Chat & Messaging
Part of Collaboration data security and retention
Reviewing retention settings for business conversations
Check effective retention rules for channels, direct messages and external conversations across Slack, Teams and Google Chat.
Match each business conversation to the retention rule that governs it, then check what participants can still see and what an authorised administrator can retrieve. Check the effective rule before shortening a period, as a new setting may affect older messages.
Start with conversation types
Classify public project channels, restricted channels, direct messages, group conversations and conversations created by another organisation. Record each conversation’s purpose, audience, who can change its setting and where an approved outcome should remain if chat history expires.
Compare current settings with the proposed plan: one channel’s rule may not cover direct messages or external conversations. Record when the retention period starts, how edits and deletions are treated, and whether another policy or hold changes the result.
Read the controls by product
Slack: By default, Slack retains all messages and files indefinitely. Workspace and organisation owners can set a workspace-wide rule or custom rules for specific channels and direct messages: keep all messages, including edits and deletions; keep messages without tracking edits and deletions; or delete messages and revisions after a custom period.
For Pro and Business+ subscriptions, open the workspace name, then Settings and Administration → Workspace settings, and expand Message Retention and Deletion. On the free plan, messages are retained for up to one year but visibility is limited to the past 90 days; users need to contact Slack support to view older messages. A paid plan unlocks visibility to history older than 90 days, while editing a message on the free plan replaces its earlier version.
Microsoft Teams: Retention policies cover chat and channel messages, including shared channels. Administrators can apply them across the organisation or to specific users and teams, choosing to retain messages, delete them, or retain them for a set period and then delete them; the period starts when a message is created. Teams does not support retention labels.
When a Teams policy retains messages, users can still edit or delete their messages but may no longer see the edited or deleted versions. Compliance administrators can search the copy stored in a secured location using eDiscovery; permanent deletion waits until the configured period ends unless another retention policy or an eDiscovery hold applies.
When a Teams policy is set to delete chat or channel messages, they become eligible for automatic deletion. If they are still displayed in the Teams app, they disappear from there.
Google Chat: Administrators can set auto-deletion separately for 1:1 direct messages, group messages and spaces. This applies only to messages sent with history on; supported editions are Frontline Plus, Business Plus, Enterprise Standard, Enterprise Plus, Education Standard, Education Plus, Enterprise Essentials and Enterprise Essentials Plus.
For an externally created conversation, the creator organisation’s auto-deletion policy governs; your organisation’s Vault rules do not cover messages in externally owned spaces. Google Vault covers messages and attachments sent with history on, but not history-off messages, linked files or messages in external Chat spaces.
Auto-deletion can remove a message from the conversation while Vault retains it. Without a Vault rule, auto-deleted or user-removed messages are kept for 30 days after removal; where Vault rules apply, a removed message remains in Vault for the rest of its retention period or at least 30 days. Purging begins on day 30 and may take several days.
A Vault hold prevents user data from being deleted and can apply to individual accounts or entire organisational units. Holds do not apply to messages in extra-large spaces with over 50k users.
Key Retention Facts by Platform
- Slack - Paid Plan VisibilityHistory beyond 90 days accessible
- Teams - Policy ApplicationApplies to chat, channel, and shared channels
- Google Chat - Vault CoverageMessages with history on only; does not cover linked files or external spaces
Record and check the decision
Use one record per conversation type: purpose, audience, history state, effective rule, setting owner, exceptions or holds, what users can see, and what an authorised administrator can retrieve. Mark unclear entries for administrator review.
Before a broad change, test with safe material and a limited set of intended account types. Check the participant view and ask an authorised administrator to confirm the applicable retrieval route; that check does not prove the same behaviour for every conversation.
For organisations subject to the Australian Privacy Principles, the OAIC says reasonable steps to destroy or de-identify personal information no longer needed are required unless an exception applies. Exceptions include a Commonwealth record or retention required by Australian law or a court or tribunal order.
Have the responsible owner assess that obligation alongside operational needs. Record the decision and its next review trigger.



