Back to Frameworks

Article 29 Working Party Opinion 2/2017 on Data Processing at Work (WP249)

European Union and EEA
vWP 249, Opinion 2/2017, adopted 8 June 2017 (the only version; EDPB Opinion 12/2018 of 25 September 2018 states it remains valid)
5 domains
41 controls

The Article 29 Working Party's opinion on employee monitoring under EU data protection law: consent almost never works at work, legitimate interest needs a necessary, least intrusive and time, place and data-limited method, workers must be told what is monitored and why, and nine scenarios from social media screening and TLS inspection to keystroke logging, BYOD, wearables, CCTV analytics and vehicle tracking with a private-use switch. Guidance, not law; the EDPB has said it remains valid. Built from the complete English text.

Verified

Article 29 Working Party Opinion 2/2017 on Data Processing at Work (WP249) is a compliance framework from European Union and EEA with 5 domains and 41 controls that map to 1 other frameworks. The largest domains are Section 3: Principles, legal grounds and GDPR duties for employers – Article 29 Working Party Opinion 2/2017 on Data Processing at Work (WP249) (13 controls), Sections 5.3 and 5.4: Monitoring ICT use at and outside the workplace – Article 29 Working Party Opinion 2/2017 on Data Processing at Work (WP249) (13 controls), Sections 4, 5.1 and 5.2: Further processing, recruitment and in-employment screening – Article 29 Working Party Opinion 2/2017 on Data Processing at Work (WP249) (6 controls). Every control below carries what it requires and what an assessor expects to see.

Maintained by Gerard Blokdyk

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (5)

Section 3: Principles, legal grounds and GDPR duties for employers – Article 29 Working Party Opinion 2/2017 on Data Processing at Work (WP249)

13 controls
Controls in the Section 3: Principles, legal grounds and GDPR duties for employers – Article 29 Working Party Opinion 2/2017 on Data Processing at Work (WP249) domain of Article 29 Working Party Opinion 2/2017 on Data Processing at Work (WP249) — 13 controls
CodeTitle
article-29-working-party-opinion-2-2017-on-data-processing-at-work-wp249::3.1(a)3.1(a) Specified, legitimate purposes and data that are adequate, relevant and not excessive
article-29-working-party-opinion-2-2017-on-data-processing-at-work-wp249::3.1(b)3.1(b) Proportionality and subsidiarity, whatever the legal ground, tested before monitoring starts
article-29-working-party-opinion-2-2017-on-data-processing-at-work-wp249::3.1(c)3.1(c) Let workers exercise access, rectification, erasure and blocking
article-29-working-party-opinion-2-2017-on-data-processing-at-work-wp249::3.1(d)3.1(d) Accurate data kept no longer than needed, with a set retention period
article-29-working-party-opinion-2-2017-on-data-processing-at-work-wp249::3.1(e)3.1(e) Security of monitoring data and staff awareness of data protection duties
article-29-working-party-opinion-2-2017-on-data-processing-at-work-wp249::3.1.1(a)3.1.1(a) Consent is not the legal ground for most processing at work; default settings are not consent
article-29-working-party-opinion-2-2017-on-data-processing-at-work-wp249::3.1.1(b)3.1.1(b) Contract and legal obligation as grounds, with workers fully informed of legally required processing
article-29-working-party-opinion-2-2017-on-data-processing-at-work-wp249::3.1.1(c)3.1.1(c) Legitimate interest: a legitimate purpose, a necessary and least intrusive method, a demonstrated balance
article-29-working-party-opinion-2-2017-on-data-processing-at-work-wp249::3.1.1(d)3.1.1(d) Limits on monitoring: places, data and time
article-29-working-party-opinion-2-2017-on-data-processing-at-work-wp249::3.1.23.1.2 Tell workers that monitoring exists, why, and what else fairness requires
article-29-working-party-opinion-2-2017-on-data-processing-at-work-wp249::3.1.33.1.3 No decision based solely on automated evaluation of work performance without a permitted ground
article-29-working-party-opinion-2-2017-on-data-processing-at-work-wp249::3.2.13.2.1 Data protection by design and default in monitoring devices and tools
article-29-working-party-opinion-2-2017-on-data-processing-at-work-wp249::3.2.23.2.2 Data protection impact assessment for high-risk monitoring and prior consultation if residual risk stays high

Sections 4, 5.1 and 5.2: Further processing, recruitment and in-employment screening – Article 29 Working Party Opinion 2/2017 on Data Processing at Work (WP249)

6 controls
Controls in the Sections 4, 5.1 and 5.2: Further processing, recruitment and in-employment screening – Article 29 Working Party Opinion 2/2017 on Data Processing at Work (WP249) domain of Article 29 Working Party Opinion 2/2017 on Data Processing at Work (WP249) — 6 controls
CodeTitle
article-29-working-party-opinion-2-2017-on-data-processing-at-work-wp249::44 No incompatible further use of monitoring data
article-29-working-party-opinion-2-2017-on-data-processing-at-work-wp249::5.1(a)5.1(a) Recruitment: social media and public data only with a legal ground, when relevant to the job, and with prior notice
article-29-working-party-opinion-2-2017-on-data-processing-at-work-wp249::5.1(b)5.1(b) Recruitment data deleted once no offer is made or it is declined
article-29-working-party-opinion-2-2017-on-data-processing-at-work-wp249::5.2(a)5.2(a) No generalised screening of employees' social media during employment
article-29-working-party-opinion-2-2017-on-data-processing-at-work-wp249::5.2(b)5.2(b) No demand for access to what employees or applicants share on social networks
article-29-working-party-opinion-2-2017-on-data-processing-at-work-wp249::5.2(c)5.2(c) Employees keep a private profile; no compulsory employer-provided profile

Sections 5.3 and 5.4: Monitoring ICT use at and outside the workplace – Article 29 Working Party Opinion 2/2017 on Data Processing at Work (WP249)

13 controls
Controls in the Sections 5.3 and 5.4: Monitoring ICT use at and outside the workplace – Article 29 Working Party Opinion 2/2017 on Data Processing at Work (WP249) domain of Article 29 Working Party Opinion 2/2017 on Data Processing at Work (WP249) — 13 controls
CodeTitle
article-29-working-party-opinion-2-2017-on-data-processing-at-work-wp249::5.3(a)5.3(a) Network and TLS inspection tuned to prevent permanent logging of employee activity
article-29-working-party-opinion-2-2017-on-data-processing-at-work-wp249::5.3(b)5.3(b) Exclude sensitive traffic from inspection and tell employees what is monitored
article-29-working-party-opinion-2-2017-on-data-processing-at-work-wp249::5.3(c)5.3(c) Policy on who may access suspicious log data and when, reviewed at least annually
article-29-working-party-opinion-2-2017-on-data-processing-at-work-wp249::5.3(d)5.3(d) Acceptable use and privacy policies implemented and communicated before monitoring
article-29-working-party-opinion-2-2017-on-data-processing-at-work-wp249::5.3(e)5.3(e) Involve a representative sample of employees, and the works council where the law requires it
article-29-working-party-opinion-2-2017-on-data-processing-at-work-wp249::5.3(f)5.3(f) Data loss prevention: transparent rules and a warning before an email is blocked
article-29-working-party-opinion-2-2017-on-data-processing-at-work-wp249::5.3(g)5.3(g) Private spaces in employer-provided online applications
article-29-working-party-opinion-2-2017-on-data-processing-at-work-wp249::5.3(h)5.3(h) Prefer prevention to detection: block rather than monitor
article-29-working-party-opinion-2-2017-on-data-processing-at-work-wp249::5.4.15.4.1 Home and remote working: no keystroke, mouse, screen or webcam capture
article-29-working-party-opinion-2-2017-on-data-processing-at-work-wp249::5.4.2(a)5.4.2(a) Bring your own device: separate private from business use and keep out of private areas
article-29-working-party-opinion-2-2017-on-data-processing-at-work-wp249::5.4.2(b)5.4.2(b) Bring your own device: secure the employer's data, weigh monitoring during personal use, or bar private use
article-29-working-party-opinion-2-2017-on-data-processing-at-work-wp249::5.4.35.4.3 Mobile device management: DPIA first, a specified purpose, tracking held back until a device is lost
article-29-working-party-opinion-2-2017-on-data-processing-at-work-wp249::5.4.45.4.4 Wearables: health and activity data stay with the employee

Sections 5.5 to 5.7: Time and attendance, video and vehicles – Article 29 Working Party Opinion 2/2017 on Data Processing at Work (WP249)

6 controls
Controls in the Sections 5.5 to 5.7: Time and attendance, video and vehicles – Article 29 Working Party Opinion 2/2017 on Data Processing at Work (WP249) domain of Article 29 Working Party Opinion 2/2017 on Data Processing at Work (WP249) — 6 controls
CodeTitle
article-29-working-party-opinion-2-2017-on-data-processing-at-work-wp249::5.55.5 Time and attendance and access control: informed, necessary, and not reused for performance evaluation
article-29-working-party-opinion-2-2017-on-data-processing-at-work-wp249::5.65.6 Video monitoring: no video analytics of expressions or movements, no facial recognition
article-29-working-party-opinion-2-2017-on-data-processing-at-work-wp249::5.7(a)5.7(a) Vehicle tracking: necessary, proportionate, with a private-use opt-out and no evaluation of drivers
article-29-working-party-opinion-2-2017-on-data-processing-at-work-wp249::5.7(b)5.7(b) Tell drivers a tracker is fitted and that movements, and possibly driving behaviour, are recorded; notice in the vehicle
article-29-working-party-opinion-2-2017-on-data-processing-at-work-wp249::5.7(c)5.7(c) No location monitoring outside agreed working hours, save a proportionate theft safeguard
article-29-working-party-opinion-2-2017-on-data-processing-at-work-wp249::5.7.15.7.1 Event data recorders and in-cab cameras: only where necessary and proportionate; no continuous recording of drivers

Sections 5.8, 5.9 and 6: Disclosure, transfers and fundamental rights – Article 29 Working Party Opinion 2/2017 on Data Processing at Work (WP249)

3 controls
Controls in the Sections 5.8, 5.9 and 6: Disclosure, transfers and fundamental rights – Article 29 Working Party Opinion 2/2017 on Data Processing at Work (WP249) domain of Article 29 Working Party Opinion 2/2017 on Data Processing at Work (WP249) — 3 controls
CodeTitle
article-29-working-party-opinion-2-2017-on-data-processing-at-work-wp249::5.85.8 Disclosure of employee data to customers only where proportionate
article-29-working-party-opinion-2-2017-on-data-processing-at-work-wp249::5.95.9 International transfers of HR and monitoring data: adequacy preferred, minimum data, limited group access
article-29-working-party-opinion-2-2017-on-data-processing-at-work-wp249::6.16.1 Owning the equipment does not remove employees' secrecy of communications; location tracking only where strictly necessary

Maps to 1 other framework

41 total controls
GDPR
41 source controls mapped|17 target controls covered
100%

Coverage is not the same as your position

This page shows what Article 29 Working Party Opinion 2/2017 on Data Processing at Work (WP249) overlaps with in general. Where your organisation actually stands, against the standard you are going for and the certifications you already hold, is a different question. Same graph and the same recorded refutations, scoped to you rather than to a pair.

The Compliance Position Diagnostic, $5,000 fixed, ten business days

What is Article 29 Working Party Opinion 2/2017 on Data Processing at Work (WP249) and who does it apply to?

Article 29 Working Party Opinion 2/2017 on Data Processing at Work (WP249) is a compliance framework from European Union and EEA with 5 domains and 41 controls. The Article 29 Working Party's opinion on employee monitoring under EU data protection law: consent almost never works at work, legitimate interest needs a necessary, least intrusive and time, place and data-limited method, workers must be told what is monitored and why, and nine scenarios from social media screening and TLS inspection to keystroke logging, BYOD, wearables, CCTV analytics and vehicle tracking with a private-use switch. Guidance, not law; the EDPB has said it remains valid. Built from the complete English text. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

What does Article 29 Working Party Opinion 2/2017 on Data Processing at Work (WP249) actually require?

Article 29 Working Party Opinion 2/2017 on Data Processing at Work (WP249) has 41 controls organised across 5 domains. The largest domains are Section 3: Principles, legal grounds and GDPR duties for employers – Article 29 Working Party Opinion 2/2017 on Data Processing at Work (WP249) (13 controls), Sections 5.3 and 5.4: Monitoring ICT use at and outside the workplace – Article 29 Working Party Opinion 2/2017 on Data Processing at Work (WP249) (13 controls), Sections 4, 5.1 and 5.2: Further processing, recruitment and in-employment screening – Article 29 Working Party Opinion 2/2017 on Data Processing at Work (WP249) (6 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

If I already comply with another framework, how much of Article 29 Working Party Opinion 2/2017 on Data Processing at Work (WP249) do I already cover?

Article 29 Working Party Opinion 2/2017 on Data Processing at Work (WP249) maps to 1 other compliance frameworks. The top mapping partners are GDPR (100% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I implement Article 29 Working Party Opinion 2/2017 on Data Processing at Work (WP249)?

Start your Article 29 Working Party Opinion 2/2017 on Data Processing at Work (WP249) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Article 29 Working Party Opinion 2/2017 on Data Processing at Work (WP249) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 41 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 844 frameworks.

Get Started Free →

Free forever — no credit card required