Knowledge route | Business messages

Control WhatsApp and chat messages across your organisation

Your organisation does not need to retain every message indefinitely, but it must be able to explain which information matters and why it is managed, blocked, destroyed or transferred. Business messages may fall within Dutch freedom-of-information and archival duties. BronVast brings risk, context, appraisal, access, holds and destination together in one accountable route.

Specialist reviewing digital message source packages
2dA BronVast

Messages

1

Start with task and risk

Map roles, processes, channels and situations in which relevant public information can arise.

2

Secure context

An isolated line without participants, time, replies, attachments and process relationships may lose its meaning.

3

Decide with authority and evidence

Appraisal, disclosure, holds, destruction and transfer remain decisions of the authorised organisation.

Evidence route

From source package to accountable destination

01

Information value

does the message relate to a public task?

02

Risk

which roles, processes and events require greater control?

03

Capture

which lawful export or capture output is available?

04

Context

participants, time, attachments, case and process

05

Assessment

appraisal framework, access, privacy and holds

06

Destination

manage, destroy or transfer under control

Format does not make information unimportant

Business information may arise in WhatsApp, SMS, Signal, Teams or another messaging environment. Content, context and the relationship with organisational action matter more than the application brand.

  • define working arrangements for business and private devices
  • connect roles and processes to risk
  • record responsibility and escalation
  • allow for changing export and capture capabilities

Not retaining everything is also sound records management

A defensible approach combines risk analysis with applicable appraisal frameworks. Process, key-role and hotspot methods may coexist; an active FOI, investigation or dispute hold may temporarily block destruction.

  • document the appraisal route used
  • separate proposal, decision and execution
  • prevent destruction under an active block
  • record exceptions and departures

Capture does not resolve the archival question

After capture, provenance, integrity, relationships, metadata, access and destination still require design. BronVast Messages therefore starts with a lawfully obtained source package and exposes every derivation and human decision.

  • keep source files unchanged
  • use manifests and SHA-512 for verification
  • separate source values from derived proposals
  • test the receiving DMS, RMA or e-depot profile in advance
Deliverables

What your organisation receives

Policy and working arrangements

Who acts, when and why

Roles, channels, exceptions, capture and escalation in one executable route.

Controlled processing

From export to understandable information

Source registration, reconstruction, metadata, human review and visible uncertainty.

Lifecycle

Control through to destination

Holds, appraisal, accountable destruction and controlled transfer.

Reference points

Reference points

These references show the professional basis for our choices. The requirements that apply in practice are determined with you from your situation, responsibilities and receiving environment.

Open GovernmentDutch guidance on technology, privacy, roles, processes and working arrangements.National ArchivesGuidance covering risk analysis and business and private communication.Appraisal methodsProcess, key-function and hotspot methods may be used alongside each other.
FAQ

Questions about this route

Must a public body retain every WhatsApp message?

No. Information value, risk, applicable appraisal frameworks and exceptions determine which information must be managed and for how long.

Is a screenshot sufficient?

A screenshot may help in a specific situation but does not automatically retain all provenance, relationships, attachments, events and technical metadata that may be required.

Can 2dA extract messages directly from every application?

No. 2dA starts with a lawfully obtained export or agreed capture output and profiles the concrete source variant before promising processing.

Next step

Start with evidence, not assumptions

A first engagement can be limited to one lawful source package, one process and one receiving profile.