Datenschutz am Arbeitsplatz (data protection in the workplace: GDPR and works council)

Data protection in the workplace in Austria: email monitoring, video surveillance, HR data and the works council. Engelbrecht Rechtsanwälte, Vienna, explains.

Datenschutz am Arbeitsplatz in Austria – GDPR, works council and rights | Engelbrecht

Definition

Data protection in the workplace means protecting the personal data of employees in connection with their employment. The legal basis is formed in particular by the EU General Data Protection Regulation (GDPR, in German DSGVO) and the Austrian Data Protection Act (DSG). Subject to the statutory requirements, employees have rights to transparency, access, rectification and erasure of their data. The works council also plays an important role: under § 96 para 1 no 3 ArbVG it must consent to control measures and technical control systems where these affect human dignity.

Scope of application

Data protection in the workplace is relevant in particular to the following measures:

  • video surveillance and monitoring of emails or internet use
  • GPS tracking of company vehicles and mobile devices
  • biometric time recording systems
  • use of HR software, AI-supported tools and digital performance appraisal systems

‍

Legal basis

The statutory basis for data protection in the employment relationship is:

  • GDPR (EU 2016/679): basic rules for the processing of personal data and the rights of data subjects
  • DSG (Data Protection Act): supplementary Austrian data protection provisions
  • § 96 ArbVG: consent of the works council to control measures that affect human dignity
  • § 96a ArbVG: co-determination for certain systems for processing employee data and for staff appraisal systems

‍

Deadlines

The following important time limits apply to data protection in the workplace:

  • Access requests: The employer must generally respond within one month of receiving the request. For complex or numerous requests, an extension of up to two months is possible, provided the data subject is informed in good time (Art. 12 para 3 GDPR).
  • Data breaches: A notifiable breach must be reported to the data protection authority without undue delay and, where possible, within 72 hours of becoming known (Art. 33 GDPR).
  • Retention periods: These vary according to the category of data and the purpose of processing. Data must be erased when there is no permissible reason for retaining them any longer.

‍

Rights and obligations

Rights:

The data protection rights of employees and the works council include:

  • Employees: the right to access, rectification and, subject to the statutory requirements, erasure of their personal data
  • Employees: the right to lodge a complaint with the Austrian data protection authority (DSB)
  • Works council: co-determination rights for measures under §§ 96 and 96a ArbVG, where the respective requirements are met

Obligations of employers:

  • transparent information for employees about the purposes, legal bases and key circumstances of data processing
  • appropriate technical and organisational safeguards under Art. 32 GDPR
  • keeping and updating a record of processing activities, where required by law

‍

Common mistakes

The following mistakes frequently occur in workplace data protection:

  1. A control measure requiring consent is introduced without the consent of the works council. Whether data collected in this way may be used in proceedings must be assessed separately.
  2. Access requests from employees are ignored or answered late. A permissible extension of the time limit must also be communicated in good time.
  3. Data breaches are not checked to see whether they must be notified, or are not reported in time despite an existing risk.
  4. For potentially high-risk processing, such as certain biometric systems or extensive monitoring, the need for a data protection impact assessment is not examined.

‍

Recommended steps

The following measures are recommended for organising the workplace in line with data protection law:

  1. When introducing control and data systems, check at an early stage whether the works council has rights under §§ 96 or 96a ArbVG.
  2. Appoint a data protection officer where this is required by law, and define clear responsibilities for data protection matters.
  3. Answer access requests from employees in a structured way and within the time limit.
  4. Review the record of processing activities regularly and update it where necessary.

Frequently asked questions

No items found.

Any questions?

Questions about organising your control measures in line with data protection law, or about employees' access requests? We advise you on a sound legal footing.