Blog » DON’T BE A COPYCAT! DON’T COPY THE ID CARDS OF YOUR EMPLOYEES UNDER GDPR!
DON’T BE A COPYCAT! DON’T COPY THE ID CARDS OF YOUR EMPLOYEES UNDER GDPR!
24 October 2018
During our GDPR compliance projects I often hear from clients that they copy or scan the identity cards of their employees. It may not be my most thrilling article, but I find it important to clarify once and for all that is a bad practice as it is against the GDPR and the recommendations of the Hungarian Data Protection Authority. Below I shortly explain you why copying ID cards is problematic and what you should do instead.
Why do clients copy?
The most common case of copying ID cards is when hiring new employees. Even though the employees need to fill out a data sheet, they are often requested to send their ID cards before the signature of the labour contract.
The HR colleagues almost always tell me that the reason for this is that they need to register the employee at the tax authority before their starting date.
If the data provided by the employee is inaccurate, the employer is not able to make the registration and may face fines. Requesting the copy of ID cards and other documents, like tax cards or social security card allows HR colleagues to check the accuracy of the data and make the registration correctly.
Why is copying not GDPR compliant?
At a starting point, a valid ID card is an authentic instrument and the data contained by it shall be accepted as true and accurate. Nevertheless, the copy made of the ID card by the employer does not have an evidential value, as it is not a certified true copy and is not appropriate to establish the identity of a person.
Thus, a “simple” copy made by the employer cannot prove the accuracy of the data contained by the ID card. Hence, copying the ID cards and storing the copies is not necessary as it cannot fulfil the purpose specified by the employer, briefly said it is against the principle of the purpose limitation.
In addition, the ID cards contain the photo of the employee and other data which may not be necessary for the reporting. Therefore, copying of the ID cards is against the principle data minimisation, too.
Last but not least, imagine the risk that the stealing of the copies could cause to the employees…
What you should do instead of copying?
It seems quite obvious, but instead of copying you can request your employee to show his ID card when you sign the labour contract and you can compare it with the data provided in the data sheet and check whether the latter is correct.
When I tell this to the HR colleagues of the clients, I usually receive two objections. On the one hand, they say that this is not feasible as the reporting of the employee to the tax authority shall happen before the starting day of the employee, while signature of the labour contract happens only on the first working days.
The second one is: what if the HR colleague has a bad day, does not recognize the error when she checks the data and the mistake only emerges only at the reporting when it cannot be solved anymore.
I have a solution for the above problems: you need to review and slightly amend your onboarding procedure.
If you sign the labour contract with your employee before his starting date you can carry out the data check at this time and can make the reporting to the tax authority as usual.
When signing the labour contract, in line with the ‘four-eyes’ principle, you can instruct a second colleague to check the ID card and to confirm the accuracy of the recorded data.
I know that this might need extra effort or resources but in a recent recommendation, the Data Protection Authority made it clear that the aspects of convenience or faster administration cannot justify the copying of ID cards.
To summarize the above instead of copying your employees’ ID cards for certain reasons you should only request them to show their ID cards and compare it with your records. By doing so, you can remain GDPR compliant and avoid the possibility of a data protection fine for unlawful data processing.
CAN YOUR DEBTOR ESCAPE LIQUIDATION BY SETTING OFF CLAIMS IN HUNGARY?
The initiation of a liquidation procedure is an effective debt collection method, since the debtor may only avoid being liquidated by paying the claim if the conditions specified in the Act on Bankruptcy Proceedings and Liquidation (Bankruptcy Act) are met. For this reason, in the case of liquidation, one of the most common defences of the debtor is the reference to offsetting. But can the debtor refer to offsetting without limitation during liquidation? In our short article we answer this question.Read more »
SZIGET FESTIVAL FINED RECORD HUF 30 MILLION FOR GDPR BREACHES – WHAT WENT WRONG?
A few days prior to the first anniversary of the entry into force of the GDPR the Hungarian Data Protection Authority imposed the biggest data protection fine in Hungary so far. The target was the biggest Hungarian festival organizer company thanks to whom the public may enjoy the SZIGET, the VOLT or the Balaton Sound Festival. The Data Protection Authority reviewed the check-in system of the festival and the data processing in relation with the check-in. In our short article we summarize the mistakes the Authority identified.Read more »
CONSTRUCTION TRUSTEESHIP IN HUNGARY - GETTING PAID IN CONSTRUCTION PROJECTS AS SUBCONTRACTOR
Construction trusteeship, as mandatory collateral management of major private construction projects in Hungary, strives for protecting subcontractors against non-paying general contractor, by allowing direct payments from employer under certain conditions. How does it work in practice and what are the limits of subcontractor protection? We address these issues in this article.Read more »