To undertake

Drafting an internal employee privacy statement: what belongs in it

Drafting an internal employee privacy statement? Read about the components that should be included, common mistakes, and when to hire a lawyer.

Published on August 23, 2026 by MKBjuristen.nl
Request a free quote Call 085 25000 44

MKB Juristen drafts custom legal documents

It is best not to cobble together or copy important contracts, terms and conditions, and other legal documents yourself. We help entrepreneurs on a budget with customized legal solutions, clear costs upfront, and practical explanations.

  • Custom contracts, terms and conditions, and legal documents
  • Budget-friendly and clear about the costs upfront
  • Request a free consultation or a no-obligation quote
Free consultation Request a free quote

Drafting an internal employee privacy statement involves documenting, for each type of data processing, which data you process, for what purpose, on what legal basis, and for how long you retain it. This document fulfills the duty to inform your staff under the GDPR. The greatest benefit lies in completeness and accuracy: a statement that mixes up legal bases or misses retention periods offers a false sense of security. Below is a list of what should be included and what to look out for.

The short answer

  1. Controller: who is responsible and how to contact them.
  2. Which data: by category, from name and address to absenteeism.
  3. Purpose and basis: why you process and on what basis under Article 6 of the GDPR.
  4. Retention periods: how long you keep each category.
  5. Sharing and rights: with whom you share and what rights the employee has.
  6. Special data and tracking systems: health, cameras and monitoring, with the role of the Works Council.

Drafting an internal employee privacy statement starts with an inventory

Drafting an internal privacy statement for employees begins with an inventory of processing activities

Before you start writing, map out which personal data you process from employees and applicants. Consider payroll administration, personnel files, absence registration, performance reviews, access passes, and potentially CCTV surveillance. This inventory forms the basis: only what you have a clear picture of can you describe correctly in the statement. Also, align with your processing register if you already have one, as the statement and the register must correspond.

Purpose and legal basis per processing

Record the purpose and legal basis for each processing activity in the internal privacy statement

For each category of data, state the purpose and the legal basis. The legal basis is derived from Article 6 of the GDPR. In the employment relationship, these are the most common:

  • Performance of employment contract (Article 6, paragraph 1, sub b GDPR): salary, schedules, performance.
  • Statutory obligation (Article 6, paragraph 1, subparagraph c GDPR): payroll records and tax retention obligation.
  • Legitimate interest (Article 6(1)(f) GDPR): security and business interest, with a balancing of interests.

Be cautious with consent (Article 6(1)(a) GDPR). Due to the hierarchical relationship between employer and employee, consent is often not a valid legal basis. Therefore, preferably base processing on one of the other legal bases and use consent only where it is truly appropriate, for example for a photo on the website.

Special information and the company doctor

Health data is special personal data and falls under Article 9 of the GDPR, which in principle prohibits processing. For absence registration, this means that as an employer you may only record limited data: that someone is ill, the expected duration, and agreements regarding a return to work, but not the nature of the complaints or the diagnosis. The medical assessment lies with the company doctor or occupational health service. Explicitly describe in the statement how you handle absence and health data, so that employees know what you do and do not record.

Making retention periods concrete

Include specific retention periods in the internal employee privacy statement

The GDPR requires that you do not retain data longer than necessary. Therefore, make the retention periods specific per category. Common retention periods:

  • Application data: four weeks after rejection, or up to a maximum of one year with the applicant's consent.
  • Wage tax data: seven years pursuant to the fiscal retention obligation (Article 52 AWR).
  • Copy of proof of identity: up to five years after the end of employment.
  • Other personnel file: generally up to two years after termination of employment, longer only if there is a reason for it.

Also include how you will delete or destroy data after the term has expired. A term without a cleanup process remains a paper promise.

Employee tracking systems and the works council

If you use camera surveillance, access registration, or monitoring of internet and email usage, this constitutes an employee tracking system. In addition to a legal basis and proper information provision, employee participation plays a role here. A decision to introduce or modify such a system, or a regulation concerning the processing and protection of personal data, requires consent pursuant to Article 27 of the Works Councils Act (WOR). If you have a Works Council, request consent in a timely manner. Without consent, the decision may be void. Describe in the statement which tracking systems you use and for what purpose.

A brief illustration: an SME transport company introduced trip registration via track-and-trace in its delivery vans. The employer stipulated in the internal privacy statement which data was processed and for what purpose (planning and security), based this on legitimate interest, and sought the consent of the Works Council. Consequently, the registration was based on a legally sound foundation.

Honest recommendation

Legal expert reviews a draft internal privacy statement for employees

For a small employer with standard payroll administration and without cameras, monitoring, or sensitive data, an internal privacy statement can easily be drafted independently with a solid foundation. In that case, you do not need a lawyer. However, as soon as you work with sensitive data, implement an employee tracking system, or have a works council, drafting becomes real work: ensuring the legal bases are correct, setting retention periods properly, and arranging the works council's consent. In that case, have the statement drafted or reviewed by a professional. An incorrect legal basis or a missed consent procedure can lead to fines or void decisions.

Want to read more? View the internal employee privacy statement on our contracts page, first read what an internal employee privacy statement is, or discover what it costs to have an internal employee privacy statement drafted .

Frequently Asked Questions

What should be included in an internal employee privacy statement?

The data controller, which data you process per category, the purpose and legal basis (Article 6 GDPR), the retention periods, with whom you share, the rights of employees, and how you handle special categories of data and employee tracking systems.

Which legal basis do I use for personnel data?

Usually performance of the employment contract (Article 6(1)(b) GDPR), a statutory obligation ((c)), or a legitimate interest ((f)) involving a balancing of interests. Consent ((a)) is often not a valid legal basis due to the hierarchical relationship.

How do I record absenteeism?

You may record that someone is ill, the expected duration, and agreements regarding a return to work, but not the nature of the complaints or the diagnosis. Health data are special categories of data (Article 9 GDPR). The medical assessment is conducted by the company doctor or occupational health service.

Which retention periods shall I include?

Application data for four weeks (or one year with consent), payroll tax data for seven years (Article 52 AWR), a copy of proof of identity for up to five years after employment, and other file data often for up to two years after termination. Also describe how you clean up the records.

Do I need to involve the Works Council?

For an employee tracking system such as camera surveillance, trip registration, or monitoring, or for a regulation concerning the processing of personal data, the consent of the Works Council is required pursuant to Article 27 of the Works Councils Act (WOR). Without consent, the decision may be void.

Does the declaration need to align with the processing register?

Yes. The internal privacy statement and the processing register describe the same processing operations. They must correspond with each other regarding data categories, purposes, legal bases, and retention periods; otherwise, inconsistencies will arise.

Can I draft the statement myself?

For a small employer with standard processing and without tracking systems or special data, a solid foundation works perfectly well. As soon as special data, an employee tracking system, or a works council comes into play, it pays to have the declaration checked.

Please note: an article provides general information, but your legal situation may turn out differently.

A contract, conflict, or legal risk must always be assessed based on the facts, documents, evidentiary position, and interests. Are you in doubt? Have your situation assessed before you act.

Legal question regarding this article?

A blog provides explanation, but your situation often requires a concrete legal choice. MKB Juristen helps entrepreneurs with contracts, terms and conditions, GDPR documents, employment documents, disputes, and customized legal solutions.

Drafting, reviewing, and amending contracts
Legal Assistance Help with conflicts and disputes.
Expertise Specialist legal experts and lawyers.
Fixed rates. Clarity on costs in advance.

Latest articles

August 23, 2026

Drafting a disclaimer of liability: this is what belongs in it

Drafting a disclaimer of liability? Read which components should be included, common mistakes, and when to hire a lawyer.

August 23, 2026

Drafting a model contract for personal data outside the EU: this should be included

Drafting a model contract for personal data outside the EU? Read which components should be included, common mistakes, and when to consult a lawyer.

August 23, 2026

Drafting an internal employee privacy statement: what belongs in it

Drafting an internal employee privacy statement? Read about the components that should be included, common mistakes, and when to hire a lawyer.

August 22, 2026

Having employer's confirmation of employee termination of employment contract drafted: costs and process

Having a lawyer draft a confirmation from the employer regarding the termination of the employment contract by the employee: what does it cost, how does the process work, and when?

  • We worked for, among others:
  • MKBjuristen.nl partner
  • MKBjuristen.nl partner
  • MKBjuristen.nl partner
  • MKBjuristen.nl partner
Newsletter for entrepreneurs

Receive practical legal tips in your mailbox

Register now

Enter your email address and receive our newsletter.

No spam. Only legal tips.
By registering, you agree to our privacy statement.
SME Lawyers at the Chamber of Commerce Source: Chamber of Commerce 2019
Free consultation