🗂️ Inbox and organisation

The work email account when an employee leaves: what to do

The last day goes well. The leaving drinks, the boxes, the pass handed back, the laptop sitting on your desk. You tick the equipment line on your checklist, you say goodbye at the door, and you go back to work. Nobody said anything about the work email account, because a mailbox is not an object. You cannot put it down on a desk.

It carries on receiving, though. Three days later, a client chases a quote. Two weeks later, a supplier sends an invoice. Six weeks later, somebody wonders why they never got a reply. Meanwhile nobody is reading it, or everybody is reading a bit of it, or the password is doing the rounds of the office because someone needed one attachment.

The laptop has an owner, a return date and a signature. The work email account, in most small businesses, has none of those three things. That is exactly what this article sets out to fix.

Quick answer: the work email account when an employee leaves is handled in five phases. You prepare during the notice period, you switch over on the last day, you keep the handover going through the first week, you transfer the relationship over the first month, then you close the account. The closing date is decided in advance and put in writing to the person leaving. Published ICO guidance on monitoring workers is cited below for the questions it does cover, and this article does not stretch it past that. Every step below has a named owner and a concrete action in Outlook.

What this article is, and what it is not. It describes a working method and points to published UK guidance from the Information Commissioner's Office, with sources named and linked. It informs. It does not give legal advice and it makes no promise of compliance. For a specific case, a dispute, a regulated activity or an employment law question, speak to your usual adviser.

Contents
  1. The work email account when an employee leaves: the UK framework
  2. Before the departure: what gets prepared during the notice period
  3. The last day: the sequence of the day
  4. The first week: the handover holds, or it does not
  5. The first month: transfer the relationship, not the messages
  6. Closing the account: tell, allow time, delete
  7. Summary: who does what, and when
  8. What not to do
  9. Personal messages: the one clear boundary
  10. When a former employee asks for their data
  11. What an email assistant does, and does not do, with a mailbox in transition
  12. Outside the UK: this article describes the UK framework
  13. FAQ: seven questions that always come up

The work email account when an employee leaves: the UK framework

The mailbox of an employee who leaves remains a company tool. It sits on company infrastructure, it carries the company domain name, it holds correspondence about company matters. That is the easy part. The harder part is that it also holds information about a person, which is why it is not an object you reallocate like a monitor.

The closest published UK reference to this situation is the ICO guidance Employment practices and data protection: monitoring workers, published on 3 October 2023. It is written for employers of every size, in the public and private sectors, and it covers how data protection law applies when an employer looks at what workers do.

Three points from that guidance shape everything that follows.

First point: people must be told in advance. The ICO states that an employer wanting to monitor workers must make them aware of the nature, extent and reasons for the monitoring. The rules of the game are therefore written before, not on the day somebody hands in their notice. If your business has no written email and IT policy, that is the first project, and it does not get done in the rush of a final week.

Second point: the purpose must be defined and the means proportionate. The same guidance asks for a clearly defined purpose, for the least intrusive means capable of achieving it, and for a lawful basis for the processing. The ICO's own summary puts it plainly: data protection law does not prevent monitoring, but monitoring must be necessary, proportionate and respectful of workers' rights.

Third point, the one people skip: email content is treated as high risk. On the ICO page covering specific considerations for different methods of monitoring, monitoring emails and messages requires a data protection impact assessment, because it poses a high risk to workers' rights and is likely to capture special category data. The same page states that you must not access content unless you have a clear policy explaining the circumstances in which such monitoring may take place.

The point to carry through the rest of this article. The ICO does not publish a leaver checklist, and this article will not pretend that it does. What it publishes is a direction of travel: tell people in advance, define the purpose, do the least intrusive thing that meets it, and write the policy before you need it. None of it is a procedure for a departure. The sequence below is a working method, not a reading of the guidance: you tell the person the closing date, you leave them time to remove what is theirs, then you close. Everything below is the logistics of getting there without breaking the business in the meantime.

What the guidance does not say

This matters as much as what it does say, because it is where the internet fills in the gaps. The guidance sets no retention period for a leaver's mailbox: not three months, not six, not a year. It does not recommend setting up an automatic forward to a colleague either. If you read that a UK authority recommends a specific number of months, check the source before you build a process on it.

This article also does not re-explain UK GDPR from first principles. For the wider data protection frame, particularly where software reads the content of business email, we cover it separately in AI email and GDPR: the 2026 compliance guide. The rest of this page is about actions.

One clarification, because the confusion is common: no period attaches to the mailbox itself, but periods do attach to the documents inside it. Section 388(4) of the Companies Act 2006 requires accounting records to be kept for three years in a private company and six years in a public one. Those periods, not any deadline attached to the account, decide what has to be filed into the company records before the address is closed. We set them out category by category in how long to keep business emails.

Before the departure: what gets prepared during the notice period

The notice period is the only window in which the person who holds the information is still there, still paid and still contactable. It is an asset with an expiry date. In a business of five to fifty people, everything not done during the notice period gets paid for later, in interruptions, chased clients and files nobody can find.

Fifteen days out: map the contacts (owner: the manager)

The manager sits down with the leaver for thirty minutes and produces a written list, not a mental one. Three columns are enough: the contact, the live subject, the person taking over. In Outlook the raw material is already there. Sent Items for the last six months gives the real list of active correspondents, far better than an address book nobody has kept up to date.

The manager is looking in particular for what appears nowhere else: suppliers contacted by one person only, online accounts opened with the work address, distribution lists, subscriptions, automated alerts. Those are the dormant flows that wake up three weeks after the account closes to announce that something has stopped working.

Ten days out: decide who takes over (owner: the manager)

One rule, and only one: every active contact gets a named successor. Not "the sales team", not "accounts". A first name, a surname, an address. An orphaned mailbox does not exist in practice. It exists only on org charts.

This is also the moment to decide what happens to the Outlook folders. If the leaver built a personal folder tree inside their mailbox, it needs lifting into a team space while they are still there to explain the logic. A folder called "Smith follow up" makes sense only to the person who created it. On filing rules that outlive their author, our guide Automatic Email & Attachment Filing for Outlook: Complete 2026 Guide covers how a filing system stops depending on one individual.

Ten days out: brief the IT provider (owner: you)

In a business of this size there is usually no internal administrator. There is a provider, a managed service company, or the co-director who knows a bit about computers. The title does not matter. What matters is a single point of contact and a written request that fits in five lines:

That written message earns its keep twice: once so the work gets done, once so you can show when and how it was done.

Five days out: put the closing date in writing (owner: you)

This is the step most small businesses forget, and the one that holds the rest together. You send the leaver something written, by letter or by email, stating the date on which their mailbox will be closed and inviting them to remove their personal messages before then.

Put simply: "Your work email account will be closed on [date]. Please remove any personal messages you wish to keep before then. After that date, the address will be deleted." Keep a copy in the employee file. Note what this does: it puts the person on notice in advance, and it leaves you a written trace. Telling someone a date is not monitoring them, and this step stands on its own.

Two days out: the sorting window (owner: the leaver)

The leaver needs real time to sort, not a theoretical slot in the last quarter of an hour. Two hours identified in their calendar, on their own machine, with no meeting booked over the top. They are the only person who can separate the personal from the professional inside that mailbox. That is the point of the window: it moves the sorting to the one person who can do it without anyone else opening anything.

The last day: the sequence of the day

The last day is not a day for improvising. The sequence below takes about an hour of cumulative work, spread across the day, and it leaves nothing in an intermediate state overnight.

  1. Morning, before lunch: the leaver finishes sorting. A final pass over personal messages, a final export of what legitimately belongs to them, a final question to the manager about an unclear file. Owner: the leaver.
  2. The leaver writes their own out of office message. In Outlook, File then Automatic Replies. First person, they announce that they have left, they name the replacement contact and give that person's address. A message written by the person concerned lands far better than an administrative note bolted on afterwards. Owner: the leaver, approved by the manager.
  3. Late morning: the manager signs off the takeover list. They read back through the contact map and confirm that no line was left without a name. Owner: the manager.
  4. After lunch: the leaver's access is removed. The IT provider removes access at the agreed time. This is not mistrust. It is the consequence of the contract ending: the company tool stops being made available. Owner: the IT provider.
  5. Straight after: the automatic reply goes live. If the out of office was not set in the morning, the provider activates it from the approved text. Owner: the IT provider.
  6. Conversion into a shared mailbox. The mailbox stops being an individual account and becomes a space that named people can open. Owner: the IT provider.
  7. Distribution lists and aliases. Every internal list and every alias of the contact@ or quotes@ type that pointed at the address is redirected to the named successor. Thirty minutes of work, three months of holes avoided. Owner: the IT provider.
  8. End of day: you write it down. One line in the employee file: date access was removed, date of conversion to a shared mailbox, who has access, announced closing date. Owner: you.

The detail that changes everything in the automatic reply. Write "I left the company on [date]. For anything about [subject], please write to [name, address]." Avoid "I am currently away": absence implies a return, and the sender then waits and does nothing. The purpose of the message is not politeness. It is to trigger an action, so that the correspondent writes to somebody else, on their own initiative, at a working address.

The first week: the handover holds, or it does not

The week that follows decides the rest. Either the shared mailbox is read every day by one identified person, or it becomes a pile of untouched messages nobody dares open after ten days.

Opening the shared mailbox in Outlook

A shared mailbox is not opened with a password. It appears in the successor's Outlook, underneath their own mailbox, once they have the rights. Microsoft's documentation on shared mailboxes in Outlook describes the user side: once an administrator has added someone as a member, the mailbox appears after Outlook restarts, and it can also be added manually through Account Settings. Depending on the rights granted, it becomes possible to read the messages and to send from the shared address.

Two practical advantages over sharing a password, which is the natural instinct and the classic mistake. First, everybody works from their own account, so you know who did what. Second, access is removed one person at a time, without changing anything for anyone else. A shared mailbox closes cleanly. A shared password never does.

One person responsible for reading it daily

Two people reading the same mailbox means nobody reads it. Name one daily reader with a fixed slot, ten minutes at the end of the morning for instance. The other accounts exist so someone can search for an old message, not to handle the flow.

That reader applies a single rule to every incoming message: does this need a reply, or only filing? If it needs a reply, they reply from their own address and explain that they have taken the file over. If it only needs filing, it goes into the matching team folder. Within a fortnight the flow usually halves, because correspondents have updated their address books.

Reply in your own name, never in the name of the person who left

A shared mailbox technically allows you to send from the old address. That can be justified for a functional address such as accounts@. It is never justified for the personal address of someone who has left. Writing under the identity of a departed colleague puts everyone in an awkward position, including the recipient who thinks they are talking to somebody else. The successor writes from their own address, in one sentence: "I have taken over this file since [name] left, here is where we are."

The first month: transfer the relationship, not the messages

This is the point technical checklists almost always miss. The objective of the first month is not to forward messages. It is to make sure correspondents no longer need the mailbox at all. Two opposite approaches: forwarding prolongs the dependency, an active announcement removes it.

Week 2: tell the contacts yourself

The successor writes personally, one by one or in small groups, to the twenty or thirty genuinely active correspondents on the contact map. A short message, in their own name, saying three things: who they are, which file they have taken over, which address to use from now on. Twenty messages written once are worth more than six months of automatic forwarding, because they change the address book on the other side.

Week 3: filing into the team folders

Business messages that document a live file belong where the team works: the client folder, the supplier folder, the matter folder. A mailbox is not an archive, it is a channel things pass through. As long as information sits in the mailbox of someone who has left, it is out of reach of the people who need it, and it forces you to keep that mailbox open longer than necessary.

This filing work is also a good moment to check something simple: how many messages in this mailbox should have been somewhere else from the start? The answer is often uncomfortable, and it explains why departures hurt. A team whose files live inside individual mailboxes loses information every time somebody leaves. Our articles Piloting your inbox in 2026: the complete method and Optimize Your Email Inbox: 10 Methods to Stop Wasting Time deal with exactly that shift, outside any leaving context.

Week 4: measure what is left

For one week, the daily reader counts the messages that still arrive and still need an action. Close to zero means the mailbox has done its job and the planned closing date holds. Still significant means there is a cause to find: a forgotten alias, a website form still pointing at the address, a supplier who never updated their records. Identifiable causes, fixable one at a time. Not a reason to postpone the closure indefinitely.

Closing the account: tell, allow time, delete

Closing an account is not an event that happens to you. It is a date decided in advance and communicated. Three practical consequences follow, and they explain the order of the notice period steps above.

  1. The notice comes first, not last. That is why the written message goes out during the notice period, five days out, and not on the day you finally decide to tidy up.
  2. The opportunity to clear the mailbox has to be real. The person needs access, with time, before access is removed. A deadline announced after access has been cut allows nobody to remove anything.
  3. Deletion is the final step. The shared mailbox is a transition, not a permanent state. One kept for three years "just in case" is no longer a transition: it is the mailbox of a person who no longer works for you, left running with no end date.

How long between the departure and the closure?

There is no published UK figure that fits every business, and this article will not invent one. What determines the duration is four things you know and no generic article can know for you:

The method itself does not depend on your sector: set the date in writing before the departure, communicate it, and if you have to move it, move it in writing too. A date that moves in a documented way is still a date. A mailbox with no date never closes.

What is left after the closure

If the first three weeks were done properly, nothing critical is left when the closing date arrives. The live files are in the team spaces, correspondents write to the right person, the aliases point elsewhere. Deletion becomes a non-event. That is the sign the method worked: on the day the account closes, nobody notices.

Summary: who does what, and when

The table below fits on one page and can be pasted straight into your internal procedure. The day counts assume a standard notice period. Adapt them, keep the order.

WhenActionOwnerWhere, concretely
Fifteen days out Map the contacts and the live subjects The manager, with the leaver Sent Items for the last 6 months, written list in 3 columns
Ten days out Assign every file to a named successor The manager One name per line of the map, no blank line
Ten days out Written brief to the IT provider You Five line email: dates, shared mailbox, named access, aliases
Five days out Written notice of the closing date to the leaver You Letter or email, copy in the employee file
Two days out Sorting window for personal messages The leaver 2 hours blocked in the calendar, on their own machine
Last day, morning Out of office written in the first person The leaver, approved by the manager Outlook, File then Automatic Replies
Last day, afternoon Access removed, automatic reply live, conversion to shared mailbox, aliases redirected The IT provider Account closed to the user, shared mailbox open to named people
Last day, evening Record the dates and the access list You Employee file, one dated line
Week 1 Daily reading of the shared mailbox, 10 minutes The named successor Shared mailbox added in their Outlook
Week 2 Outbound announcement to active correspondents The named successor Individual messages from their own address
Week 3 File the useful messages into team folders The named successor Client, supplier and matter folders
Week 4 Measure the residual flow and fix the causes The named successor, you One week count, hunt for forgotten aliases
Announced date Delete the address The IT provider, on your written request Account deleted, written confirmation in the file

What not to do

This is the part internal procedures never write down, and the part that prevents the most damage. Each point describes a situation that comes up routinely in businesses of this size, with nobody acting in bad faith.

We do not share the password

The number one reflex, because it is instant and free. Two problems. Nobody knows who read what or who replied, and the day you need to remove one person's access you have to remove everybody's. And the password then travels by email or by message, ends up in three different mailboxes, and outlives the account. The shared mailbox exists precisely to avoid this.

We do not set a blanket permanent forward

Forwarding the whole mailbox to a colleague looks like the simplest solution. It has three defects. It forwards business messages and everything else indiscriminately, with no sorting at all, which sits badly with the ICO's expectation that monitoring is proportionate and no more intrusive than the purpose requires. It is invisible to the sender, who keeps writing to the wrong address for years. And it pollutes the successor's mailbox with two mixed flows they cannot tell apart. The automatic reply naming a contact does the opposite: it informs, and it hands the decision back to the sender.

We do not reply under the identity of the person who left

Technically possible from a shared mailbox, humanly bad. The correspondent thinks they are talking to somebody who is no longer there, the conversation restarts on a misunderstanding, and the discovery always happens at the worst moment. The successor writes in their own name.

We do not open messages that look personal

The ICO's position on the wider question is that monitoring must be necessary, proportionate and no more intrusive than the purpose requires, and that content should not be accessed without a clear policy explaining when that may happen. Curiosity is not a purpose. In practice: do not open them, do not forward them, do not file them into an archive intended for the team.

We do not export the whole mailbox onto personal storage

Copying an entire mailbox into a file on a colleague's machine, a USB stick or a personal storage space creates a copy with no owner, no deletion date and no traceability. What needs keeping is filed into the company folders, message by message. What does not need keeping disappears with the mailbox, and that is exactly as it should be.

We do not keep the mailbox open "just in case", with no end date

A mailbox kept with no end date is a decision that will not admit to being one. It carries on receiving, nobody reads it, and it resurfaces two years later during a change of provider. If you need more time, decide on a new date and write it down. A documented extension is worth far more than an oversight.

We do not recycle the address for the new joiner

Giving the old address to the replacement, because clients already know it, looks efficient. The new joiner inherits conversations that have nothing to do with them, chasers on files they have never seen, and lasting confusion on the correspondent's side. Functional addresses, of the contact@ or invoices@ type, exist to carry continuity. Personal addresses carry people.

We do not forget the things that are not the inbox

The shared calendar, the recurring meetings the person organised, the internal distribution lists, assigned tasks, file shares opened from their account, the website forms pointing at their address. These stop working when the account closes, usually in silence. That is why they belong in the written brief to the IT provider.

Personal messages: the one clear boundary

Everything else in this article is organisation. This point is something else, and it is the one most often summarised badly.

The UK guidance does not work by declaring a mailbox off limits or fair game. It works by asking questions before anyone looks at anything: what is the purpose, is this necessary, is there a less intrusive way, have the people concerned been told, and is there a policy saying when content may be accessed. The ICO adds a strong signal for email specifically, by treating the monitoring of emails and messages as high risk and expecting a data protection impact assessment beforehand.

Read that as an operational rule rather than a legal one and it becomes very usable. Two concrete consequences.

First, the sorting window during the notice period is not a courtesy. It is the moment the leaver removes what belongs to them, which is the least intrusive route by a wide margin, because nobody else opens anything. Skip it and you end up facing a mailbox whose contents you cannot sort yourself without doing the very thing the guidance asks you to justify.

Second, the policy comes before the need. The ICO is explicit that content should not be accessed unless a clear policy explains the circumstances in which it may be. A policy written the week somebody resigns is not a policy, it is a justification. Written a year earlier and shared with the team, it is a working rule everybody can rely on, including the person leaving.

And if a personal message is still sitting in the mailbox on the closing date? It disappears with the mailbox, which is precisely why the date is announced in advance and why the sorting window exists.

When a former employee asks for their data

It happens, often several months later, sometimes in a tense context. The request is not abnormal, and it is better to know what it is before you receive one.

The mechanism is the right of access, usually called a subject access request. The ICO's subject access request questions and answers for employers address the situation directly: a worker can make a request after leaving, and where the content of an email relates to that person, you must provide a copy of those emails, redacted where necessary. A message about a business matter can still contain personal information, depending on what it says.

The same guidance sets the limits. A request may involve information relating both to the requester and to somebody else, which means balancing one person's right of access against another person's rights. Where a duty of confidence applies to third party information, it is usually reasonable to withhold it unless that third party consents. Redaction is a normal part of answering.

What that means at your desk: a request of this kind is not handled in a rush or on instinct. You acknowledge it, you record it, and you take advice before you answer. It is not the subject of this article, which stops here and refers you to the ICO pages listed in the sources.

How this connects back to the method. A mailbox closed on the announced date, with business messages filed into the company folders and a written trace of the dates, puts you in a far better position to answer a request six months later than a mailbox left open with no record of any decision. The discipline of the last day is also an insurance policy for later.

What an email assistant does, and does not do, with a mailbox in transition

A word on tools, because the question comes up when one person suddenly absorbs somebody else's flow: the successor's email load jumps overnight, on files they barely know.

Neston is an email assistant integrated with Outlook. It learns your style from your emails, builds a profile for each correspondent, files automatically and prepares a reply that you read before it goes out. Let us be precise about what it is not, because that is the subject here: Neston is not a compliance tool, not an HR tool, not a security product, it does not handle departures and it decides nothing about a mailbox. On a mailbox in transition it does nothing in particular, and nothing is sent unless a person has read and approved it first. You decide what goes out, under your name, from your address. The rest, removing access, the shared mailbox, the closure, is a matter of the method described above and of no software at all.

On the hosting and data processing questions such tools raise, we treat them elsewhere rather than summarising them here: see France-hosted AI email assistant: the 2026 guide and CLOUD Act and professional email: the real risks in 2026.

Outside the UK: this article describes the UK framework

Everything above relies on published UK guidance from the Information Commissioner's Office. That is a UK source and it describes the UK framework. It does not describe the rules that apply elsewhere, and it would be wrong to transpose it as it stands.

The organising method travels without difficulty: the contact map during the notice period, the named owner, the shared mailbox rather than a shared password, the outbound announcement, the closing date in writing. Those are management actions, not rules of law. What does not travel are the statements about what an employer may look at, when, and on what conditions. If your business is established outside the United Kingdom, check those points with your own national data protection authority and your local adviser before applying anything here.

Neston is in early access.

The assistant plugs into Outlook, learns your style from your emails, files automatically and prepares a reply that you read and approve before it is sent. Early access is free, on a waiting list.

Join the waiting list →

Windows 10/11 · Outlook · Optional Mistral EU

Further reading

FAQ: seven questions that always come up

Can we read a former employee's emails after they leave?
Data protection law does not forbid it, but the ICO sets conditions in its guidance on monitoring workers. Workers must be made aware of the nature, extent and reasons for monitoring, the purpose must be clearly defined, and the least intrusive means must be used. The ICO also states that you must not access the content of emails and messages without a clear policy explaining the circumstances in which that may happen. Write that policy before anyone leaves.
What do we do with messages that look personal?
Leave them closed. The ICO expects monitoring to be necessary, proportionate and no more intrusive than the purpose requires, so opening what looks like private correspondence in order to find a business attachment is hard to justify. In practice: do not open them, do not forward them, do not file them into a team archive. Give the person time to remove their own messages before the account closes.
Can we set an automatic forward to a colleague, and should senders be told?
A blanket permanent forward sends everything to a colleague, personal messages included, and it sorts nothing. That sits badly with the ICO's expectation that monitoring is proportionate and limited to what is necessary. An automatic reply naming a replacement contact does the opposite. It tells the sender what has changed and lets them decide who to write to next, updating their own address book in the process.
How long should we keep the mailbox?
No published figure fits every business, and this article will not invent one. What sets the duration is your own email and IT policy, the rhythm of your activity, the state of the files handed over, and the record-keeping obligations of your sector. Set the date in writing before the person leaves, tell them what it is, and if you have to move it, move it in writing too.
Should we delete the address or turn it into a shared mailbox?
Both, in that order. A shared mailbox is a transition step: Microsoft's documentation describes how named colleagues open it inside their own Outlook once an administrator has added them as members. Deletion is the final step. A shared mailbox kept open for years is no longer a transition. It is the mailbox of someone who no longer works for you, left running with no end date.
Can a former employee ask for their work emails?
They can make a subject access request. The ICO's subject access request questions and answers for employers state that a worker can make a request after leaving, and that where the content of an email relates to them you must provide a copy, redacted if necessary. Third party information can usually be withheld where a duty of confidence applies. Acknowledge the request, record it, and take advice before answering.
Who needs to be told inside the business, and when?
Three circles, in this order. The manager and the person taking over the files, from the start of the notice period, so the handover can be organised. The IT provider, one or two weeks ahead, to prepare the shared mailbox and diarise the closing date. The team and outside contacts on the last day or just after, through the automatic reply. And the leaver, told the closing date in writing.
Note on sources. The regulatory material quoted here comes exclusively from the Information Commissioner's Office pages listed below, in the state they were in at the date of consultation. The ICO guidance on monitoring workers was published on 3 October 2023. The Microsoft documentation cited describes a product feature at the date of consultation.
YB
Yvan Bosser
Founder of Neston · Ex-founder of Comptasanté (IK Partners exit 2023)
Yvan designs Neston, the AI email assistant integrated with Outlook, based on his own experience as an executive. Contact: yvan@neston.fr · LinkedIn.

🔬 Sources

Published 1 September 2026 · Reading time: 24 minutes · approx. 6,113 words