The most talked-about aspect of switching to electronic documents is the ease of issuing them. However, the real obligation begins after the document is issued: archiving.
In the paper era, folders sat on shelves; even if something was lost, there was a chance of a physical search. With electronic documents, the "it must be somewhere" approach does not work.
In this article, we covered the scope of the retention obligation, a practical archive layout, and the habits that guarantee access to documents during an audit.
Table of Contents
Who holds the retention obligation?
Both the party issuing the document and the party receiving it are obligated to store their own copies. This responsibility is not transferred to the integrator or software provider.
The provider may offer you a storage service; this is a practical convenience. However, you are the party required to present the document during an audit.
This distinction becomes critical when changing providers. Make sure you can export your documents in bulk at the end of the contract. We listed the criteria in the integrator selection article.
What exactly is stored?
What needs to be stored is not the visual representation of the document, but its signed electronic copy. A PDF output is a convenience, but it does not replace the original.
This distinction is often overlooked. Saving invoices to a folder as PDFs does not count as archiving; the electronically signed file itself must be preserved.
The scope is not limited to invoices. e-Archive, e-delivery notes, producer receipts, and self-employment receipts are also subject to the same obligation. You can check out our e-Delivery Note and e-producer receipt articles.
Incoming documents are also stored. Archiving only the documents you issue is an incomplete approach.
For how long?
Tax legislation prescribes a specific retention period for ledgers and documents. A separate period may also apply in terms of commercial legislation.
The practical approach is to base it on the longest period. To avoid getting caught at the intersection of different legislations, it is wise not to rush into deleting documents.
Confirm current periods with your financial advisor; legislation can change, and there may be industry-specific regulations.
The format must also remain readable throughout the retention period. A file that cannot be opened ten years later is considered unstored.
Accessibility: storing is not enough
The obligation is not just to keep the file, but to present it when requested. This requires search capability.
In a good archive organization, a document should be retrievable by date, current account, document number, amount, and document type. Archives based on folder hierarchies do not offer this flexibility.
Having the same list logic work across every module facilitates the team's search habits; standard list experience addresses this need.
Linking the operation record related to the document also provides benefits. Seeing which order an invoice came from while viewing it makes explanations easier during an audit; check out the document matching article.
Backup strategy
A single copy is not a copy. A fundamental rule is that the archive must exist in at least two different places.
If you use a cloud-based platform, backups are handled on the infrastructure side. Still, taking periodic exports under your own control is valuable for provider independence.
If there is a structure running on a local server, backups must be tested. A backup that has been taken but cannot be restored is not a backup. We explained the bridge between local and cloud in the on-prem agent article.
Access authorization is just as important as backup. Who can reach the archive must be limited; the sensitive operation permissions article covers this distinction.
Audit day scenario
Audits usually request documents belonging to a specific period. The request is concrete: all documents issued to a specific current account within a given date range.
If your archive is organized, this request is met within minutes. If it is not organized, a days-long search begins, which changes the tone of the audit.
The easiest way to be prepared is to run a drill once a year: pick a random period and try to pull the documents. Find the problem on your own time, not during the audit.
User action log records can also be illuminating; you can look at the audit trail management article.
The personal data dimension
Documents carry not only commercial data; they also contain personal data. The names, addresses, and identity information of real-person customers are included in invoices.
This means the archive also falls under the scope of personal data legislation. Retention periods, access authorizations, and security measures must be evaluated at the intersection of both legislations.
The practical takeaway is this: access to the archive must be restricted, and it must be trackable who viewed which document and when. A structure where everyone can access all documents carries both commercial and legal risks.
We discussed general customer data management in the KVKK-compliant customer data article; the document archive is part of this framework.
What to do when the retention period expires must also be planned. Storing indefinitely is not always the safest option; retaining unnecessary data also creates an obligation. Evaluate this issue together with your financial advisor and legal counsel.
During a provider or system change
The moment the archive obligation is tested the most is when you change systems or providers. The structure that seemed seamless until that day reveals flaws during the transition.
The question to ask before the transition is clear: how will I access my past documents in the new structure? If the answer is "from the former provider," it must be clarified whether your access will continue at the end of the contract.
The safest approach is to take a bulk export before the transition. Downloading the documents to an environment under your own control eliminates any subsequent access issues.
The format of the export is also important. Signed electronic copies must be obtained; a list or PDF output alone does not fulfill the obligation.
This topic is also a criterion in provider selection; we covered the data ownership heading in the integrator selection article.
Frequently asked questions
Is storing as PDF sufficient?
No. The signed electronic copy must be preserved; PDF is merely a readable presentation.
If the integrator is archiving, should I store them myself as well?
Since the obligation lies with you, it is recommended to secure your own access.
What happens to documents if the company closes down?
The retention obligation continues until the period expires. Make a plan with your financial advisor for this scenario.
How is the archive separated in a multi-company structure?
Documents are scoped on a per-company basis; the multi-company model provides this separation.
Archiving is an area that goes unnoticed today but determines everything when needed. Being able to find the document is as much a part of the obligation as storing it.
By meeting with the EQLEM team, you can plan your document archive layout and access permissions together.

