Almost every company has an address that belongs to everyone: info@, accounts@, service@ or orders@. It sits on the website, on the letterhead and in every signature, and it is the reason the company can be reached at all. It is also the place where deadlines start running without anyone asking for them. A subject access request sets a one-month clock in motion on arrival (GDPR), an internal report has to be acknowledged within seven days (Whistleblower Protection Act), and a business message counts as a received commercial letter that must be retained for six years (German Commercial Code). None of that depends on whether anyone has read the message. This article describes how a shared mailbox turns into a distributor with lanes: one owner per type of incoming item, a deadline attached visibly to the case, a status that means something other than „read“, and a backlog row for everything that cannot be assigned.
Key takeaways
- Arrival starts the clock, not reading. A subject access request must be answered within one month of receipt (GDPR), an internal report acknowledged within seven days (Whistleblower Protection Act), and a breach reported within 72 hours (GDPR).
- A business email is a received commercial letter and must be kept for six years (German Commercial Code); invoices run to eight years (German VAT Act). The period only starts at the end of the calendar year in which the message arrived (German Commercial Code).
- Retention means more than storage: available at any time throughout the period, readable without delay and capable of machine evaluation (German Fiscal Code). A folder inside one person's personal mailbox rarely meets that, because it disappears with the account.
- The inbox is also an attack path. In the German government networks the monthly average of daily spam rates was 51 percent (BSI); 73 percent of those spam messages were attacks (BSI), and among the fraudulent messages phishing accounted for 93 percent (BSI).
- Ownership is a matter of organisation, not courtesy: from 50 employees an internal reporting channel is mandatory (Whistleblower Protection Act), and from 20 people in automated processing a data protection officer must be appointed (Federal Data Protection Act).
What a shared mailbox actually is
Figures from the Federal Statistical Office draw a clear picture of what case handling in many companies rests on. Slightly more than half, namely 54 percent of companies with ten or more employees, purchased paid IT services over the internet in 2025 (Destatis). Among those that use such services, email leads the field of applications at 76 percent (Destatis), while systems for enterprise resource planning and customer relationship management reach 23 percent each (Destatis). Put differently: the one system everything runs through, across the board, is the inbox. The specialist systems in which a case would carry a number, an owner and a status are less widespread than the message that triggers the case. That the same question arises for machine data is set out in the article on access to machine data under the Data Act.
In everyday use a shared mailbox has three properties that make it unsuitable for steering cases. First, the read status is the only status: a message is unread, read or moved, and none of those three states says anything about whether someone is acting. Second, ownership is a matter of shouting across the room. Whoever looks in first decides whether an item concerns them, and messages in the grey zone stay put because both sides consider the other responsible. Third, there is no deputy in the sense of a rule, only a person who happens to be present. If that person is away, the backlog grows quietly because nobody counts it.
Those three properties are fine for a messaging channel and too thin for case management. The difference shows the moment somebody asks what became of a particular message. In the mailbox it can only be reconstructed: you search for the subject line, read the reply chain and infer the state from it. A case carries the answer itself, with time of arrival, owner, deadline, status and filing location. How such a structure can be introduced without a large project is described in the article on digitising approval workflows.
Three clocks that start on arrival
Deadlines that start on arrival
The practical core is unspectacular: nearly every relevant deadline attaches to arrival, not to awareness. That is why a mailbox left unreviewed on a Friday afternoon carries a risk of which part is already spent by Monday. Only the access deadline can be stretched, and even then by no more than two further months and only if the data subject is informed within the first month (GDPR). The overview below collects the deadlines that can accumulate in an ordinary shared mailbox at a mid-size company.
| Type of item | What it triggers | Deadline | Reference |
|---|---|---|---|
| Subject access request | Answer to the request | within one month of receipt | Article 12(3) (GDPR) |
| Access request, complex or numerous | Extension with notice inside the first month | two further months | Article 12(3) (GDPR) |
| Report to the internal reporting channel | Acknowledgement of receipt | within seven days at the latest | Section 17 (Whistleblower Protection Act) |
| The same report | Feedback to the reporting person | within three months | Section 17(2) (Whistleblower Protection Act) |
| Notice of a personal data breach | Notification to the supervisory authority | within 72 hours, otherwise with reasons | Article 33(1) (GDPR) |
| Security incident at a regulated entity | Early warning after becoming aware | within 24 hours | Section 32 (BSI Act) |
| The same incident | Final report | one month after the notification at the latest | Section 32(1) no. 4 (BSI Act) |
| Request for an invoice | Issuing the invoice | within six months of performing the service | Section 14(2) (German VAT Act) |
Alongside the deadlines that come from law run the deadlines made of money. An invoice left sitting in the shared mailbox does not become cheaper because nobody has seen it. Where a debtor who is not a consumer is in default, a flat sum of 40 euros falls due (German Civil Code), and the interest rate for payment claims in transactions without consumer involvement stands at nine percentage points above the base rate (German Civil Code). On the outgoing side the same applies in reverse: anyone who writes a requested invoice only months later gives away the period in which they could have chased payment. The interplay between invoicing and automated dunning therefore begins in the inbox.
That the number of triggers is not falling becomes clear from the supervisory side. The Bavarian Data Protection Authority received a total of 3603 data breach notifications in 2025, an increase of 23 percent on the previous year (BayLDA). Part of those notifications originate in the mailbox itself: a reply to the wrong recipient, a distribution list in the open header, an attachment carried over from the previous message. For the 72-hour clock it makes no difference whether the mistake sat in the technology or in the manual step (GDPR).
Retention means more than keeping
A second reason why the shared mailbox is the wrong place for retention comes from commercial law. Received commercial letters must be kept for six years (German Commercial Code), and an email concerning a commercial transaction is such a letter. Tax law sets the same frame: six years for other records and eight years for accounting vouchers (German Fiscal Code). Invoices arriving in the mailbox must be retained for eight years (German VAT Act). And the period does not start on the day of the message but at the end of the calendar year in which the commercial letter was received (German Commercial Code) - so a message from January stays in the holdings almost a year longer than the bare number of years suggests.
The decisive part is the second half of the provision. Retained records must be available at any time throughout the retention period, capable of being made readable without delay and capable of machine evaluation (German Fiscal Code). Those three requirements shape the filing far more than the length of the period does. A mailbox organised by person regularly fails on the first: when someone leaves the company, access to messages that still have years to run disappears with their account. How accounts and rights can be tied to joining and leaving is covered in the article on account access when staff join and leave.
- Filing follows the case rather than the person: a departing employee must not leave a gap in holdings that have to stay available at any time (German Fiscal Code).
- The time of arrival is recorded, because it determines the start of the period at the end of the calendar year (German Commercial Code).
- Attachments move into the filing with the case and not only into the message: an invoice has to be retained for eight years (German VAT Act).
- The holdings are searchable, because access has to be granted within one month (GDPR) and every occurrence has to be found for that.
- The filing stays capable of machine evaluation and is not merely readable as an image file (German Fiscal Code).
- The storage location is described so that the documentation can name it - see writing process documentation for audits.
Time pressure arrives from a further direction. For transactions carried out after 31 December 2026 and before 1 January 2028, invoices may still be transmitted on paper or in an unstructured electronic format only if the issuing trader's total turnover in the preceding calendar year did not exceed 800 000 euros (German VAT Act). What lands today as a PDF in the shared mailbox and is retyped by hand will then arrive structured - and an inbox without assignment makes little of that advantage. Rebuilding the invoice flow is described in detail in the 2027 e-invoicing mandate; assignment at the point of arrival is the prerequisite for it.
The inbox is also an attack path
Anyone talking about the inbox is talking about one of the largest attack surfaces in the company. The Federal Office for Information Security measures that surface in the German government networks and publishes the figures every year. In the reporting period from 1 July 2024 to 30 June 2025 the monthly average of daily spam rates stood at 51 percent (BSI). Of those spam messages an average of 73 percent were not advertising but cyber attacks (BSI), and among the fraudulent messages phishing made up the largest share at 93 percent (BSI).
Those rates are no reason for comfort, because they describe the traffic in front of the filter. Behind the filter a residue remained: the government networks were addressed with an average of around 753 malicious emails per day (BSI), spread across an attack surface of roughly 684,000 email addresses (BSI). A mid-size company moves in different orders of magnitude but in the same proportion: what arrives is what the filter does not yet recognise, and it hits the address that is published. That address is precisely the shared one.
For a shared mailbox an organisational effect comes on top. When several people see the same messages, in case of doubt nobody checks the sender closely, because each assumes someone else has already done it. An attack aimed at a changed bank account needs exactly that gap. A lane with a fixed owner closes it not through technology but through naming: there is a role whose task is the first review, and a deputy with the same task. In addition the inbox belongs in the monitoring described in monitoring interfaces properly; that maintenance and running operations need not exclude each other is shown in applying updates without downtime.
Review of the shared mailbox - fixed order
1 Compare sender and reply address
diverging reply address -> lane "check", do not reply
2 Payment data in the body?
IBAN or change of account -> lane "check", call back on a known number
3 Determine the category
invoice / order / access request / report / other
4 Assign the lane
category -> owner -> deputy
5 Set the clock
access request 1 month from arrival (GDPR Art. 12)
report 7 days to acknowledge (HinSchG s. 17)
breach 72 hours to notify (GDPR Art. 33)
6 Create the case, attach the message, empty the mailbox
cannot be assigned -> backlog row, reviewed dailyThe rule set is deliberately short. It should fit on a wall and be understood in a single morning of onboarding. The most important point comes last: the mailbox gets emptied, because it is not a place of record. As long as messages stay there, a second set of holdings grows next to the case system, one that nobody maintains and that the retention duty for received commercial letters nonetheless covers (German Commercial Code).
From shouted ownership to a lane
A lane is more than a folder. It consists of four details that together make a case steerable: the category of the incoming item, the owning role, the deputy for that role, and the deadline that starts on arrival. Whoever settles those four details once for the most frequent types of item has done the larger part of the work; the technical remainder is a rule set in the mailbox or in the case system and can be planned as part of process automation.
Two lanes are laid down by law and therefore do not belong in the general mailbox. Companies with as a rule at least 50 employees must set up an internal reporting channel (Whistleblower Protection Act); its intake needs a path of its own, because confidentiality of identity otherwise founders on the sheer number of people reading along. And anyone employing as a rule at least 20 people permanently in the automated processing of personal data must appoint a data protection officer (Federal Data Protection Act); that intake, too, is worth a separate address, so that the one-month deadline for access requests does not vanish into the general backlog (GDPR).
One intake, several addresses
The public shared address stays as it is, with separate addresses alongside it for the reporting channel and for data protection. What gets separated is not the channel but the access: a different circle of people, its own log, its own rule for deputies.
Role instead of person
The owner is a role - accounts, sales, data protection - and not a name. That way the rule survives holidays, changes and departures, and the deputy is named in advance rather than looked for when it matters.
Deadline on the case
The deadline hangs on the case and not in somebody's head. An access request has to be answered within one month of receipt (GDPR); that date belongs visibly on the record, with the time of arrival as its starting value.
Status with meaning
Accepted, in progress, waiting on input, done: four states are enough as long as each of them describes an action. The read status of a message is not among them, because it only says something about the reader.
Filing with a retention link
Attachments and message text move into the filing of the case. Invoices must be kept for eight years (German VAT Act), other received commercial letters for six (German Commercial Code), counted from the end of the calendar year.
Backlog as a metric
Whatever cannot be assigned lands in a visible row with a count and an age. A backlog row reviewed daily is the place where a forgotten item shows up before a deadline is touched.
The six points can be modelled in any tool that keeps records with a status and a date: a ticket system, an ERP system, a list built in-house. The difference between the tools is smaller than the difference between a defined lane and none at all. Which processes are suited to a first attempt is sorted out in which processes to tackle first.
What a case has to carry
A case is not a ticket with a number but a record that answers two questions: what is to be done, and what has already happened? The status answers the first, the log the second. Together they replace the reconstruction from the reply chain, and together they are the basis on which an access request can be answered at all.
The fields are manageable. More important than their number is that the time of arrival is taken from the channel rather than typed in: it determines both the start of the one-month deadline for access requests (GDPR) and the start of the retention period at the end of the calendar year (German Commercial Code). A time of arrival entered by hand is a statement about a statement.
Case 2026-4711
arrival_time 2026-09-11T08:14:22+02:00 (from the channel, not typed)
channel info@ (shared address)
sender request@example.org
category subject access request
lane data protection
owner role: data protection
deputy role: management
due 2026-10-11 (one month from arrival)
extension two further months, notice by 2026-10-11
status in progress
filing /cases/2026/4711/
log 08:14 arrival | 08:31 lane set | 09:02 receipt confirmed
Retention
kind received commercial letter
period_start 2026-12-31 (end of the calendar year)
period_end 2032-12-31 (six years)The last block is the one shared mailboxes most often fail to deliver. Without a calculated start and a calculated end of the retention period, retention is a declaration of intent. With both figures it becomes a rule that a filing system can apply, and it also permits deletion once the period has run out. Anyone who wants to approach the subject from the filing side will find the entry point in getting started with document management and the tax requirements in compliant document storage.
Access, logging and data protection in a shared mailbox
A shared mailbox is as a rule open to a wider circle of people than any specialist system. That means people see messages that are none of their professional business: a sick note that went to info@ by mistake, an application, a complaint about a colleague. Access is therefore broader than the task requires, and that is exactly where the supervisory authorities start.
The fine framework makes the difference between the two kinds of failure visible. Infringements of the rights of data subjects are subject to administrative fines of up to 20 000 000 euros or up to 4 percent of the total worldwide annual turnover, whichever is higher (GDPR). Missing technical and organisational measures sit one step below: up to 10 000 000 euros or 2 percent (GDPR). Both are upper limits rather than standard amounts, but they show the ranking. The practical steps are set out in data protection when digitising processes.
The backlog is a notification topic too
Getting there in five steps
The rebuild can be run in small steps, and it should be: the assignment only holds if it is derived from the items that actually arrive rather than from an assumption about them.
Step 1: count incoming items for two weeks
Every message gets a category and a role, at first as a tally on paper. After ten working days it is clear which types of item actually occupy the company and how the volume spreads across the week. That record replaces every estimate and costs half an hour a day.
Step 2: define the lanes
For the four or five most frequent categories, owner, deputy and deadline are put in writing. The deadlines do not come from instinct: one month for an access request (GDPR), seven days for acknowledging a report (Whistleblower Protection Act), six months for a requested invoice after the service has been performed (German VAT Act).
Step 3: separate the sensitive intakes
The reporting channel and data protection get their own addresses with their own access. From 50 employees the internal reporting channel is mandatory (Whistleblower Protection Act), from at least 20 people in permanent automated processing the data protection officer is (Federal Data Protection Act). Both need a smaller circle of readers than the general mailbox.
Step 4: create a case instead of answering an email
Every assigned message becomes a record with time of arrival, deadline, status and filing location. The message itself moves into the filing, because it has to stay available, readable and capable of machine evaluation throughout the retention period (German Fiscal Code).
Step 5: measure the backlog and read it weekly
The row with unassigned items gets a count and an age. If it rises over two weeks, a lane or a deputy is missing. This single metric replaces most status meetings, because it shows a problem before it touches a deadline.
Every message gets a category and a role, at first as a tally on paper. After ten working days it is clear which types of item actually occupy the company and how the volume spreads across the week. That record replaces every estimate and costs half an hour a day.
For the four or five most frequent categories, owner, deputy and deadline are put in writing. The deadlines do not come from instinct: one month for an access request (GDPR), seven days for acknowledging a report (Whistleblower Protection Act), six months for a requested invoice after the service has been performed (German VAT Act).
The reporting channel and data protection get their own addresses with their own access. From 50 employees the internal reporting channel is mandatory (Whistleblower Protection Act), from at least 20 people in permanent automated processing the data protection officer is (Federal Data Protection Act). Both need a smaller circle of readers than the general mailbox.
Every assigned message becomes a record with time of arrival, deadline, status and filing location. The message itself moves into the filing, because it has to stay available, readable and capable of machine evaluation throughout the retention period (German Fiscal Code).
The row with unassigned items gets a count and an age. If it rises over two weeks, a lane or a deputy is missing. This single metric replaces most status meetings, because it shows a problem before it touches a deadline.
Nearly all of the effort sits in steps one and two. Once the lanes are defined, the technical work is a matter of rules in the mailbox and fields in the case system. How the benefit can be calculated is shown in what a single case really costs; where the step fits into a wider automation is described on the page about automating workflows.
The status is the real change
How success can be read off
- Age of the oldest unassigned item, measured in working days and read off daily.
- Share of items that were given a lane on the day they arrived - the metric closest to the deadlines.
- Number of deadlines that arose from an item and carry a date in the system, such as the one-month period for access requests (GDPR).
- Time between arrival and acknowledgement for reports to the internal reporting channel, measured against seven days (Whistleblower Protection Act).
- Share of incoming invoices recorded before the payment term expired - the counter-check to the flat default sum of 40 euros (German Civil Code).
- Completeness of the filing: a sample of ten cases per quarter checked for availability and machine evaluable form (German Fiscal Code).
These six values can be collected without an additional tool, provided the case carries the right fields. They replace the question of whether things are running with a figure that can be compared against last week. How to build a small, load-bearing set from them is set out in metrics that actually help; the connection to throughput is described in shortening lead times.
The most expensive message is not the one nobody answered but the one nobody can say was answered. It costs twice: once for the search, and once for the reply that gets written a second time just to be safe.
Sources and studies
Related Articles
Verification of payee in payment runs: handling mismatches
Since October 2025, banks check name and IBAN before every credit transfer. How supplier master data, payment blocks and call-backs handle the bank's responses.
Interim Payments and Variations on Building Sites
How a stage of completion becomes an interim invoice, why a variation is a case with a deadline of its own, and how that produces a final account that can be checked without rework.
Shift rosters that check rest periods upfront
How rest periods, working time limits, qualification and availability are calculated as rules while the roster is built - and how plan and actual finally come together.