The entrepreneur needs the consent of the works council for every proposed decision to adopt, amend or withdraw an arrangement on facilities aimed at, or suitable for, observing or checking the presence, behaviour or performance of the persons working in the undertaking (personnel tracking systems: camera surveillance, email and internet monitoring, keystroke and screenshot tools, GPS and vehicle telematics, access badges and biometric time clocks, call recording, productivity scoring), insofar as it concerns all or a group of the persons working in the undertaking. The proposal is submitted in writing with reasons and expected consequences, consent follows at least one consultation meeting, and the entrepreneur states in writing which decision he took and from when he will implement it (27(2)); without consent or the cantonal court's permission the decision is void if the council invokes nullity in writing within one month (27(4) and (5)). The test is suitability, not intent: a facility capable of monitoring staff needs consent even if bought for another purpose. The Autoriteit Persoonsgegevens' 'OR-privacyboekje' gives test questions for personnel tracking systems; the GDPR (lawful basis, proportionality, transparency, a DPIA where the AP list requires one, such as covert camera surveillance by employers) applies on top of consent.
This control maps to 3 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 3 it maps to, and the evidence behind each claim, over MCP and REST.