Privacy
Focus topic

Employee data protection

Organise employee data from recruitment to departure, limit access and document workplace controls in a comprehensible way.

BRANDAUER Rechtsanwälte
Contact person

Mag. Bernhard Brandauer, Rechtsanwalt

BRANDAUER Rechtsanwälte

Mag. Bernhard Brandauer advises businesses on the legal classification and practical implementation of data protection requirements.

Employee data protection accompanies the entire employment relationship. Recruitment involves applications and contact details. During employment, the data may include working time, absences, pay, communication, performance and access logs. When employment ends, handover, account blocking, deletion and statutory retention must be kept separate.

This focus topic addresses the organisational framework for businesses in Austria. It does not replace an assessment of a particular employment process or monitoring system. The dedicated articles on digital employee monitoring, AI at work and former employee data therefore provide deeper treatment of those specific situations.

For a business, the topic also connects with privacy governance, the assessment of external providers and a documented response to personal data breaches. This focus remains on employee data and its lifecycle.

Verfasst von Mag. Bernhard Brandauer, Rechtsanwalt

First orientation

Where is your current review need?

Three short questions help identify the next organisational step for employee data.

01 Question 1

Are access rights to employee data limited by role and task?

Look beyond HR and include managers, IT, payroll and external providers.

Ergebnis

Ihre Orientierung

01

Organise permissions first

Map which roles need which data for which task. Remove rights that are no longer required, document approvals and schedule regular reviews. More sensitive data requires tighter access control.
Review governance and responsibility →
02

Separate retention by purpose

Create an overview by data category and processing purpose. Record which statutory duty or specific claim supports continued storage and when data should be deleted, anonymised or made accessible only on a restricted basis.
Read about former employee data →
03

Classify control systems before use

Describe the purpose and the specific analysis before focusing on technical capability. Review necessity, proportionality, alternatives, access rights and whether the works council has a role.
Read about employee monitoring →
04

The framework is broadly prepared

Keep the review active when circumstances change. New software, organisational changes, providers, incidents and departures should trigger a fresh check of purpose, access and retention.
Connect the privacy governance framework →
Employee data lifecycle

Which question arises at which stage?

The legal assessment changes when purpose, role, access or the reason for retention changes. The process should therefore not begin only when employment starts.

Which question arises at which stage?
Stage Typical data and questions Organisational focus
Recruitment and entry Applications, contact details, qualifications, identity and contract data Limit purpose, provide information and define access
Employment Working time, pay, absence, communication, performance and security data Review roles, necessity, security and controls
Changes New software, remote work, provider, location or new analysis Clarify privacy review and potential co-determination first
Departure and handover Account blocking, handover, contact and evidence data End active rights and assess retention separately
After departure Statutory records, claims, evidence and archived data Control deletion, restriction and access over time

The data needed and the period for which it may be retained depend on purpose, legal basis and the circumstances of the employment relationship.

Organise employee data by purpose and legal basis

Processing employee data requires a defined purpose and an appropriate legal basis. Article 5 GDPR requires, among other things, lawfulness, purpose limitation and data minimisation. Article 6 lists legal bases for personal data. Special categories, such as health data, are subject to the additional requirements of Article 9.

For each material HR process, the business should record which data is actually needed, who provides it, who uses it and when the purpose ends. A field retained for convenience is not necessary merely because the system can store it. Recruitment, sickness, performance assessment and internal reports deserve separate analysis.

The information provided under Articles 13 or 14 GDPR should reflect the actual process. General notices may not be enough when new analysis tools, control systems or external platforms are introduced.

  • Describe purpose and data category for each HR process.
  • Assess the legal basis and any special category separately.
  • Collect only data necessary for the specific purpose.
  • Update information when a material process changes.

Access rights must match the task

Employee data is often stored in payroll, time recording, recruitment, sickness, document and communication systems. Access should not follow from department membership alone. Article 32 GDPR requires a level of security appropriate to the risk. This includes organisational rules that limit and review permissions.

A workable access model describes roles, categories, approval, removal and substitution. Payroll needs different information from a manager. IT administrators may have broad technical rights without automatically becoming the function entitled to inspect every personnel record. Logs can support controls, but they should not be collected indefinitely without a defined purpose and clear access to the analysis.

At departure, the process must react quickly and in coordination. Accounts, keys, mobile devices, shared folders and external access need review. That is separate from deciding which documents must be retained for statutory duties or specific claims.

Control systems do not automatically permit monitoring

Time recording, GPS, video, login logs, communications and performance analytics can serve different purposes. Technical availability does not mean that every analysis is lawful. Before implementation, the business should describe the purpose, data volume, affected people, authorised users and deletion logic. Continuous behavioural or performance monitoring is particularly intrusive.

Employment law may apply alongside the GDPR. Section 96(1)(3) of the Austrian Labour Constitution Act addresses control measures and technical systems for monitoring employees where they affect human dignity. Section 96a contains separate rules for certain automated systems processing employee data. Whether works council consent is needed can therefore only be assessed from the concrete system and its effects.

The dedicated article on monitoring employees with software examines that situation. AI systems at work also raise questions about purpose, training data, evaluation and works agreements, addressed in the article on AI at work.

  • Document the purpose and analysis before selecting a control system.
  • Assess necessity and less intrusive alternatives.
  • Limit access to raw data and results to defined roles.
  • Start privacy review and possible works council involvement early.

Distinguish retention, deletion and restriction

The GDPR does not provide one retention period for all employee data. Article 5(1)(e) limits storage to what is necessary. Employment, tax, social security and corporate law duties, as well as specific claims, may support continued retention. The reason should be recorded for each data category.

At departure, the whole personnel file should not be deleted immediately, but the entire account should not be archived without a time limit either. A sound process separates active access, handover material, restricted evidence and records supported by a specific legal or litigation reason. Article 17 provides exceptions to erasure, including where a legal obligation or the establishment, exercise or defence of legal claims requires storage.

A deletion concept should record more than periods. It should identify triggers, owners, technical routines, restrictions and the treatment of archives or backups. The dedicated article on former employee data provides more detail on departure situations.

Handle data subject requests inside the business

Employees can exercise GDPR rights as data subjects. This includes the right of access under Article 15. A business should have a process covering identity, systems, deadlines, participating functions and possible restrictions. A request must not disappear between HR, IT and the privacy function.

For access, the business must assess which personal data is processed and which information Article 15 requires. Rights and freedoms of other people, trade secrets or legal restrictions may matter. The response must therefore reflect the actual records and circumstances of the case.

The focus topic on data subject rights and access provides a general process. Employee data should also remain connected to the governance framework, processing records, policies and controls.

A workable process for businesses

Good employee data protection is not a single document. It connects HR, IT, managers, the privacy function, information security and, where needed, the works council. For each new processing activity, it should be clear who describes the purpose, which data is needed, which risks exist and how the decision is documented.

A focused legal and organisational review will usually benefit from the processing record, information notices, access model, deletion and retention rules, provider overview, policies, system description and relevant works agreements. These materials show whether the main issue concerns purpose, access, control, retention or co-determination.

We review the specific processing with you and organise the legal and operational steps so that HR, IT and managers can work with them. For new systems, a review before implementation is usually simpler than correcting ongoing analyses later.

Frequently asked questions

Questions businesses ask about employee data protection

May an employer store all employee data? +
No. Processing requires a defined purpose and an appropriate legal basis. Under the GDPR principles, only data necessary for that purpose may be processed and retained. Statutory retention duties or specific claims may justify continued storage of particular records.
May a business monitor performance digitally? +
This depends on the specific system, purpose, scope and effects. Technical capability is not enough. Necessity, proportionality, access rights, information and possible works council involvement should be assessed before implementation.
How long may personnel and employee data be retained? +
There is no single period for all employee data. The period depends on purpose, statutory duty and specific legal claims. A deletion concept should assign categories, triggers, reasons, access and deletion or restriction.
Can employees request access to their data? +
Yes. The right of access under Article 15 GDPR can cover employee data. The business must identify the request, check identity, search relevant systems and consider the rights of others or legal restrictions. The answer should reflect the actual records.
When must the works council be involved in a control system? +
This depends on the concrete system and its effects. Section 96(1)(3) of the Austrian Labour Constitution Act covers control measures and technical systems affecting human dignity. Section 96a contains separate rules for certain automated employee data systems. Review before implementation prevents late involvement.

Sources

BRANDaktuelle Legal News

Subscribe to legal news

Receive new articles and legal information from the firm with BRANDaktuelle Legal News.

Subscribe to legal news

Discuss employee data protection for your business

We review data flows, permissions, control systems, retention and the next organisational steps with you.

Contact

Clarify a data protection question

Address

BRANDAUER Rechtsanwälte GmbH Giselakai 51 5020 Salzburg Österreich