Co-funded by the European Union

Italy: The Data Protection Authority provides important guidance on the retention of company e-mail data

  • Data Protection Authority's (DPA) Guidance Document no. 642, published on 21 December 2023 and highlighted in their 6 February 2024 newsletter, introduced new guidelines on workplace email management. 
  • Employers in the public and private sectors who leverage computer programmes and cloud-based services to manage employee emails are now restricted to retaining the metadata of these emails for a maximum of seven days. An extension of up to 48 hours may be granted in cases of proven necessity. 
  • It poses potential challenges for companies in terms of compliance and operational flexibility.

Email metadata are essential information such as the date, time, sender, recipient, subject, and size of the email messages.

For companies requiring retention periods longer than seven days, the DPA refers to procedures outlined in Article 4 of the Workers' Statute, which delineates the conditions under which performance monitoring tools and systems can be employed within the workplace.

Specifically, such tools may only be utilized for organizational, production, safety, and asset protection purposes, and their implementation is contingent upon either a union agreement or authorization from the Labour Inspectorate. This legal framework exempts essential work tools, including emails, from these constraints, acknowledging their critical role in daily business operations.

However, the DPA's stance that the retention of email metadata beyond the 7-day limit falls outside the scope of "necessary working tools" requires employers to seek union agreement or inspectorate authorisation, introducing a potential source of contention.

This scenario forces employers to explore advanced technological solutions that can seamlessly segregate necessary operational data from personal employee information, ensuring they can retain critical data for extended periods without infringing upon the DPA's regulations.

In response to numerous requests for clarification received, on 27 February 2024, the Supervisory Authority announced the launch of a 30-day public consultation on the forms and methods of use that would make it necessary to store metadata beyond what was assumed in the Guideline Document.