When litigation strikes or a regulatory audit arrives, your legal team needs data—fast. Google Vault is the archiving and eDiscovery tool built directly into Google Workspace that lets administrators search, hold, and export organizational data across Gmail, Drive, Chat, Groups, Voice, and Meet recordings. Understanding how to use Vault effectively is the difference between a smooth legal response and a scramble that costs your organization time, money, and credibility.
What Is Google Vault?
Google Vault is an information governance and eDiscovery solution included with Google Workspace Business Plus, Enterprise, Education Fundamentals, Education Plus, and as a standalone add-on. It provides three core capabilities:
- Retention: Define how long data is preserved, regardless of whether users delete it from their accounts.
- Legal holds: Preserve specific users' data indefinitely to meet litigation or investigation requirements.
- Search and export: Find relevant data using powerful search operators and export it in standard formats for legal review.
Vault operates on data already stored in Workspace services—it does not create separate copies. Instead, it prevents data that would otherwise be purged from being permanently deleted, ensuring that nothing falls through the cracks during an active legal matter.
Creating and Managing Matters
A matter in Vault is a container that groups holds, searches, and exports related to a specific legal case or investigation. Think of it as a case folder.
Best Practices for Matters
- Use descriptive naming conventions: Include the case number, date, and a brief description (e.g., "2026-IP-Dispute-AcmeCorp").
- Restrict collaborators: Only add team members who have a legitimate need to access the matter. Vault supports granular sharing controls.
- Close matters when resolved: Closing a matter releases all holds associated with it. Only close once legal counsel confirms the obligation has ended.
- Audit matter activity: Vault logs who accessed, searched, and exported data within each matter. Review these logs periodically and as part of your audit log monitoring practices.
Legal Holds: Preserving Data Under Obligation
A legal hold overrides both user actions and retention rules. When you place a hold on a user's account, their data is preserved even if they delete emails, empty trash, or if a retention policy would otherwise purge the data. Holds are non-negotiable in litigation—failing to preserve relevant data can result in sanctions, adverse inferences, or case dismissal.
Types of Holds
- Account-based holds: Preserve all data for specific user accounts across selected services (Gmail, Drive, Chat).
- Organizational unit holds: Hold data for all users in a specific OU—useful for department-wide investigations.
- Query-based holds: Preserve only messages matching specific search criteria (date ranges, keywords, senders). Use with caution, as overly narrow queries risk missing relevant data.
When placing holds, always err on the side of over-inclusion. It is far less costly to preserve too much data than to face spoliation claims because a relevant document was purged.
Searching and Exporting Data
Vault's search interface supports Gmail-style operators, making it familiar to most administrators. You can search across Gmail, Drive, Groups, Chat, and Voice using operators such as from:, to:, subject:, has:attachment, and date ranges with before: and after:.
Export Formats and Considerations
Once you've identified relevant data, Vault exports it in industry-standard formats:
- Gmail: Exported as MBOX files with associated metadata in XML format.
- Drive: Files are exported in their original format (Google Docs become DOCX, Sheets become XLSX) with metadata.
- Chat: Exported as PST or MBOX files depending on configuration.
Exports are generated asynchronously and stored in Google Cloud Storage for 15 days. Large exports may take hours—plan accordingly when facing court deadlines. For organizations managing frequent exports, consider automating export workflows to reduce manual overhead.
Retention Policies: The Foundation of Data Governance
Retention policies define how long your organization keeps data. They operate independently of holds and apply across organizational units or the entire domain.
Default vs. Custom Retention Rules
- Default retention rule: Applies to all data in a service that isn't covered by a custom rule. For example, "retain all Gmail messages for 7 years."
- Custom retention rules: Target specific OUs, date ranges, or message types. Custom rules take precedence over the default rule.
Retention Strategy Recommendations
Your retention strategy should align with your industry's regulatory requirements:
- Financial services: SEC Rule 17a-4 requires broker-dealers to retain certain electronic communications for at least 3 years (6 years for some records).
- Healthcare: HIPAA requires covered entities to retain certain records for 6 years from the date of creation or last effective date.
- General business: In the absence of specific regulations, a 7-year default retention period covers most statute-of-limitations windows.
Document your retention policies and review them annually with legal counsel. For ongoing monitoring, integrate retention compliance into your compliance reporting workflow.
Compliance and Regulatory Alignment
Google Vault directly supports compliance with frameworks that require data preservation and accessibility:
- SOC 2 (Trust Services Criteria): Vault's retention and hold capabilities demonstrate that data is retained and retrievable per policy.
- GDPR (Article 17 - Right to Erasure): Retention rules ensure data is deleted on schedule, but legal holds can override deletion requests when a legitimate legal basis exists.
- HIPAA (45 CFR §164.530): Vault helps covered entities maintain required documentation retention periods.
- FRCP (Federal Rules of Civil Procedure): Legal holds satisfy the duty to preserve electronically stored information (ESI) in US litigation.
Strengthen your compliance posture further by combining Vault with context-aware access policies that control who can access sensitive data in the first place.
Frequently Asked Questions
Does Google Vault store a separate copy of my data?
No. Vault does not duplicate your data. It acts as a governance layer on top of existing Workspace data. When a hold is placed, Vault prevents the underlying data from being permanently deleted—even if the user removes it from their inbox or Drive. The data remains in its original service but is flagged as preserved.
What happens when a retention period expires?
When a retention period expires and no hold is in place, Vault allows the data to be permanently purged. This process is not instant—Google's systems may take up to several days to complete the purge after the retention period ends. Once purged, the data cannot be recovered by Google or the administrator.
Can I use Vault to search data from users who have left the organization?
Yes, but only if their data is still retained. If you delete a user's account and no retention rule or hold covers their data, it will be purged according to Google's standard deletion timeline. Best practice is to transfer departing users' data to a manager or archive account and ensure retention rules apply before deleting the original account. See our user lifecycle management guide for detailed offboarding procedures.
How does Vault interact with Google Workspace DLP policies?
Vault and DLP serve different purposes. DLP prevents sensitive data from leaving the organization (blocking external sharing, redacting credit card numbers in emails). Vault preserves data for legal and compliance purposes. They operate independently—a DLP policy that blocks an email from being sent does not create a Vault record, and a Vault hold does not restrict how users interact with their data day to day.