Earlier quoted context omitted.
> In the corporate world, if there were a legal requirement for compliance, the auditor would verify that all work email is going over work servers Legal compliance audits that I have been involved in tend to go beyond what is unquestionably prohibited by the law and also seek to identify and eliminate activities which might arguably violate the law (and thus create legal risk) including, but not limited to, those wh…
As to #3, quoting from the article, as of 2009 (emphasis mine): > agencies that allow employees to send and receive official electronic mail messages using a system not operated by the agency must ensure that federal records sent or received on such systems are preserved in the appropriate agency record-keeping system. How did they ensure this? As a few news stories, including the linked article, have reported, they…
Yes, that's exactly the question this raises.
> As a few news stories, including the linked article, have reported, they would have been immune from FOIA requests.
They would not have been immune. They may have been overlooked in the course of handling such requests, although assuming anyone in the State Department offices responsible for conducting document searches in response to FOIA requests (or subpoenas, etc.) was aware of the practice, they quite probably wouldn't have been, there just would have been an extra step involved in handling the requests.