Nobody chose how long your messages are kept. A default did, and the platform owns the default.
Editing the contract takes notice, a countersignature and a diary entry. Editing what the software does when nobody touches it takes a release note.

Draft, not yet edited. Written by Nadia Berger, and not yet through the desk: nothing here has been checked against the sources listed at the foot of the page. Do not act on it.
Two documents in your organisation say how long a message is kept. One went to a committee, was reviewed by legal, and lives in the records management folder with a version number on it. The other is a dropdown in an administrator console that somebody set once, or more likely never opened.
The dropdown is the one that is true. It is also the one the platform can change.
The shredder nobody bought
Picture an office where the paper is yours and the building is not. You own the files in the cabinets. The landlord's facilities contractor supplies the shredder in the corner, empties it on Fridays, and — this is the part that matters — sets the timer on it. Nobody in your organisation chose thirty days. Thirty days came with the building. Every document that goes in the tray is gone at thirty days, because that is what the machine does when nobody touches it.
Then the contractor changes the timer to seven. Your lease has not changed. Your records policy has not changed. Nothing anyone signed has changed. But the papers you would have had in week three are confetti, and you learn this during the first argument in which you needed them.
The analogy holds further than it is comfortable to push it. A legal hold is a phone call telling the contractor to switch the machine off, which works, and which you can only make if you knew the machine was running. Backups are the sack by the loading bay: the confetti has left the office, which is what "deleted" means in most terms, and it sits outside for another month.The seam, and it is worth knowing where it is: with paper you can see the bin filling. A retention default produces no tray, no noise and no bin bag, which is why the change is usually discovered by its absence, months later, by someone looking for a specific message.
Changing a clause is loud. Changing a default is silent.
Your agreement with a platform has two change-control doors, and almost everything interesting turns on which one a change goes through.
Material changes to the terms — the processing addendum, the security schedule, the service description — carry notice. Thirty days, or ninety, sometimes a right to terminate without penalty, usually an email to a named contact. There is a paper trail because the contract insists on one.
Changes to the service go through the other door: the clause permitting the provider to improve, modify and discontinue features. A default value is a feature. It arrives in a release note.
| Editing the clause | Editing the default | |
|---|---|---|
| Announced by | Notice under the agreement | Release note, admin banner |
| Who has to act | The customer | Nobody |
| If nobody acts | Usually nothing happens | The change takes effect |
| Trace afterwards | A dated document | A changelog, if it is still up |
Two levers, one outcome, and only one of them is written down in a place your auditor will look. That asymmetry is not a trick. It is what the difference between a contract and a product is for. It means only that the most consequential setting in a workspace is governed by the looser of the two instruments.
The setting that decides what evidence exists in three years' time is filed under features, not under terms.
The one deletion duty in the contract is about leaving
There is a deletion obligation written into every compliant processing agreement in Europe, and it is the wrong one for this problem. Article 28(3)(g) of the GDPR requires the processor to "delete or return" all the personal data at the end of the provision of services, at the controller's choice, and to delete existing copies. That is the exit. It says nothing at all about Tuesday.
Nothing in Article 28 sets a retention period during the relationship. The regulation leaves that to the controller, which is you, and the mechanism by which you exercise it is the dropdown.
Storage limitation, meanwhile, is your duty and not the platform's. Article 5(1)(e) says personal data is kept in identifiable form no longer than necessary for the purpose, and Article 5(2) puts the burden of demonstrating that on the controller. So the obligation sits with the organisation, the enforcement sits with the product, and the product's default sits with the vendor. Three parties, and the one carrying the liability is in the middle.We have quoted no platform's wording in this piece, because we have not opened one for it. What is described here is the shape these agreements take and what the regulation permits them to leave out, not a report on any named company's current terms.
Both directions of the change cost something
A shorter default deletes the thing somebody needed. The message that showed when a decision was taken, the thread an investigator would have walked back through, the record a former employee's solicitor asks for. A shortened default is no defence to a preservation duty, either: if you were obliged to hold it, you were obliged to hold it, and "the vendor changed the setting" is a sentence that has never improved anyone's position in a hearing.
A longer default keeps everything, which sounds safer and is not. Every message ever sent is then discoverable, indexable, and inside the scope of the next access request. Storage limitation does not have a vendor exception.
Which direction a given change runs in is a product decision, and it is usually made for storage cost or for a feature that needs history to work against. It is not made with any particular customer's obligations in mind. It cannot be.
The question nobody has answered
Here is the hinge, and it is the thing to ask before anything else.
When a platform changes a default, does the change reach workspaces created before it? Sometimes the new value applies only to new tenants and everyone existing is grandfathered. Sometimes it applies to every tenant that has not set an explicit value. Those are entirely different events, and the terms do not distinguish them because the terms do not mention defaults at all.
The second case produces an outcome worth sitting with. An administrator who opened the console, looked at ninety days, and deliberately chose ninety days has an explicit setting and is untouched. An administrator who opened the console, agreed with ninety days and closed it has nothing, and is moved. Two organisations with identical policies and identical intentions, separated by whether somebody once clicked a value that changed nothing at the time.
Opened the console and set 90 daysexplicit value
Opened the console, agreed, closed itinherits the default
So the question for the account manager is one sentence long. When you change a default, does it apply to workspaces created before the change, and does an explicitly set value that matches the old default count as set?
The answer will not be in the contract. It will be in a changelog, and a changelog is not a document anyone has agreed to keep.
Written from
Primary The document itself. Claims in this piece rest only on these.
- Regulation (EU) 2016/679 (GDPR), Article 5(1)(e) and Article 17Storage limitation and erasure. Read and paraphrased, not quoted. The point the piece rests on is whose duty it is: 5(2) makes the controller responsible for demonstrating compliance with 5(1), and the controller is the customer, not the platform. An editor should read 5(1)(e) and 5(2) off the consolidated text before this runs.
- Regulation (EU) 2016/679 (GDPR), Article 28(3)(g)Cited for one point, negatively: it obliges the processor to delete or return the data at the end of the provision of services, at the controller's choice. It says nothing about how long anything is kept while the service is running. Two operative words quoted. If the quotation cannot be checked against the consolidated text, cut it rather than approximate it.
Reporting Attributed, not relied on. Where the reporting is the fact, it says so.
- Placeholder: reporting on retention defaults surfacing in litigation and in regulatory investigationsAttributed if used. Nothing in the piece rests on it. We could not establish whether any supervisory authority has ruled on a controller's position where a processor changed a default retention value without a contractual change, and the piece says so rather than assuming.
Lead Pointed us at the story. Nothing here is cited as authority.
- Placeholder: the standard terms, data processing addenda and administrator documentation of the collaboration suites this piece describesWe have not opened a current agreement or admin console for this article and no product is named for that reason. Everything here about change control, deletion wording and default values is a description of the shape these contracts take, not a report of any particular one. If the piece is to name a platform, someone must pull the current terms, the current default and an archived copy of the earlier default, and put all three in front of the editor.
- Placeholder: the administrator changelog entries that prompted this pieceWe have reproduced no entry and dated none. The claim in the piece is about where such a change is announced, not about any specific announcement.
