CommunicationOS

Compliance·13 August 2026·9 min read·Adam Albastov

Messaging compliance for regulated trade

Retention schedules, legal hold, eDiscovery and GDPR when the deal happens on WhatsApp. How regulated firms keep messaging records without breaking storage limitation rules.

The short answer

Regulated companies have legal duties to preserve transaction records, verify client identities, and protect personal data. Trading discussion has moved from formal email servers to mobile messaging apps, and firms often fail those retention standards without noticing. Meeting the duties takes an append-only archive that captures messages on receipt, applies legal holds, and produces a documented export trail.

This article describes how regulated firms usually handle messaging records. It is not legal advice. The duties that apply to you depend on your sector, your licences, and your country, and the wording of a national implementing law can change the retention period or the lawful basis you rely on. Take the checklist at the end to your own counsel and have them mark it up against your licence.

The gap nobody planned

When companies ran internal mail servers, archiving happened by default through journaling rules and scheduled backups. A legal team could pull message archives when auditors asked, and nobody had to plan for it.

Mobile messaging bypassed that infrastructure. Staff installed WhatsApp to reach colleagues, suppliers, and clients directly, and the informal shortcut became the primary commercial channel. Those message streams never pass through a corporate mail server, so firms built high-volume operations with no record-keeping system underneath them.

Retention rules and data minimisation

Regulated sectors work under strict record-keeping rules:

  • Financial trading in the EU. MiFID II Article 16(7) requires investment firms to record electronic communications relating to the reception, transmission, and execution of client orders. Those records are kept for five years, or up to seven years where a competent supervisory authority asks for them.
  • Broker-dealers in the United States. SEC Rule 17a-4 sets a three-year retention period for general business communications. Since 2021 the SEC and the CFTC have brought a series of enforcement actions against firms whose staff conducted business on personal messaging apps that nobody archived.
  • Anti-money laundering rules. The EU AML framework, implemented in Belgium through the Law of 18 September 2017 and updated by the 2024 EU AML package taking effect in 2027, requires obliged entities to retain transaction records and customer due diligence files for five years after the end of a commercial relationship. The definition of an obliged entity reaches well beyond banks, and dealers in high-value goods are inside it.
  • Cross-border goods trade. Customs and export-control paperwork carries its own statutory retention period, and the commercial discussion behind a shipment belongs to the same evidential chain as the documents.

Those retention rules pull against the General Data Protection Regulation. GDPR Article 5(1)(c) sets data minimisation and Article 5(1)(e) sets storage limitation. Article 17 gives individuals a right to erasure, and Article 17(3)(b) removes that right where retention is necessary to comply with a legal obligation under EU or national law.

Firms reconcile the two by classifying messages on content. Communications documenting trade executions, pricing agreements, and customer identification are retained under GDPR Article 6(1)(c) to satisfy the record-keeping duty. Routine non-commercial chat goes through automated deletion once its operational purpose ends, which is what storage limitation asks for.

A retention schedule has three parts: a start event, a period, and a disposal step. A schedule with no disposal step is a filing cabinet, and it puts the firm on the wrong side of Article 5(1)(e). Disposal also depends on knowing what a message is about, which is why classification sits underneath all of this. Our conversation history documentation covers the retention mechanics.

A legal hold suspends the normal disposal schedule for specific records. It freezes automated deletion as soon as litigation becomes anticipated and keeps the files until a compliance team releases the hold. Under United States civil litigation, the duty to preserve electronically stored information starts when litigation is reasonably anticipated, well before a court serves formal discovery orders. Federal Rule of Civil Procedure 37(e) provides for sanctions where a party fails to preserve digital records, and FRCP 26 and FRCP 34 govern how records are produced.

A hold that works in practice meets four operational criteria:

  1. Rapid deployment. Administrators can place an employee or an account under hold within hours of the notice arriving.
  2. Granular targeting. Holds apply to named custodians, counterparties, and date ranges without freezing unrelated archives.
  3. Personnel resilience. An active hold survives the employee leaving and the phone going back in the drawer.
  4. Immutable retention. The hold prevents destruction of the message even when a user deletes the thread on their own device.

The fourth criterion is the hard one on messaging. The platform can remove a message while your hold is in force, and the hold has no authority over Meta's servers or the other party's handset. That is the argument for capturing at receipt.

Production standards for eDiscovery

A discovery request arrives with four things in it: a custodian list, a date range, a set of search terms, and a production format. Handing back unsorted mobile screenshots fails evidentiary standards and invites a procedural challenge. Threads with no boundaries, voice notes that hold the decision, and group chats where most of the traffic is irrelevant all make messaging harder to produce than email.

An evidentiary production for messaging data includes:

  • Full conversation threads in strict chronological order.
  • Participant identification that maps phone numbers and handles to verified real-world identities.
  • Timestamps normalised to a single timezone across every channel.
  • Voice notes paired with both their audio files and their text transcripts.
  • Cryptographic hash values, such as SHA-256, attached to the package to show the records were not altered during export.

Our data export documentation covers the technical specifications.

Managing personal devices in business operations

A firm cannot escape record-keeping duties by letting staff work on personal hardware. When an employee agrees a price or executes a client order on a personal phone, those messages are corporate business records under the law.

A BYOD policy that prohibits business messaging on personal devices with no software controls behind it creates exposure rather than removing it. If regulatory scrutiny later shows that executives routinely dealt with clients over unmonitored apps, the written prohibition shows that management understood the requirement and did not supervise it.

Monitoring personal phone accounts raises serious employee privacy problems under GDPR and domestic labour law. In several European jurisdictions, employer monitoring requires formal consultation with the works council before it starts.

The workable standard is a separate business account on the employee's device. The company captures and archives the business account with the employee's knowledge, the personal account stays unmonitored, and a written policy says business is not conducted on the personal one.

Evidentiary issues with deleted messages

Relying on device backups for compliance archiving leaves an evidentiary hole:

Backup-based archive:
Sender writes: "Price is 500" ---> Sender deletes message ---> Sync runs ---> Message missing from archive

Gateway-level capture:
Sender writes: "Price is 500" ---> Gateway records text (Event #1)
Sender deletes message       ---> Gateway records deletion timestamp (Event #2)
Result: the original text and the deletion event both stay in the record.

When an archive syncs periodically with a phone, a message the counterparty deleted before the sync disappears from the corporate record. An archive that holds up captures traffic at the network gateway on arrival. When a sender deletes a message, the system logs the deletion as its own event and keeps the original text. In a dispute over a price, the record of who removed which number at 16:42 on a Friday often carries more weight than the number.

Operational compliance checklist

Use this to audit your own messaging retention practice this quarter:

  1. Appoint a named compliance officer responsible for electronic messaging archives.
  2. Survey all staff and catalogue every messaging channel used for commercial discussion, including the unauthorised ones.
  3. Identify the statutory retention duties that govern your sector, such as MiFID II, AML law, or SEC rules.
  4. Write retention schedules with explicit disposal rules for each category of business communication.
  5. Establish your lawful basis under GDPR Article 6 for retaining customer and employee communications.
  6. Sign a data processing agreement under GDPR Article 28 with each archive and software vendor.
  7. Run a test legal hold on a sample custodian account and confirm that disposal stops.
  8. Run an end-to-end test of a subject access request under GDPR Article 15 with real customer identifiers.
  9. Confirm that your message data sits in a jurisdiction that satisfies your data residency requirements.
  10. Restrict archive query permissions to authorised compliance personnel and keep an immutable access log.
  11. Document an offboarding protocol that preserves and transfers message archives when an employee resigns.

Built-in compliance architecture

CommunicationOS provides infrastructure for regulated firms and enterprise operations. The platform keeps an append-only archive with legal hold controls, eDiscovery exports, and audit logging on each access.

The SOC 2 Type II audit is under way and ISO 27001 is planned, with data residency inside the European Union today. Enterprise teams manage identities through SAML SSO and SCIM provisioning, bring their own encryption keys, and transfer account ownership when staff move on.

Our security architecture guide covers the technical controls, and the service level agreement covers the uptime commitments.

Bring your message history into one inbox

Connect an account for new messages, then upload an archive or authorise a supported migration for earlier history. Voice notes are transcribed and document text is read on the way in.

No card required. We reply with an onboarding slot and a connection guide.

Talk to us