Legal holds and permanent deletion
How a hold keeps data beyond the retention period, how a deletion request under Article 17 works, and what happens when the two meet.
Legal hold
A hold keeps backed-up states beyond the configured retention period. It applies either to the entire tenant or to a single protection unit.
Imposing one requires a case or file reference. That is a mandatory field and not a formality: a hold without a stated cause cannot later be assessed by anyone, and it keeps data indefinitely.
Releasing one requires a reason and is recorded, with person and time.
A released hold does not trigger deletion. It merely returns the content to the ordinary retention period; it is removed once that period expires and the deletion run is armed.
Deletion request under Article 17
A deletion request removes a protection unit permanently. There is no recycle bin and no way back.
The procedure requires three things:
- The name of the protection unit, typed out as confirmation
- A reason, at least four characters
- Confirmation that the deletion is permanent
Blocks that also belong to another person's content are retained. A message addressed to several people resides in several mailboxes; deleting one unit does not remove it from the others.
Deletion per protection unit, not per person
This is the most important limitation, and it follows from the architecture: in a Microsoft 365 backup, information about a person does not reside in that person's own unit but is distributed across the mailboxes, channels, chats and documents of their correspondents. Encryption operates at the level of the protection unit.
A request under Article 17 can therefore only be fulfilled by deleting the protection units of the person concerned. This is stipulated in the Data Processing Agreement and applies equally to every vendor encrypting at this level.
When a hold and a deletion request meet
The hold prevails. A unit under hold cannot be deleted while the hold stands — otherwise the hold would be worthless.
In practice: release the hold first, with a reason and an audit entry, then delete. Both actions require their own permissions, and both are recorded.