Employment law

Privacy in employment law

GDPR in the workplace, legally balanced

Employers constantly process employees' personal data. Our lawyers and corporate legal experts help you set up this processing in compliance with the GDPR, from camera surveillance to data breaches.

  • We worked for, among others:
  • MKBjuristen.nl partner
  • MKBjuristen.nl partner
  • MKBjuristen.nl partner
  • MKBjuristen.nl partner

What we do

Employers frequently process employees' personal data. Consider, for example, name and address details and the bank account number for salary payments. A wide range of legal regulations applies to the processing of personal data, which an organization must comply with. Personal data must be handled with the utmost care to prevent financial or reputational damage and fines. Responsibility regarding privacy is interwoven with virtually every file within the organization. Consequently, the protection of personal data occupies an important place within employment law. With our specialist expertise and experience, we can advise and guide the organization and share our knowledge. Examples include:

  • Compliance issues and implementation of the GDPR
  • Conducting risk assessments (DPIA)
  • The appointment of a Data Protection Officer
  • Drafting, reviewing, and editing privacy documentation, such as a privacy policy or data processing agreement
  • Drafting, reviewing, and editing privacy policies
  • Retention periods
  • Privacy protection during restructuring or reorganization
  • Privacy regarding job applicants, dismissal, or disability
  • Reporting data breaches
  • Providing courses and presentations in the field of employment law and privacy

Questions regarding privacy? Please contact us directly:

Privacy and employment law: where do we stand?

Privacy in the workplace lies at the intersection of employment law and privacy law. On the one hand, the employee has the right to protection of their personal life, even during working hours; on the other hand, the employer has the right to issue instructions and a legitimate interest in protecting the organization, company property, and colleagues. The processing of employee data must comply with the General Data Protection Regulation (GDPR). Consequently, virtually every employer decision – from performance files to camera surveillance – touches upon privacy. Our mixed teams of lawyers and (corporate) legal experts help you strike that balance in a legally responsible manner, whether you are an international corporation or the baker on the corner with a few employees. This page is part of our broader expertise in Employment Law.

The legal basis: may the employer process this data?

Every processing of employees' personal data requires a valid legal basis. The GDPR specifies these bases in Article 6 of the General Data Protection Regulation. In an employment relationship, the employee's "consent" is usually not a usable basis, because consent in a relationship of authority is rarely given freely. Employers therefore often rely on "legitimate interest" or on a statutory obligation. In this regard, the principle of purpose limitation and data minimization from Article 5 of the General Data Protection Regulation applies: processing no more data than is strictly necessary for a clearly defined purpose, and retaining data no longer than necessary. For special categories of personal data, such as the health data of a sick employee, the stricter regime of Article 9 of the General Data Protection Regulation applies: in principle, a prohibition on processing, with limited exceptions.

Control and monitoring of employees

If an employer wishes to monitor employees – via camera surveillance, email and internet usage, GPS tracking in vehicles, or monitoring of working from home – then that monitoring must meet three requirements:

  • Legitimate interest: there is a concrete, legitimate reason, such as theft prevention, security, or efficiency.
  • Proportionality: the means are proportionate to the end; no more checks are carried out than necessary.
  • Subsidiarity: there is no less intrusive means available to achieve the same goal.

Moreover, employees must be informed in advance, for example in a privacy statement or monitoring protocol, in accordance with the duty to inform under Articles 13 and 14 of the General Data Protection Regulation. Covert camera surveillance is permitted only in exceptional circumstances, and business email may be accessed under certain conditions, but private communication generally not. Camera footage is generally not retained for longer than four weeks, unless an incident has occurred.

The role of the works council

Privacy is not merely an individual matter between employer and employee. If an employer wishes to introduce or amend a regulation concerning the processing of personal data of personnel, or provisions aimed at observing or monitoring attendance, behavior, or performance, the consent of the Works Council is required. This obligation to obtain consent follows from Article 27 of the Works Councils Act. If this consent is omitted, an introduced control measure may be void. We assist both the employer and the Works Council throughout this process.

Applicants, sick employees and termination

Privacy plays a role throughout the entire employment cycle. During the application and screening process , an employer may not collect unlimited data; pre-employment screening must be proportionate and appropriate for the position. In the event of illness, an employer may not record medical data or the nature of the complaints – that is reserved for the company doctor – but only functional limitations and reintegration information. See also our page on illness and reintegration within employment law. Upon termination of employment, personal data must be deleted or anonymized as soon as the statutory retention periods have expired; a former employee retains their rights to access, correction, and deletion.

Data breaches and the DPIA

If things go wrong – for example, a stolen laptop, a misaddressed payslip, or a hack – this may constitute a data breach. A data breach subject to notification must be reported to the Dutch Data Protection Authority within 72 hours, and where applicable also to the employees concerned, pursuant to Articles 33 and 34 of the General Data Protection Regulation. Prior to high-risk processing operations, such as large-scale monitoring, a Data Protection Impact Assessment (DPIA) may be mandatory pursuant to Article 35 of the General Data Protection Regulation. We draft monitoring protocols and DPIAs and assist organizations in their dealings with the Dutch Data Protection Authority.

What MKB Juristen does for you

Privacy in employment law requires knowledge of two legal fields simultaneously. Our mixed teams of lawyers and in-house counsel combine expertise in employment law and privacy law. We draft privacy policies, data processing agreements, and monitoring protocols, guide the consent process with the Works Council, conduct DPIAs, and advise on data breaches, dismissals, and reorganizations. Whether you are a corporation with hundreds of employees or a small business owner with just a handful of staff, we translate the rules into workable agreements for your organization. For the broader context, we refer you to our Employment Law.

Mr. Jaime Boogaers
Mr. Jaime Boogaers
Corporate Law · Lawyer

In specialized legal cases, it is not just about the legal rule. It is also about evidence, timing, negotiating position, and the business implications of every step.

How we help you

We combine employment law and privacy law expertise in one team.

  • Drafting and reviewing privacy policies, privacy statements, and data processing agreements
  • Monitoring protocols for camera, email, internet, and GPS
  • Guiding the consent process with the Works Council
  • Conducting DPIAs for high-risk processing operations
  • Advice and reporting of data breaches to the Dutch Data Protection Authority
  • Privacy regarding job applications, illness, dismissal, and reorganization

Where things go wrong

An incorrect approach to privacy can lead to fines, invalid measures, and reputational damage. The most common pitfalls:

  • Control or monitoring without a valid basis or without prior information
  • Failure to seek the consent of the Works Council, rendering the measure void
  • Register medical data of sick employees instead of only functional limitations
  • Failure to report a reportable data breach, or reporting it too late
  • Retaining personal data longer than necessary

Our approach

We start with a sober analysis: what data do you process, for what purpose, and on what legal basis? Next, we assess every measure for proportionality and subsidiarity, record agreements in workable protocols, and ensure that the consent process with the Works Council proceeds correctly. Pragmatic where possible, legally watertight where necessary.

This is how we work

From inventory to formalized agreements.

01

Intake and initial assessment

We will briefly discuss the situation, the available documents, and your primary interests.

02

Analysis of position and risks

We assess your legal position, supporting documents, deadlines, and possible next steps.

03

Strategic advice

You will receive concrete advice on the best course of action: responding, negotiating, settling, or litigating.

04

Execution

We assist with correspondence, negotiation, litigation strategy, or further legal assistance.

Specialists for entrepreneurs

We combine legal analysis with practical experience in cases for entrepreneurs, directors, and organizations.

All our legal experts and lawyers possess broad knowledge of employment law. In addition, they have specialized in one or more areas of focus within employment law. We have organized several areas of focus into various practice groups. Based on his or her specialism(s), each lawyer is part of one or more practice groups. Clients can go directly to the appropriate practice group for each case. Here, they are assisted by the lawyer or legal expert most suitable for the case. Where necessary, we draw upon the expertise and experience of our specialist colleagues from other practice groups.

Frequently Asked Questions

The most frequently asked questions about privacy in employment law.

When is legal advice advisable?

Legal advice is wise as soon as pressure arises, deadlines are running, an opposing party takes a position, or when the financial or strategic interests are significant.

Can MKB Juristen also help if there is already a conflict?

Yes. We assess your legal position, advise on strategy, and can assist with correspondence, negotiation, defense, or further legal steps.

How much does specialist legal advice cost?

Specialist advice is provided on an hourly basis in principle. Where possible, we provide clarity in advance regarding the expected approach, costs, and next steps.

Can I have a no-obligation consultation first?

Yes. You can request a free consultation. We will briefly discuss your situation and indicate which course of action is likely the sensible one.

Properly regulating privacy in employment law?

Our lawyers and in-house counsel help you set up workplace privacy in compliance with the GDPR. Contact us without obligation.

Contact us

Contact us

Leave your details. We will contact you to briefly discuss your situation.

Contact us

Jaime Boogaers

Want to know more about our services?
Then contact our specialists.

Newsletter for entrepreneurs

Receive practical legal tips in your mailbox

Register now

Enter your email address and receive our newsletter.

No spam. Only legal tips.
By registering, you agree to our privacy statement.
SME Lawyers at the Chamber of Commerce Source: Chamber of Commerce 2019
Free consultation