Employee data protection
Organise employee data from recruitment to departure, limit access and document workplace controls in a comprehensible way.
Mag. Bernhard Brandauer, Rechtsanwalt
BRANDAUER Rechtsanwälte
Mag. Bernhard Brandauer advises businesses on the legal classification and practical implementation of data protection requirements.
Employee data protection accompanies the entire employment relationship. Recruitment involves applications and contact details. During employment, the data may include working time, absences, pay, communication, performance and access logs. When employment ends, handover, account blocking, deletion and statutory retention must be kept separate.
This focus topic addresses the organisational framework for businesses in Austria. It does not replace an assessment of a particular employment process or monitoring system. The dedicated articles on digital employee monitoring, AI at work and former employee data therefore provide deeper treatment of those specific situations.
For a business, the topic also connects with privacy governance, the assessment of external providers and a documented response to personal data breaches. This focus remains on employee data and its lifecycle.
Verfasst von Mag. Bernhard Brandauer, Rechtsanwalt
Where is your current review need?
Three short questions help identify the next organisational step for employee data.
Are access rights to employee data limited by role and task?
Look beyond HR and include managers, IT, payroll and external providers.
Ihre Orientierung
Separate retention by purpose
Classify control systems before use
The framework is broadly prepared
Which question arises at which stage?
The legal assessment changes when purpose, role, access or the reason for retention changes. The process should therefore not begin only when employment starts.
| Stage | Typical data and questions | Organisational focus |
|---|---|---|
| Recruitment and entry | Applications, contact details, qualifications, identity and contract data | Limit purpose, provide information and define access |
| Employment | Working time, pay, absence, communication, performance and security data | Review roles, necessity, security and controls |
| Changes | New software, remote work, provider, location or new analysis | Clarify privacy review and potential co-determination first |
| Departure and handover | Account blocking, handover, contact and evidence data | End active rights and assess retention separately |
| After departure | Statutory records, claims, evidence and archived data | Control deletion, restriction and access over time |
The data needed and the period for which it may be retained depend on purpose, legal basis and the circumstances of the employment relationship.
Organise employee data by purpose and legal basis
Processing employee data requires a defined purpose and an appropriate legal basis. Article 5 GDPR requires, among other things, lawfulness, purpose limitation and data minimisation. Article 6 lists legal bases for personal data. Special categories, such as health data, are subject to the additional requirements of Article 9.
For each material HR process, the business should record which data is actually needed, who provides it, who uses it and when the purpose ends. A field retained for convenience is not necessary merely because the system can store it. Recruitment, sickness, performance assessment and internal reports deserve separate analysis.
The information provided under Articles 13 or 14 GDPR should reflect the actual process. General notices may not be enough when new analysis tools, control systems or external platforms are introduced.
- Describe purpose and data category for each HR process.
- Assess the legal basis and any special category separately.
- Collect only data necessary for the specific purpose.
- Update information when a material process changes.
Access rights must match the task
Employee data is often stored in payroll, time recording, recruitment, sickness, document and communication systems. Access should not follow from department membership alone. Article 32 GDPR requires a level of security appropriate to the risk. This includes organisational rules that limit and review permissions.
A workable access model describes roles, categories, approval, removal and substitution. Payroll needs different information from a manager. IT administrators may have broad technical rights without automatically becoming the function entitled to inspect every personnel record. Logs can support controls, but they should not be collected indefinitely without a defined purpose and clear access to the analysis.
At departure, the process must react quickly and in coordination. Accounts, keys, mobile devices, shared folders and external access need review. That is separate from deciding which documents must be retained for statutory duties or specific claims.
Control systems do not automatically permit monitoring
Time recording, GPS, video, login logs, communications and performance analytics can serve different purposes. Technical availability does not mean that every analysis is lawful. Before implementation, the business should describe the purpose, data volume, affected people, authorised users and deletion logic. Continuous behavioural or performance monitoring is particularly intrusive.
Employment law may apply alongside the GDPR. Section 96(1)(3) of the Austrian Labour Constitution Act addresses control measures and technical systems for monitoring employees where they affect human dignity. Section 96a contains separate rules for certain automated systems processing employee data. Whether works council consent is needed can therefore only be assessed from the concrete system and its effects.
The dedicated article on monitoring employees with software examines that situation. AI systems at work also raise questions about purpose, training data, evaluation and works agreements, addressed in the article on AI at work.
- Document the purpose and analysis before selecting a control system.
- Assess necessity and less intrusive alternatives.
- Limit access to raw data and results to defined roles.
- Start privacy review and possible works council involvement early.
Distinguish retention, deletion and restriction
The GDPR does not provide one retention period for all employee data. Article 5(1)(e) limits storage to what is necessary. Employment, tax, social security and corporate law duties, as well as specific claims, may support continued retention. The reason should be recorded for each data category.
At departure, the whole personnel file should not be deleted immediately, but the entire account should not be archived without a time limit either. A sound process separates active access, handover material, restricted evidence and records supported by a specific legal or litigation reason. Article 17 provides exceptions to erasure, including where a legal obligation or the establishment, exercise or defence of legal claims requires storage.
A deletion concept should record more than periods. It should identify triggers, owners, technical routines, restrictions and the treatment of archives or backups. The dedicated article on former employee data provides more detail on departure situations.
Handle data subject requests inside the business
Employees can exercise GDPR rights as data subjects. This includes the right of access under Article 15. A business should have a process covering identity, systems, deadlines, participating functions and possible restrictions. A request must not disappear between HR, IT and the privacy function.
For access, the business must assess which personal data is processed and which information Article 15 requires. Rights and freedoms of other people, trade secrets or legal restrictions may matter. The response must therefore reflect the actual records and circumstances of the case.
The focus topic on data subject rights and access provides a general process. Employee data should also remain connected to the governance framework, processing records, policies and controls.
A workable process for businesses
Good employee data protection is not a single document. It connects HR, IT, managers, the privacy function, information security and, where needed, the works council. For each new processing activity, it should be clear who describes the purpose, which data is needed, which risks exist and how the decision is documented.
A focused legal and organisational review will usually benefit from the processing record, information notices, access model, deletion and retention rules, provider overview, policies, system description and relevant works agreements. These materials show whether the main issue concerns purpose, access, control, retention or co-determination.
We review the specific processing with you and organise the legal and operational steps so that HR, IT and managers can work with them. For new systems, a review before implementation is usually simpler than correcting ongoing analyses later.
Questions businesses ask about employee data protection
May an employer store all employee data? +
May a business monitor performance digitally? +
How long may personnel and employee data be retained? +
Can employees request access to their data? +
When must the works council be involved in a control system? +
Sources
- General Data Protection Regulation, in particular Articles 5, 6, 9, 13, 15, 17, 24, 25, 32 and 35
Foundations for purpose limitation, legal bases, special categories, information, access, erasure, security and impact assessments.
- Austrian Data Protection Act, in particular section 1
The Austrian framework for the protection of personal data.
- Austrian Labour Constitution Act, in particular sections 96 and 96a
Co-determination for certain control measures and automated systems at work.
- EDPB Guidelines 05/2020 on consent under Regulation 2016/679
The voluntariness of consent and dependency in the employment context.
- Austrian Data Protection Authority
Practical information from the Austrian supervisory authority.
Related topics
Employee data protection touches several processes. These topics deepen adjacent questions without repeating the lifecycle explained here.
Privacy compliance and governance
Responsibilities, processing records, policies and evidence in the business.
Data subject rights and access
Structure requests, identity checks, deadlines and copies of data.
Processors and service providers
Classify external providers and their access to employee data.
BRANDaktuelle Legal News
Subscribe to legal news
Receive new articles and legal information from the firm with BRANDaktuelle Legal News.
Subscribe to legal newsDiscuss employee data protection for your business
We review data flows, permissions, control systems, retention and the next organisational steps with you.
Clarify a data protection question
Address
BRANDAUER Rechtsanwälte GmbH Giselakai 51 5020 Salzburg Österreich
Phone
+43 662 6280000