that said, they are still very slow with many things.

---

## Post 4 by @anonymous520 — 2025-12-30T16:07:09Z

> [@anon57862721](#):
>
> they are still very slow with many things.

Yeah. I get that. Just surprised they would have a business offering without data retention policies. Usually its a pretty critical component.

---

## Post 5 by @privacy.slouchy — 2025-12-30T16:09:38Z

If ProtonMail is trusted to store emails with [zero knowledge encryption](https://zero%20knowledge%20encryption), does this have any value?

I suppose it would serve as a precaution against data leakage, should your account get breached. But given their encryption scheme, that should only be possible with your account credentials in-hand. Mitigate this risk with proper account security & 2FA, passkey tied to a device

So it’s a duress guardrail? If you are under duress and forced to hand account credentials to an adversary, your data has already been sanitized by policy

I only imagine this is meaningful to a very small number of incredibly high-risk individuals. Still, nice

---

## Post 6 by @anonymous520 — 2025-12-30T16:15:14Z

Your company still has access to the data. You (the employee) are just a user, the account owner is your company.

I think you are misunderstanding which parties are accessing this data.

> [@privacy.slouchy](#):
>
> zero knowledge encryption

is to protect your data from proton not from the account owner.

---

## Post 7 by @ph00lt0 — 2025-12-30T16:55:35Z

Yes it does. Legal requirements on retention apply regardless of encryption and general security practices too. Don’t hold on to data that is no longer necessary.

Retention policy surely is topic in many standard audits, and legal compliance such as with GDPR.
