Retention policies in MCO eComms control how long captured messages and alerts are stored before they are automatically deleted. Legal holds allow you to suspend that automatic deletion indefinitely for specific communications or participant groups. Together, these two features give your organization control over its data lifecycle and may assist with meeting regulatory requirements for electronic communications recordkeeping.
Retention periods and legal hold decisions must be configured to meet your organization's regulatory and internal requirements. MCO does not provide legal advice on appropriate retention periods or hold criteria.
What is retention?
Retention refers to the period during which MCO eComms keeps a captured message or alert accessible in the system. Each message and alert has a calculated purge date — the date on which it becomes eligible for automatic deletion.
Purge dates are calculated differently depending on the record type:
Messages — the purge date is calculated from the original Sent At date of the message.
Alerts — the purge date is calculated from the date the risk was detected, not the date the message was sent.
How retention policies work
MCO eComms evaluates retention at the message level based on the participants involved. When a message is captured, eComms examines all senders and recipients and applies the retention policy associated with those participants.
When participants in the same message are subject to different retention policies, eComms always applies the longest applicable policy. This ensures the message is retained for the full period required by any participant's policy.
Message retention
Each participant in a message is evaluated individually:
Participants with no group membership are subject to the account-level Retention Policy.
Participants who belong to one or more groups are subject to the longest group-level policy that applies to them.
Because a single message is stored once but may be visible across multiple groups, its retention period reflects the maximum policy across all participants involved.
Alert retention
Alert retention is determined by the policy that generated the alert:
Alerts generated by an account-level policy are subject to the account-level Retention Policy.
Alerts generated by a group-level policy are subject to that group's Retention Policy.
The message that triggered an alert is retained for at least as long as the alert itself, along with any surrounding message context needed to support the alert.
What gets retained
MCO eComms retains more than the message body. The following are held until all associated messages have passed their purge date:
Message attachments
Source files
Batch files containing the message
For alerts, the triggering message and its supporting messaging context are retained for at least as long as the alert.
Account-level and group-level policies
Retention policies can be defined at two levels.
Account level
An account-level Retention Policy sets a default retention period across your entire organization. It applies to all captured messages and alerts that do not match a more specific group-level policy.
Group level
A group-level Retention Policy applies to a defined set of participants — for example, a business unit, desk, or regulatory group. When a message involves participants belonging to a group with a specific Retention Policy, that policy takes precedence over the account-level default.
This layered approach allows you to apply longer retention periods to higher-risk groups — such as traders subject to Financial Industry Regulatory Authority (FINRA) or Securities and Exchange Commission (SEC) requirements — while applying shorter periods to lower-risk populations.
Default retention settings
Your account includes the following default retention periods:
Record type | Default retention period |
Mapped messages | 7 years |
Alerts | 7 years |
Unmapped messages | 90 days |
Mapped messages are messages where at least one participant is matched to a monitored user profile in MCO eComms. These messages are subject to compliance review and are retained for 7 years by default.
Unmapped messages are messages where no participants match a monitored user profile. Because these messages fall outside the scope of active compliance monitoring, they are retained for 90 days by default.
Note: These defaults may not satisfy the retention requirements of all applicable regulations. Review your retention settings with your compliance and legal teams before going live.
To change your account or group-level retention settings, see Configure retention policies.
Legal holds
A legal hold suspends automatic purging for specific communications, overriding any retention policy that would otherwise delete them. Records under a legal hold are not purged until the hold is removed, regardless of their calculated purge date. Multiple legal holds can apply to the same record simultaneously.
When a legal hold is removed, any records that have already passed their purge date are deleted in the next processing cycle.
MCO eComms supports two types of legal holds.
Collection-based holds
A collection-based hold applies to a specific set of identified communications grouped into a Collection. All records in the Collection are held together for as long as the hold is active.
This approach is suited to targeted preservation — for example, holding all communications related to a specific investigation or regulatory inquiry.
Group-based holds
A group-based hold applies to all messages involving members of a specific group. Once enabled, automatic purging is suspended for all messages that include a group member as a participant — including historical messages already in the system and all future messages captured while the hold is active.
This approach is suited to broad preservation — for example, placing all communications for a trading desk on hold during an audit.
