Blog » DON’T BE A COPYCAT! DON’T COPY THE ID CARDS OF YOUR EMPLOYEES UNDER GDPR!
DON’T BE A COPYCAT! DON’T COPY THE ID CARDS OF YOUR EMPLOYEES UNDER GDPR!
24 October 2018
During our GDPR compliance projects I often hear from clients that they copy or scan the identity cards of their employees. It may not be my most thrilling article, but I find it important to clarify once and for all that is a bad practice as it is against the GDPR and the recommendations of the Hungarian Data Protection Authority. Below I shortly explain you why copying ID cards is problematic and what you should do instead.
Why do clients copy?
The most common case of copying ID cards is when hiring new employees. Even though the employees need to fill out a data sheet, they are often requested to send their ID cards before the signature of the labour contract.
The HR colleagues almost always tell me that the reason for this is that they need to register the employee at the tax authority before their starting date.
If the data provided by the employee is inaccurate, the employer is not able to make the registration and may face fines. Requesting the copy of ID cards and other documents, like tax cards or social security card allows HR colleagues to check the accuracy of the data and make the registration correctly.
Why is copying not GDPR compliant?
At a starting point, a valid ID card is an authentic instrument and the data contained by it shall be accepted as true and accurate. Nevertheless, the copy made of the ID card by the employer does not have an evidential value, as it is not a certified true copy and is not appropriate to establish the identity of a person.
Thus, a “simple” copy made by the employer cannot prove the accuracy of the data contained by the ID card. Hence, copying the ID cards and storing the copies is not necessary as it cannot fulfil the purpose specified by the employer, briefly said it is against the principle of the purpose limitation.
In addition, the ID cards contain the photo of the employee and other data which may not be necessary for the reporting. Therefore, copying of the ID cards is against the principle data minimisation, too.
Last but not least, imagine the risk that the stealing of the copies could cause to the employees…
What you should do instead of copying?
It seems quite obvious, but instead of copying you can request your employee to show his ID card when you sign the labour contract and you can compare it with the data provided in the data sheet and check whether the latter is correct.
When I tell this to the HR colleagues of the clients, I usually receive two objections. On the one hand, they say that this is not feasible as the reporting of the employee to the tax authority shall happen before the starting day of the employee, while signature of the labour contract happens only on the first working days.
The second one is: what if the HR colleague has a bad day, does not recognize the error when she checks the data and the mistake only emerges only at the reporting when it cannot be solved anymore.
I have a solution for the above problems: you need to review and slightly amend your onboarding procedure.
If you sign the labour contract with your employee before his starting date you can carry out the data check at this time and can make the reporting to the tax authority as usual.
When signing the labour contract, in line with the ‘four-eyes’ principle, you can instruct a second colleague to check the ID card and to confirm the accuracy of the recorded data.
I know that this might need extra effort or resources but in a recent recommendation, the Data Protection Authority made it clear that the aspects of convenience or faster administration cannot justify the copying of ID cards.
To summarize the above instead of copying your employees’ ID cards for certain reasons you should only request them to show their ID cards and compare it with your records. By doing so, you can remain GDPR compliant and avoid the possibility of a data protection fine for unlawful data processing.
Hungary: Steps Towards Differentiating Between Domestic and International Procedural Public Policy
Drawing a well-defined line of demarcation between domestic and international public policy when enforcing foreign arbitral awards sends a clear pro-arbitration message from national courts in any jurisdiction. Does Hungarian case law come close to this level of sophistication? This post analyses this question in the context of procedural public policy, and it does so based on two recent appellate court decisions rendered in the context of enforcement of arbitral awards in accordance with the New York Convention.Read more »
EU ISSUED NEW GDPR STANDARD CONTRACTUAL CLAUSES – WHEN AND HOW TO USE THEM?
During summer 2021, the European Commission published two new "standard contractual clauses" on data protection regulation, which can be applied on the one hand, to the legal relationship between data controllers and data processors covered by the GDPR , and to the transfers of personal data to third countries, on the other. In this article, we answer the questions: what these SCCs regulate, how do they differ from the previous SCCs and how can your company use the new SCCs?Read more »
CAN THE NON-COMPETITION AGREEMENT BE VALID WITHOUT A PRECISE COMPENSATION IN HUNGARY?
The non-compete agreement may provide protection of the legitimate economic interests of the employer even after the termination of employment relationship. However, the Hungarian Labour Code lays down strict requirements for the agreement. In our article we analyse a recent decision of the Supreme Court about the importance of the precise determination of the compensation, so you as an employer can conclude a valid non-compete agreement.Read more »