Alessandro AleddaInsider Threat and Risk

INTRA/MD/MD009Retention of web and network activity records

The retention of a record of the network resources a worker reached, and when.

Pillar
MD  |  Monitoring and detection
Sources cited
3
Added
30 AUGUST 2026
Updated
30 AUGUST 2026
ControlJurisdictionSourceWhat it establishesPrerequisite or recommendation
MD009/ITMandatoryItalyProvvedimento n. 243Garante per la protezione dei dati personali · read 11 Aug 2026Provvedimento n. 165, ITAS MutuaGarante per la protezione dei dati personali · read 16 Aug 2026That ninety days of metadata and browsing logs, kept without the procedural steps, draws a fine, the reasoning turning on the steps and not the purpose.Browsing logs are an instrument from which remote monitoring may follow, so retaining them engages the article 4 route as metadata does.
MD009/NOMandatoryNorwayForskrift om arbeidsgivers innsyn i e-postkasse og annet elektronisk lagret materialeArbeids- og inkluderingsdepartementet · read 29 Aug 2026When an employer may look into a work mailbox or a worker’s personal areas on its equipment, that monitoring of internet use is outside what it may do at all, and that the regulation cannot be contracted around.A record of what the worker reached may be kept where the purpose is administering the network or detecting and resolving a security breach in it, the regulation putting other purposes outside what the employer may do.