Alessandro Del Ninno
Conferences
Secure Password Storage and E-mail Metadata Management: Data Protection Authority Decisions and Their Operational Implementation in Corporate IT Systems.
Workshop Finlombarda S.p.A. - 27 February 2026.
27/02/2026
Secure Password Storage and E-mail Metadata Management: Data Protection Authority Decisions and Their Operational Implementation in Corporate IT Systems.

Alessandro Del Ninno delivered a practical lecture to the IT Department of Finlombarda S.p.A., focusing on the operational implementation of two significant decisions adopted by the Italian Data Protection Authority that have a direct impact on the management of corporate information systems.

During the session, Attorney Del Ninno examined in particular the practical implementation of the requirements set out in the joint decision issued in December 2023 by the Italian Data Protection Authority and the National Cybersecurity Agency (ACN) concerning the secure storage of passwords, illustrating the technical and organisational measures that organisations are expected to adopt in order to ensure adequate protection of authentication credentials.

The presentation analysed the technical and legal implications of managing access credentials, with particular reference to the storage of passwords within information systems, the adoption of hashing and cryptographic protection techniques, the secure management of authentication processes, and the security risks arising from inadequate credential storage practices.

A second part of the lecture was devoted to the analysis of the Data Protection Authority’s decision of 6 June 2024 concerning the retention of metadata relating to employees’ e-mail communications, which introduced important clarifications regarding the limits on the retention of such information and its legal classification under data protection law and the rules governing employee monitoring.

In this context, the presentation addressed the practical implications for corporate IT infrastructures, with particular focus on the management of corporate e-mail systems, metadata retention policies, and the need to align such practices with the safeguards established by labour law and data protection regulations.

The session also provided an opportunity to examine the main operational challenges that organisations may encounter when adapting their information systems to these regulatory requirements, identifying possible technical and organisational solutions capable of ensuring an appropriate balance between cybersecurity needs, personal data protection, and the protection of employees’ rights.

Through a strongly practice-oriented approach, Attorney Del Ninno’s lecture provided participants with operational guidance on translating the requirements imposed by supervisory authorities into concrete technical measures and internal procedures, highlighting the strategic importance of cooperation between legal, privacy and IT functions in the management of technology-related compliance.