Grotabyte
Contact SalesBook a Demo

Compliance / MiFID II & FCA

Compliance framework

MiFID II & UK FCA Communications Recording

European and UK investment firms must record the conversations and electronic communications that relate to client orders — whether or not the order is ever placed — and be able to hand them to a regulator years later. MiFID II sets the EU baseline; the UK onshored it and the FCA enforces materially the same rule through SYSC 10A.

Applies to: EU investment firms and credit institutions performing MiFID investment services, their branches, and third-country firms dealing with EU clients. In the UK, MiFID investment firms and collective portfolio managers under FCA SYSC 10A.

At a glance

RegulationMiFID II Art. 16(7); FCA SYSC 10A
Applies toEU & UK investment firms
Retention5 years; up to 7 on request
CoversCalls and electronic communications on client orders

What MiFID II & FCA requires

Record what could lead to a transaction

MiFID II Article 16(7) covers conversations and electronic communications relating to the reception, transmission and execution of client orders — including those that never result in a transaction. Firms must take all reasonable steps, and the obligation follows firm-provided or firm-permitted devices.

Five years, extendable to seven

Records are kept for five years, and where the competent authority requests it, for up to seven. The FCA states the same periods in SYSC 10A: five years, and up to seven where the FCA asks.

Stored so the original cannot be altered

SYSC 10A requires records be kept in a durable medium and in a format that does not allow the original record to be altered or deleted, with the firm accountable for the quality, accuracy and completeness of what it holds.

Retrievable for the client and the regulator

Records must be readily accessible — available to the client on request, and produced to the regulator on demand. Firms must have a written recording policy and evidence of management oversight of it.

How Grotabyte helps with MiFID II & FCA

One archive across the channels in scope
Email from Microsoft 365, Google Workspace, on-premise Exchange with journaling and any IMAP or POP3 mailbox, plus Microsoft Teams 1:1 and group chats and Claude Enterprise AI conversations — each captured as its own record.
Retention that runs from custody
Retention templates carry the rule they implement, the longest applicable rule wins, and the clock starts when the record enters custody. A five-year MiFID period and a seven-year extension are policy settings, not a migration.
Sealed and hash-verified, with the caveat stated
Records are sealed onto a hash-chained, tamper-evident ledger, so alteration or excision is detectable and reportable. Where your written policy calls for storage-level retention locking, it is available on request and can be applied to an archive you already hold.
Production without a second system
Search across thirteen fields with phrase, proximity and fuzzy operators, then export — ad hoc to PST, EML, PDF, HTML and CSV, or as a full production with load files, Bates numbering and a chain-of-custody report.

Frequently asked questions

Did Brexit change the UK recording rules?

Not materially. The UK onshored MiFID II at exit day, and the FCA's SYSC 10A continues to mirror the substantive EU requirement — including the five-year retention period and the extension to seven years where the FCA requests it. Firms operating in both jurisdictions generally run one policy against both.

Do we have to record communications that never became an order?

Yes. The obligation covers communications intended to result in a transaction, whether or not one follows. That is why firms capture the channel rather than trying to judge which individual messages are in scope.

Does Grotabyte satisfy the requirement that records cannot be altered?

Grotabyte seals each record onto a hash-chained, tamper-evident ledger, so any alteration or removal breaks the chain and is reported by verification. Storage-level retention locking, which prevents deletion and overwriting for a set term, is available on request and can be enabled for an existing archive. Grotabyte does not describe its storage as WORM, immutable or non-rewriteable — see the WORM compliance page for what that distinction means in practice.

How does this interact with GDPR erasure requests?

A recordkeeping obligation is a lawful basis for continued processing, so a MiFID retention period generally survives an erasure request for the records it covers. Grotabyte implements GDPR Article 17 erasure under dual control, and where a record is under a retention rule or legal hold the refusal is written to the ledger with its legal basis.

Related

Financial services archiving →Legal holdRetention policyChain of custody

Meet MiFID II & FCA with confidence

See how Grotabyte captures, preserves, and produces your records to satisfy MiFID II & FCA and the other regulations that govern your organization.

Book a demoAll compliance frameworks

Stay in the loop

Subscribe to receive the latest product releases, compliance insights, and event invites from Grotabyte.

Grotabyte

Next-generation enterprise archiving and eDiscovery platform trusted by leading organizations worldwide.

Secure • Scalable • Reliable

Platform

  • Solutions
  • Features
  • Workflows
  • Data Sources
  • Email Archiving
  • Data Archiving
  • Records Management
  • Compliance

Industries

  • Financial Services
  • Education
  • Government
  • Healthcare
  • Public Safety

Resources

  • Complete Guide
  • Glossary
  • Compare
  • Case Studies
  • Whitepapers
  • Blog

Company

  • About
  • Contact

Trust & Legal

  • EULA
  • Support Terms
  • Privacy Policy

© 2026 Grotabyte. All rights reserved. Built with enterprise security and compliance in mind.