Blog » DON’T BE A COPYCAT! DON’T COPY THE ID CARDS OF YOUR EMPLOYEES UNDER GDPR!
DON’T BE A COPYCAT! DON’T COPY THE ID CARDS OF YOUR EMPLOYEES UNDER GDPR!
24 October 2018
During our GDPR compliance projects I often hear from clients that they copy or scan the identity cards of their employees. It may not be my most thrilling article, but I find it important to clarify once and for all that is a bad practice as it is against the GDPR and the recommendations of the Hungarian Data Protection Authority. Below I shortly explain you why copying ID cards is problematic and what you should do instead.
Why do clients copy?
The most common case of copying ID cards is when hiring new employees. Even though the employees need to fill out a data sheet, they are often requested to send their ID cards before the signature of the labour contract.
The HR colleagues almost always tell me that the reason for this is that they need to register the employee at the tax authority before their starting date.
If the data provided by the employee is inaccurate, the employer is not able to make the registration and may face fines. Requesting the copy of ID cards and other documents, like tax cards or social security card allows HR colleagues to check the accuracy of the data and make the registration correctly.
Why is copying not GDPR compliant?
At a starting point, a valid ID card is an authentic instrument and the data contained by it shall be accepted as true and accurate. Nevertheless, the copy made of the ID card by the employer does not have an evidential value, as it is not a certified true copy and is not appropriate to establish the identity of a person.
Thus, a “simple” copy made by the employer cannot prove the accuracy of the data contained by the ID card. Hence, copying the ID cards and storing the copies is not necessary as it cannot fulfil the purpose specified by the employer, briefly said it is against the principle of the purpose limitation.
In addition, the ID cards contain the photo of the employee and other data which may not be necessary for the reporting. Therefore, copying of the ID cards is against the principle data minimisation, too.
Last but not least, imagine the risk that the stealing of the copies could cause to the employees…
What you should do instead of copying?
It seems quite obvious, but instead of copying you can request your employee to show his ID card when you sign the labour contract and you can compare it with the data provided in the data sheet and check whether the latter is correct.
When I tell this to the HR colleagues of the clients, I usually receive two objections. On the one hand, they say that this is not feasible as the reporting of the employee to the tax authority shall happen before the starting day of the employee, while signature of the labour contract happens only on the first working days.
The second one is: what if the HR colleague has a bad day, does not recognize the error when she checks the data and the mistake only emerges only at the reporting when it cannot be solved anymore.
I have a solution for the above problems: you need to review and slightly amend your onboarding procedure.
If you sign the labour contract with your employee before his starting date you can carry out the data check at this time and can make the reporting to the tax authority as usual.
When signing the labour contract, in line with the ‘four-eyes’ principle, you can instruct a second colleague to check the ID card and to confirm the accuracy of the recorded data.
I know that this might need extra effort or resources but in a recent recommendation, the Data Protection Authority made it clear that the aspects of convenience or faster administration cannot justify the copying of ID cards.
To summarize the above instead of copying your employees’ ID cards for certain reasons you should only request them to show their ID cards and compare it with your records. By doing so, you can remain GDPR compliant and avoid the possibility of a data protection fine for unlawful data processing.
THE FIDIC IN HUNGARY – INDEPENDENCY AND IMPARTIALITY OF ENGINEER AND DB MEMBERS IN COURT PRACTICE
To what extent shall the engineer be independent and impartial under FIDIC construction contracts? Are the same standards applicable to the members of the dispute board? Do they have an obligation of disclosure? We address these questions in the light of the Hungarian court practice.Read more »
WHAT ARE THE RISKS OF CHANGING YOUR SUPPLIER IN HUNGARY?
Changing your supplier is a common situation in business. Can you switch between suppliers without restrictions, if there is no fixed term or exclusive contract? Do you have to purchase from the supplier during the notice period? What are the risks of failing to give purchase orders? In our article, we answer the above questions by analysing the Hungarian judicial practice.Read more »
THE FIRST CUCKOO HAS ARRIVED – HERE IS THE FIRST HUNGARIAN GDPR-FINE
The Hungarian data protection authority, the NAIH has imposed the first data protection fine in December 2018 which was based on the infringement of the GDPR. It appears that in relation with the „first cuckoo” the NAIH applied the so called „early bird” discount known as a marketing strategy. Indeed, the fine was not particularly high considering that it should be imposed because of the infringement of data subject rights. Well, let’s see the details of the case.Read more »