MKB Juristen drafts custom legal documents
It is best not to cobble together or copy important contracts, terms and conditions, and other legal documents yourself. We help entrepreneurs on a budget with customized legal solutions, clear costs upfront, and practical explanations.
- Custom contracts, terms and conditions, and legal documents
- Budget-friendly and clear about the costs upfront
- Request a free consultation or a no-obligation quote
Drafting an internal employee privacy statement involves documenting, for each type of data processing, which data you process, for what purpose, on what legal basis, and for how long you retain it. This document fulfills the duty to inform your staff under the GDPR. The greatest benefit lies in completeness and accuracy: a statement that mixes up legal bases or misses retention periods offers a false sense of security. Below is a list of what should be included and what to look out for.
The short answer
- Controller: who is responsible and how to contact them.
- Which data: by category, from name and address to absenteeism.
- Purpose and basis: why you process and on what basis under Article 6 of the GDPR.
- Retention periods: how long you keep each category.
- Sharing and rights: with whom you share and what rights the employee has.
- Special data and tracking systems: health, cameras and monitoring, with the role of the Works Council.
Drafting an internal employee privacy statement starts with an inventory
Before you start writing, map out which personal data you process from employees and applicants. Consider payroll administration, personnel files, absence registration, performance reviews, access passes, and potentially CCTV surveillance. This inventory forms the basis: only what you have a clear picture of can you describe correctly in the statement. Also, align with your processing register if you already have one, as the statement and the register must correspond.
Purpose and legal basis per processing
For each category of data, state the purpose and the legal basis. The legal basis is derived from Article 6 of the GDPR. In the employment relationship, these are the most common:
- Performance of employment contract (Article 6, paragraph 1, sub b GDPR): salary, schedules, performance.
- Statutory obligation (Article 6, paragraph 1, subparagraph c GDPR): payroll records and tax retention obligation.
- Legitimate interest (Article 6(1)(f) GDPR): security and business interest, with a balancing of interests.
Be cautious with consent (Article 6(1)(a) GDPR). Due to the hierarchical relationship between employer and employee, consent is often not a valid legal basis. Therefore, preferably base processing on one of the other legal bases and use consent only where it is truly appropriate, for example for a photo on the website.
Special information and the company doctor
Health data is special personal data and falls under Article 9 of the GDPR, which in principle prohibits processing. For absence registration, this means that as an employer you may only record limited data: that someone is ill, the expected duration, and agreements regarding a return to work, but not the nature of the complaints or the diagnosis. The medical assessment lies with the company doctor or occupational health service. Explicitly describe in the statement how you handle absence and health data, so that employees know what you do and do not record.
Making retention periods concrete
The GDPR requires that you do not retain data longer than necessary. Therefore, make the retention periods specific per category. Common retention periods:
- Application data: four weeks after rejection, or up to a maximum of one year with the applicant's consent.
- Wage tax data: seven years pursuant to the fiscal retention obligation (Article 52 AWR).
- Copy of proof of identity: up to five years after the end of employment.
- Other personnel file: generally up to two years after termination of employment, longer only if there is a reason for it.
Also include how you will delete or destroy data after the term has expired. A term without a cleanup process remains a paper promise.
Employee tracking systems and the works council
If you use camera surveillance, access registration, or monitoring of internet and email usage, this constitutes an employee tracking system. In addition to a legal basis and proper information provision, employee participation plays a role here. A decision to introduce or modify such a system, or a regulation concerning the processing and protection of personal data, requires consent pursuant to Article 27 of the Works Councils Act (WOR). If you have a Works Council, request consent in a timely manner. Without consent, the decision may be void. Describe in the statement which tracking systems you use and for what purpose.
A brief illustration: an SME transport company introduced trip registration via track-and-trace in its delivery vans. The employer stipulated in the internal privacy statement which data was processed and for what purpose (planning and security), based this on legitimate interest, and sought the consent of the Works Council. Consequently, the registration was based on a legally sound foundation.
Honest recommendation
For a small employer with standard payroll administration and without cameras, monitoring, or sensitive data, an internal privacy statement can easily be drafted independently with a solid foundation. In that case, you do not need a lawyer. However, as soon as you work with sensitive data, implement an employee tracking system, or have a works council, drafting becomes real work: ensuring the legal bases are correct, setting retention periods properly, and arranging the works council's consent. In that case, have the statement drafted or reviewed by a professional. An incorrect legal basis or a missed consent procedure can lead to fines or void decisions.
Want to read more? View the internal employee privacy statement on our contracts page, first read what an internal employee privacy statement is, or discover what it costs to have an internal employee privacy statement drafted .
Frequently Asked Questions
The data controller, which data you process per category, the purpose and legal basis (Article 6 GDPR), the retention periods, with whom you share, the rights of employees, and how you handle special categories of data and employee tracking systems.
Usually performance of the employment contract (Article 6(1)(b) GDPR), a statutory obligation ((c)), or a legitimate interest ((f)) involving a balancing of interests. Consent ((a)) is often not a valid legal basis due to the hierarchical relationship.
You may record that someone is ill, the expected duration, and agreements regarding a return to work, but not the nature of the complaints or the diagnosis. Health data are special categories of data (Article 9 GDPR). The medical assessment is conducted by the company doctor or occupational health service.
Application data for four weeks (or one year with consent), payroll tax data for seven years (Article 52 AWR), a copy of proof of identity for up to five years after employment, and other file data often for up to two years after termination. Also describe how you clean up the records.
For an employee tracking system such as camera surveillance, trip registration, or monitoring, or for a regulation concerning the processing of personal data, the consent of the Works Council is required pursuant to Article 27 of the Works Councils Act (WOR). Without consent, the decision may be void.
Yes. The internal privacy statement and the processing register describe the same processing operations. They must correspond with each other regarding data categories, purposes, legal bases, and retention periods; otherwise, inconsistencies will arise.
For a small employer with standard processing and without tracking systems or special data, a solid foundation works perfectly well. As soon as special data, an employee tracking system, or a works council comes into play, it pays to have the declaration checked.