Summary

  • Resolution 2026-14 added an immediately effective rule that all Internet Society Board mailing lists be retained under the organisation’s Records Retention and Management Policy.
  • The public procedure names the obligation but not the retention period, record class, custodian, legal-hold treatment or disposition; that is a visibility gap, not evidence of missing internal controls or lost mail.
  • A privacy-safe archive-control receipt can publish the applicable clock and custody state without exposing confidential messages, addresses, attachments or legal advice.

A rule finally reaches the procedure

On 10 July 2026, Internet Society’s Board approved Resolution 2026-14 by unanimous written consent. Among several governance changes, it renamed the mailing-list procedure to make its Board scope explicit and added a fourth section. The new sentence says that all Board mailing lists shall be retained for the period set out in the Records Retention and Management Policy. The revised procedure took effect immediately.

That sentence is small, but it governs an important institutional memory. The procedure says the main Board list is confidential. Board members and officers must be subscribed; another person may be added if no trustee objects or by motion. Each Board committee has a list, to which its chair may add people, and those lists are confidential unless designated otherwise. The Board may also create other lists and determine both membership and confidentiality.

The retention clause therefore reaches more than one inbox. It covers the principal list, committee lists and any other Board-authorised list. It creates a common duty across communications whose subscribers, decision authority and confidentiality can differ.

The change also repairs a documentary split. The public 2016 procedure described the same three list classes but had no retention section. In November 2018, the Board separately directed staff to retain archives of the Board and committee email lists according to the organisation’s retention policy for general correspondence. At the same meeting, it adopted amendments and clarifications to the wider retention policy for Board materials. In 2026, the retention instruction finally entered the operating procedure that readers are most likely to consult.

This is progress. A responsibility that exists only in old minutes is harder to discover and easier to detach from current operations. Putting it beside the rules for list creation and membership makes preservation part of ordinary administration.

The clock remains one document away

The public rule stops at the reference. It does not state how long any list is retained, when the clock begins, which record class applies, who holds the archive, what system is authoritative, how a legal hold changes disposition, or what proves that a permitted deletion actually occurred. The checked governance-policy index links the mailing-list procedure but does not list the referenced Records Retention and Management Policy as a separate public document.

That finding has a narrow meaning. It does not show that the internal policy is absent, vague or unimplemented. It does not show that any message has been lost or destroyed. It shows that an outside reader cannot bind the public obligation to a versioned clock from the public governance surface alone.

Internet Society demonstrates elsewhere that it can publish precise record outcomes. Its current trustee-selection procedure says public election-site material is kept in perpetuity, while nomination forms are deleted after the annual nominations and election process ends. Those rules distinguish durable public history from sensitive applicant data. They do not govern Board mail, but they show why “retained under another policy” is less auditable than a named outcome.

The missing information is not a demand for one universal duration. A temporary logistics list may deserve a different class from a committee archive. A message that merely schedules a call is not identical to a consent withdrawal, a conflict disclosure or an attachment containing legal advice. Good retention maps those differences. It does not pretend they are one object because they travelled through one service.

Discussion, consent and action are different records

The Board’s electronic-vote procedure makes the distinctions concrete. A vote administrator posts the call to the Board email list. Trustees supply written consent through DocuSign. A trustee may withdraw consent by emailing the list before the vote ends. The administrator announces the result to the list, and a passed resolution is then noted in the minutes of the next Board meeting.

At least four records may therefore surround one decision: the call, signed consents, a possible withdrawal or result message, and the later minutes. They serve different evidentiary functions. The complete mailbox is not automatically the binding consent instrument. The minutes are not a substitute for every communication that explains how an issue developed. Retaining a list does not relieve the Secretary or another custodian of preserving the required corporate action record in its proper system.

D.C. law reinforces that boundary. A nonprofit must keep permanent records of Board and committee actions, including actions taken without a meeting. It may maintain records electronically. The law does not say that every deliberative email must be permanent, nor that confidential correspondence must be public. Internet Society’s bylaws separately assign the Secretary custody of books, records and documents other than those maintained by the Treasurer and treat retrievable email as writing.

The governance question is therefore classification, not maximal accumulation. Which message or attachment is a corporate action record? Which is general correspondence? Which is a duplicate working copy? Which must be held because litigation, audit or investigation suspends the normal clock? A public procedure need not answer each message-level question, but it should identify the policy version and accountable route that answers them.

An archive-control receipt

The smallest public repair is an archive-control receipt. Give each list or list class a stable identity and the authority that created it. Record its confidentiality class, retention-policy version, record category, trigger and duration. Name the accountable custodian and the system that holds the authoritative archive. State whether routine disposition is active, suspended by a legal hold, migrated to a successor system or completed under authorised deletion.

The receipt should keep state changes. A list can be created, renamed, merged, closed, exported, migrated, frozen, released from hold and disposed. Each transition needs a timestamp, responsible role, governing rule and integrity fingerprint. If a retention schedule changes, the record should preserve which version applied before and after the change instead of rewriting the past.

None of that requires publishing message bodies. The public layer can omit names, addresses, subscriber histories, attachments, legal advice, personnel material and security-sensitive detail. A protected layer can preserve what authorised reviewers need. The public claim is smaller: this archive class exists, this role is responsible, this clock applies, and this is its current preservation or disposition state.

Such a receipt would not prove that the Board made a wise decision, that every subscriber behaved properly or that every email is authentic. It would prove that institutional memory is governed as a function rather than left as an implied property of a mail server.

Sources

  1. Procedure for Board Mailing Lists
  2. Resolutions approved by unanimous written consent
  3. Procedure for mailing lists, 2016 version
  4. Minutes of Board Meeting No. 142
  5. Governance Committee annual report 2015–2016
  6. Procedure for conducting electronic votes
  7. Procedures for selecting Trustees
  8. Amended and Restated By-Laws
  9. D.C. Code § 29-413.01, Corporate records
  10. D.C. Code § 29-406.21, Action without meeting
  11. Internet Society Governance & Policies index