In some of the countries, not all of them (definitely not "for a long time"). But it is retained at the ISPs, with legally mandated security controls, except for government access. It would be better if they were not kept.
As far as I know, the only privacy of records the US law cares about is health care records, through the HIPAA act.
Comments
> lack of public comments about requiring ISPs to store all session information for a long time
Data retention is there since a long time in Europe...
In some of the countries, not all of them (definitely not "for a long time"). But it is retained at the ISPs, with legally mandated security controls, except for government access. It would be better if they were not kept.
As far as I know, the only privacy of records the US law cares about is health care records, through the HIPAA act.