Blog » A GDPR-PROOF WORKPLACE – 5 MUST-KNOWS FOR EMPLOYERS
A GDPR-PROOF WORKPLACE – 5 MUST-KNOWS FOR EMPLOYERS
28 September 2017
In a very fresh judgement, the Strasbourg Court of Human Rights ruled that employers can monitor their employees’ messages only within certain limits. This judgement gave me the idea to collect 5 areas of the employment relationship where personal data of employees may be collected and processed and thus the principles of the GDPR such as lawfulness or purpose limitation should be taken into account.
Can you check the candidates Facebook profile?
Personal data handling issues arise even during the recruitment process. I hear from more and more employers that during the recruitment of new staff, they check the social media profiles of the candidates.
Just to mention some aspects, the principle of lawfulness allows employers to collect and process personal data relating to job applicants to the extent that the collection of those data is necessary and relevant to the performance of the job. Thus, if you inform candidates in advance, it can be GDPR-compliant to review their career path on the LinkedIn. Nevertheless, there is no legal ground for checking the relationship status of the possible employee on Facebook.
It is very common that during the recruitment employers ask the candidates to fill out fitness tests. Based on the principle of the data minimization the employer should not send to an office-job applicant a questionnaire with specific question about his health condition that are only relevant for blue-collar workers.
Last but not least, as soon as it becomes clear that an offer for the job would not be made to the applicant, his data should be deleted in accordance with the principle of storage limitation, unless he specifically consented to the retention.
Can you monitor employees’ ICT usage?
Nowadays it is quite usual that employers monitor the electronic communication (eg. e-mail, instant messaging) or Internet-use of their employees in the workplace. There are several types of monitoring systems, for example DLP-tools which enable to monitor outgoing communication for the purpose of detecting potential data breaches.
However, the prevention of data loss can be a legitimate interest for personal data processing, deploying a monitoring system may only be lawful if the employer takes into consideration the privacy principles. First and foremost, to comply with the principle of proportionality, the employer must consider whether he could use other, less invasive method, for example instead of monitoring the Internet usage, simply blocking the websites he does not want for his employees to visit. This means that in some cases no monitoring may take place at all.
If the monitoring is possible, it must be transparent which requires from the employer the prior notification of the employee. Also, the monitoring practice should include some limitations where it is possible, like sampling instead of continuous monitoring.
Can you control your employee working remotely?
It has become more common that employers allow their employees to work from home. In fact, some studies show that employees who work from home are more productive compared with their in-office counterparts. However, working from home without the implementation of appropriate technical safeguards can be very risky for the employer. In order to reduce the risk, employers may implement software packages. Some of them are even capable of logging keystrokes or mouse movements.
Nevertheless, before deploying such packages employers should consider the principle of lawfulness. It is very unlikely that the legitimate interest of protecting the employer’s business secrets may be a ground for recording an employee’s mouse movements.
With proportionate methods and accurate policies, employers can reach the goal of being protected without the violation of the employees right for private life.
Can you use the entry-exit system for performance evaluation?
To measure attendance and the time spent at the workplace employers often use systems that enable them to track the employees’ entries and exist. In some cases, these devices are used because of safety reasons, for example to monitor who has entered into a room where business-sensitive data is maintained.
On the one hand, based on the Labour Code, employers are obliged to keep records about the working time, so the necessity to fulfill this legal obligation may be a legitimate ground to use the entry-exit system.
On the other hand, the continuous monitoring of the frequency and the exact entrance and exit times of the employees could be hardly justified if these data would be used for performance evaluation since this would not be in compliance with the principle of lawfulness.
Can you track your employees’ company car?
Some positions require the use of company vehicles by employees and because of safety reasons technologies that enable employers to monitor their vehicles have become widely adopted. Some kind of these devices do not only collect data about the car itself but also about the employee (eg. driving behavior). If the employer allows the employee to use the car for private purposes, collection of personal data is even more concerned.
Employers must bear in mind the principles of proportionality and subsidiarity. Where private use of the car is allowed, it is unlikely that there will be a legal basis for monitoring the locations of the employees’ vehicles outside the working time. Thus, in order to be compliant with data protection rules, employees should have the possibility to turn off the location tracking.
To sum up the above I suggest you to pay particular attention of the privacy principles and to take the necessary measures (eg. setting up policies) when you decide to deploy monitoring systems or otherwise collect the personal data of your employees.
CAN YOUR DEBTOR ESCAPE LIQUIDATION BY SETTING OFF CLAIMS IN HUNGARY?
The initiation of a liquidation procedure is an effective debt collection method, since the debtor may only avoid being liquidated by paying the claim if the conditions specified in the Act on Bankruptcy Proceedings and Liquidation (Bankruptcy Act) are met. For this reason, in the case of liquidation, one of the most common defences of the debtor is the reference to offsetting. But can the debtor refer to offsetting without limitation during liquidation? In our short article we answer this question.Read more »
SZIGET FESTIVAL FINED RECORD HUF 30 MILLION FOR GDPR BREACHES – WHAT WENT WRONG?
A few days prior to the first anniversary of the entry into force of the GDPR the Hungarian Data Protection Authority imposed the biggest data protection fine in Hungary so far. The target was the biggest Hungarian festival organizer company thanks to whom the public may enjoy the SZIGET, the VOLT or the Balaton Sound Festival. The Data Protection Authority reviewed the check-in system of the festival and the data processing in relation with the check-in. In our short article we summarize the mistakes the Authority identified.Read more »
CONSTRUCTION TRUSTEESHIP IN HUNGARY - GETTING PAID IN CONSTRUCTION PROJECTS AS SUBCONTRACTOR
Construction trusteeship, as mandatory collateral management of major private construction projects in Hungary, strives for protecting subcontractors against non-paying general contractor, by allowing direct payments from employer under certain conditions. How does it work in practice and what are the limits of subcontractor protection? We address these issues in this article.Read more »