Computers in the workplace: employee data protection

What data can employers collect about employees and applicants? Can the boss control how employees use the Internet and e-mail? Who can employees contact? An overview of employee data protection.

GDPR

Everyone has heard of data protection before, but only a few know that there is also superior employee data protection. It also applies to working with computers, in the course of adapting German laws to the EU-wide General Data Protection Regulation (GDPR), which came into force in May 2018, the regulations on employee data protection. Many specifications have been retained – they are now only found elsewhere – and at the same time, there were also innovations in certain aspects from the GDPR.

As before, the respective employer – regardless of whether it is a company, organization, or authority – is by no means allowed to carry out any monitoring of its employees that it deems appropriate. He is also not allowed to collect all the data about employees that he would like to have. After all, every employer is in a particular position of power over its employees, which is why they need additional protection of their rights. Electronic behavior control procedures make it cheaper and easier to collect and evaluate employee’s or job applicants’ information.

Employers may collect specific data on the person and their employees’ employability in personnel files but must handle these files with particular care even after the employment relationship has ended and are generally not allowed to pass them on to third parties.

In addition to data on employees, this also includes trainees, interns, applicants, civil servants, civil and voluntary service providers, and former employees about previous employment relationships. If you want to know which data can and cannot be entered in the personnel files, you must take a closer look and consider the individual case’s circumstances. There are specific data collected for every employment relationship, under certain conditions, and a third group is generally taboo for the employer. The following general principle:

“Personal data” may only be collected – that is, managed and stored – if the person concerned has expressly consented to this or if a law or a particular circumstance allows it.

The GDPR also makes it clear that data processing is only permitted if it is demonstrably necessary. Essential data on the employment relationship may be collected.

One such exceptional circumstance is an employment relationship. According to a regulation in the Federal Data Protection Act, employers are allowed to collect, process, and use data from employees to the extent that “is necessary for the decision on the establishment of an employment relationship or, after establishment of the employment relationship.” If, for example, it is necessary to know the employee’s bank details to pay wages, the employer may also collect this bank data. Also, it may be noted in personnel files what career and what skills employees have.

On the other hand, it is not permissible to log the entire behavior of employees at the workplace. Therefore, the employer cannot keep records of, for example, when employees drive their cars into the company’s underground car park. Conventional time recording systems, such as electronic time clocks, may only be introduced and operated in coordination with the relevant works or staff council if there is such a representation of interest. It can be established from a company size of five permanent employees. Since May 2018, “employees within the meaning of the law also expressly include temporary workers and those who work in the course of federal voluntary service.

What information about the employee may the employer use?

The employees can also expressly consent to collecting and using personal data by a contractual agreement allowing this, for example, in the employment contract, and no stronger regulation is stating otherwise.

In general, the Works Constitution Act, a company agreement of the respective company or a service agreement of the respective authority, prohibits such consent or already regulates the case. It takes precedence over the individual employment contract.

Personal data may be collected, managed, and stored – if the person concerned has expressly consented to this or if a law or an exceptional circumstance allows it. Otherwise, consent can only be explicitly given – not tacitly – and revoked at any time. Exceptionally, it is considered “wordless” if an applicant willingly provides the employer with data. Anyone who voluntarily states in a recorded interview that they are not a fan of teamwork is, in case of doubt, at the same time consenting to note this. What can be meant by “voluntary” is problematic because many employees do not know precisely what information the employer can ask for and what cannot be asked.

Data protection experts advise employers and work councils to review all existing company agreements to adapt them to the new requirements for company data protection or to convert them into an overarching framework company agreement. The personnel file as the linchpin, also electronically. The following documents are typically viewed as legally permissible parts of a personnel file.

Of course, employees have the right to view their files. If certain information is wrongly noted in the file or remained pointed out after the consent to storage has been revoked, the person concerned can request deletion.

Also, it must not be possible for anyone to read the personal file. It must be secured against unauthorized access, even if it is kept electronically. Those who have access to the file must be limited to those who depend on the file’s information. Suppose security is neglected and confidential contents of the personnel file get into the hands of unauthorized persons or even into the public. In that case, this can result in a claim for damages.

The EU-wide General Data Protection Regulation was accompanied by the fact that employees have more rights and those responsible have more information obligations. In this way, data subjects can request information about data use or the deletion of specific data. Their data is processed and transmitted to them only to a limited extent. In some instances, you can also object to the processing of personal data. In this context, experts advise companies to create specific deletion and storage concepts. These would be of use to them anyway to fulfill their information obligations.