Good morning,
I need information about gmail's metadata. Does Google save mail's metadata?If yes, Can I delete the metadata every week? Is there a procedure?
Thanks in advance
Solved! Go to Solution.
Yes, Google Workspace Admins have access to gmail message metadata for a period of 6 months.
No, for security and threat assessment reasons, this data cannot be purged at will.
What is the business problem you are trying to solve ?
Yes, Google Workspace Admins have access to gmail message metadata for a period of 6 months.
No, for security and threat assessment reasons, this data cannot be purged at will.
What is the business problem you are trying to solve ?
This is not a business problem, it's a legal problem. The Italian Privacy Autority set the data retention limit for mail metadata to 7 days. Our municipality could pay a very huge santion if we not obey. The other only solution will be move to another mail provider.
So the solution can't be acceptable!
Can you please reopen this topic? We all are having this urgent issue in Italy
Hello Kevin.
We have this urgen issue in Italy, we cannot retain gmail metadata for more than 7 days.
Hello, thank you for your quick reply.
I'have asked this question because the Italian data protection Authority asked all the companies to delete all the gmail's metadata older than one week if it's possible.
If it's not possible we have to create a document that explains this and we will solve the problem.
Bye!
Hello, this is a big issue for Italian customers. Italian Data Protection Authority ("Garante della Privacy") requested that all companies workers email metadata retention will be limited to 7 days for privacy concerns (+2 days under certain circumstances).
This is the document: https://www.garanteprivacy.it/web/guest/home/docweb/-/docweb-display/docweb/9978728
Are you working on it? Otherwise, it will be very hard to manage (companies will need to obtain specific trade union approvals...)
Hello,
Same problem here. I am italian as well as the OP.
Hoping for a change in the law enforcement, we might have serious problems for the future ๐
Hello, I'm italian customer and we have the same problem.
This is the document where the italian "Garante della Privacy" asks companies to remove email metadata within 7 days:
(Site Link Removed by Staff)
+1
Hello @KevinApodaca please check the replies above, in order to help us and in general italian customers (this kind of request will surely grow) to solve this issue asap
Hallo, we are an italian municipality, we need to remove email metadata in 7/9 days too.
Hello, we are an italian Agency for Environmental Protection, we need to remove email metadata in 7 days too.
its a very urgent problem: in the meantime, some of our customers have arranged syndicates agreements to correct this specific issue, but for the majority of customers this is not applicable.
It's important to have metadata control on email logs to avoid legal and penal consequences.
All italian Customers are affected. Please consider this issue.
+1
we have the same here
any news on this topic?
Google appreciates the Garante's incorporation of observations and suggestions received during the public consultation into its guidelines adopted on 6 June 2024. We welcome the fact that the Garante has recognised the vital importance of the security of the IT environment and the need to mitigate security incidents as reasons justifying the retention of email metadata.
This means that the Garante has moved away from its proposed fixed 7-day retention period (in its original guidelines) towards a more balanced approach. Indeed, whilst the Garante suggests a 21-day retention period as a โguidelineโ, it nonetheless permits employers to retain email metadata for longer periods - without an express limit - in the interests of security, provided this longer period is proportionate. For instance, it states that โpurposes related to IT security and the protection of IT assets justify the conservation of metadata for a period of time appropriate to the objective of detecting and mitigating any security incidentsโ.
The Garante further clarifies that โno new obligations or responsibilitiesโ arise from its current guidelines, meaning that employers and their service providers can remain fully focused on compliance with their existing obligations under GDPR (whilst taking the guidelines into account).
Major cybersecurity incidents experienced by another email and collaboration provider have reinforced that email logs are indispensable in reconstructing the sequence of events during those kinds of incidents. Indeed, in its assessment of these incidents, the U.S. Cyber Safety Review Board specifically recommends that cloud providers should retain logs for at least six months to ensure this reconstruction is possible. We believe this kind of retention period is fully aligned with the security-related objectives outlined by the Garante: reducing the retention period to a matter of days would be very likely to significantly impair an organisationโs ability to conduct thorough forensic investigations, identify the root cause of incidents, and implement effective remediation measures. Administrators often do not become aware of incidents occurring within their own organisation until well after many days from the incident date and, therefore, access to historical email metadata can be pivotal in minimizing the impact of security breaches and safeguarding sensitive information. For that reason, we believe it is crucial for customers - at their choice - to be able to access Gmail log events extending back 6 months.
I log oggetto del provvedimento del Garante Privacy Italiano sono i log dei Mail User Agent e dei Mail Transfer Agent, che non sono utili per le analisi post incidente, nessuno dei principali fornitori di soluzioni di cyber security li ritiene rilevanti e normalmente non sono oggetto di analisi nei SIEM.
La loro conservazione รจ inutile. In ogni caso, la cosa importante รจ sapere se Google ufficialmente si sta attivando per riscontrare alle prescrizioni del Garante. Qual รจ la posizione ufficiale dell'azienda?
Sempre ai fini del rispetto da parte delle imprese italiane del provvedimento del Garante citato, e alla luce della posizione da Voi espressa in merito allโimpossibilitร di personalizzare le tempistiche di conservazione dei metadati acquisiti, chiediamo se sia invece possibile, pur mantenendo il periodo di conservazione da Voi impostato, renderli accessibili alle imprese solo ed esclusivamente per un periodo molto limitato, che non superi i 21 giorni indicati dal Garante. Allo stato, ci risulta invece che tali dati siano consultabili dalle imprese fino a 30 giorni dalla rilevazione.
Buongiorno a tutti,
ci sono delle novitร in merito a questo problema?
Grazie
This topic should be re-opened.
Do we have any news?
Hey there, the previous response is still accurate and the stance has not changed as far as I'm aware.