TL;DR
Twenty-one indicative days on employee email metadata; the ban on asking about cancer treated more than ten years ago; the duty to keep the reasoning behind an AML report you decided NOT to file. Three register entries almost nobody writes.
One: email metadata, configured by your provider
The Italian DPA's guidance document of 6 June 2024 indicates twenty-one days as an orientative retention period for the metadata generated by email management software — sender, recipient, date, time, size. Not content: logs. It is the rule a controller most often breaches without knowing, because the breach is the default setting of the suite they bought: many keep logs for months or years, nobody chose that, and precisely for that reason nobody entered it in the register. Going beyond twenty-one days is not banned outright — the document is guidance, and documented technical needs can justify it — but Art. 4 of the Workers' Statute still applies where retention enables remote monitoring.
Two: the cancer right to be forgotten is not a retention period, it is a collection ban
Law 193 of 7 December 2023 prohibits asking about oncological conditions whose active treatment ended, without recurrence, more than ten years ago; five years if the illness arose before the age of twenty-one. It covers banking, financial and insurance contracts, adoption and public competitions. A questionnaire asking «have you ever had cancer» with no time limit is unlawful upstream, and no retention period makes it lawful. The ministerial decree of 22 March 2024 then identifies conditions for which the right matures earlier than ten years: applying the general period to all of them is still a breach, by default.
Three: the file of the report you did NOT send
Art. 35 of Legislative Decree 231/2007 requires suspicious transaction reports. What registers leave out is the other half: the analysis preceding the decision, and the reasoning for internal filing when no report goes out. That file holds a judgment on an identified person — a suspicion assessed and set aside — and it is more sensitive than the report itself, because it stays internal and is not covered by the confidentiality the law grants to a report that was sent. Who can open it, and for how long it stays, has to be written down.
- What they share: none of the three arises from a decision to collect data. The logs are already there, the questionnaire predates the statute, the file is the residue of a negative decision.
- What happens under review: these are real archives the register does not describe, and their absence is not a formal oversight — it means nobody set a period, and therefore nobody deletes.
- Where to start: ask your email provider how long it keeps logs, re-read your health questionnaires, open the drawer of filed AML assessments.
The common thread
A record of processing describes what an organisation decided to do. These three archives exist without anyone deciding on them: they were created by a default setting, an inherited form, a procedure that produces paper even when it ends in a no. That is where the register ages — not in the activities somebody designed.
All three are now in the Italian retention matrix, with the source cited and the verification status declared entry by entry.
Looking for a workspace for your DPO work?
DPO Workspace is built by a certified DPO. 30-day free trial.
Start free