HR-Glossar

Datenschutz für Beschäftigte (employee data protection)

What German employers may base employee data processing on, why consent rarely holds and what a works agreement achieves that consent cannot.

1. What is Datenschutz für Beschäftigte (employee data protection)?

Employee data protection covers the rules under which personal data may be processed in the employment relationship – from the application, through the employment itself, to retention after the person has left.

The framework comes from the General Data Protection Regulation. Article 88 GDPR permits member states to create their own, more specific rules for the employment context. Germany has done so in Section 26 BDSG: employee data may be processed so far as this is necessary for entering into, carrying out or terminating the employment relationship.

That provision, however, is subject to a caveat. The Court of Justice of the European Union has held, on a state-law provision drafted in the same terms, that such an opening clause must meet the specific requirements of Article 88 GDPR and may not merely restate the general principles. Anyone relying on Section 26 BDSG alone today is therefore on uncertain ground – the lawful bases in Article 6 GDPR remain applicable alongside it and carry most processing in any case.

For a group that has run a GDPR programme centrally, this is the point to note: the Regulation is common ground, but the German employment layer on top of it is not.

2. Origin and development

The employment relationship is a special case for data protection, because two things coincide there that are otherwise separate: continuous, comprehensive data processing, and a structural imbalance of power.

From that follows the most important practical feature: consent is a weak instrument in the employment relationship. It must be freely given, and freedom is doubtful where refusing might be expected to bring disadvantages. The Act therefore requires the degree of dependence to be assessed in the individual case, and requires written form – and in practice consent holds only where the processing brings the employee an advantage of their own, for instance photographs on the intranet or voluntary additional benefits.

Everything else needs a different basis. The two most robust are necessity for the employment relationship and the collective agreement: Article 88 GDPR expressly names works agreements as a possible basis, and in businesses with a works council they are therefore the instrument of choice – they settle co-determination under Section 87 BetrVG at the same time.

3. Core principles and how it works

Necessity is the standard

What may be processed is what is necessary for entering into, carrying out or terminating the employment relationship. "Useful" or "convenient" does not suffice.

Consent only where it is genuinely free

In a relationship of dependence, freedom is the exception. It comes into consideration mainly where the processing brings the employee an advantage of their own. It is revocable at any time – which also makes it unsuitable as the basis for systems the business depends on.

A works agreement as a lawful basis in its own right

Article 88 GDPR expressly names collective agreements. They can legitimise processing and at the same time satisfy co-determination under Section 87 BetrVG – two things at once, and the usual route in businesses with a works council.

Purpose limitation and erasure

Data may be processed only for the purpose for which it was collected and must be erased when that purpose falls away. Tax and social security retention periods cut across this – an erasure concept has to bring both together.

The right of access under Article 15 GDPR

Employees can request information about the data processed about them, and a copy. In conflict situations this right is regularly used – and it must be met within a deadline.

Special categories need more

Health data, trade union membership, religious affiliation: additional conditions apply to these. Health data in particular arises continuously in the employment relationship – on incapacity for work, integration management and occupational health.

4. Who is Datenschutz für Beschäftigte (employee data protection) relevant for?

- HR – they process employee data in almost every transaction. - Works councils – co-determination and data protection interlock wherever technical systems are concerned. - IT leads – every system rollout raises both questions at once. - Payroll – they process particularly sensitive data and pass it to third parties. - Businesses with outsourced payroll – a processing agreement is mandatory there, and responsibility stays with the employer.

5. How it differs from related terms

- Section 26 BDSG and Article 6 GDPR – the national provision is a specification, not an exhaustive special regime. Where it does not hold, the general lawful bases remain applicable. - Data protection and co-determination – two separate tests with different standards. A works agreement can satisfy both, but does not automatically replace the data protection assessment. - Processor and joint controller – a payroll services provider is as a rule a processor; responsibility stays with the employer. - Personnel file and payroll account – the personnel file is subject to data protection law, the payroll account additionally to tax recording and retention duties. Erasure therefore follows different periods. - Employee data protection and whistleblower protection – reporting systems process personal data about third parties; separate confidentiality rules apply there in addition.

6. Variants and adaptations

Typical processing situations and what is special about them:

- Application – data of rejected applicants must be erased after a reasonable period; retention in view of possible AGG claims is permissible within limits. - Time recording and access control – regularly also subject to co-determination under Section 87 BetrVG. - Health data – incapacity for work, integration management, occupational health checks. Diagnoses do not as a rule belong in the personnel file. - Internal investigations – where a breach of duty is suspected, heightened requirements apply to proportionality and documentation. - After leaving – erasure follows the longest applicable retention period, not the end of the employment relationship.

7. Advantages and challenges

Advantages

  • Protects employees at the point where their bargaining power is weakest
  • Works agreements create legal certainty for entire systems at a stroke
  • Clear purpose limitation prevents the creeping extension of data once collected
  • The right of access makes processing verifiable
  • A clean erasure concept reduces effort and risk at the same time

Challenges

  • Section 26 BDSG is subject to a caveat under Union law – the position is uncertain
  • Consent mostly does not hold in employment and creates a false sense of security
  • Erasure duties and tax retention periods appear to contradict each other
  • Access requests are used as leverage in disputes and tie up capacity
  • Health data arises continuously and is often filed thoughtlessly in personnel files
  • Every system rollout needs two assessments – data protection and co-determination

8. Best practices for implementation

A works agreement rather than consent

Where a works council exists, the works agreement is the more robust route. It covers all employees, is not revocable by the individual, and settles co-determination at the same time.

Keep diagnoses out of the personnel file

What matters to the employer is the incapacity for work, not its cause. Filing diagnoses means processing special categories without necessity.

Build the erasure concept around the periods, not the leaving date

Tax and social security retention periods run beyond the employment relationship and differ from one another. A concept that maps the longest period per data type holds; one that starts from the leaving date does not.

Ask both questions together at system selection

The lawful basis and co-determination under Section 87 BetrVG belong at the start of the selection, not immediately before the rollout.

Be ready for access requests

Anyone who only starts assembling which systems hold employee data once a dispute has arisen will miss the deadline. A record of processing activities that answers this question is the practical benefit of an otherwise tiresome duty.

9. Tips for employers and employees

For employers

  • **Test necessity, not usefulness** – that is the statutory standard
  • **Consent rarely holds** – in a relationship of dependence, freedom is the exception
  • **Use a works agreement** – Article 88 GDPR expressly names it as a basis
  • **No diagnoses in the personnel file** – what is relevant is the incapacity, not its cause

For employees

  • **You can request access** – Article 15 GDPR, including a copy
  • **Consent is revocable** – a withdrawal must not be held against you
  • **You need not state a diagnosis** – towards your employer the incapacity itself suffices
  • **The works council is your point of contact** – for systems capable of recording conduct or performance

10. Conclusion

Employee data protection in Germany has one feature that shapes everything else: consent mostly does not hold here. Where a relationship of dependence exists, freedom is doubtful – and a revocable basis is unsuitable for systems the business depends on in any case.

Two other routes are robust: necessity for the employment relationship, and the works agreement, which Article 88 GDPR expressly names as a basis and which satisfies co-determination under Section 87 BetrVG at the same time. For a group used to running consent as the default instrument, that is the substitution to make.

One caveat belongs with this: Section 26 BDSG does not stand securely under Union law. The Court of Justice has held, on a state-law provision drafted in the same terms, that such a rule must meet the requirements of Article 88 GDPR and may not merely restate general principles. In practice that changes little, because Article 6 GDPR remains applicable alongside it – but anyone building their entire case on Section 26 BDSG should know that this foundation is open to challenge.

Sources

Related terms

Our promise

Software supports. People take responsibility.

Let us talk about your payroll – no strings attached, specific, and with a dedicated contact from day one.

Set up fail-safetrue to detail, e.g. shadow payroll
Four-eyes reviewbefore every approval
Hosted in GermanyISO 27001 · GDPR