--- title: "Archive emails in compliance with GoBD: What is required" description: "Which emails you must retain, when the email itself becomes a document, and how to automatically secure attachments like invoices in compliance with GoBD." type: "wissen" product: "documents" slug: "gobd-email-archivierung" language: "en" source_id: "wissen/gobd-email-archivierung" published: "2026-06-10" status: "publish" faq_json: - q: "Must all emails be archived?" a: "No. Emails that serve as business correspondence or accounting documents are subject to retention requirements—for example, quotes, order confirmations, or invoices. Pure transport emails without their own content are generally not required to be kept." - q: "When is an email considered business correspondence?" a: "When it prepares, concludes, executes, or reverses a transaction—for example, when it contains contract details, terms, or binding commitments." - q: "Is it sufficient to secure the invoice attachment and delete the email?" a: "If the email serves only as a transport medium and the attachment is archived in full and unchanged, this is generally considered sufficient. If the email itself contains business-relevant statements, it should also be retained." - q: "How long must business emails be retained?" a: "Depending on the email's function, the statutory retention periods for business correspondence or accounting documents under the German Commercial Code and Tax Code apply." - q: "Does a standard mailbox meet the requirements?" a: "Usually not: In ordinary mailboxes, emails can be deleted and edited. GoBD-compliant retention requires protection against modification throughout the entire retention period." --- Emails must be archived in compliance with GoBD when they are tax-relevant—that is, when they serve as business correspondence or accounting documents, such as quotes, order confirmations, or invoices as attachments. Not every email is affected: pure transport messages ("please find our invoice attached") without their own business content are generally not subject to retention requirements—though their attachments are. ## Which emails you must retain The function determines the requirement, not the medium. An email is typically subject to retention if it - **prepares, concludes, executes, or reverses** a transaction (business correspondence), - itself serves as an **accounting document** or documents terms, prices, and commitments, - carries an attachment subject to retention requirements—in this case, at least the attachment must be secured. Newsletters, internal scheduling notes, or spam do not fall under these requirements. Mixed cases are more difficult: if the email about an invoice attachment also states "as discussed, we grant a 5% discount," the email itself is business-relevant and should be included in the archive. ## Why a mailbox is not an archive A standard mailbox generally does not meet GoBD requirements on its own: emails can be deleted, moved, and mailboxes fill up or are closed when employees leave. GoBD, however, requires immutability, completeness, and organized accessibility over years. You therefore need a process that transfers relevant content from the mailbox into a protected storage system. ## The practical approach: automatically secure attachments For most small businesses, the most important lever is the document flow via email—especially incoming invoices. [webRichtung documents](https://www.webrichtung.de/en/modules/documents/) opens the first door into the shared operating system: the email import transfers incoming attachments into the document inventory. The key points are: - **Attachments** are imported rather than manually removed from the mailbox. - **Batch processing** handles larger volumes of incoming documents in a single workflow. - AI evaluation and archive search subsequently make imported documents discoverable and usable. How the setup works in detail is described in the article [Import documents via email](/en/knowledge/import-documents-via-email.html); you can find the technical documentation at [docs.webrichtung.de/documents](https://docs.webrichtung.de/en/documents/). ## A simple rule for your team To ensure nothing slips through in daily operations, a clear convention helps: business-relevant correspondence runs through defined company mailboxes (e.g., invoice@, info@), not personal addresses. What comes in as a document attachment goes into storage through the regulated email import; emails with their own contract content you deliberately file in addition. ## Quick checklist for your company - Do invoices and order confirmations come in through defined company mailboxes? - Are attachments automatically transferred to a protected storage system—or does this depend on one person? - Can archived documents be found again by content, date, and amount? - Is there a process in place for what happens to old emails when mailboxes are closed or staff changes occur? If you answer no to any question, that is the place to start. Begin with this one incoming path and expand the process only once it is running reliably. This article provides general information and does not replace legal or tax advice.