The U.S. Department of Justice (DOJ) Criminal Division updated its Evaluation of Corporate Compliance Programs (ECCP) guidance, requiring corporations to enforce strict messaging app retention policies. Under the revised framework, prosecutors evaluating corporate cooperation will consider whether companies maintained operational control and archival access over messaging platforms used by employees for business communications.
This article provides legal news coverage and does not constitute legal advice. Organizations should consult white-collar defense counsel to review messaging compliance protocols.
What specific messaging practices does the updated DOJ guidance target?
The revised ECCP targets ephemeral and encrypted messaging applications, such as Signal and WhatsApp, when auto-deletion settings prevent data preservation during internal investigations. According to the official advisory released by the DOJ, failure to archive business-related chat communications can result in a loss of cooperation credit during criminal resolutions.
Which operational mandates apply to corporate mobile device policies?
Companies must institute clear policies governing bring-your-own-device (BYOD) programs and mobile messaging. Policies must grant corporate legal and compliance teams technical authority to preserve and collect electronic business communications.
What this means in practice
- Prohibit auto-deletion on business apps: Disable ephemeral auto-delete features on enterprise communication software used by executives and key personnel.
- Update BYOD retention agreements: Require employees using personal devices for business to execute data access agreements permitting legal hold extraction.
- Deploy mobile archiving software: Implement enterprise mobile management (EMM) tools that archive commercial chat applications automatically.
For more context, read On the DPRK’s Recent Launches Using Ballistic Missile Technology.

