Article 29 Working Party Opinion 2/2017 on Data Processing at Work (WP249)
Sections 5.3 and 5.4: Monitoring ICT use at and outside the workplace – Article 29 Working Party Opinion 2/2017 on Data Processing at Work (WP249)

Article 29 Working Party Opinion 2/2017 on Data Processing at Work (WP249) 5.4.4: 5.4.4 Wearables: health and activity data stay with the employee

Workplace wearables that track health and activity process health data, which is prohibited without an exception, and valid explicit consent is highly unlikely given workers' dependence on the employer; aggregated reporting through a third party does not cure this, because anonymisation is hard and individuals can be singled out. Health data from devices offered to staff should be accessible to the employee only, and the employer should check the manufacturer's or provider's privacy policy before choosing a device.

Maintained by Gerard Blokdyk

What else in your programme already covers this

This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

GDPR · 1 control

  • GDPR-Art.9 Processing of special categories of personal data

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Sections 5.3 and 5.4: Monitoring ICT use at and outside the workplace – Article 29 Working Party Opinion 2/2017 on Data Processing at Work (WP249)

Query this from an agent

The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.