INTRA/PS/PS008Leaver process
What happens when employment ends: access withdrawn, assets recovered, continuing obligations restated, and the accounts themselves closed within a period the organization has stated in advance.
| Control | Jurisdiction | Source | What it establishes | Prerequisite or recommendation |
|---|---|---|---|---|
| PS008/EUMandatory | European Union | Commission Implementing Regulation (EU) 2024/2690European Commission · read 29 Aug 2026 | What the directive’s categories hold, in an annex setting out asset classification, the inventory, access control, privileged accounts, and removable media as requirements rather than as headings. | For the digital infrastructure and service providers it reaches, access rights are modified on termination, and the register of what was granted is what the withdrawal is checked against. |
| PS008/ITMandatory | Italy | Provvedimento del 17 aprile 2026, Framos ItaliaGarante per la protezione dei dati personali · read 29 Aug 2026Determinazione ACN n. 379907 del 18 dicembre 2025Agenzia per la cybersicurezza nazionale · read 29 Aug 2026 | That a company mailbox left running after the employment ends is a processing needing a ground of its own, and that a smooth handover and the chance of wanting something later are not one. | Leaving the account running after the employment ends is itself a processing and needs a ground of its own. Telling correspondents the person has gone, and keeping what may be wanted later, are not grounds, and running past the period the employer itself declared counts against it. Separately, obligations in the field of information security that stay valid after the employment ends, or changes, are fixed at the contractual level, confidentiality clauses among the examples given, on essential subjects. |
| PS008/NOMandatory | Norway | Forskrift om arbeidsgivers innsyn i e-postkasse og annet elektronisk lagret materialeArbeids- og inkluderingsdepartementet · read 29 Aug 2026 | When an employer may look into a work mailbox or a worker’s personal areas on its equipment, that monitoring of internet use is outside what it may do at all, and that the regulation cannot be contracted around. | The mailbox is closed when the employment ends, and stays open only where there is a particular need and only for a short period. |
| Recommended | Finlandwhere written | Katakri 2020Kansallinen turvallisuusviranomainen · read 29 Aug 2026 | The criteria an authority audits against, among them the requirement to recognize which functions call for special trustworthiness, a clearance graded on three scales, and log retention set by the limitation periods of the criminal law. | On the termination of the employment the keys, the badges, and the classified material are collected in, the access, handling, and use rights are deleted, and the person is reminded of the responsibilities of non-disclosure that remain. |
| Recommended | Francewhere written | Guide d'hygiène informatiqueAgence nationale de la sécurité des systèmes d'information · read 29 Aug 2026 | Forty two measures at a standard and a reinforced level, among them the joining, leaving, and function change procedures written with the human resources function, and a minimum retention of one year for security critical events. | The rights assigned to a person are revoked on their departure, and the procedure covers the accounts and mailboxes, the badges and keys, the mobile equipment issued, and the passwords and codes on existing systems, which are transferred or changed. |
| Recommended | Germanywhere written | IT-Grundschutz-Kompendium, Edition 2023Bundesamt für Sicherheit in der Informationstechnik · read 29 Aug 2026 | What the German federal authority holds to be the state of the art, in numbered requirements, among them the checking of a candidate’s own account of themselves, a logging infrastructure the administrators who run it cannot alter, a regular audit of the detection systems against the state they are supposed to be in, and how evidence is secured. | The successor is briefed in time, by the person leaving where that can be done, and where it cannot the person leaving writes the documentation instead. Every document, key, device, badge, and access right received in the course of the work is collected back. The obligations of confidentiality are put to the person once more before they go, and to keep conflicts of interest from arising a non-competition clause and a waiting period should be agreed. Contingency and other plans are updated, and every part of the organization affected is told, the security staff and the IT function among them. |
| Recommended | United Kingdomwhere written | Ongoing Personnel Security: A Good Practice GuideNPSA · read 11 Aug 2026 | Good practice for personnel security through employment rather than at the door, holding that protective monitoring should be proportionate. | Exit is covered as a stage of personnel security, with what is withdrawn and what is restated set out together. |
