About Newsletter Contact
Guide

Disappearing messages and disclosure: a retention guide for firms

A message retention policy is defensible when it sets a period the firm can justify, carves out matter-related material before deletion, and can be suspended at platform level.

Last UpdatedAugust 2026
6 min read Litigation, Costs and Procedures
Who This Guide Is For

This guide is written for solicitors, trainees and law students in England and Wales.

Solicitors Trainees Law Students Litigation, Costs and Procedures

A message retention policy is defensible when it does three things: sets a period the firm can justify, carves out matter-related material before the timer runs, and can be suspended at platform level when a hold bites. R (BB) v Commissioner of Police of the Metropolis [2026] EWHC 1986 (Admin) upheld a 90-day auto-deletion policy on exactly that basis, and the carve-out was what carried it.

This guide covers what a defensible period looks like, how to build the carve-out, and why most litigation holds never reach the platform they are aimed at.

Who is this guide for?

COLPs, COFAs, risk and IT leads, and anyone who has been asked whether the firm can switch on disappearing messages. It assumes client and internal communications already run across WhatsApp, Teams and comparable platforms, because in most firms they do, whether or not the policy says so.

Is auto-deletion lawful?

It can be. In R (BB), McKendrick J dismissed all four grounds of a challenge to Metropolitan Police guidance requiring officers to run WhatsApp’s 90-day disappearing messages function on force devices. The guidance had been adopted in 2023 despite documented ICO concerns and reservations recorded in the force’s own data protection impact assessment, and it survived anyway.

What makes the case useful outside policing is the structure of the policy rather than the outcome. The guidance did not simply switch deletion on and leave the consequences where they fell. It required evidential material shared by members of the public to be exported to another system before the timer ran. Strip that requirement out and a different policy is left: one that deletes material of potential evidential value on a fixed schedule with nothing preserved. Nothing in the judgment suggests that version would have survived. Our note on what the ruling means for firms sets out the reasoning.

One further point worth carrying to a risk committee: a DPIA that flags a risk is not, on this judgment, fatal to the policy it assesses. Documenting a concern and proceeding with reasons is a stronger position than not documenting it.

What a defensible retention period looks like

There is no fixed number, and any guide offering one is guessing. What makes a period defensible is that the firm can say why it chose it, against four things at once.

Driver Pull Where it comes from
Disclosure duties Towards longer retention CPR Part 31 and PD 57AD
Regulatory record-keeping Towards longer retention SRA Standards and Regulations
Limitation exposure on the matter type Towards longer retention Limitation Act 1980 and the retainer
Storage limitation Towards shorter retention UK GDPR
Breach exposure Towards shorter retention Risk appetite, insurer requirements

Those pull in opposite directions on purpose. The answer is a reasoned position between them, recorded, rather than a number adopted because another firm uses it.

Firms often try to resolve the tension by setting one period for everything, which is administratively simple and evidentially weak, because the storage limitation argument for a short period is strongest exactly where the disclosure argument for a long one is weakest, and a single number cannot be right for both. A more defensible structure sets a short default for genuinely transient traffic and a longer period for anything exported to a matter, which is why the carve-out below is doing more work than it looks.

How do you build the export carve-out?

This is the part that made the difference in R (BB), and it is the part most firm policies omit.

How do litigation holds reach a messaging app?

Usually they do not, and this is the failure most firms have never tested.

A hold circulated by email to fee earners does nothing to a timer running server-side on a platform the firm may not administer. Individuals cannot reliably suspend a setting they did not configure, and a policy that depends on them remembering to preserve will fail under CPR Part 31 and PD 57AD at the point it is examined.

Three questions settle it for each platform:

  1. Who administers the tenancy? If the answer is a personal account, the firm has no hold mechanism at all and the platform should not be carrying matter communications.
  2. Can retention be suspended centrally? Enterprise deployments generally allow it. Consumer deployments generally do not.
  3. How long does suspension take to apply, and does it reach material already inside the deletion window? A hold applied on day 89 of a 90-day timer is a race.

The review checklist

Personal devices deserve their own answer before the checklist begins, because they are where most of the risk actually sits. A fee earner messaging a client from a personal account on a personal handset is outside every control described above: the firm does not administer the tenancy, cannot apply a hold, cannot audit the retention setting and may not know the communication exists. That is a policy problem rather than a technical one, and the only workable positions are to prohibit it and enforce the prohibition, or to bring the platform inside the estate so that the controls reach it.

  1. List every platform carrying client or matter communications, including the ones not formally approved.
  2. Record the retention setting actually configured on each, rather than the one the policy states.
  3. Confirm whether each has an export carve-out, and whether it names a destination.
  4. Establish whether a hold can be applied at platform level or only requested at user level.
  5. Document the reasoning behind the chosen period against the five drivers above.
  6. Record the decision, the date and the decision-maker, in the DPIA.
  7. Test one hold end to end and record what happened.
  8. Set a review date.

Common mistakes

Assuming the written policy describes the configuration. The gap between what the retention policy says and what is switched on across the estate is where the exposure sits, and it is usually wider than anyone expects.

Treating disappearing messages as a data protection question only. It is a disclosure question first, and the two point in different directions.

Relying on individual preservation. Documented processes are what regulators and courts examine, which is the same theme running through complaints handling under UK GDPR.

Leaving the DPIA undated or unsigned. The trail is the defence. An undated assessment proves nothing about what the firm knew and when.

Official sources

The judgment in R (BB) v Commissioner of Police of the Metropolis is on the Judiciary website. Part 31 and PD 57AD sit on the Ministry of Justice procedure rules pages, and the ICO publishes guidance on storage limitation and on data protection impact assessments.

Why It Matters

Most firms have a retention policy on paper and a different one running on the devices. Auto-deletion is not unlawful in itself, but the policy that survived judicial review had an export step for material that mattered. A firm running disappearing messages with no carve-out, and no hold that reaches the platform, is relying on a policy this judgment would not have saved.

Last updated: 6 August 2026.