INTRA/MD/MD009Retention of web and network activity records
The retention of a record of the network resources a worker reached, and when.
| Control | Jurisdiction | Source | What it establishes | Prerequisite or recommendation |
|---|---|---|---|---|
| MD009/ITMandatory | Italy | Provvedimento n. 243Garante per la protezione dei dati personali · read 11 Aug 2026Provvedimento n. 165, ITAS MutuaGarante per la protezione dei dati personali · read 16 Aug 2026 | That ninety days of metadata and browsing logs, kept without the procedural steps, draws a fine, the reasoning turning on the steps and not the purpose. | Browsing logs are an instrument from which remote monitoring may follow, so retaining them engages the article 4 route as metadata does. |
| MD009/NOMandatory | Norway | Forskrift om arbeidsgivers innsyn i e-postkasse og annet elektronisk lagret materialeArbeids- og inkluderingsdepartementet · read 29 Aug 2026 | When an employer may look into a work mailbox or a worker’s personal areas on its equipment, that monitoring of internet use is outside what it may do at all, and that the regulation cannot be contracted around. | A record of what the worker reached may be kept where the purpose is administering the network or detecting and resolving a security breach in it, the regulation putting other purposes outside what the employer may do. |
