INTRA/DP/DP014Personal material in company accounts
The handling of a worker’s personal material held on systems the employer controls, during employment and after it.
| Control | Jurisdiction | Source | What it establishes | Prerequisite or recommendation |
|---|---|---|---|---|
| DP014/FIMandatory | Finland | Laki yksityisyyden suojasta työelämässä (759/2004)Parliament of Finland · read 29 Aug 2026 | One act for the whole subject, holding processing to what is directly necessary, naming the conditions for cameras and for opening the employer’s electronic mail, and putting technical monitoring through a cooperation procedure before it is introduced. | What the employer may reach is the message belonging to it, identified from the sender, the recipient, or the title, and what is opened may not be processed further than the purpose requires nor disclosed during the employment or after it. |
| DP014/ITMandatory | Italy | Provvedimento n. 165, ITAS MutuaGarante per la protezione dei dati personali · read 16 Aug 2026 | That mailbox backups and browsing logs are instruments from which remote monitoring may follow, that an answer given in stages and handed over in part without saying what was withheld does not discharge the right of access, and that a five year backup of employee mail has to be disclosed to the people whose mail it holds. | A former worker retains a claim on personal material left in the account, and the employer has to be able to answer a request for access to it. |
| DP014/NOMandatory | Norway | Forskrift om arbeidsgivers innsyn i e-postkasse og annet elektronisk lagret materialeArbeids- og inkluderingsdepartementet · read 29 Aug 2026 | When an employer may look into a work mailbox or a worker’s personal areas on its equipment, that monitoring of internet use is outside what it may do at all, and that the regulation cannot be contracted around. | The worker’s personal areas on the undertaking’s network and equipment are reached on the same conditions as the mailbox, and so is what was deleted from them and survives on a backup. |
| Recommended | Austriawhere written | Österreichisches Informationssicherheitshandbuch 4.4.0Bundeskanzleramt und A-SIT · read 29 Aug 2026 | That logging is only effective as a security measure once someone independent reads it, that where nobody independent can, the administrators’ own activity is what stops being checkable, and that the evaluation goes before the data protection officer either way. | There is no right for a worker to use the employer’s resources privately. Minor private or half private use within ordinary human social behavior should nonetheless be allowed or ignored, and a total prohibition pronounced only in extreme cases. |
