Employee Data Protection
Personal data is essential in the workplace, from application documents to health information. However, how much control can an employer exercise without violating employees' privacy? Employee data protection regulates this sensitive area, ensuring that employees' personal information is processed within the legally defined framework of Section 26 et seq. BDSG. It balances legal requirements, technological developments, and employee trust.
What is employee data protection?
Employee data protection involves safeguarding personal employee data processed as part of the employment relationship. The goal is to protect employees' privacy and ensure their data is used only for legitimate purposes, such as payroll accounting or vacation entitlement administration. Employee data protection aims to meet the requirements of the GDPR and the special regulations in the BDSG while complying with various labor law regulations. Companies must create transparent guidelines and inform employees about the type and scope of data processing.
What are the advantages of efficiently implemented employee data protection?
Efficiently implemented employee data protection ensures compliance with the regulatory requirements of the GDPR and BDSG, while also strengthening trust and the bond between employer and employee. Transparency in data processing and adherence to data protection regulations minimize the risk of legal consequences, such as fines or lawsuits. Transparent employee data protection contributes to a positive corporate culture by demonstrating that the employer takes employees' rights seriously. Additionally, a clear data protection strategy ensures secure and efficient data processing, enhancing the company's long-term reputation.
Our services in the area of employee data protection
- Drafting works agreements and negotiating with works councils
We work with you to develop clear regulations that take into account data protection and the interests of your employees and negotiate these with your works council. - Creation of guidelines
Our experts craft guidelines that inform your employees and ensure compliance with data protection regulations. - Advice on the introduction of modern tools
Whether time recording systems or HR software - we ensure that your digital solutions can be used in compliance with data protection regulations. - Advice on the implementation of data protection impact assessments
In the HR sector, the question often arises whether a data protection impact assessment is necessary and how it should be carried out. We support you in determining this and implementing the assessment. - Training and awareness-raising
We train your managers and employees in securely handling personal data. - Legal support in the event of conflicts
In the event of disputes or audits by data protection authorities, we competently and efficiently represent your interests.
Contact person
FAQ: Employee Data Protection
Monitoring is permissible only to a limited extent and depends largely on whether private use of the business email account is permitted. If private use is permitted, the employer is subject to additional restrictions. In every case, access must have a legitimate purpose, be necessary and proportionate, and be made transparent to employees; where there is a works council, its co-determination rights must be observed. A clear policy on email use, communicated in advance, provides legal certainty for both sides.
Video surveillance in the workplace is permissible only under strict legal conditions. It requires a legitimate interest of the employer, that the surveillance be necessary to achieve that purpose and a balancing exercise in which the employees’ personality rights do not prevail. Legitimate interests may include, for example, protection against theft, the investigation of specific offences, the protection of employees or the security of particularly sensitive areas. Permanent, comprehensive or purely precautionary surveillance of employees is, by contrast, generally impermissible because it interferes significantly with their personality rights. Transparency is particularly important: employees must generally be informed that video surveillance is taking place, the purpose for which the recordings are made and how long the data will be stored. Covert surveillance is permissible only in narrowly defined exceptional cases, for example where there is a specific suspicion of a serious breach of duty or criminal offence by individual employees and less intrusive means of investigation are not available. If there is a works council in the company, it must be involved at an early stage. Under Section 87(1) no. 6 BetrVG (German Works Constitution Act), the introduction and use of video surveillance systems are subject to the works council’s mandatory co-determination because such systems are suitable for monitoring employees’ conduct or performance. The employer may therefore generally not introduce video surveillance unilaterally; if no agreement is reached, the conciliation committee decides. The specific framework conditions, such as the areas monitored, the storage period, access rights and deletion concepts, are often addressed in a works agreement. Co-determination by the works council does not replace the data protection requirements, but it makes a significant contribution to achieving an appropriate balance between the employer’s interests and the employees’ personality rights.
As a general rule, only data necessary for the decision on whether to establish the employment relationship may be processed, such as qualifications and professional background. Special categories of personal data, such as information on health or pregnancy, may generally not be requested. If an application is rejected, the application documents must be deleted after the applicable periods have expired, in particular after expiry of the period for asserting claims under the AGG (German General Equal Treatment Act), taking into account a reasonable period for any judicial assertion. If the applicant is hired, applicant data that remain necessary for the employment relationship may be transferred to the personnel file; the complete and blanket retention of all application documents is not readily compatible with the principle of data minimisation under Article 5(1)(c) GDPR and should therefore be justified and documented by reference to the purpose.
The retention period depends on the particular purpose: statutory retention periods of several years apply to documents relevant for wage tax and social security law, while other personal data must be deleted promptly if there is no continuing purpose. Blanket, undifferentiated retention ‘just in case’ is impermissible under data protection law. A deletion policy with clear periods for each category of data provides legal certainty.
Yes. Since such systems are suitable for monitoring and assessing the conduct or performance of applicants or employees, their introduction and use are regularly subject to the works council’s mandatory co-determination under Section 87(1) no. 6 BetrVG. Co-determination does not mean mere consent: the system may not be introduced without agreement with the works council, and if no agreement is reached, the conciliation committee decides. This applies in particular where the software also processes internal applications or talent pools. There are additional participation rights: under Section 90 BetrVG, the works council must be informed in good time about the planning of technical equipment and work processes and the measure must be discussed with it, at the planning stage. If selection criteria for recruitment or transfers are established, a right of co-determination in relation to selection guidelines under Section 95 BetrVG may arise. In addition, under Section 80(3) sentence 2 BetrVG, the engagement of an expert is considered necessary where the works council requires expert assistance to assess the use of Artificial Intelligence. From a data protection perspective, a works agreement may serve as a legal basis under Article 88 GDPR in conjunction with Section 26(4) BDSG, but it does not replace the substantive requirements of the GDPR. Under the AI Act, AI systems used for the selection or filtering of applications fall within the high-risk category under Annex III, because they may materially affect the career prospects, livelihoods and employee rights of the data subjects; the obligations for high-risk systems become applicable in stages, so the specific date of application must be determined in each case. In addition, as deployer, the employer has a duty to inform the employees concerned and their representatives about the use before the system is put into operation. The requirements under works constitution law and AI law must be examined in parallel before introduction.
