GoBD and other record-keeping rules
Restow’s archive (see Archive and journaling, available since 0.1.0) is built for German GoBD requirements. This page lays out what that actually means, requirement by requirement, and looks at a few other record-keeping regimes people sometimes ask about (SEC Rule 17a-4, FINRA, Switzerland, Austria) without claiming to satisfy any of them.
Requirement → Restow mechanism
Section titled “Requirement → Restow mechanism”| GoBD requirement | Restow mechanism | Status |
|---|---|---|
| Complete and correct | Journaling captures a copy before a user can change or delete anything; Graph/IMAP sync fills in what journaling could not have seen and is marked as such | Available (journaling from Business) |
| Timely | Capture happens before the recipient’s mailbox can be altered (journaling), not on a later schedule | Available (Business) |
| Orderly, traceable | Full-text search, per-item metadata, EML/ZIP export with a manifest | Search available; EML/ZIP export with a manifest and checksums available; chain-value file and evidence report in development |
| Unalterable | Hash chain over every archived item with daily anchors; object lock (WORM) at the storage layer where the target supports it | Hash chain and verification available; external anchors and WORM default in development |
| Machine-evaluable | Original format retained (an email stays an email), full-text search over content and attachments | Available |
| Original format | Byte-exact message/rfc822 storage of the original, not a converted or printed copy |
Available |
| Procedural documentation (Verfahrensdokumentation) | A per-tenant template pre-filled from the actual configuration (capture path, storage, encryption, access rights, retention, deletion procedure, controls), which the organization completes; the full document, including its organizational processes, stays the taxpayer’s own responsibility under GoBD | In development |
| Change / deletion logging | Every deletion run writes what it deleted into the same hash chain | Available (Business) |
| Defined retention period | Policy per tenant, 6/8/10 years or unlimited, matching HGB/AO periods | Available (Business) |
| Legal hold (not itself a GoBD requirement, but often needed alongside retention) | Per tenant, mailbox or search result, with reason, creator and date; blocks deletion | Available (Business) |
| Access control, audited access | Role-scoped search (tenant admin, end user, provider admin with four-eyes release) | In development |
The archive-specific mechanisms in this table ship with 0.1.0 where marked available; the rest are still in development; see Archive and journaling for the full design and Archiving for status. Separately from the archive, Restow encrypts and isolates each tenant’s data today; every read, restore or export is recorded in the tamper-evident audit log (who, when, what, on whose behalf, from which IP) in every edition; the viewer with search and chain verification, exportable as CSV and PDF, comes with Business and is in development. See Audit log.
A fixed retention period is also not automatically the last word: under § 147(3) AO, a record must be kept longer while it still matters for a tax assessment that is not yet final. A deletion run that always deletes at the fixed 6/8/10-year mark without checking this could delete too early. Applying that check, or extending a policy by hand, is your organization’s own decision, not something Restow automates.
Is WORM storage required?
Section titled “Is WORM storage required?”Not explicitly. GoBD Rz. 110 of the BMF’s guidance gives access-authorization concepts (Zugriffsberechtigungskonzepte) as its example of an organizational measure that can support immutability, alongside hardware measures (tamper-proof media) and software measures (write locks, deletion markers, automatic logging, versioning). The same paragraph also states that storing records in an ordinary file system “regularly does not meet” the immutability requirement unless additional measures ensure it. Restow makes hardware WORM (S3-compatible Object Lock, COMPLIANCE mode) the planned default target for its archive for exactly that reason. A filesystem target without object lock is planned to remain usable only after an explicit, audited opt-out, relying on Restow’s application-level controls (the hash chain, access restriction, deletion logging) as the kind of “additional measures” Rz. 110 refers to. Whether those are enough for your setup is for your own tax advisor or auditor to assess, not something Restow decides for you.
Outside Germany, the picture is different in one specific case. US SEC Rule 17a-4(f) governs electronic records for broker-dealers: it requires either a WORM (“non-rewriteable, non-erasable”) storage medium, or, since amendments adopted 2022-10-12 (effective 2023-01-03, compliance date 2023-05-03), an “audit-trail alternative”: a system that can recreate an original record if it is modified or deleted. Both routes also require an undertaking to furnish records to regulators, which since the 2022 amendments can be given by a designated executive officer instead of only a designated third party. FINRA Rule 4511 incorporates the same 17a-4 electronic-storage standard by reference for its members, plus a 6-year default retention for any record without its own specified period.
This regime applies to US broker-dealers, FINRA members, and, under the same 2022 rulemaking, security-based swap dealers and major participants (Rule 18a-6). It has no bearing on a German (or other EU) business archiving ordinary mail under GoBD. If it does apply to you, meeting Rule 17a-4(f) is a separate assessment your organization would need to arrange with its own counsel and auditor, not something this product certifies.
A few other regimes, briefly
Section titled “A few other regimes, briefly”- Switzerland (OR Art. 958f, detailed in the GeBüV, the ordinance on keeping and retaining business records): books, accounting vouchers and business correspondence are retained 10 years from the end of the fiscal year. Books and vouchers may be kept electronically or on comparable media (OR Art. 958f(3)); the annual report and the audit report must be kept in written, signed form (OR Art. 958f(2)), so the electronic option does not cover those two. GeBüV Art. 9 sets the media rules for the electronic option: either an unalterable medium, or an alterable medium combined with integrity procedures (for example digital signatures), a verifiable storage time (for example timestamps) and documented procedures, so there is a WORM-like option, but also an alterable-plus-controls alternative, not a strict WORM mandate.
- Austria (BAO § 132): 7 years for most records (longer periods apply to some, for example real-estate-related records, up to 22 years), extended for as long as a document remains relevant to a pending tax proceeding; the period starts at the end of the calendar year for which the entries were made or to which the documents relate.
Neither of these is a target Restow’s design has been built against specifically. The mechanisms above (journaling, hash chain, retention policy, legal hold) are broadly the same kind of measure these laws also ask for, but Restow makes no claim of meeting either regime’s specific requirements.
What Restow does not claim
Section titled “What Restow does not claim”Restow does not claim certification, conformity or compliance with GoBD, SEC Rule 17a-4, FINRA, SOC 2, ISO, or any other standard: no software can certify that for you. GoBD Rz. 179–181 are explicit that tax authorities issue no positive attestations (Positivtestate) of conformity, neither in a tax audit nor in a binding ruling, and that a third party’s certificate does not bind the tax authority either. What Restow says instead: the archive is built for German GoBD requirements, with the specific measures named on this page and on Archive and journaling. Whether a given deployment actually meets your organization’s obligations, under GoBD or any other regime, is something only your own tax advisor, auditor or compliance counsel can confirm for your specific situation.
Sources
Section titled “Sources”- BMF, GoBD (as amended, letter dated 2025-07-14): https://www.bundesfinanzministerium.de/Content/DE/Downloads/BMF_Schreiben/Weitere_Steuerthemen/Abgabenordnung/2025-07-14-GoBD-2-aenderung.pdf
- § 147 AO (retention periods): https://www.gesetze-im-internet.de/ao_1977/__147.html
- § 257 HGB (retention periods): https://www.gesetze-im-internet.de/hgb/__257.html
- SEC, 2022 amendments to electronic recordkeeping requirements for broker-dealers: https://www.sec.gov/investment/amendments-electronic-recordkeeping-requirements-broker-dealers
- Federal Register, Electronic Recordkeeping Requirements for Broker-Dealers: https://www.federalregister.gov/documents/2022/11/03/2022-22670/electronic-recordkeeping-requirements-for-broker-dealers-security-based-swap-dealers-and-major
- FINRA Rule 4511: https://www.finra.org/rules-guidance/rulebooks/finra-rules/4511
- Switzerland, OR Art. 958f (SR 220): https://www.fedlex.admin.ch/eli/cc/2002/216/de
- Switzerland, GeBüV (SR 221.431): https://www.fedlex.admin.ch/eli/cc/2002/582/de
- Austria, BAO § 132: https://www.ris.bka.gv.at/NormDokument.wxe?Abfrage=Bundesnormen&Gesetzesnummer=10003940&Artikel=&Paragraf=132&Anlage=&Uebergangsrecht=
Where to read more
Section titled “Where to read more”- GoBD and evidence: the German legal detail behind “unalterable” and “timely”, in full.
- Archive and journaling: the full design this page’s mechanisms come from.
- Archiving: current status.