GDPR
Chapter IX - Specific Processing Situations

GDPR GDPR-Art.88: Processing in the context of employment

Article 88 is addressed to Member States: it lets national law or collective agreements set more specific rules for handling workers' personal data across the employment relationship, from hiring through the running of the contract, work organisation, equality, health and safety, protection of property and the exercise of employment rights, to its end. An employer therefore identifies, for every country in which it employs people, which national employment-context rules made under this article apply, and applies the safeguards those rules must contain for dignity, legitimate interests and fundamental rights: openness about the processing, data passed between companies in the same group, and any system used to monitor people at work. The article is not itself a lawful basis; the Article 6 basis, and an Article 9 condition where special category data is involved, is still needed (CJEU C-34/21 found that a national rule which only restates the general conditions of the Regulation is not a more specific rule under this article).

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 36 controls across 15 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • 3.1.1(d) 3.1.1(d) Limits on monitoring: places, data and time
  • 5.2(a) 5.2(a) No generalised screening of employees' social media during employment
  • 5.2(c) 5.2(c) Employees keep a private profile; no compulsory employer-provided profile
  • 5.3(e) 5.3(e) Involve a representative sample of employees, and the works council where the law requires it
  • 6.1 6.1 Owning the equipment does not remove employees' secrecy of communications; location tracking only where strictly necessary
  • L1121-1 L1121-1 Justify and proportion every restriction on rights and freedoms
  • L1222-4 L1222-4 Collect no personal information on an employee through a device not previously disclosed
  • L2312-38 al2 L2312-38 al2 Inform the CSE before introducing automated personnel-management processing and before changing it
  • L2312-38 al3 L2312-38 al3 Inform and consult the CSE before deciding to implement any means or technique for controlling employees' activity
  • s26-1 s 26(1) sentence 1 Process employee data only where necessary for the employment relationship, on a GDPR legal basis
  • s26-1-s2 s 26(1) sentence 2 Investigate suspected crimes by employees only on documented suspicion and proportionately
  • s26-4 s 26(4) Where a collective or works agreement governs employee data, meet GDPR Art. 88(2)
  • s75-2 s 75(2) Protect and promote employees' free development of personality
  • s77-1-2 s 77(1), (2) Implement agreements with the council, record works agreements in writing and display them
  • s87-1-6 s 87(1) no. 6 Co-determine the introduction and use of technical devices capable of monitoring employees' conduct or performance
  • 12.2(b) 12.2(b) Inform and consult representatives before introducing electronic monitoring
  • 6.14(1) 6.14(1) Tell workers in advance about monitoring and minimize intrusion
  • 6.14(2) 6.14(2) Secret monitoring only where lawful or on reasonable suspicion
  • Art. 111 Art. 111 Follow the Garante's rules of ethics for employment processing, including on information to workers
  • Art. 114 Art. 114 Apply the Workers' Statute art. 4 guarantees to any remote monitoring
  • Art. 115(1) Art. 115(1) Respect the personality and moral freedom of domestic, remote and agile workers
  • Art. 2(3) Art. 2(3) Do not use security guards to supervise work
  • Art. 4(1) Art. 4(1) Install remote-monitoring equipment only for permitted purposes and after a union agreement or labour inspectorate authorisation
  • Art. 4(3) Art. 4(3) Give workers adequate information before using monitoring data, and comply with the data protection code
  • ACT-6 ACT-6 Submit the device to the staff representative bodies before implementation
  • VID-10 VID-10 Inform and consult the staff representative bodies before deciding to install cameras
  • 3.3(b) 3.3(b) Employers should not rely on consent; employment-specific rules may come from national law or works agreements
  • 5(c) 5(c) An employer must not use footage of a demonstration to identify strikers
  • 30(1) Art. 30(1) Process employee health data only as necessary for statutory, pension or collective-agreement entitlements or for reintegration
  • 33(3) Art. 33(3) Process criminal-offence data about staff only under rules adopted through the works council procedure
  • 27(1)(k) Art. 27(1)(k) Obtain the works council's consent to a staff arrangement: processing and protection of staff personal data
  • 27(1)(l) Art. 27(1)(l) Obtain the works council's consent to a staff arrangement: personnel tracking systems (monitoring of presence, behaviour or performance)
  • 13 s 13 Written notice of surveillance, 14 days ahead, with the required content
  • 31-48d(b)(2) 31-48d(b)(2) Monitor without prior notice only on reasonable grounds of misconduct
  • s10 s 10 Written notice of surveillance at least 14 days before it starts
  • 41.1.1(2) para 1.ii 41.1.1(2) para 1 ii State the purposes for which monitoring information may be used

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

You are reading one control. How much of GDPR have you already done?

GDPR GDPR-Art.88 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of GDPR your existing evidence covers. Hold ISO 27701:2019 and 21 of 41 GDPR controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the ISO 27701:2019 pair alone.

Query this from an agent

The graph holds this control, the 36 it maps to, and the evidence behind each claim, over MCP and REST.