From what I've read, the US doesn't have any data retention requirements for ISPs and other providers unless required to do so by a warrant. This is primarily for user privacy reasons, but I am betting the investigatory organizations don't need you to retain the data in order for them to skim it when needed. So, I think its probably up to you how long you hold on to data and what data you hold on to. If you're approached with a warrant to retain user X's communications for a period of 90 days - then you'd want to adjust your process for that user and implement a legal hold of sorts. I don't have any specific background in this however so hopefully other users can comment here as well.
Kyle Kerst
IT Coordinator
SmarterTools Inc.
www.smartertools.com