Employees
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.Employee data protection and workplace privacy
Overview
14 sources · Jul 23, 2026Legal Framework
Employee data processing is governed primarily by Articles 5, 6, 9, 13–14, and 88 GDPR. Article 6(1)(b) covers processing necessary for employment contract performance; Article 6(1)(c) covers legal obligations (e.g., payroll tax compliance); Article 6(1)(f) covers legitimate employer interests such as workplace safety and fraud prevention. Article 9 restricts special category data (health, biometrics) unless an Article 9(2) exception applies — notably Article 9(2)(b) for employment obligations. Article 88 permits Member States to adopt specific employee monitoring rules. The fairness principle in Article 5(1)(a) requires employers to inform employees about data transfers to recipients, as confirmed in Bara. Transparency obligations under Articles 13–14 apply regardless of whether data is collected directly or indirectly from the employee.
Key Developments
The CJEU in Bara established that national law permitting data transfers cannot substitute for the employer's obligation to inform employees about recipients of their data under Articles 10–11 of Directive 95/46. The fairness principle requires active notification of transfers, not passive reliance on statutory authorization.
Dutch case law sets practical thresholds for employer investigations. In the Sif case, the court held that an employer conducting a saliva test on an employee was impermissible, even where the employee violated safety policy — the employer's legitimate interest in safety did not override data protection requirements for biometric testing. The court nonetheless upheld dismissal on the basis of a disturbed employment relationship (i-ground), separating the legality of data processing from the consequences of employee misconduct.
In the recherchebureau case, the court validated an employer's engagement of a private investigation agency where the company doctor had identified inconsistencies in reported limitations. The legitimate interest basis under Article 6(1)(f) was satisfied because the employer had concrete, reasonable suspicion rather than speculative monitoring. However, the RET case demonstrates limits: where an investigation report is central to dismissal proceedings, pseudonymization must be offered before disclosure, and blanket refusal of employee access is impermissible under Article 15.
Enforcement actions reinforce these thresholds. The Belgian DPA fined a technology company €177,000 for lacking a valid legal basis for employee data processing, and the Spanish DPA fined SIPHONE 2020 €4,000 for the same deficiency — confirming that employer convenience does not constitute a lawful basis.
Practical Guidance
- Map every processing activity to a specific Article 6 lawful basis before implementation. Reliance on consent is rarely valid in employment contexts due to the power imbalance; prioritize Article 6(1)(b), (c), or (f) with documented balancing tests for the latter.
- Notify employees of all data recipients, including internal departments and external investigators. Bara makes clear that statutory authorization for a transfer does not discharge the transparency obligation — employees must be actively informed.
- Before engaging private investigators or conducting testing (drug, saliva, biometric), document concrete, reasonable suspicion. The recherchebureau ruling shows that generalized suspicion is insufficient; the employer must articulate specific facts justifying the intrusion.
- Provide pseudonymized access to investigation reports when employees exercise Article 15 access rights. The RET decision prohibits blanket refusal where the report forms the evidentiary basis for dismissal.
- Ensure camera monitoring is proportionate and time-limited. Recent developments on permanent driver monitoring confirm that continuous surveillance without a specific, documented purpose violates Article 5(1)(c) and (e).