Datenschutz am Arbeitsplatz (data protection in the workplace: GDPR and works council)
Data protection in the workplace in Austria: email monitoring, video surveillance, HR data and the works council. Engelbrecht Rechtsanwälte, Vienna, explains.

Definition
Data protection in the workplace means protecting the personal data of employees in connection with their employment. The legal basis is formed in particular by the EU General Data Protection Regulation (GDPR, in German DSGVO) and the Austrian Data Protection Act (DSG). Subject to the statutory requirements, employees have rights to transparency, access, rectification and erasure of their data. The works council also plays an important role: under § 96 para 1 no 3 ArbVG it must consent to control measures and technical control systems where these affect human dignity.
Scope of application
Data protection in the workplace is relevant in particular to the following measures:
- video surveillance and monitoring of emails or internet use
- GPS tracking of company vehicles and mobile devices
- biometric time recording systems
- use of HR software, AI-supported tools and digital performance appraisal systems
Legal basis
The statutory basis for data protection in the employment relationship is:
- GDPR (EU 2016/679): basic rules for the processing of personal data and the rights of data subjects
- DSG (Data Protection Act): supplementary Austrian data protection provisions
- § 96 ArbVG: consent of the works council to control measures that affect human dignity
- § 96a ArbVG: co-determination for certain systems for processing employee data and for staff appraisal systems
Deadlines
The following important time limits apply to data protection in the workplace:
- Access requests: The employer must generally respond within one month of receiving the request. For complex or numerous requests, an extension of up to two months is possible, provided the data subject is informed in good time (Art. 12 para 3 GDPR).
- Data breaches: A notifiable breach must be reported to the data protection authority without undue delay and, where possible, within 72 hours of becoming known (Art. 33 GDPR).
- Retention periods: These vary according to the category of data and the purpose of processing. Data must be erased when there is no permissible reason for retaining them any longer.
Rights and obligations
Rights:
The data protection rights of employees and the works council include:
- Employees: the right to access, rectification and, subject to the statutory requirements, erasure of their personal data
- Employees: the right to lodge a complaint with the Austrian data protection authority (DSB)
- Works council: co-determination rights for measures under §§ 96 and 96a ArbVG, where the respective requirements are met
Obligations of employers:
- transparent information for employees about the purposes, legal bases and key circumstances of data processing
- appropriate technical and organisational safeguards under Art. 32 GDPR
- keeping and updating a record of processing activities, where required by law
Common mistakes
The following mistakes frequently occur in workplace data protection:
- A control measure requiring consent is introduced without the consent of the works council. Whether data collected in this way may be used in proceedings must be assessed separately.
- Access requests from employees are ignored or answered late. A permissible extension of the time limit must also be communicated in good time.
- Data breaches are not checked to see whether they must be notified, or are not reported in time despite an existing risk.
- For potentially high-risk processing, such as certain biometric systems or extensive monitoring, the need for a data protection impact assessment is not examined.
Recommended steps
The following measures are recommended for organising the workplace in line with data protection law:
- When introducing control and data systems, check at an early stage whether the works council has rights under §§ 96 or 96a ArbVG.
- Appoint a data protection officer where this is required by law, and define clear responsibilities for data protection matters.
- Answer access requests from employees in a structured way and within the time limit.
- Review the record of processing activities regularly and update it where necessary.
Frequently asked questions
Any questions?
Questions about organising your control measures in line with data protection law, or about employees' access requests? We advise you on a sound legal footing.