Email Archiving in the Finance Sector - Sectors Subject to Regulation
On this blog, articles generally discuss local and international regulations affecting how companies and organizations handle their email traffic. For example, Austria has the Federal Tax Code (Bundesabgabenordnung – BAO), the Commercial Code (Unternehmensgesetzbuch – UGB), and the Value Added Tax Act (Umsatzsteuergesetz – UStG).

Requirements for Compliance in the Financial Sector
In Switzerland, there is a Debt Law (Obligationenrecht - OR), while in Germany, "Principles regarding the proper management and storage of records and documents in electronic form as well as data access" (or shortly GoBD) establishes the requirements for processing commercially important e-mails. According to this, certain e-mails must be archived in a secure manner against tampering. In addition to these national decrees, laws, and administrative regulations, the European General Data Protection Regulation (EU-GDPR) also has an impact on how e-mails are managed in commercial organizations. The above-mentioned regulations apply to companies in all sectors. In addition, there are sector-specific regulations that may be valid only nationally and not globally. For example, in the United States, health companies are subject to the Health Insurance Portability and Accountability Act (HIPAA). Therefore, all U.S. health companies must comply with strict rules designed to protect the confidentiality and integrity of patient information.
Compliance Requirements in the Financial Sector
Globally, there are other rules that require the keeping of records of commercial transactions, which also affect the management and archiving of e-mails. For example, in the United States, the Financial Industry Regulatory Authority (FINRA) oversees operations in the investment banking sector and requires providers of securities trading services to retain e-mails for a certain period (see). The financial sector in the EU is currently another heavily regulated sector. In 2018, the second version of the Markets in Financial Instruments Directive (MiFID II) came into force across Europe and required companies operating in the financial sector within EU member states (e.g., investment firms, financial advisors, and credit institutions) to comply with record-keeping obligations. Article 16 of MiFID II states:
"Records shall include at least the recording of telephone conversations or electronic communications related to transactions carried out on one's own account, as well as the provision of customer order services for the receipt, transmission, and execution of customer orders." It continues: "Such telephone conversations and electronic communications shall also include the execution of transactions carried out on one's own account or the provision of customer order services, even if these conversations or communications do not result in the execution of such transactions or the provision of customer order services."
Archiving Requirements
In practice, this means that investment firms must maintain records in an environment that allows for the storage of information and enables access to it at a later date.
- Information should be easily accessible, and each important step of processing each transaction should be reconstructable.
- All versions should be easily identifiable - any corrections or other changes, and the content of records prior to such corrections or changes should be easily identifiable.
- Records should not be manipulable or modifiable.
- Considering the volume and nature of data, there should be methods for the efficient use of records when analysis of data is required.
Therefore, it is clear that investment firms, financial advisors, and credit institutions must closely monitor how they manage and archive their electronic communication environment if they wish to comply with MiFID II.
E-Mail Archiving with MailStore Server in Banks
Banks use, for example, MailStore Server to comply with these legal requirements for compliant e-mail archiving. In fact, individual branches of public sector credit institutions in Germany have been using MailStore Server for many years. In Eastern Europe, banks and financial institutions are increasingly preferring our software. Therefore, MailStore Server is frequently the preferred environment for e-mail archiving in the financial sector. Our software provides features that help companies and organizations in the financial sector meet their compliance requirements. These include, among others:
- Auditability: MailStore Server uses its own control log or Windows event log to record the activities of MailStore administrators and users. This allows, for example, a compliance officer to monitor compliance with legal and operational regulations, while an external auditor can be assigned a special user role for control purposes.
- Encryption: The e-mail archives themselves, as well as access to them and the communication between MailStore Server and the e-mail system are encrypted. MailStore Server applies AES256 encryption to e-mails, attachments, and control logs. This ensures that archived data cannot be tampered with later. TLS encryption is used at the level of communication between MailStore Server and the e-mail system.
- Monitoring and Limiting Privileges: By configuring user roles in MailStore Server, it is possible to require who has access to an archive and its contained e-mails. In addition, user logins/logouts and all archive accesses are logged, making it possible to track who accessed the e-mails and when this occurred.
Source: E-Mail Archiving in Finance, FINRA, MiFID II - MailStore