Employment relationship Flashcards
Is GDPR the only law regulating processing of employees personal data?
No, GDPR allows MS to provide more specific rules
Rules must include suitable and specific measures to safeguard the DS’s human dignity, legitimate interests and fundamental rights with particular regard to:
the transparency of processing
transfer within a group of undertakings or enterprises engaged in a joint economic activity
monitoring systems at workplace
If a MS implements national law, who does it have to notify?
European Commission
Does employer need to ensure data processing in accordance with all aspects of GDPR?
Yes, including the right to access
What are the most common legal grounds to process Employee’s data?
fulfilment of employment contract
compliance with legal obligation to which the employer is subject
legitimate interests
Why is consent not an appropriate ground?
Employees don’t have genuine freedom due to the unequal balance power in a relationship.
If consent is withdrawn the employer will not be able to further process PD lawfully
Is consent always possible?
No, MS law may stipulate consent can not be given for particular type of processing or particular PD or processing could be disproportionate
Example of processing necessary to fulfill employment contract
E’s name, bank details to pay salary
Use of Employer’s communications systems
Example of processing necessary for a legal obligation
To provide salaries details to tax authorities - it must be EU/MS law
Legitimate interests and public authorities
PA can rely on LI only when processing is not for performance of public authority’s task
What legal ground can the employer rely on for processing of employee’s sensitive data?
to carry out obligation and exercise specific rights under employment, social security and social protection law under EU, MS law or collective agreement.
Does an employer need to provide notice to the employees?
yes, regardless of lawful ground
through employee handbook, specific notification document
How long can an employer store employees PD?
For the duration of the employment, afterwards depending on different local laws (labour, tax, social security, health&safety)
The data on former employees must be securely archived.
Is employer allowed to compile a blacklist through a background check?
No, BL are generally illegal as considered to be a significant intrusion into a person’s privacy. .
What are DLP technologies?
Data loss protection tools to protect Business’s IT infrastructure and confidential business information from external and internal threats
They inevitably involve processing of PD of employees and 3rd parties as they operate on NW and systems used by employees and are considered a form of monitoring
Which DP principles are particularly important with employee monitoring
Legitimacy - lawful grounds, fairness
Necessity - monitoring must be really necessary
Proportionality
Transparency - inform employees
must be held securely and only accessed by those who have a legitimate reason to view it
it should be deleted when no longer needed