Governance and Compliance

Make content governance a seamless part of the way you work

Document Retention

Simplify Document Lifecycle Management

Businesses often struggle with how to handle content while staying compliant with policies, regulations and litigation requirements. Box Governance solves this challenge by enabling you to manage the entire lifecycle of your documents while complying with regulatory mandates, e-discovery requests and data retention policies with ease. 

Read the Box Governance Datasheet

Box Governance Features

Data Retention
Deploy Data Retention

Simplify content retention by setting automated policies to control preservation and deletion schedules of business documents.

Support Defensible eDiscovery

Easily comply with legal reviews with the ability to identify relevant content, preserve documents and metadata and prevent information deletion and modification with legal holds.

Data Policies
Bring Security Policies to the Cloud

Trigger alerts or restrictions when files are uploaded, downloaded or shared, and extend Data Loss Prevention policies into Box with our trusted partners.

Global Compliance

Enable Global Privacy & Compliance

Box provides the necessary safeguards to help you meet your security requirements and compliance standards, including supporting storage of customer data in Europe, Asia, Australia, and Canada.


Box supports global customers with ISO 27001, ISO 27018, PCI DSS, TÜV Rheinland Cloud Security Certification, UK G-Cloud Approval for Official Data, FedRAMP, FIPS 140-2, SEC 17a-4, and HIPAA/HITECH. You can leverage third-party assessments and reports, such as SOC 1 (SSAE 16) Type II, SOC 2 Type II and SOC 3.


We effectuate EU personal data transfers pursuant to Box's Processor Global Binding Corporate Rules and Controller Global Binding Corporate Rules (BCRs) approved in August 2016 by the European Data Protection Authorities. Our BCRs FAQs help address common queries and answers. We are also certified under the Asia-Pacific Economic Cooperation (APEC) Cross-Border Privacy Rules (CBPR) System.

Review Our Privacy Policy
Box Customer, Jon Wooten - Engle Martin, Quote
“Box Governance is a truly scalable content management solution that will grow with our business. We love the retention policies because we can easily access data that was stored a very long time ago. It is a huge help in maintaining our SSAE16 Type II compliance.”


Jon Wooten, IT Manager, Engle Martin

Transform Content Governance and Compliance with Box