Skip to content
Topic Contested in court

Employees

LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.

Employee data protection and workplace privacy

383 linked items 10 Case Law43 Guidance275 Enforcement29 News26 Literature

Overview

14 sources · Jul 23, 2026

Legal Framework

Employee data processing is governed primarily by Articles 5, 6, 9, 13–14, and 88 GDPR. Article 6(1)(b) covers processing necessary for employment contract performance; Article 6(1)(c) covers legal obligations (e.g., payroll tax compliance); Article 6(1)(f) covers legitimate employer interests such as workplace safety and fraud prevention. Article 9 restricts special category data (health, biometrics) unless an Article 9(2) exception applies — notably Article 9(2)(b) for employment obligations. Article 88 permits Member States to adopt specific employee monitoring rules. The fairness principle in Article 5(1)(a) requires employers to inform employees about data transfers to recipients, as confirmed in Bara. Transparency obligations under Articles 13–14 apply regardless of whether data is collected directly or indirectly from the employee.

Key Developments

The CJEU in Bara established that national law permitting data transfers cannot substitute for the employer's obligation to inform employees about recipients of their data under Articles 10–11 of Directive 95/46. The fairness principle requires active notification of transfers, not passive reliance on statutory authorization.

Dutch case law sets practical thresholds for employer investigations. In the Sif case, the court held that an employer conducting a saliva test on an employee was impermissible, even where the employee violated safety policy — the employer's legitimate interest in safety did not override data protection requirements for biometric testing. The court nonetheless upheld dismissal on the basis of a disturbed employment relationship (i-ground), separating the legality of data processing from the consequences of employee misconduct.

In the recherchebureau case, the court validated an employer's engagement of a private investigation agency where the company doctor had identified inconsistencies in reported limitations. The legitimate interest basis under Article 6(1)(f) was satisfied because the employer had concrete, reasonable suspicion rather than speculative monitoring. However, the RET case demonstrates limits: where an investigation report is central to dismissal proceedings, pseudonymization must be offered before disclosure, and blanket refusal of employee access is impermissible under Article 15.

Enforcement actions reinforce these thresholds. The Belgian DPA fined a technology company €177,000 for lacking a valid legal basis for employee data processing, and the Spanish DPA fined SIPHONE 2020 €4,000 for the same deficiency — confirming that employer convenience does not constitute a lawful basis.

Practical Guidance

  • Map every processing activity to a specific Article 6 lawful basis before implementation. Reliance on consent is rarely valid in employment contexts due to the power imbalance; prioritize Article 6(1)(b), (c), or (f) with documented balancing tests for the latter.
  • Notify employees of all data recipients, including internal departments and external investigators. Bara makes clear that statutory authorization for a transfer does not discharge the transparency obligation — employees must be actively informed.
  • Before engaging private investigators or conducting testing (drug, saliva, biometric), document concrete, reasonable suspicion. The recherchebureau ruling shows that generalized suspicion is insufficient; the employer must articulate specific facts justifying the intrusion.
  • Provide pseudonymized access to investigation reports when employees exercise Article 15 access rights. The RET decision prohibits blanket refusal where the report forms the evidentiary basis for dismissal.
  • Ensure camera monitoring is proportionate and time-limited. Recent developments on permanent driver monitoring confirm that continuous surveillance without a specific, documented purpose violates Article 5(1)(c) and (e).
Everything on this topic ranked by relevance · links go to the exact provision / paragraph / section
V & EDPS V. EUROPEAN PARLAMENT, 5.7.2011 (“V v. European Parliament”) V. v. Parliament CJEU Case Law CJEU Jul 2011 employment law necessity for medical data transfer
why this is here
an obligation which arises from Articles 82 and 83 of the CEOS and which can be regarded as an ‘obligation in the field of employment law’ within the meaning of Article 10(2)(b)

The core issue is whether the transfer of medical data to check fitness for duty was necessary under employment law obligations, making it a leading case for employee data protection.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

C-465/00 Österreichischer Rundfunk and Others CJEU: Publishing employee names and salaries may interfere with private life (Rundfunk) Lawful basis for proceeding (Necessity requirement): The CJEU held that for an employer to publish the names and incomes of employees to a third party is an interference with the… Case Law CJEU May 2003 employee privacy vs public interest
why this is here
the seriousness of the interference with the right of the persons concerned to respect for their private life

The document involves employee data and workplace privacy, specifically salary disclosure and its impact on employees' private life and employment prospects.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

ICO Publishes Draft Employee Monitoring Guidance for Consultation > On October 14, 2022, the Federal Trade Commission announced it is extending the deadline by one month to submit comments on its Advanced Notice of Proposed Rulemaking on… News Hunton Andrews Kurth Oct 2022 Employee data protection
why this is here
The Draft Guidance is primarily targeted at employers, and aims to help employers comply with the UK General Data Protection Regulation

The document is directly about employee monitoring and workplace privacy, making it a primary source for employee data protection.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

CJEU: National employee protection schemes must comply with Article 88 AVG ECJ EU March 30, 2023, IT 4246; ECLI:EU:C:2023:270 (Hauptpersonalrat der Lehrerinnen und Lehrer beim Hessischen Kultusministerium v. Minister des Hessischen Kultusministeriums)… News IT en Recht Apr 2023 Employee privacy and workplace data
why this is here
safeguard employees' rights with respect to the processing of personal data

The document directly addresses employee data protection and workplace privacy, specifically the conditions for processing teachers' data without consent.

assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026

HAN fined 175,000 euros for insufficient security of personal data ⇄ De Autoriteit Persoonsgegevens (AP) legt HAN University of Applied Sciences (HAN) een boete op van 175.000 euro voor het overtreden van de Algemene verordening gegevensbescherming… News Autoriteit Persoonsgegevens Dec 2025 Employees as data subjects affected
why this is here
persoonsgegevens van onder meer studenten en werknemers

Employees are mentioned as one group of data subjects, but the document does not address employee-specific data protection or workplace privacy issues.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

This is the top of each pile — all 43 Guidance · all 275 Enforcement · all 26 Literature · all 29 News