Skip to content
Automation & interfaces

From shared mailbox to a traceable case

A shared mailbox starts deadlines nobody ordered. How incoming messages become cases with an owner, a deadline and a filing location, and what the law expects.

17 min read PosteingangZuständigkeitAutomatisierung

Almost every company has an address that belongs to everyone: info@, accounts@, service@ or orders@. It sits on the website, on the letterhead and in every signature, and it is the reason the company can be reached at all. It is also the place where deadlines start running without anyone asking for them. A subject access request sets a one-month clock in motion on arrival (GDPR), an internal report has to be acknowledged within seven days (Whistleblower Protection Act), and a business message counts as a received commercial letter that must be retained for six years (German Commercial Code). None of that depends on whether anyone has read the message. This article describes how a shared mailbox turns into a distributor with lanes: one owner per type of incoming item, a deadline attached visibly to the case, a status that means something other than „read“, and a backlog row for everything that cannot be assigned.

Key takeaways

  • Arrival starts the clock, not reading. A subject access request must be answered within one month of receipt (GDPR), an internal report acknowledged within seven days (Whistleblower Protection Act), and a breach reported within 72 hours (GDPR).
  • A business email is a received commercial letter and must be kept for six years (German Commercial Code); invoices run to eight years (German VAT Act). The period only starts at the end of the calendar year in which the message arrived (German Commercial Code).
  • Retention means more than storage: available at any time throughout the period, readable without delay and capable of machine evaluation (German Fiscal Code). A folder inside one person's personal mailbox rarely meets that, because it disappears with the account.
  • The inbox is also an attack path. In the German government networks the monthly average of daily spam rates was 51 percent (BSI); 73 percent of those spam messages were attacks (BSI), and among the fraudulent messages phishing accounted for 93 percent (BSI).
  • Ownership is a matter of organisation, not courtesy: from 50 employees an internal reporting channel is mandatory (Whistleblower Protection Act), and from 20 people in automated processing a data protection officer must be appointed (Federal Data Protection Act).

What a shared mailbox actually is

Figures from the Federal Statistical Office draw a clear picture of what case handling in many companies rests on. Slightly more than half, namely 54 percent of companies with ten or more employees, purchased paid IT services over the internet in 2025 (Destatis). Among those that use such services, email leads the field of applications at 76 percent (Destatis), while systems for enterprise resource planning and customer relationship management reach 23 percent each (Destatis). Put differently: the one system everything runs through, across the board, is the inbox. The specialist systems in which a case would carry a number, an owner and a status are less widespread than the message that triggers the case. That the same question arises for machine data is set out in the article on access to machine data under the Data Act.

In everyday use a shared mailbox has three properties that make it unsuitable for steering cases. First, the read status is the only status: a message is unread, read or moved, and none of those three states says anything about whether someone is acting. Second, ownership is a matter of shouting across the room. Whoever looks in first decides whether an item concerns them, and messages in the grey zone stay put because both sides consider the other responsible. Third, there is no deputy in the sense of a rule, only a person who happens to be present. If that person is away, the backlog grows quietly because nobody counts it.

Those three properties are fine for a messaging channel and too thin for case management. The difference shows the moment somebody asks what became of a particular message. In the mailbox it can only be reconstructed: you search for the subject line, read the reply chain and infer the state from it. A case carries the answer itself, with time of arrival, owner, deadline, status and filing location. How such a structure can be introduced without a large project is described in the article on digitising approval workflows.

Three clocks that start on arrival

The first clock belongs to data protection: access, rectification or erasure must be handled without undue delay and in any event within one month of receipt of the request (GDPR). The second belongs to the internal reporting channel: receipt of a report must be acknowledged within seven days at the latest (Whistleblower Protection Act). The third belongs to the incident: where a personal data breach is notified later than 72 hours, the notification has to be accompanied by reasons for the delay (GDPR). For essential and important entities a 24-hour clock is added that starts with becoming aware of the incident (BSI Act). None of these clocks waits for the message to be noticed.

Deadlines that start on arrival

The practical core is unspectacular: nearly every relevant deadline attaches to arrival, not to awareness. That is why a mailbox left unreviewed on a Friday afternoon carries a risk of which part is already spent by Monday. Only the access deadline can be stretched, and even then by no more than two further months and only if the data subject is informed within the first month (GDPR). The overview below collects the deadlines that can accumulate in an ordinary shared mailbox at a mid-size company.

Type of itemWhat it triggersDeadlineReference
Subject access requestAnswer to the requestwithin one month of receiptArticle 12(3) (GDPR)
Access request, complex or numerousExtension with notice inside the first monthtwo further monthsArticle 12(3) (GDPR)
Report to the internal reporting channelAcknowledgement of receiptwithin seven days at the latestSection 17 (Whistleblower Protection Act)
The same reportFeedback to the reporting personwithin three monthsSection 17(2) (Whistleblower Protection Act)
Notice of a personal data breachNotification to the supervisory authoritywithin 72 hours, otherwise with reasonsArticle 33(1) (GDPR)
Security incident at a regulated entityEarly warning after becoming awarewithin 24 hoursSection 32 (BSI Act)
The same incidentFinal reportone month after the notification at the latestSection 32(1) no. 4 (BSI Act)
Request for an invoiceIssuing the invoicewithin six months of performing the serviceSection 14(2) (German VAT Act)

Alongside the deadlines that come from law run the deadlines made of money. An invoice left sitting in the shared mailbox does not become cheaper because nobody has seen it. Where a debtor who is not a consumer is in default, a flat sum of 40 euros falls due (German Civil Code), and the interest rate for payment claims in transactions without consumer involvement stands at nine percentage points above the base rate (German Civil Code). On the outgoing side the same applies in reverse: anyone who writes a requested invoice only months later gives away the period in which they could have chased payment. The interplay between invoicing and automated dunning therefore begins in the inbox.

That the number of triggers is not falling becomes clear from the supervisory side. The Bavarian Data Protection Authority received a total of 3603 data breach notifications in 2025, an increase of 23 percent on the previous year (BayLDA). Part of those notifications originate in the mailbox itself: a reply to the wrong recipient, a distribution list in the open header, an attachment carried over from the previous message. For the 72-hour clock it makes no difference whether the mistake sat in the technology or in the manual step (GDPR).

Retention means more than keeping

A second reason why the shared mailbox is the wrong place for retention comes from commercial law. Received commercial letters must be kept for six years (German Commercial Code), and an email concerning a commercial transaction is such a letter. Tax law sets the same frame: six years for other records and eight years for accounting vouchers (German Fiscal Code). Invoices arriving in the mailbox must be retained for eight years (German VAT Act). And the period does not start on the day of the message but at the end of the calendar year in which the commercial letter was received (German Commercial Code) - so a message from January stays in the holdings almost a year longer than the bare number of years suggests.

The decisive part is the second half of the provision. Retained records must be available at any time throughout the retention period, capable of being made readable without delay and capable of machine evaluation (German Fiscal Code). Those three requirements shape the filing far more than the length of the period does. A mailbox organised by person regularly fails on the first: when someone leaves the company, access to messages that still have years to run disappears with their account. How accounts and rights can be tied to joining and leaving is covered in the article on account access when staff join and leave.

  • Filing follows the case rather than the person: a departing employee must not leave a gap in holdings that have to stay available at any time (German Fiscal Code).
  • The time of arrival is recorded, because it determines the start of the period at the end of the calendar year (German Commercial Code).
  • Attachments move into the filing with the case and not only into the message: an invoice has to be retained for eight years (German VAT Act).
  • The holdings are searchable, because access has to be granted within one month (GDPR) and every occurrence has to be found for that.
  • The filing stays capable of machine evaluation and is not merely readable as an image file (German Fiscal Code).
  • The storage location is described so that the documentation can name it - see writing process documentation for audits.

Time pressure arrives from a further direction. For transactions carried out after 31 December 2026 and before 1 January 2028, invoices may still be transmitted on paper or in an unstructured electronic format only if the issuing trader's total turnover in the preceding calendar year did not exceed 800 000 euros (German VAT Act). What lands today as a PDF in the shared mailbox and is retyped by hand will then arrive structured - and an inbox without assignment makes little of that advantage. Rebuilding the invoice flow is described in detail in the 2027 e-invoicing mandate; assignment at the point of arrival is the prerequisite for it.

The inbox is also an attack path

Anyone talking about the inbox is talking about one of the largest attack surfaces in the company. The Federal Office for Information Security measures that surface in the German government networks and publishes the figures every year. In the reporting period from 1 July 2024 to 30 June 2025 the monthly average of daily spam rates stood at 51 percent (BSI). Of those spam messages an average of 73 percent were not advertising but cyber attacks (BSI), and among the fraudulent messages phishing made up the largest share at 93 percent (BSI).

Those rates are no reason for comfort, because they describe the traffic in front of the filter. Behind the filter a residue remained: the government networks were addressed with an average of around 753 malicious emails per day (BSI), spread across an attack surface of roughly 684,000 email addresses (BSI). A mid-size company moves in different orders of magnitude but in the same proportion: what arrives is what the filter does not yet recognise, and it hits the address that is published. That address is precisely the shared one.

For a shared mailbox an organisational effect comes on top. When several people see the same messages, in case of doubt nobody checks the sender closely, because each assumes someone else has already done it. An attack aimed at a changed bank account needs exactly that gap. A lane with a fixed owner closes it not through technology but through naming: there is a role whose task is the first review, and a deputy with the same task. In addition the inbox belongs in the monitoring described in monitoring interfaces properly; that maintenance and running operations need not exclude each other is shown in applying updates without downtime.

inbox-review.txt
Review of the shared mailbox - fixed order

1  Compare sender and reply address
   diverging reply address     -> lane "check", do not reply
2  Payment data in the body?
   IBAN or change of account   -> lane "check", call back on a known number
3  Determine the category
   invoice / order / access request / report / other
4  Assign the lane
   category -> owner -> deputy
5  Set the clock
   access request  1 month from arrival     (GDPR Art. 12)
   report          7 days to acknowledge    (HinSchG s. 17)
   breach          72 hours to notify       (GDPR Art. 33)
6  Create the case, attach the message, empty the mailbox

cannot be assigned -> backlog row, reviewed daily

The rule set is deliberately short. It should fit on a wall and be understood in a single morning of onboarding. The most important point comes last: the mailbox gets emptied, because it is not a place of record. As long as messages stay there, a second set of holdings grows next to the case system, one that nobody maintains and that the retention duty for received commercial letters nonetheless covers (German Commercial Code).

From shouted ownership to a lane

A lane is more than a folder. It consists of four details that together make a case steerable: the category of the incoming item, the owning role, the deputy for that role, and the deadline that starts on arrival. Whoever settles those four details once for the most frequent types of item has done the larger part of the work; the technical remainder is a rule set in the mailbox or in the case system and can be planned as part of process automation.

Two lanes are laid down by law and therefore do not belong in the general mailbox. Companies with as a rule at least 50 employees must set up an internal reporting channel (Whistleblower Protection Act); its intake needs a path of its own, because confidentiality of identity otherwise founders on the sheer number of people reading along. And anyone employing as a rule at least 20 people permanently in the automated processing of personal data must appoint a data protection officer (Federal Data Protection Act); that intake, too, is worth a separate address, so that the one-month deadline for access requests does not vanish into the general backlog (GDPR).

One intake, several addresses

The public shared address stays as it is, with separate addresses alongside it for the reporting channel and for data protection. What gets separated is not the channel but the access: a different circle of people, its own log, its own rule for deputies.

Role instead of person

The owner is a role - accounts, sales, data protection - and not a name. That way the rule survives holidays, changes and departures, and the deputy is named in advance rather than looked for when it matters.

Deadline on the case

The deadline hangs on the case and not in somebody's head. An access request has to be answered within one month of receipt (GDPR); that date belongs visibly on the record, with the time of arrival as its starting value.

Status with meaning

Accepted, in progress, waiting on input, done: four states are enough as long as each of them describes an action. The read status of a message is not among them, because it only says something about the reader.

Filing with a retention link

Attachments and message text move into the filing of the case. Invoices must be kept for eight years (German VAT Act), other received commercial letters for six (German Commercial Code), counted from the end of the calendar year.

Backlog as a metric

Whatever cannot be assigned lands in a visible row with a count and an age. A backlog row reviewed daily is the place where a forgotten item shows up before a deadline is touched.

The six points can be modelled in any tool that keeps records with a status and a date: a ticket system, an ERP system, a list built in-house. The difference between the tools is smaller than the difference between a defined lane and none at all. Which processes are suited to a first attempt is sorted out in which processes to tackle first.

What a case has to carry

A case is not a ticket with a number but a record that answers two questions: what is to be done, and what has already happened? The status answers the first, the log the second. Together they replace the reconstruction from the reply chain, and together they are the basis on which an access request can be answered at all.

The fields are manageable. More important than their number is that the time of arrival is taken from the channel rather than typed in: it determines both the start of the one-month deadline for access requests (GDPR) and the start of the retention period at the end of the calendar year (German Commercial Code). A time of arrival entered by hand is a statement about a statement.

case.txt
Case 2026-4711
  arrival_time    2026-09-11T08:14:22+02:00   (from the channel, not typed)
  channel         info@ (shared address)
  sender          request@example.org
  category        subject access request
  lane            data protection
  owner           role: data protection
  deputy          role: management
  due             2026-10-11  (one month from arrival)
  extension       two further months, notice by 2026-10-11
  status          in progress
  filing          /cases/2026/4711/
  log             08:14 arrival | 08:31 lane set | 09:02 receipt confirmed

Retention
  kind            received commercial letter
  period_start    2026-12-31  (end of the calendar year)
  period_end      2032-12-31  (six years)

The last block is the one shared mailboxes most often fail to deliver. Without a calculated start and a calculated end of the retention period, retention is a declaration of intent. With both figures it becomes a rule that a filing system can apply, and it also permits deletion once the period has run out. Anyone who wants to approach the subject from the filing side will find the entry point in getting started with document management and the tax requirements in compliant document storage.

Access, logging and data protection in a shared mailbox

A shared mailbox is as a rule open to a wider circle of people than any specialist system. That means people see messages that are none of their professional business: a sick note that went to info@ by mistake, an application, a complaint about a colleague. Access is therefore broader than the task requires, and that is exactly where the supervisory authorities start.

The fine framework makes the difference between the two kinds of failure visible. Infringements of the rights of data subjects are subject to administrative fines of up to 20 000 000 euros or up to 4 percent of the total worldwide annual turnover, whichever is higher (GDPR). Missing technical and organisational measures sit one step below: up to 10 000 000 euros or 2 percent (GDPR). Both are upper limits rather than standard amounts, but they show the ranking. The practical steps are set out in data protection when digitising processes.

The backlog is a notification topic too

When a message in the shared mailbox describes a personal data breach - a misaddressed distribution list, a lost device, access from outside - the 72-hour clock is running, and a later notification to the supervisory authority requires reasons for the delay (GDPR). For essential and important entities the early warning within 24 hours of becoming aware is added (BSI Act), followed by a final report one month after the notification of the incident at the latest (BSI Act). A mailbox left unreviewed over the weekend spends a considerable part of that before anyone even decides. What else applies to regulated entities is set out in NIS2 and mid-size companies.

Getting there in five steps

The rebuild can be run in small steps, and it should be: the assignment only holds if it is derived from the items that actually arrive rather than from an assumption about them.

Every message gets a category and a role, at first as a tally on paper. After ten working days it is clear which types of item actually occupy the company and how the volume spreads across the week. That record replaces every estimate and costs half an hour a day.

Nearly all of the effort sits in steps one and two. Once the lanes are defined, the technical work is a matter of rules in the mailbox and fields in the case system. How the benefit can be calculated is shown in what a single case really costs; where the step fits into a wider automation is described on the page about automating workflows.

The status is the real change

Of all the building blocks, one changes everyday work the most, and it costs nothing: a status that says something about the action rather than about the reader. As soon as „accepted“ and „in progress“ come apart, it becomes visible what a message is waiting for - an input, a decision, a person on holiday. Everything else, from the deadline to the filing, attaches itself to that single distinction.

How success can be read off

  • Age of the oldest unassigned item, measured in working days and read off daily.
  • Share of items that were given a lane on the day they arrived - the metric closest to the deadlines.
  • Number of deadlines that arose from an item and carry a date in the system, such as the one-month period for access requests (GDPR).
  • Time between arrival and acknowledgement for reports to the internal reporting channel, measured against seven days (Whistleblower Protection Act).
  • Share of incoming invoices recorded before the payment term expired - the counter-check to the flat default sum of 40 euros (German Civil Code).
  • Completeness of the filing: a sample of ten cases per quarter checked for availability and machine evaluable form (German Fiscal Code).

These six values can be collected without an additional tool, provided the case carries the right fields. They replace the question of whether things are running with a figure that can be compared against last week. How to build a small, load-bearing set from them is set out in metrics that actually help; the connection to throughput is described in shortening lead times.

The most expensive message is not the one nobody answered but the one nobody can say was answered. It costs twice: once for the search, and once for the reply that gets written a second time just to be safe.

Project experience

Sources and studies

This article draws on: the German Commercial Code, section 257 (retention and start of the period), the German Fiscal Code, section 147 (retention, availability and machine evaluation), the German VAT Act, sections 14, 14b and 27 (issuing, retention, transitional rule for electronic invoices), the German Civil Code, section 288 (default flat sum and default interest), Regulation 2016/679, Articles 12, 33 and 83 (deadlines for data subject rights, notification of breaches, fine framework), the BSI Act, section 32 (notification duties), the Whistleblower Protection Act, sections 12 and 17 (reporting channel, acknowledgement, feedback), the Federal Data Protection Act, section 38 (data protection officers of non-public bodies), the Federal Office for Information Security, The State of IT Security in Germany 2025 (spam, attack and address figures for the government networks), the Bavarian Data Protection Authority, 15th activity report (data breach notifications 2025), and the Federal Statistical Office, press release 416 of 24 November 2025 (cloud computing). All deadlines and amounts are taken from the version in force at the time; this article does not replace an assessment of an individual case.

Related Articles

Automation & interfaces

Verification of payee in payment runs: handling mismatches

Since October 2025, banks check name and IBAN before every credit transfer. How supplier master data, payment blocks and call-backs handle the bank's responses.

16 min read
Automation & interfaces

Interim Payments and Variations on Building Sites

How a stage of completion becomes an interim invoice, why a variation is a case with a deadline of its own, and how that produces a final account that can be checked without rework.

14 min read
Automation & interfaces

Shift rosters that check rest periods upfront

How rest periods, working time limits, qualification and availability are calculated as rules while the roster is built - and how plan and actual finally come together.

15 min read