Blog » A GDPR-PROOF WORKPLACE – 5 MUST-KNOWS FOR EMPLOYERS
A GDPR-PROOF WORKPLACE – 5 MUST-KNOWS FOR EMPLOYERS
28 September 2017
In a very fresh judgement, the Strasbourg Court of Human Rights ruled that employers can monitor their employees’ messages only within certain limits. This judgement gave me the idea to collect 5 areas of the employment relationship where personal data of employees may be collected and processed and thus the principles of the GDPR such as lawfulness or purpose limitation should be taken into account.
Can you check the candidates Facebook profile?
Personal data handling issues arise even during the recruitment process. I hear from more and more employers that during the recruitment of new staff, they check the social media profiles of the candidates.
Just to mention some aspects, the principle of lawfulness allows employers to collect and process personal data relating to job applicants to the extent that the collection of those data is necessary and relevant to the performance of the job. Thus, if you inform candidates in advance, it can be GDPR-compliant to review their career path on the LinkedIn. Nevertheless, there is no legal ground for checking the relationship status of the possible employee on Facebook.
It is very common that during the recruitment employers ask the candidates to fill out fitness tests. Based on the principle of the data minimization the employer should not send to an office-job applicant a questionnaire with specific question about his health condition that are only relevant for blue-collar workers.
Last but not least, as soon as it becomes clear that an offer for the job would not be made to the applicant, his data should be deleted in accordance with the principle of storage limitation, unless he specifically consented to the retention.
Can you monitor employees’ ICT usage?
Nowadays it is quite usual that employers monitor the electronic communication (eg. e-mail, instant messaging) or Internet-use of their employees in the workplace. There are several types of monitoring systems, for example DLP-tools which enable to monitor outgoing communication for the purpose of detecting potential data breaches.
However, the prevention of data loss can be a legitimate interest for personal data processing, deploying a monitoring system may only be lawful if the employer takes into consideration the privacy principles. First and foremost, to comply with the principle of proportionality, the employer must consider whether he could use other, less invasive method, for example instead of monitoring the Internet usage, simply blocking the websites he does not want for his employees to visit. This means that in some cases no monitoring may take place at all.
If the monitoring is possible, it must be transparent which requires from the employer the prior notification of the employee. Also, the monitoring practice should include some limitations where it is possible, like sampling instead of continuous monitoring.
Can you control your employee working remotely?
It has become more common that employers allow their employees to work from home. In fact, some studies show that employees who work from home are more productive compared with their in-office counterparts. However, working from home without the implementation of appropriate technical safeguards can be very risky for the employer. In order to reduce the risk, employers may implement software packages. Some of them are even capable of logging keystrokes or mouse movements.
Nevertheless, before deploying such packages employers should consider the principle of lawfulness. It is very unlikely that the legitimate interest of protecting the employer’s business secrets may be a ground for recording an employee’s mouse movements.
With proportionate methods and accurate policies, employers can reach the goal of being protected without the violation of the employees right for private life.
Can you use the entry-exit system for performance evaluation?
To measure attendance and the time spent at the workplace employers often use systems that enable them to track the employees’ entries and exist. In some cases, these devices are used because of safety reasons, for example to monitor who has entered into a room where business-sensitive data is maintained.
On the one hand, based on the Labour Code, employers are obliged to keep records about the working time, so the necessity to fulfill this legal obligation may be a legitimate ground to use the entry-exit system.
On the other hand, the continuous monitoring of the frequency and the exact entrance and exit times of the employees could be hardly justified if these data would be used for performance evaluation since this would not be in compliance with the principle of lawfulness.
Can you track your employees’ company car?
Some positions require the use of company vehicles by employees and because of safety reasons technologies that enable employers to monitor their vehicles have become widely adopted. Some kind of these devices do not only collect data about the car itself but also about the employee (eg. driving behavior). If the employer allows the employee to use the car for private purposes, collection of personal data is even more concerned.
Employers must bear in mind the principles of proportionality and subsidiarity. Where private use of the car is allowed, it is unlikely that there will be a legal basis for monitoring the locations of the employees’ vehicles outside the working time. Thus, in order to be compliant with data protection rules, employees should have the possibility to turn off the location tracking.
To sum up the above I suggest you to pay particular attention of the privacy principles and to take the necessary measures (eg. setting up policies) when you decide to deploy monitoring systems or otherwise collect the personal data of your employees.
Hungary: Steps Towards Differentiating Between Domestic and International Procedural Public Policy
Drawing a well-defined line of demarcation between domestic and international public policy when enforcing foreign arbitral awards sends a clear pro-arbitration message from national courts in any jurisdiction. Does Hungarian case law come close to this level of sophistication? This post analyses this question in the context of procedural public policy, and it does so based on two recent appellate court decisions rendered in the context of enforcement of arbitral awards in accordance with the New York Convention.Read more »
EU ISSUED NEW GDPR STANDARD CONTRACTUAL CLAUSES – WHEN AND HOW TO USE THEM?
During summer 2021, the European Commission published two new "standard contractual clauses" on data protection regulation, which can be applied on the one hand, to the legal relationship between data controllers and data processors covered by the GDPR , and to the transfers of personal data to third countries, on the other. In this article, we answer the questions: what these SCCs regulate, how do they differ from the previous SCCs and how can your company use the new SCCs?Read more »
CAN THE NON-COMPETITION AGREEMENT BE VALID WITHOUT A PRECISE COMPENSATION IN HUNGARY?
The non-compete agreement may provide protection of the legitimate economic interests of the employer even after the termination of employment relationship. However, the Hungarian Labour Code lays down strict requirements for the agreement. In our article we analyse a recent decision of the Supreme Court about the importance of the precise determination of the compensation, so you as an employer can conclude a valid non-compete agreement.Read more »