Retention periods and WORM immutability

Retention periods of 6, 8 and 10 years under German commercial and tax law, the WORM principle and immutable storage with an externally anchored hash chain.

Archived messages stay immutable until their retention period expires. The period depends on the kind of message, and immutability follows the WORM principle.

Retention periods under German commercial and tax law

Three classes are preconfigured:

  • 6 years for commercial and business letters under section 257 HGB and section 147 AO.
  • 8 years for accounting documents including invoices, since 1 January 2025 under the Fourth Bureaucracy Relief Act.
  • 10 years for annual financial statements and opening balance sheets.

The period starts at the end of the calendar year in which the message was created. Custom classes per department, group or mailbox are possible. Periods are only extended, never shortened. Classes and deletion runs are managed in the archive area under retention and deletion concept.

Retention policies in the archive with periods and deletion rules

Retention classes and periods.

Custom retention rules

New messages without a rule of their own receive a default retention period. Beyond that, custom rules can be created in the rule editor. Every rule gets a scope, either the entire organisation, a single mailbox or a group, and a retention class in years. If a message meets several rules, the longest period applies, because periods are only extended, never shortened. Groups as a scope come from groups and organisation.

The WORM principle and immutability

Under the WORM principle, write once read many, every message is written once and afterwards only read. In the standard storage Archive enforces this in software: archived messages are locked against change, and the deletion run refuses deletion before the period expires. In the compliance storage an object lock is added that holds every object immutable until the end of the period. Conbool provides both storage classes. Details see setup and storage and capacity.

Evidence through the hash chain

Every entry in the audit trail is chained to the previous one through a hash chain whose head is anchored externally. Interventions in the holding or the audit trail are thereby detectable and provable at any time. Archive data at rest is additionally stored encrypted, and the encryption is always active.

Further reading: deletion concepts, search and access and the solution page GoBD-compliant email archiving.