Italian Data Protection Authority (‘IDPA’): guidelines on the use of company email management programs and on so-called “metadata” retention have been updated following recent public consultation by the IDPA
With order no. 364 of 6 June 2024 called “Computer programs and services for the management of e-mail in the workplace and metadata processing”, the IDPA has returned to the topic of company e-mail metadata retention.
What is “metadata”?
“Metadata” does not mean information contained in the “body” of the email but rather the information relating to the sending, receiving and sorting the messages. This may include the email addresses of the sender and of the recipient, the IP addresses of the servers or clients involved in the routing of the message, the times of sending, retransmission or reception, the size of the message, the presence and size of any attachments and, in certain cases, depending on the email management system used, may also include the subject of the message sent or received.
How long can employers retain this information?
With respect to the IDPA’s guidelines before the public consultation, the guidelines of 6 June 2019 extended the retention period to 21 days.
This retention period is merely “indicative”.
Retention for longer is only permitted if specific conditions that make the extension necessary are satisfied and are adequately proven.
Applying the principle of accountability, it is therefore up to each employer to adopt all technical and organisational measures to ensure compliance with the principle of purpose limitation, selective accessibility by only authorised and adequately trained individuals and the tracking of access carried out.
These requirements must be met while keeping in mind that generalised metadata collection and retention can lead to indirect remote control of workers’ activities and, in this case, the safeguards provided for by Article 4 of the Workers’ Charter apply i.e., it is necessary to enter into a union agreement or, failing that, obtain authorisation from the National or Local Labour Inspectorate.
Please contact our Privacy Focus Team for further information.
The Italian Data Protection Authority (i.e. “Garante per la protezione dei dati personali”) has once again provided guidance on how employers should manage corporate email accounts after the…
With order no. 4077 of 23 February 2026, the Italian Supreme Court addressed the issue of oral dismissal, holding that an employee challenging the termination of the employment…
The Italian Supreme Court, with order no. 4198 of 25 February 2026, held that an employee’s transfer may be lawfully implemented also in the presence of a situation…
In the organizational language of companies, terms such as “breaks,” “waiting times,” or “downtime” are often used. In operational practice, these expressions tend to be treated almost as…
Claudia Cerbone and Martina De Angeli, professionals at the De Luca & Partners firm, author this article dedicated to the draft legislative decree approved last February 5 by…
With Order No. 4198 of 25 February 2026, the Italian Supreme Court (Court of Cassation) – Labour Section – reaffirmed that a situation of environmental incompatibility may justify…