Why Should Financial Institutions Be Cautious About Email Management?

The pandemic has caused many organizations to feel the need to become more agile and adaptable to change. At the core of this shift is moving towards a hybrid work approach that includes a broader distributed workforce and refocusing on employee experience and opportunities for collaboration with third parties.

28 Apr 2024 SintelSedat Akfidan 5 min read
Why Should Financial Institutions Be Cautious About Email Management?

Email Management and Storage Policies in the Financial Sector

The shift to a hybrid work approach in the digital business environment has pushed financial institutions to take on more responsibility regarding data, including implementing strong email management strategies.

An important driving force behind this is that the financial sector is now more strictly regulated than ever before. For example, the second version of the pan-European Markets in Financial Instruments Directive (MiFID II) came into force in 2018, requiring companies operating in the financial sector within EU member states (e.g., investment firms, credit institutions, or data reporting service providers) to implement record-keeping obligations.

As stated in MiFID II Article 16 (6), an investment firm must ensure that sufficient records are kept of all services, activities, and operations undertaken by the business to enable the competent authority to perform its supervisory duties and in particular to determine compliance with all obligations. Therefore, it is clear that financial institutions must closely monitor how they manage and archive their electronic communications.

Email Archiving and Email Backup

The primary purpose of email archiving is to ensure that email data remains in its original form and can be retrieved at any time. Organizations must analyze which types of emails should be archived for how long. Examples of business-critical information in emails include invoices, price quotes, support inquiries, or service complaints. In addition, an email management strategy must also take into account requirements according to data privacy regulations such as the EU-GDPR and similar regulations. As a result, it may not be advisable to archive all emails indefinitely.

Email archiving capabilities are distinct from backup solutions that are used together to create temporary copies of the email server's data in an external storage environment or cloud. There is a backup system for disaster recovery: In the event of data loss or system outages, such as hardware failures caused by cyberattacks, it allows for the retrieval of temporary, backed-up data sets from external storage.

Basic Requirements for Complying with Data Privacy Regulations

Business-related emails almost always contain personal data or other sensitive information. Sector-specific regulations such as the EU-GDPR and data privacy laws have been a significant driving force in increasing awareness of email management strategies among businesses over the past few years. Privacy laws include provisions aimed at protecting individuals' fundamental rights and freedoms regarding the processing of personal data. General EU-GDPR principles include purpose limitation, data minimization, storage limitation, as well as integrity and confidentiality. The organization that defines the purposes and means of processing, known as the "controller," will be held responsible for compliance with these principles.

For example, an email archiving solution should allow for the automatic deletion of archived emails when appropriate, thereby freeing up storage space and complying with data privacy principles such as data minimization and purpose limitation under EU-GDPR Article 5.

Data Location, Data Sovereignty, and the Use of External Providers

Creating an email management strategy involves assessing whether emails are stored within a company's own IT infrastructure or on a server managed by an independent SaaS provider or subcontractors. When it comes to data storage, leveraging cloud technology is a great option due to its scalability. However, this does not address where the email data is located, how it is protected, and how it is managed.

Financial businesses evaluating the implementation of a cloud solution will need to carefully consider sector-specific requirements, such as guidelines for the use of external service providers by the European Banking Authority (EBA) or the European Insurance and Occupational Pensions Authority (EIOPA).

On the other hand, it is essential to determine where emails are processed and archived, that is, where the data centers are located and from where access is possible. This is governed by Article 44 et seq. of the EU-GDPR, which states that the transfer of personal data to a third country will only occur if the level of protection in that country is not reduced. In the past, businesses could rely on Safe Harbor Privacy Principles to ensure an adequate level of protection. However, the Safe Harbor was invalidated by the European Court of Justice ("ECJ") in 2015. This was the first "Schrems" decision, named after Austrian activist Max Schrems. The EU-US Privacy Shield, which replaced Safe Harbor, was also invalidated in another European Court of Justice case known as Schrems II in 2020. As a result, legally transferring personal data to third countries has become significantly more difficult.

Additionally, when working with a SaaS provider, a business should consider entering into a Data Processing Agreement ("DPA"). A DPA is a contract that covers the requirements of Article 28 of the EU-GDPR. It is required when a third party ("processor") is engaged to process personal data on behalf of the controller. In addition to other requirements, the controller must ensure that the processor applies appropriate technical and organizational measures to protect the data.

Email Archiving as Part of Your Business Continuity Strategy

We recommend that all financial institutions implement a robust email governance approach as part of their integrated business strategy, including an independent email archiving solution.

Identifying and managing security and data risks within the organization can also be challenging. Email archiving can help reduce internal risks by strengthening compliance with sector-specific and country or region-specific regulations.

Professional email archiving solutions allow businesses to choose from different strategic archiving approaches based on their needs. However, selecting the right archiving strategy is very important. If legal compliance is the main focus of email archiving, daily archiving may be the best option. Alternatively, if the main goal is to clear out the email server, mailbox archiving with specific deletion rules may be a better option.

Combining both approaches is also possible, allowing financial institutions to use email archiving as an essential part of their corporate strategy.

Source: Why Financial Institutions Should Be Cautious About Email Management (mailstore.com)