Mailing List CGatePro@mail.stalker.com Message #95779
From: ish Support <support@ish.com.au>
Subject: Re: E-mail Archiving Solutions
Date: Fri, 8 Aug 2008 08:11:48 +1000
To: CommuniGate Pro Discussions <CGatePro@mail.stalker.com>
X-Mailer: Apple Mail (2.926)
Shaun

Thanks for your email, I will look that up. We are in NSW.

Support.
On 06/08/2008, at 12:26 PM, Shaun Gamble wrote:

ish Support wrote:
Hi!

Thanks for hijacking my thread but I see your point! :)

I have no idea what the laws are for all of this in Australia, something I think we should know before we go to much further.

Thank you very much for the advice.


From my understanding, after speaking to our lawyers, Australia does not have a federal law on this issue. States do and it depends which state you are "in". Our company covers two states. We have taken the approach in our industry (hospitality and tourism) HR and tax records must be kept for seven years. After getting no where with lawyers, we have taken the decision to keep emails for seven years. Once someone can tell us what the retention period actually is, we will change. We have shipping containers for our paper records and now we have servers that simply hold archived email records. Any archived emails older than two years are moved to the archiving server. It sounds ridiculous, especially since we are a small company, and it is but we feel these steps are necessary.

http://www.zdnet.com.au/insight/security/soa/E-mail-archiving-a-whole-of-company-issue/0,139023764,139241752,00.htm
http://www.elaw.net.au/WhitePapers/DocumentRetentionPolicies.pdf
http://www.elaw.net.au/WhitePapers/SampleDocumentRetentionPolicy.pdf

may be of some help to you, however I suggest you talk to a lawyer. I still have no idea how long emails must be retained. Our offices are in the Northern Territory (head office) and Queensland.

Support
On 05/08/2008, at 6:54 PM, Graeme Fowler wrote:

Hi

On Tue, 2008-08-05 at 16:39 +1000, ish Support wrote:
I would really like something more polished, as this is ok for someone
whom is technically minded it is not that useful for those whom are
not. I would really like an indexed database of all the mails, etc.

Now we're getting somewhere - you produce a requirements specification
which takes into account your local legal frameworks, and then we're
talking :)

At the moment for my office, I already save all emails on a HDD in
text. I use a rule and a script but I find with this I get a
"processing" error every now and then which just looses the whole mail
and cgate support has been unable to help me solve this and it happens
so rare that I am not sure where to look. I am not keen to implement
this on a server which is processing 10x the email. The script in
question is below, as you can see it creates a directory structure for
year/month/date/hour and the emails are saved in those hour
directories.

OK, that's pretty simple (errors notwithstanding).

If you want something you can use an ordinary mail client with, you
could use the suggestion others have made to use a mirroring rule (not
necessarily to the same server) into an account to which you have
webmail access, or IMAP access, or MAPI. That way you get all the
functionality of your favourite client with all the simplicity of it
being email rather than some sort of searchable database backend.

But the same problem still remains, I have all these emails but no
ACL/indexed/searchable interface to make this usable.

You have an additional problem, too: how long are you permitted to
retain the information, and how do you respond to Freedom of Information
requests? In the UK we have a set of opposing regulations in the Data
Protection Act, the Freedom of Information Act, and the Regulation of
Investigatory Powers act amongst others which amend or modify them.

The first states, in very simple terms, that you must only keep
information pertaining to a person for "as long as is necessary".

The second states, again in very simple terms, that if you hold
information pertaining to a person then when requested you must be able
to produce it within a reasonable timeframe when requested.

The third restricts (that term is actually arguable, since it's a very
large group!) which third parties are permitted to request information
from your organisation - when requested for this information there is a
strict framework in which you must produce the information.

So in your case (if you were in the UK), if you're known to be retaining
all email communications, but you can't produce the copies when
requested by a person or an organisation then you are legally up the
creek without a paddle. Additionally, if an ex employee comes back in
ten years and demands any information you have about them and you still
have information from ten years previously, did you need to keep it?

Again, I realise that this isn't a technical reply but it's worth
mentioning - even if you go ahead and buy an off-the-shelf product you
*must* consider producing policies within your organisation to manage
the consequences - the basic one being to set a retention period, which
most appliances or off-the-shelf products will do for you.

Yes, it is perfectly legal (in the UK at least) to say in response to an
FoI request "I'm afraid those emails have now been destroyed in
accordance with our data retention policies", providing that doesn't
conflict with other legislation (like that applying to financial
transactions, healthcare, pharmaceuticals, stocks/shares, company
directors... etc etc etc)  :)

It's a minefield!

Graeme


--

Shaun
http://www.crocosauruscove.com http://www.destinationnt.com
http://www.momdarwin.com http://www.valueinn.com.au
Please do not send any unsolicited email. It is not wanted.

#############################################################
This message is sent to you because you are subscribed to
the mailing list <CGatePro@mail.stalker.com>.
To unsubscribe, E-mail to: <CGatePro-off@mail.stalker.com>
To switch to the DIGEST mode, E-mail to <CGatePro-digest@mail.stalker.com>
To switch to the INDEX mode, E-mail to <CGatePro-index@mail.stalker.com>
Send administrative queries to  <CGatePro-request@mail.stalker.com>

-------------------------->

ish

http://www.ish.com.au

Level 1, 30 Wilson Street Newtown 2042 Australia

phone +61 2 9550 5001   fax +61 2 9550 4001


Subscribe (FEED) Subscribe (DIGEST) Subscribe (INDEX) Unsubscribe Mail to Listmaster