This is a pretty common strategy. Many companies have poor record retention and backup policies because it's in their best interest to "forget" the things they do. I know of large companies that limit email boxes to 50 MB partially because it forces deletion of old, possibly incriminating email. Government agencies are generally supposed to be better about this due to stuff like the Freedom of Information Act. I wonder if there's any teeth in the act for non-compliance like this?
I am reminded of the whole (and multi-part / -dimension) GWB email "fiasco".
"Lost" servers. "Deleted" emails. Suspicious hints of use of non-governmental email accounts for government business and/or avoiding detection of campaigning using official resources (time, location, staff, "trades").
What ever became of that? Not much.
This has a bit of a different flavor in the press. Nonetheless, I'm not optimistic.
There's an entire e-discovery "market"(updside down question mark) for software and services that are frequently quoted as running into six-figure territory at even the mention of the word "lawsuit" (actual quote).
A legal hold is nothing more than the inability to delete when you think you might get sued and culling and deduplication, if anticipated, can always be made easier by better business practices on the front-end instead of incurring costs on the backend.
Of course, as you mentioned there are ZERO companies that would want to be better in this regard. They want to be able to tell a court that it's a pain in the ass to institute these practices and the courts and legislatures have seemingly accepted this proposition either because they are themselves complicit or because they literally hear the word "technology" and piss their pants and cry for their secretary.
tl;dr, the best business from a risk management perspective is an IT nightmare
>"This is a pretty common strategy. Many companies have poor record retention and backup policies because it's in their best interest to "forget" the things they do."
Yep.
From a slightly less nefarious angle, retention costs and servicing discovery requests costs more. It's in your best interest to minimize what's retained even if you don't need to "forget" anything in particular.
I'm not sure how it's less nefarious from a discovery viewpoint as I said below. It's just a cheat, a hack, albeit a commonly accepted one. It would hold no water in an effective and optimally-run business - so it goes that since you are not legally obligated to operate as effective and optimal as against outsiders, only shareholders (and even then only competently), your ineffectiveness and in-optimalness but purposeful conduct is shielded from liability.
In other words, the best run business for your shareholders is somehow demonstrated by being a pain in the ass for the public than it is as actually being a better run company by objective internal standards.
Don't get me wrong, great strategy that works and anyone who runs a business should continue to follow it lest they want to be ousted for cause, but sad reality that it's the state of things.
Don't get me wrong, great strategy that works and anyone who runs a business should continue to follow it lest they want to be ousted for cause, but sad reality that it's the state of things.
I know of large companies that limit email boxes to 50 MB partially because it forces deletion of old, possibly incriminating email.
Fortunately it doesn't stop me from archiving locally. I've got emails from 2006 on my desktop machine. It is damn frustrating that my free gmail account is drastically less trouble to manage and search than my (probably expensive) corporate Exchange account.
Archiving my work email by forwarding to a personal email literally won me a decision against a former employer. When they can cut off your credentials in anticipation of firing you and they think it means you don't have access to those emails anymore, it's really satisfying to show up at the next hearing with clear proof that they've come down with a terminal case of foot-mouth syndrome.
Comments
This is a pretty common strategy. Many companies have poor record retention and backup policies because it's in their best interest to "forget" the things they do. I know of large companies that limit email boxes to 50 MB partially because it forces deletion of old, possibly incriminating email. Government agencies are generally supposed to be better about this due to stuff like the Freedom of Information Act. I wonder if there's any teeth in the act for non-compliance like this?
I am reminded of the whole (and multi-part / -dimension) GWB email "fiasco".
"Lost" servers. "Deleted" emails. Suspicious hints of use of non-governmental email accounts for government business and/or avoiding detection of campaigning using official resources (time, location, staff, "trades").
What ever became of that? Not much.
This has a bit of a different flavor in the press. Nonetheless, I'm not optimistic.
There's an entire e-discovery "market"(updside down question mark) for software and services that are frequently quoted as running into six-figure territory at even the mention of the word "lawsuit" (actual quote).
A legal hold is nothing more than the inability to delete when you think you might get sued and culling and deduplication, if anticipated, can always be made easier by better business practices on the front-end instead of incurring costs on the backend.
Of course, as you mentioned there are ZERO companies that would want to be better in this regard. They want to be able to tell a court that it's a pain in the ass to institute these practices and the courts and legislatures have seemingly accepted this proposition either because they are themselves complicit or because they literally hear the word "technology" and piss their pants and cry for their secretary.
tl;dr, the best business from a risk management perspective is an IT nightmare
>"This is a pretty common strategy. Many companies have poor record retention and backup policies because it's in their best interest to "forget" the things they do."
Yep.
From a slightly less nefarious angle, retention costs and servicing discovery requests costs more. It's in your best interest to minimize what's retained even if you don't need to "forget" anything in particular.
I'm not sure how it's less nefarious from a discovery viewpoint as I said below. It's just a cheat, a hack, albeit a commonly accepted one. It would hold no water in an effective and optimally-run business - so it goes that since you are not legally obligated to operate as effective and optimal as against outsiders, only shareholders (and even then only competently), your ineffectiveness and in-optimalness but purposeful conduct is shielded from liability.
In other words, the best run business for your shareholders is somehow demonstrated by being a pain in the ass for the public than it is as actually being a better run company by objective internal standards.
Don't get me wrong, great strategy that works and anyone who runs a business should continue to follow it lest they want to be ousted for cause, but sad reality that it's the state of things.
Huh?
Fortunately it doesn't stop me from archiving locally. I've got emails from 2006 on my desktop machine. It is damn frustrating that my free gmail account is drastically less trouble to manage and search than my (probably expensive) corporate Exchange account.
Archiving my work email by forwarding to a personal email literally won me a decision against a former employer. When they can cut off your credentials in anticipation of firing you and they think it means you don't have access to those emails anymore, it's really satisfying to show up at the next hearing with clear proof that they've come down with a terminal case of foot-mouth syndrome.
>"Fortunately it doesn't stop me from archiving locally. I've got emails from 2006 on my desktop machine."
That's a rather poorly implemented policy by and future landmine for your IT department.
I would guess they use MS Exchange internally, and that is the issue.
Seems to turn Hanlon's razor on its head.
Heinlein's Razor - "Never attribute to malice that which can be adequately explained by stupidity, but don't rule out malice"
"Never X..but don't rule out X"?
Seems like "Don't be quick to..." or something similar would be better.