# Employees — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/werknemers
> Sources are cited per item. Verify against the official texts before relying on them.

Employee data protection and workplace privacy

## Overview

## Legal Framework

Employee data processing is governed primarily by Articles 5, 6, 9, 13–14, and 88 GDPR. Article 6(1)(b) covers processing necessary for employment contract performance; Article 6(1)(c) covers legal obligations (e.g., payroll tax compliance); Article 6(1)(f) covers legitimate employer interests such as workplace safety and fraud prevention. Article 9 restricts special category data (health, biometrics) unless an Article 9(2) exception applies — notably Article 9(2)(b) for employment obligations. Article 88 permits Member States to adopt specific employee monitoring rules. The fairness principle in Article 5(1)(a) requires employers to inform employees about data transfers to recipients, as confirmed in *Bara*. Transparency obligations under Articles 13–14 apply regardless of whether data is collected directly or indirectly from the employee.

## Key Developments

The CJEU in *Bara* established that national law permitting data transfers cannot substitute for the employer's obligation to inform employees about recipients of their data under Articles 10–11 of Directive 95/46. The fairness principle requires active notification of transfers, not passive reliance on statutory authorization.

Dutch case law sets practical thresholds for employer investigations. In the *Sif* case, the court held that an employer conducting a saliva test on an employee was impermissible, even where the employee violated safety policy — the employer's legitimate interest in safety did not override data protection requirements for biometric testing. The court nonetheless upheld dismissal on the basis of a disturbed employment relationship (i-ground), separating the legality of data processing from the consequences of employee misconduct.

In the *recherchebureau* case, the court validated an employer's engagement of a private investigation agency where the company doctor had identified inconsistencies in reported limitations. The legitimate interest basis under Article 6(1)(f) was satisfied because the employer had concrete, reasonable suspicion rather than speculative monitoring. However, the *RET* case demonstrates limits: where an investigation report is central to dismissal proceedings, pseudonymization must be offered before disclosure, and blanket refusal of employee access is impermissible under Article 15.

Enforcement actions reinforce these thresholds. The Belgian DPA fined a technology company €177,000 for lacking a valid legal basis for employee data processing, and the Spanish DPA fined SIPHONE 2020 €4,000 for the same deficiency — confirming that employer convenience does not constitute a lawful basis.

## Practical Guidance

- **Map every processing activity to a specific Article 6 lawful basis before implementation.** Reliance on consent is rarely valid in employment contexts due to the power imbalance; prioritize Article 6(1)(b), (c), or (f) with documented balancing tests for the latter.
- **Notify employees of all data recipients, including internal departments and external investigators.** *Bara* makes clear that statutory authorization for a transfer does not discharge the transparency obligation — employees must be actively informed.
- **Before engaging private investigators or conducting testing (drug, saliva, biometric), document concrete, reasonable suspicion.** The *recherchebureau* ruling shows that generalized suspicion is insufficient; the employer must articulate specific facts justifying the intrusion.
- **Provide pseudonymized access to investigation reports when employees exercise Article 15 access rights.** The *RET* decision prohibits blanket refusal where the report forms the evidentiary basis for dismissal.
- **Ensure camera monitoring is proportionate and time-limited.** Recent developments on permanent driver monitoring confirm that continuous surveillance without a specific, documented purpose violates Article 5(1)(c) and (e).

## Case law

### Judgment of the Court (Eighth Chamber) of 19 December 2024.#MK v K GmbH.#Request for a preliminary ruling from the Bundesarbeitsgericht.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 88(1) and (2) – Processing in the context of employment – Employees’ personal data – More specific rules provided for by a Member State pursuant to that Article 88 – Obligation to comply with Article 5, Article 6

*Source: Court of Justice of the European Union, C-65/23, 2024-12-19 — https://overview.legal/posts/132156 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62023CJ0065*

In a preliminary ruling requested by the German Federal Labour Court (Bundesarbeitsgericht), the Court of Justice of the European Union interpreted Article 88 of the GDPR regarding Member States' ability to adopt more specific rules for processing employee data in the employment context. The case arose from a dispute between an employee (MK) and his employer (K GmbH) over compensation for non-material damage allegedly caused by the processing of personal data based on a works agreement. The Court held that Article 88 does not grant Member States or social partners a margin of discretion to deviate from the core GDPR requirements of Article 5, Article 6(1), and Article 9, meaning national courts must conduct full judicial review of whether such data processing complies with these fundamental GDPR provisions.

### Judgment of the Court (First Chamber) of 30 March 2023.#Hauptpersonalrat der Lehrerinnen und Lehrer beim Hessischen Kultusministerium v Minister des Hessischen Kultusministeriums.#Request for a preliminary ruling from the Verwaltungsgericht Wiesbaden.#Reference for a preliminary ruling – Protection of personal data – Regulation (EU) 2016/679 – Article 88(1) and (2) – Processing of data in the employment context – Regional school system – Teaching by videoconference due to the COVID-19 pandemic –

*Source: Court of Justice of the European Union, C-34/21, 2023-03-30 — https://overview.legal/posts/132292 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0034*

In Case C-34/21, the Hauptpersonalrat der Lehrerinnen und Lehrer beim Hessischen Kultusministerium challenged the Hessian Ministry of Education's introduction of mandatory videoconference teaching during the COVID-19 pandemic without the express consent of the teachers concerned. The Verwaltungsgericht Wiesbaden referred the matter to the Court of Justice for a preliminary ruling on the interpretation of Article 88(1) and (2) GDPR regarding the processing of employee data in the employment context. The Court held that Member States may authorize employers, including public authorities, to implement such processing under national law providing for suitable safeguards, without requiring the employees' express consent, provided the processing relies on a legal basis other than Article 6(1)(a) GDPR; no fine was imposed.

### Maximillian Schrems v Data Protection Commissioner

*Source: CJEU, C-362/14, 2015-10-06 — https://overview.legal/posts/51471 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62014CJ0362&ref=51471*

Invalidated Safe Harbor adequacy decision. National supervisory authorities can examine adequacy decisions.

### OVG Saarlouis - 2 A 165/24

*Source: Superior Administrative Court Saarlouis, 2025-05-13 — https://overview.legal/posts/125590 — original: https://gdprhub.eu/index.php?title=OVG_Saarlouis_-_2_A_165/24*

Facts — The data subject was an employee, the controller was the employer. On 14 January 2022, the data subject requested access to personal data from the controller under Article 15 GDPR. They did not respond. On 28 January 2022, the controller terminated the employment. On 17 February 2022, the data subject lodged a complaint with the Data Protection Authority (DPA) under Article 77 GDPR. The data subject alleged that the controller had failed to answer the access request, had taken unauthorised photographs, and had a copy of their vaccination certificate. On 24 February 2022, the employment relationship ended by a court settlement before the Labour Court. The settlement stated that all claims arising from the employment relationship and its termination, whether known or unknown and regardless of their legal basis, were settled, except for employment documents. By entering the settlement, the data subject agreed to not pursue further claims. After the settlement, the controller informed the DPA that it had not received an access request from the data subject, had not taken photographs, and had destroyed the vaccination certificate after the employee left. The data subject continued to raise issues with the DPA, including access to time-tracking data and alleged inaccuracies in the controller’s provided documents. The controller later provided partially redacted time-tracking data. On 26 July 2022, the DPA closed the administrative procedure, as it considered that the data subject no longer had a right of access under Article 15 GDPR because the settlement didn't allow for this claim. The data subject challenged the DPA’s decision before the Administrative Court. On 10 July 2024, the court dismissed the action. The data subject appealed. Holding — First, the court held that the right of access under Article 15 GDPR was, in principle, waivable. Although Article 8(2) CFR protects the right of access, the court noted that data protection law is based on self-determination, including the possibility to consent to processing under Article 7 GDPR. From this, the court inferred that a data subject could also waive the exercise of the right of access. Second, the court clarified that a waiver could not generally cover unknown future data processing. However, a waiver relating to past processing was permissible, especially after the end of an employment relationship, where the imbalance between employee and employer no longer existed. Third, the court held that the specific settlement covered the right of access under Article 15 GDPR. The clause settling all claims arising from the employment relationship and its termination, whether known or unknown and regardless of their legal basis, also included secondary claims linked to the employment relationship, such as access rights concerning employee data. The court considered the wording sufficiently clear and found no requirement to explicitly mention data protection rights. Fourth, the court noted that the data subject already knew about the access request and had raised it before concluding the settlement. Any internal intention not to waive data protection rights was legally irrelevant. Finally, the court upheld the DPA’s decision to close the procedure. Since the data subject had waived the right of access under Article 15 GDPR for past processing through the settlement, the DPA had no obligation to continue enforcement action against the employer.

### V & EDPS V. EUROPEAN PARLAMENT, 5.7.2011 (“V v. European Parliament”)

*Source: CJEU, 2011-07-05 — https://overview.legal/posts/6179 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62009CJ0092&ref=6179*

Lawful Basis: The applicant did not consent to the transfer of her medical file by the Commission to the European Parliament. The transfer was not “necessary for the purposes of complying with the specific rights and obligations of the controller in the field of employment law,” in accordance with Article 10(2)(b). The Parliament’s obligation to control fitness for duty could have been achieved by less intrusive means. Nor does Article 10(3) justify the transfer. (¶¶ 137–139)

### SMARANDA BARA ET AL. V. PRESEDINTELE CASEI NATIONALE DE ASIGURARI DE SANATATE (CNAS) ET AL., 1.10.2015 (“BARA”)

*Source: CJEU, 2015-10-01 — https://overview.legal/posts/6149 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62014CJ0201&ref=6149*

Principle of fairness and lawfulness: The requirement of fair processing laid down in Article 6 of Directive 95/46 requires a public administrative body to inform the data subjects of the transfer of their data to another public administrative body for the purpose of their processing by the latter in its capacity as recipient of those data. (¶¶ 34–38)

### SMARANDA BARA ET AL. V. PRESEDINTELE CASEI NATIONALE DE ASIGURARI DE SANATATE (CNAS) ET AL., 1.10.2015 (“BARA”)

*Source: CJEU, 2015-10-01 — https://overview.legal/posts/5957 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62014CJ0201*

Right to be informed: National law that does not require the specific transfer involved in the case cannot constitute “prior information” under Article 10 of Directive 95/46 (information requirement where data is collected from the data subject), enabling the controller to dispense with his obligation to inform the data subject of the recipients of the data. (¶¶ 34–38). Article 11 (information requirement where data is not collected from data subject) requires that specified information be provi

### ESCH-LEONHARDT AND OTHERS V EUROPEAN CENTRAL BANK

*Source: CJEU, 2004-02-18 — https://overview.legal/posts/6190 — original: http://curia.europa.eu/juris/document/document.jsf?text=&docid=48924&pageIndex=0&doclang=DE&mode=lst&dir=&occ=first&part=1&cid=16520847#excerpt-117*

Necessity/proportionality: An employer may consider whether the use of internal email by staff (i) was necessary for the performance of their contract of employment; (ii) whether the content may become relevant for a report on their conduct in the service; (iii) whether a shortened version would suffice for proper management of personal files; and (iv) the fact that the staff in question contravened rules on the use of the internal email system by using it, as members of a trade union, for purpo

### RECHNUNGSHOF V. OSTER REICHISCHER RUNDFUNK, 20.5.2003 (“RUNDFUNK”)

*Source: CJEU, ECLI:EU:C:2003:294-118, 2003-05-20 — https://overview.legal/posts/6199 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62001CJ0101&ref=6199*

Lawful basis for proceeding (Necessity requirement): The CJEU held that for an employer to publish the names and incomes of employees to a third party is an interference with the right to respect for private life, protected by article 8 of the European Convention on Human Rights (para 74), but it might be justified if it was both necessary for and appropriate to the aim of keeping salaries within reasonable limits, (that being for the national courts to determine)

## Guidance

### Opinion 22/2023 on the draft decision of the Belgian Supervisory Authority regarding the Controller Binding Corporate Rules for employee data of the UPS Group

*Source: EDPB, opinion-222023-on-the-draft-decision-of-the-belgian-en, 2023-11-16 — https://overview.legal/posts/125817 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-222023-on-the-draft-decision-of-the-belgian_en*

Adopted Opinion 22/2023 on the draft decision of the Belgian Supervisory Authority regarding the Controller Binding Corporate Rules for employee data of the UPS Group Adopted on 16 November 2023 2 Adopted 3 Adopted The European Data Protection Board Having regard to Article 63, Article 64(1)(f) and Article 47 of the Regulation 2016/679/EU of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the…

### Opinion 01/2019 on the draft list of the competent supervisory authority of the Principality of Liechtenstein regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR)

*Source: EDPB, opinion-012019-on-the-draft-list-of-the-competent-supervisory-en, 2019-01-23 — https://overview.legal/posts/126254 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-012019-on-the-draft-list-of-the-competent-supervisory_en*

Adopted 1 EDPB Plenary Meeting, 22 - 23 January 2019 Opinion 01 /201 9 on the draft list of the competent supervisory authority of the Principality of Liechtenstein regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR) Adopted on 23 January 201 9 Adopted 2 Table of c ontents 1 Summary of the Facts ................................ ................................ ................................ ..................... 4 2…

### Opinion 22/2018 on the draft list of the competent supervisory authority of the United Kingdom regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR)

*Source: EDPB, opinion-222018-on-the-draft-list-of-the-competent-supervisory-en, 2018-10-03 — https://overview.legal/posts/126295 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-222018-on-the-draft-list-of-the-competent-supervisory_en*

Opinion 22 /2018 on the draft list of the competent supervisory authority of the United Kingdom regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR) Adopted on 25th September 2018 2 Contents 1. Summary of the Facts ................................ ................................ ................................ ........ 4 2. Assessment ................................ ................................…

### Opinion 18/2018 on the draft list of the competent supervisory authority of Portugal regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR)

*Source: EDPB, opinion-182018-on-the-draft-list-of-the-competent-supervisory-en, 2018-10-03 — https://overview.legal/posts/126297 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-182018-on-the-draft-list-of-the-competent-supervisory_en*

Opinion 18 /2018 on the draft list of the competent supervisory authority of Portugal regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR) Adopted on 25th September 2018 2 Contents 1. Summary of the Facts ................................ ................................ ................................ ........ 4 2. Assessment ................................ ................................ ................................…

### Opinion 17/2018 on the draft list of the competent supervisory authority of Poland regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR)

*Source: EDPB, opinion-172018-on-the-draft-list-of-the-competent-supervisory-en, 2018-10-03 — https://overview.legal/posts/126299 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-172018-on-the-draft-list-of-the-competent-supervisory_en*

Opinion 17 /2018 on the draft list of the competent supervisory authority of Poland regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR) Adopted on 25th September 2018 2 Contents 1. Summary of the Facts ................................ ................................ ................................ ........ 4 2. Assessment ................................ ................................ ................................…

### Opinion 11/2018 on the draft list of the competent supervisory authority of Ireland regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR)

*Source: EDPB, opinion-112018-on-the-draft-list-of-the-competent-supervisory-en, 2018-10-03 — https://overview.legal/posts/126301 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-112018-on-the-draft-list-of-the-competent-supervisory_en*

Opinion 11 /2018 on the draft list of the competent supervisory authority of Ireland regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR) Adopted on 25th September 2018 2 Contents 1. Summary of the Facts ................................ ................................ ................................ ........ 4 2. Assessment ................................ ................................ ................................…

### Opinion 16/2018 on the draft list of the competent supervisory authority of the Netherlands regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR)

*Source: EDPB, opinion-162018-on-the-draft-list-of-the-competent-supervisory-en, 2018-10-03 — https://overview.legal/posts/126303 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-162018-on-the-draft-list-of-the-competent-supervisory_en*

Opinion 16 /2018 on the draft list of the competent supervisory authority of the Netherlands regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR) Adopted on 25th September 2018 2 Contents 1. Summary of the Facts ................................ ................................ ................................ ........ 4 2. Assessment ................................ ................................…

### Opinion 20/2018 on the draft list of the competent supervisory authority of Sweden regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR)

*Source: EDPB, opinion-202018-on-the-draft-list-of-the-competent-supervisory-en, 2018-10-03 — https://overview.legal/posts/126286 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-202018-on-the-draft-list-of-the-competent-supervisory_en*

Opinion 20 /2018 on the draft list of the competent supervisory authority of Sweden regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR) Adopted on 25th September 2018 2 Contents 1. Summary of the Facts ................................ ................................ ................................ ........ 4 2. Assessment ................................ ................................ ................................…

## Enforcement decisions

### Austrian DSB rules 360-degree feedback unlawful without specific works agreement

*Source: DSB (Austria), 2026-03-20 — https://overview.legal/posts/187479 — original: https://gdprhub.eu/index.php?title=DSB_(Austria)_-_2025-0.960.016*

Facts — The data subject was employed by an Austrian stock corporation (the controller) from August 2018 to June 2025. They worked as a manager in the controller’s finance department, with technical and disciplinary responsibility for up to five employees. The controller operated a 360-degree feedback process under which the data subject completed a self-assessment and 17 other individuals, including their supervisor, three subordinates and other employees, evaluated their leadership behaviour across 27 categories. Both the data subject and their supervisor had access to the results. The process was also used for other managers within the company. On 1 August 2025, the data subject lodged a complaint with the Austrian DPA, alleging a violation of their right to confidentiality. They argued that the processing carried out as part of the 360-degree feedback process required a specific works agreement and was therefore unlawful in the absence of one. The controller had concluded a framework works agreement with the central works council on the processing of employee data, as well as a supplementary agreement concerning its HR system. However, there was no specific works agreement covering the 360-degree feedback process. The controller alleged that it relied on its legitimate interests under Article 6(1)(f) GDPR and on the performance of the employment contract under Article 6(1)(b) GDPR. It argued that a works agreement would merely specify its legitimate interests and that the absence of such an agreement did not render the processing unlawful. It further maintained that whether a works agreement was required was a labour-law issue that could not be determined in the proceedings before the DPA The data subject responded that the processing of personal data in a 360-degree feedback process served to evaluate employees and therefore constituted a measure within the meaning of § 96 of the Austrian Labour Constitution Act (ArbVG). Section 96 ArbVG lists certain workplace measures that can be introduced only with the works council’s consent through a works agreement. Holding — The DPA first found that the data subject was an employee covered by the Austrian Labour Constitution Act, rather than a senior executive excluded from its scope. It further held that the assessments of the data subject’s leadership behaviour constituted personal data. The DPA explained that Article 88 GDPR enables Member States to adopt, through legislation or collective agreements, more specific rules protecting the rights and freedoms of individuals in the context of employment-related processing. Such rules must include appropriate safeguards for, among other things, human dignity, legitimate interests and the fundamental rights of data subjects. Recital 155 GDPR expressly refers to works agreements as a possible instrument for implementing such rules. It further stated that Austria had made use of the opening clause in Article 88 GDPR and that § 96 ArbVG constituted one of the more specific national rules protecting employees in the context of personal data processing. It determined that the 360-degree feedback process constituted a systematic and standardised assessment of employees falling under both § 96(1)(2) ArbVG, concerning personnel questionnaires, and § 96(1)(3) ArbVG, concerning monitoring measures affecting human dignity. It held that under § 96 ArbVG, the processing therefore required the works council’s consent through a valid works agreement. It pointed out that the controller’s existing works agreements did not cover the 360-degree feedback process or the categories of personal data collected through it. It therefore held that the processing could not be based on a works agreement under Article 88(1) GDPR in conjunction with § 96 ArbVG. The DPA held that the controller could not rely on Article 6(1)(f) GDPR. It stated that although personnel management and improving employee performance might generally constitute legitimate interests, an interest pursued through processing contrary to national law could not be regarded as lawful. It concluded that since the mandatory works council consent had not been obtained, the interest could not be regarded as legitimate under Article 6(1)(f) GDPR. Moreover, it pointed out that Article 6(1)(b) GDPR was also inapplicable because the feedback process was not necessary for the performance of the employment contract. It reasoned that the employment relationship could be performed without it, and the process was not applied to all employees. The DPA therefore found that the processing was unlawful and violated the data subject’s right to confidentiality. It prohibited the controller from continuing the 360-degree feedback process for employees covered by the ArbVG until a valid works agreement was concluded.

### AEPD fines Alkora, S.A. for ransomware breach exposing 40,000 individuals' data

*Source: AEPD (Spain), 2026-07-16 — https://overview.legal/posts/53655 — original: https://gdprhub.eu/index.php?title=AEPD_(Spain)_-_PS-00020-2025*

Facts — Alkora, S.A., the controller, is an insurance broker that was victim of a ransomware attack. The controller notified the DPA of a personal data breach after a ransomware attack affected its servers, databases, email systems and employee devices. The controller first estimated that 25,000 persons were affected. It later stated that the incident had affected around 40,000 persons, including 75 minors. The incident affected confidentiality, availability and integrity. The attacker encrypted systems and exfiltrated between 3.5 and 4 TB of information from the document management server. The affected data included identification and contact data, ID numbers, dates of birth, financial and insurance data, bank account numbers, health data, employee data and access credentials. The controller also processed data relating to minors in accident claims. A data subject complained to the DPA after being informed that their personal data had been exposed. The data subject was concerned about identity theft and requested additional information from the controller. During the investigation, the DPA found that the controller had known that its IT systems faced an extreme cybercrime risk before the breach. The forensic report could not determine the initial entry point because the servers had been encrypted, but it showed that attackers could move laterally through the infrastructure, obtain privileged access, install tools, exfiltrate data and encrypt systems. The controller had carried out a risk analysis in 2019, but this document concluded that no DPIA was necessary. After the breach, a later analysis found that a DPIA was necessary for treatments involving health data and minors. The controller did not prove that it had carried out the required DPIA. Holding — The DPA held that the controller violated Article 5(1)(f) GDPR. It considered that the controller had failed to ensure the integrity and confidentiality of the personal data under its responsibility. The DPA emphasised that the principle in Article 5(1)(f) GDPR is not limited to the existence of isolated security measures. Rather, the controller must implement adequate technical and organisational measures capable of ensuring that personal data is protected against unauthorised or unlawful processing, loss, destruction or damage. The DPA rejected the controller’s argument that the attack was an external criminal act that could not be attributed to it. The DPA found that the controller was aware of an extreme cyber risk and that its internal vulnerabilities and security posture allowed the attackers to move through the systems, access personal data and encrypt files. The DPA therefore considered that the controller’s measures were clearly insufficient. The DPA also held that the controller violated Article 35 GDPR. The controller processed high-risk categories of data, including health data and data concerning minors. In these circumstances, it should have carried out a DPIA before the processing. The DPA found that the controller’s 2019 risk analysis wrongly concluded that no high risk existed, while its later documentation acknowledged that a DPIA was necessary. The DPA proposed a fine of €150,000 for the infringement of Article 5(1)(f) GDPR and €100,000 for the infringement of Article 35 GDPR, totalling €250,000. The controller paid voluntarily without acknowledging liability, obtaining a 20% reduction under Spanish Administrative Law (39/2015). The final payable amount was therefore €200,000. The DPA also ordered the controller, under Article 58(2)(d) GDPR, to prove within three months from the enforceability of the decision that it had carried out the mandatory DPIA required under Article 35 GDPR.

### Kymen Vesi Oy: Non-compliance with general data processing principles

*Source: Deputy Data Protection Ombudsman, 2020-05-22 — https://overview.legal/posts/46395 — original: https://www.enforcementtracker.com/ETid-280*

Fine for failure to carry out a data protection impact assessment ('DPIA') for the processing of location data of employees with a vehicle information system

### Telecommunications operator (operator of electronic communications networks and services): Non-compliance with general data processing principles

*Source: Croatian Data Protection Authority (azop), 2025-11-24 — https://overview.legal/posts/49052 — original: https://www.enforcementtracker.com/ETid-2937*

Following an ex officio investigation, AZOP imposed a EUR 4.5 million fine on a telecommunications operator for multiple GDPR infringements. The controller transferred customer personal data to a processor in the Republic of Serbia (a group company maintaining software). Transfers had been based on Standard Contractual Clauses (SCCs) from 16 April 2020 until at the latest 27 December 2022; after that date, transfers continued without SCCs or equivalent safeguards, despite Serbia lacking an adequ

### Mayor: Insufficient legal basis for data processing

*Source: Hellenic Data Protection Authority (HDPA), 2022-04-04 — https://overview.legal/posts/47252 — original: https://www.enforcementtracker.com/ETid-1137*

The Hellenic DPA has fined a mayor EUR 5,000. The mayor had sent documents of an employee of the municipality to third parties without the employee's consent. The DPA considered this to be a violation of Art. 5 (1) a) GDPR.

### Italian DPA: vehicle tracking by Liguria Health Agency lawful, information duties met

*Source: Garante per la protezione dei dati personali (Italy), 2026-05-28 — https://overview.legal/posts/53883 — original: https://gdprhub.eu/index.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_382/2026*

Facts — A data subject filed a complaint before the DPA against the Liguria Health Protection Agency (the controller). The data subject was employed by the Ligurian Social and Health Care Agency, however, the organisation was later merged with the controller. According to the data subject, the controller initiated discliplinary proceedings and suspended them based on data collected unlawfully through a tracking system in the company vehicle. The data subject also argued that the controller did not sufficiently inform employees that their location was being tracked through the company vehicles. The DPA received several complaints from other data subjects, and joined the complaints. The controller argued that the geolocation system was a measure to protect its assets, to optimise the management of its vehicles, and to ensure worker safety (e.g. to ensure that an employee followed the route while carrying hazardous materials). The controller argued that it did not process employees’ personal data, as it tracked the vehicles themselves and did not link the vehicle with the employee. Finally, the controller argued that the tracking was in compliance with its workers’ statutes. Holding — The DPA first stated that the controller had complied with its information obligations. Following the collective bargaining agreement, the controller informed data subjects of how their data was going to be processed. In addition, the controller had included a notice on how their location data was processed. Therefore, the DPA did not find a violation of Article 13 GDPR. The DPA found a violation of Article 5(1)(c) GDPR. The DPA found that the controller systematically and continuously monitored employees assigned company vehicles, as they were tracked at very frequent intervals without allowing them to deactivate the tracking. The DPA found this frequent tracking particularly detrimental to data subjects’ rights and freedoms, because the controller was able to access real-time information on vehicle movements. The DPA considered that the controller processed more data than necessary for its purposes, and that it risked processing data related to data subjects’ personal lives. The controller’s need to ensure that hazardous materials are transported safely did not justify continuously monitoring employees, especially because the controller later increased the interval of monitoring to every 15 minutes. Finally, the DPA dismissed the argument that the controller only tracked vehicles and not data subjects. This is because the controller could identify the data subject at any time by checking the logbook inside the vehicles. The DPA also found a violation of Articles 5(1)(a), (b), 6 and 88 GDPR. The DPA stated that a collective bargaining agreement was a necessary but not always sufficient condition for the data processing activities to be lawful. This means that the controller must comply with both labour and data protection legislation. Given the excessive amount of data processed, the DPA found that the controller did not have a legal basis to process this data. The DPA found that the controller also unlawfully further processed the location data of data subjects for disciplinary proceedings, in violation of the principle of purpose limitation. This is because the disciplinary proceedings did not specifically concern the data subject’s movements detected by the tracking system, but rather the data subject’s failure to notify potentially dangerous situations that occurred during the performance of their duties. Finally, the DPA found a violation of Articles 25 and 35 GDPR. The DPA found that the controller failed to choose a less invasive solution during the design phase. Therefore, its processing activities did not meet the requirements of privacy by design and default (Article 25 GDPR). The controller violated Article 35 GDPR by not conducting a data protection impact assessment (DPIA) before processing data subjects’ location data. The controller’s awareness of data protection issues and evidence of introducing measures to protect data subjects was not sufficient to meet this requirement. The DPA fined the controller €6,000. The DPA took into consideration the changes the controller had made during its investigations, including adjusting the interval of tracking vehicles from every 60 seconds to every 15 minutes

### Technology Company: Insufficient legal basis for data processing

*Source: Belgian Data Protection Authority (APD), 2026-05-12 — https://overview.legal/posts/53623 — original: https://www.enforcementtracker.com/ETid-3172*

Belgian Data Protection Authority (APD) fined Technology Company €177,000 on 2026-05-12 for: Insufficient legal basis for data processing.

### Public and Private Domain SA: Insufficient legal basis for data processing

*Source: Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP), 2026-03-20 — https://overview.legal/posts/53516 — original: https://www.enforcementtracker.com/ETid-3065*

Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) fined Public and Private Domain SA €3,000 on 2026-03-20 for: Insufficient legal basis for data processing.

## Recent developments

### AEPD publishes GDPR Risk Assessment

*Source: AEPD, 2022-10-11 — https://overview.legal/posts/6259 — original: https://evalua-riesgo.aepd.es/index_en.html#entry-1032*

> GDPR RISK ASSESSMENT is intended to assist controllers and processors to identify the risk factors for the rights and freedoms of data subjects whose data are present in the processing, to make an initial assessment of the intrinsic risk, including the need to perform a DPIA, and to estimate the residual risk if measures and safeguards are used to mitigate the specific risk factors.

### ICO Publishes Draft Employee Monitoring Guidance for Consultation

*Source: Hunton Andrews Kurth, 2022-10-18 — https://overview.legal/posts/6255 — original: https://www.huntonprivacyblog.com/2022/10/18/uk-ico-publishes-draft-employee-monitoring-guidance-for-consultation/#entry-1081*

> On October 14, 2022, the Federal Trade Commission announced it is extending the deadline by one month to submit comments on its Advanced Notice of Proposed Rulemaking on commercial surveillance and lax data security practices.

### UK data protection reform: How the UK's GDPR may change

*Source: Hogan Lovells, 2022-09-06 — https://overview.legal/posts/6285 — original: https://www.engage.hoganlovells.com/knowledgeservices/news/uk-data-protection-reform-how-the-uk-gdpr-may-change#entry-214*

> The current version of the Bill seeks to maintain the majority of key principles that underpin the UK data protection law framework, while at the same time modifying certain key provisions in relation to accountability, lawful grounds for processing, data subject access requests and cookies, amongst others.

A [consolidated redline version of the UK GDPR by Hogan Lovells](https://www.engage.hoganlovells.com/knowledgeservices/attachment_dw.action?attkey=FRbANEucS95NMLRN47z%2BeeOgEFCt8EGQJsWJiCH

### Berlin DPA imposes 525K euro fine over DPO violation

*Source: IAPP, 2022-09-22 — https://overview.legal/posts/6275 — original: https://iapp.org/news/a/berlin-dpa-imposes-525k-fine-over-dpo-violation#entry-482*

> The Berlin Commissioner for Data Protection and Freedom of Information issued a 525,000 euro fine to a Berlin-based retailer for violation of data protection officer requirements under the \[GDPR]. An investigation found an alleged conflict of interest concerning the DPO's employment status and decision-making responsibilities that violated Article 38(6) of the GDPR. The company received a warning from the regulator in 2021.

### DeFine is a calculator for GDPR fines based on method of the EDPB

*Source: Kromann Reumert, 2022-02-01 — https://overview.legal/posts/6310 — original: https://www.khlaw.com/define#entry-14*

> DeFine is a translation into a calculator of part of the methodology proposed by the European Data Protection Board to calculate GDPR fines (see EDPB, Guidelines 04/2022 on the calculation of administrative fines under the GDPR, 12 May 2022, available online; it was subject to a public consultation until 27 June 2022).

## Literature

### Data Protection of Employees – Certain Aspects of ECHR and GDPR Protection

*Source: Jusletter-IT, 2021-01-01 — https://overview.legal/posts/132609 — original: https://doi.org/10.38023/bbc645d6-ab93-4bfa-b7e2-bd0a901b3b4b*

### GDPR Implementation Series ∙ Malta: An Overview of the GDPR Implementation

*Source: European Data Protection Law Review, 2020-01-01 — https://overview.legal/posts/132480 — original: https://doi.org/10.21552/edpl/2020/4/15*

### GDPR Implementation Series ∙ Portugal: A Brief Overview of the GDPR Implementation

*Source: European Data Protection Law Review, 2019-01-01 — https://overview.legal/posts/132482 — original: https://doi.org/10.21552/edpl/2019/4/12*

### GDPR Implementation Series ∙ Hungary: Introduction to the GDPR Application and a Brief History of Data Protection

*Source: European Data Protection Law Review, 2019-01-01 — https://overview.legal/posts/132426 — original: https://doi.org/10.21552/edpl/2019/4/11*

### GDPR Implementation Series ∙ France: The French Approach to the GDPR Implementation

*Source: European Data Protection Law Review, 2018-01-01 — https://overview.legal/posts/132481 — original: https://doi.org/10.21552/edpl/2018/1/12*

## Related topics

- **Processing** — https://overview.legal/topics/verwerking
  Any operation performed on personal data
- **Supervisory Authorities** — https://overview.legal/topics/supervisory-authorities
  National data protection authorities and their powers
- **Personal Data** — https://overview.legal/topics/persoonsgegevens
  Information relating to identified or identifiable natural persons
- **Processing Agreement** — https://overview.legal/topics/verwerkersovereenkomst
  Contract between controller and processor defining processing terms
- **Controllers** — https://overview.legal/topics/controllers
  Entities that determine purposes and means of processing
- **IP Address** — https://overview.legal/topics/ip-adres
  Internet protocol addresses as personal data

---
Generated by overview.legal · https://overview.legal/topics/werknemers · 2026-08-22
