Blog » A GDPR-PROOF WORKPLACE – 5 MUST-KNOWS FOR EMPLOYERS
A GDPR-PROOF WORKPLACE – 5 MUST-KNOWS FOR EMPLOYERS
28 September 2017
In a very fresh judgement, the Strasbourg Court of Human Rights ruled that employers can monitor their employees’ messages only within certain limits. This judgement gave me the idea to collect 5 areas of the employment relationship where personal data of employees may be collected and processed and thus the principles of the GDPR such as lawfulness or purpose limitation should be taken into account.
Can you check the candidates Facebook profile?
Personal data handling issues arise even during the recruitment process. I hear from more and more employers that during the recruitment of new staff, they check the social media profiles of the candidates.
Just to mention some aspects, the principle of lawfulness allows employers to collect and process personal data relating to job applicants to the extent that the collection of those data is necessary and relevant to the performance of the job. Thus, if you inform candidates in advance, it can be GDPR-compliant to review their career path on the LinkedIn. Nevertheless, there is no legal ground for checking the relationship status of the possible employee on Facebook.
It is very common that during the recruitment employers ask the candidates to fill out fitness tests. Based on the principle of the data minimization the employer should not send to an office-job applicant a questionnaire with specific question about his health condition that are only relevant for blue-collar workers.
Last but not least, as soon as it becomes clear that an offer for the job would not be made to the applicant, his data should be deleted in accordance with the principle of storage limitation, unless he specifically consented to the retention.
Can you monitor employees’ ICT usage?
Nowadays it is quite usual that employers monitor the electronic communication (eg. e-mail, instant messaging) or Internet-use of their employees in the workplace. There are several types of monitoring systems, for example DLP-tools which enable to monitor outgoing communication for the purpose of detecting potential data breaches.
However, the prevention of data loss can be a legitimate interest for personal data processing, deploying a monitoring system may only be lawful if the employer takes into consideration the privacy principles. First and foremost, to comply with the principle of proportionality, the employer must consider whether he could use other, less invasive method, for example instead of monitoring the Internet usage, simply blocking the websites he does not want for his employees to visit. This means that in some cases no monitoring may take place at all.
If the monitoring is possible, it must be transparent which requires from the employer the prior notification of the employee. Also, the monitoring practice should include some limitations where it is possible, like sampling instead of continuous monitoring.
Can you control your employee working remotely?
It has become more common that employers allow their employees to work from home. In fact, some studies show that employees who work from home are more productive compared with their in-office counterparts. However, working from home without the implementation of appropriate technical safeguards can be very risky for the employer. In order to reduce the risk, employers may implement software packages. Some of them are even capable of logging keystrokes or mouse movements.
Nevertheless, before deploying such packages employers should consider the principle of lawfulness. It is very unlikely that the legitimate interest of protecting the employer’s business secrets may be a ground for recording an employee’s mouse movements.
With proportionate methods and accurate policies, employers can reach the goal of being protected without the violation of the employees right for private life.
Can you use the entry-exit system for performance evaluation?
To measure attendance and the time spent at the workplace employers often use systems that enable them to track the employees’ entries and exist. In some cases, these devices are used because of safety reasons, for example to monitor who has entered into a room where business-sensitive data is maintained.
On the one hand, based on the Labour Code, employers are obliged to keep records about the working time, so the necessity to fulfill this legal obligation may be a legitimate ground to use the entry-exit system.
On the other hand, the continuous monitoring of the frequency and the exact entrance and exit times of the employees could be hardly justified if these data would be used for performance evaluation since this would not be in compliance with the principle of lawfulness.
Can you track your employees’ company car?
Some positions require the use of company vehicles by employees and because of safety reasons technologies that enable employers to monitor their vehicles have become widely adopted. Some kind of these devices do not only collect data about the car itself but also about the employee (eg. driving behavior). If the employer allows the employee to use the car for private purposes, collection of personal data is even more concerned.
Employers must bear in mind the principles of proportionality and subsidiarity. Where private use of the car is allowed, it is unlikely that there will be a legal basis for monitoring the locations of the employees’ vehicles outside the working time. Thus, in order to be compliant with data protection rules, employees should have the possibility to turn off the location tracking.
To sum up the above I suggest you to pay particular attention of the privacy principles and to take the necessary measures (eg. setting up policies) when you decide to deploy monitoring systems or otherwise collect the personal data of your employees.
WHY SHOULD YOU INVOLVE A LAWYER IN YOUR GDPR PROJECT?
In the last months preceding the entering into force of GDPR, the market was inundated with various service providers promising data protection compliance: data protection experts, counsels, IT experts, etc. Besides these providers, lawyers and law firms, experienced in the field of data protection also provide GDPR compliance services. We summarize the reason why you should involve them in your GDPR compliance project.Read more »
I GET “ONLY” STATISTICAL DATA FROM FACEBOOK – AM I DATA CONTROLLER UNDER GDPR?
Besides having a website, vast majority of businesses have company pages on the social networks like Facebook, Linkedin, etc. Do you become a data controller, being primarily responsible for data processing, if you get “only” statistical information of your visitors? The Court of Justice of the European Union addressed this question in its recent ruling.Read more »
HOW NOT TO DO DIRECT MARKETING? LEARN FROM THE MISTAKES OF TELEKOM!
In the recent past the Hungarian Data Protection Authority imposed a fine of 2 Million Hungarian Forints against Telekom, a major Hungarian telecommunication company, because of his unlawful direct marketing activity. Although the decision has been made before the entering into force of the GDPR, it is worth to examine the mistakes of Telekom. Indeed, the fine would have been much higher if it was imposed after the GDPR.Read more »