Email retention, PIPEDA, and the mailbox you never deleted
Keeping everything forever is not a strategy. It is a larger breach waiting for a number.
ITSIGN Administrator · October 29, 2025 · 2 min read
PIPEDA cares about what you collect and how long you keep it. A departed employee's mailbox sitting open for four years is extra fuel in a breach.
Set a retention schedule. Apply it. Legal hold is a named exception, not the default.
GRC is where we write that schedule so IT and counsel are not improvising.
Related reading
When the phish comes from a vendor you trust
Their tenant, your payment. Callback still wins. So does knowing who is allowed to change details.
2 min read
Turn off IMAP and POP before someone else uses them
Legacy protocols skip modern MFA. They are still on in tenants that were migrated in a hurry.
2 min read
External email banners that help instead of training people to ignore them
If every newsletter is tagged EXTERNAL, staff will stop reading the tag. Tune it.
2 min read
Want this applied to your environment?
A short conversation, an honest assessment of your current setup, and a clear proposal. No obligation and no pressure.
