Skip to main content

When employee consent is the start of the problem, not the end – the GDPR shows some teeth

The Greek Data Protection Authority has imposed a 150,000 EUR fine on PriceWaterhouseCoopers Business Solutions SA for – get this – asking their employees’ consent to process their personal data. It may strike you as counterintuitive (and going against everything your mother ever told you) that asking consent could get you into trouble, but where personal data are concerned, so it would appear to be.


As you know, each data processing activity has to have a legal basis. The principles of lawful, fair and transparent processing of personal data under the GDPR require that consent only be used as a legal basis only where the other legal bases do not apply.


The case at hand involved the processing of employees’ personal data. In most cases, this type of processing by an employer does not require consent, as there are other bases available:


  • the performance of the (employment) contract: in order to employ an employee, you will inevitably be required to process some of his personal data;

  • compliance with a legal obligation: e.g. as an employer, you will be required to register your employees with the local social security service or supply their earnings data to the tax authorities, etc.;

  • the employer’s legitimate interest, where the smooth and effective operation of the company requires processing of employee data regardless of whether consent is given.

Consent will only be the appropriate basis is a very limited number of cases, such as when you wish to process your employee’s biometric data (using fingerprint identification to have access to the premises, for example). In this respect, the Greek DPA reminds us of the fact that consent of employees usually cannot be regarded as genuinely freely given – a requirement for valid consent – due to the imbalance between the parties. In our view however, the GDPR has introduced some leniency to accept valid employee consent in certain circumstances, provided that Member State law or collective agreements allow it.


Why is this decision interesting for employers in Europe?


An immediate takeaway from this decision is to check your own privacy policy to make sure that you are not relying on consent as a legal basis where you shouldn’t be. At first glance the fine seems very substantial for what is in practice a purely technical breach (in the sense that PwC was fully entitled to process the same data about the same people in the same way for the same purpose, but merely on a different ground, and that there was no complaint that anyone had been disadvantaged in any practical sense by what it had done. However, commentary around the ruling seems to suggest that it could have been very much higher and that it still could be if PwC does not take the necessary corrective action in the 3 months given to it by the Greek PDA for that purpose. So if it is possible to be relaxed about the prospect of a fine of €150,000, don’t be – it could be very much more.


But while you are checking your policy, you may want to take this opportunity to also verify whether this policy meets the requirements of the GDPR in terms of your transparency obligation. For example, we discussed the legal basis for processing. Your privacy policy needs to inform the employees on which grounds you are processing their data. Does it?   If you do find gaps, the “necessary corrective action will be to amend the relevant, privacy statements and processing the particular data in question and to ensure that they are informed of this.


Other obligatory mentions which are often forgotten are the retention period for the data (or the criteria used to determine such period) and the fact that your employee has the right to lodge a complaint with the supervisory authority.


In practice we see that employers are sometimes reassured by the fact that “somewhere in the employment contract / employee handbook” there is a data protection clause, but quite often, this clause is not up to date and does not meet the requirements of the GDPR.   You might think also that the chances of any of your staff taking up the point, are negligible. You might be right, but it only takes one disgruntled member of staff to seek advice, or, as here, for the DPA to start the inquiry off its own back. Is it really worth that risk for the sake of an hour going back over your GDPR documentation?


This story may be a gentle reminder to check your policy, before the DPA does it for you ….

Comments

Popular posts from this blog

Gujarat Forestry Research Foundation (GFRF) Recruitment for Scientist Post 2019 apply

Gujarat Forestry Research Foundation (GFRF) has published an Advertisement for below mentioned Posts 2019. Other details like age limit, educational qualification, selection process, application fee and how to apply are given below. Posts  : Scientist (on contract) Total No. of Posts  : 01 Educational Qualification  : Please read Official Notification for Educational Qualification details. Age Limit  : 35 years as on 20-09-2019 Application Fee : Candidates have to pay Rs. 200/- + Rs. /- (Postal Charges)  through challan at the computer-based post office.  How to Apply :  Interested Candidates may Apply Online Through official Website. Notification : Click Here   Apply Online : Click Here     Important Dates : Starting Date of Online Application : 04-09-2019 Last Date to Apply Online : 20-09-2019 Last Date to Pay Fees in Post Office : 23-09-2019 maru gujarat rojgarjobnews Kapu meniya

Indian Army Recruitment Rally at Jamnagar for Soldier (GD) & Other Posts 2019

Indian Army has published an Advertisement for below mentioned Posts 2019. Other details like age limit, educational qualification, selection process, application fee and how to apply are given below in the advertisement. Posts : Soldier General Duty Soldier Technical Soldier Nursing Assistant/Nursing Assistant Veterinary Soldier Clerk/Store Keeper Technical/Inventory Management Soldier Tradesman (10th Pass) Soldier Tradesman (8th Pass) Soldier Pharma Educational Qualification : Soldier General Duty:  Class 10th/Matric pass with 45% marks in aggregate and 33% in each subject. For boards following grading system minimum of ‘D’ grade (33-40) in individual subjects OR grade which contains 33% and overall aggregate of C2 grade. Soldier Technical: 10+2/Intermediate Exam Pass in Science with Physics, Chemistry, Maths and English with 50% marks in aggregate and 40% in each subject Soldier Nursing Assistant/Nursing Assistant Veterinary: 10+2/Intermediate...

GPSC Recruitment For Account Officer, Project Manager, Law Officer, Horticulture Officer & Lecturer Posts 2019 Apply

Gujarat Public Service Commission has published an Advertisement for below mentioned Posts 2019. Other details like age limit, educational qualification, selection process, application fee and how to apply are given below. Posts : Law Officer: 02 Posts Vaidy Panchkarm:  15 Posts Lecturer (Homeopathy - Surgery): 01 Post Lecturer (Homeopathy - obstetrics-gynaecology): 01 Post Account Officer (Class-2): 40 Posts Horticulture Officer: 61 Posts Project Manager: 04 Posts Total No. of Posts: 124 Educational Qualification : Please read Official Notification for Educational Qualification details.  How to Apply : Interested Candidates may Apply Online Through official Website https://gpsc-ojas.gujarat.gov.in Advertisement :  Click Here     Notification :    Click Here     Apply Online :   Click Here Important Dates : Starting Date of Online Application : 24-09-2019 Last Date to Apply Online : 09-10-2019 Last Da...

IIT Gandhinagar Recruitment for Project Director & Project Manager Posts 2019

IIT Gandhinagar has published an Advertisement for below mentioned Posts 2019. Other details like age limit, educational qualification, selection process, application fee and how to apply are given below in the advertisement. Posts : Project Director Project Manager Educational Qualification : Please read Official Notification for Educational Qualification details. Selection Process:  Candidates will be selected based on an interview. How to Apply:  Interested Candidates may Apply Online Through official Website. Project Manager : Click Here Apply Online : Click Hare Important Dates: Last Date to Apply Online: Until the position is filled

NABARD Recruitment for Development Assistant Posts 2019 apply

National Agriculture & Rural Development Bank has published an Advertisement for below mentioned Posts 2019. Other details like age limit, educational qualification, selection process, application fee and how to apply are given below in the advertisement. Posts : Development Assistant (Group B’ Posts)-82 Posts Development Assistant (Hindi) (Group’B’ Posts)-09 Posts Total No. of Posts : 91 Educational Qualification : Development Assistant – Candidates having Graduation Degree in any stream with minimum 50% marks in aggregate (Gen/OBC), 33% marks in aggregate(SC/ST/PH/Ex –Service men) will be considered for this post. Development Assistant – Candidates having Graduation Degree in Hindi/English Medium with Hindi or English or any other optional subject with minimum 50% marks in aggregate(Gen/OBC) & 33% marks (SC/ST/PH/Ex-Servicemen) will be considered for this post. Please read Official Notification for More Educational Qualification details. Pay Scale ...