Monday, October 5, 2026
Home » How Do Banks Store MiFID II and Dodd-Frank Communications Records?

How Do Banks Store MiFID II and Dodd-Frank Communications Records?

MiFID II and Dodd-Frank records storage is a daily operational reality for global banks and investment firms. Both regimes require firms to capture and retain communications related to trading, and both expect records to be complete, unaltered and retrievable when supervisors ask. A bank with trading desks in London, Paris, Frankfurt, New York and Tokyo may be subject to several overlapping sets of rules, each with its own scope, retention period and format expectations. The storage behind these archives has to satisfy all of them at once, at very large scale.

This article explains what MiFID II and Dodd-Frank require in practice, how communications are captured and archived, what storage capabilities matter and how firms design archives that work across jurisdictions. It is general information, not legal advice. For the broader archive picture, see our hub on financial services archive storage.

MiFID II recording requirements

The EU’s Markets in Financial Instruments Directive II, applied since January 2018, requires investment firms to record telephone conversations and electronic communications relating to transactions concluded when dealing on own account and to client order services, including communications intended to lead to a transaction even if no transaction results. Key points include:

  • Scope: phone calls, email, chat, messaging and other electronic communications relating to in-scope activities, on firm-provided or approved devices.
  • Face-to-face conversations with clients must be documented, for example in written minutes or notes.
  • Retention: records must be kept for five years, and up to seven years where requested by the competent authority.
  • Access: records must be provided to clients on request and to regulators.
  • Integrity: records must be stored in a durable medium that allows them to be replayed or copied and prevents alteration or deletion.

The UK retained equivalent requirements after leaving the EU, enforced by the FCA.

Dodd-Frank recordkeeping

In the United States, the Dodd-Frank Act led to recordkeeping rules for swap dealers and other market participants, implemented largely through CFTC regulations. These require firms to keep records of swap transactions, including pre-trade communications, for defined periods, generally through the life of a swap and for years afterward, with specific rules for recorded oral communications. Broker-dealers are also subject to SEC Rule 17a-4 and FINRA rules for business communications.

Other jurisdictions

Firms with operations in Asia-Pacific and the Middle East face additional local rules. Regulators in Japan, Hong Kong, Singapore and the UAE set their own requirements for recording, retention and supervisory access, and many also have expectations about data location. A global firm usually builds a single capture and archive platform that applies the strictest relevant rule, or the right rule per region.

From capture to archive

Capture

Communications are captured at source by specialized systems: voice recording platforms for turrets and phones, email journaling, connectors for chat and collaboration platforms and mobile capture for approved devices. Capture must be complete; gaps can lead to regulatory findings.

Normalization and indexing

Captured items are normalized into a common format with metadata such as participants, timestamps, channel and desk, and indexed for search. Voice may be transcribed to support search and surveillance.

Archiving

Normalized items are written to an archive, which applies retention policies, legal holds and access controls. The archive writes to storage that provides immutability.

Surveillance and retrieval

Compliance teams run surveillance over communications to detect market abuse. Legal and compliance teams search and retrieve records for investigations, client requests and regulatory inquiries.

Storage capabilities that matter

Immutability

Records must not be altered or deleted before retention ends. Object lock in compliance mode provides WORM retention that administrators cannot override, which aligns with the durable, non-alterable medium expected under MiFID II and the WORM option under SEC 17a-4.

Retention by jurisdiction and record type

A single archive may hold records subject to five-year MiFID II retention, longer US retention and local rules elsewhere. Storage and the archive application must apply retention per record and handle extensions when regulators request them.

Legal holds

Investigations and litigation require holds that suspend deletion. Holds must be applied quickly and reliably across large numbers of records.

Retrieval performance

Regulators expect timely responses. Voice recordings must be replayable, and large productions must complete within deadlines. Online object storage delivers far faster retrieval than offline media.

Scale

Communications volumes are large and rising, particularly with voice, video and collaboration platforms. Storage must scale to petabytes without disruptive migrations.

Data residency

Some records must stay in specific jurisdictions. Firms often run regional archives, for example EU records in the EU and US records in the US, on the same storage technology with central management.

Resilience

Archives must survive site loss, with copies at a second site and tested recovery. DORA in the EU adds explicit ICT resilience expectations for financial entities.

Architecture patterns

Consolidated object storage behind multiple applications

Firms often use different applications for voice, email, chat and trade records. A shared S3-compatible object storage platform underneath, with separate buckets and policies per application and region, reduces cost and complexity while applying consistent immutability and resilience.

Regional deployments

Separate storage clusters in each region keep records local while sharing designs, operations and tooling. Replication between sites within a region provides resilience without moving records across borders.

Tiering within the archive

Recent records, which are searched and retrieved most, may sit on faster tiers, with older records on high-capacity storage. Object storage can serve both, with policies to move data based on age.

Testing and evidence

Regulators and auditors look for evidence that records are complete, immutable and retrievable. Firms should test capture completeness, retention enforcement, legal hold application, retrieval times and recovery from site failure, and keep records of those tests. Independent assessments of storage WORM capabilities help compliance teams demonstrate that storage meets regulatory expectations.

Personal data inside communications archives

Communications archives contain large amounts of personal data about employees, clients and counterparties. In the EU and UK, GDPR applies alongside MiFID II. Firms must keep records for the required period but should not keep them longer without justification, must restrict access to people with a legitimate need and must handle data subject requests within the limits that regulatory retention allows. Storage should support deletion at the end of retention, with evidence that records were removed, and access logging that shows who viewed what. Balancing regulatory retention with privacy obligations is a recurring theme in audits, so document how the two interact for each record type.

Planning capacity for voice and video

Voice is often the largest component of communications archives by volume, and video meetings are adding more. Capacity planning should start from the number of recorded lines and users, average recorded hours per day, codec bitrates and retention per jurisdiction, plus transcripts and indexes. Growth from new channels and higher adoption of video should be included.

Common challenges

  • Channel sprawl: new messaging and collaboration tools create capture gaps.
  • Volume growth: voice and video drive storage growth faster than forecasts.
  • Fragmented archives: multiple applications with separate storage and inconsistent policies.
  • Cross-border data: global desks generate records that fall under several regimes.
  • Legacy migrations: moving old archives without breaking chain of custody.

Checklist: MiFID II and Dodd-Frank records storage

  • Map in-scope activities, channels and jurisdictions.
  • Capture all in-scope communications, including mobile and chat.
  • Apply retention per jurisdiction and record type, with extension support.
  • Store records with compliance-mode immutability.
  • Support fast legal holds and retrieval, including voice replay.
  • Keep records in required regions with regional storage clusters.
  • Design multi-site resilience and test recovery.
  • Consolidate storage beneath archiving applications.
  • Test and document capture, retention, holds and retrieval.

Putting it together

MiFID II and Dodd-Frank records storage requires capturing every in-scope communication, keeping it unaltered for years and producing it quickly when asked, across jurisdictions with different rules. The storage layer underpins all of it: compliance-grade immutability, per-record retention, legal holds, fast retrieval, regional placement and resilience. A consolidated, scalable object storage platform deployed regionally gives global firms a consistent foundation for every archiving application they run.

Frequently asked questions

How long must MiFID II communications be kept?

Five years, and up to seven where the competent authority requests it.

Does MiFID II apply to chat and mobile messages?

Yes. Electronic communications relating to in-scope activities are covered, including chat and messaging on approved devices.

What records does Dodd-Frank require?

CFTC rules require swap market participants to keep records of swap transactions, including related communications, for defined periods, generally through the life of the swap and beyond.

Can one archive meet both MiFID II and US rules?

Yes, if it applies retention per record and jurisdiction, provides immutability, supports holds and keeps records in required locations.

Why use object storage for communications archives?

It scales to petabytes, supports compliance-mode object lock, delivers online retrieval and can be deployed regionally for data residency.

Further reading