Employee data protection: what employers can and cannot do

·

When a company hires someone, it gains access to a significant amount of personal data: name, national ID, bank account number, employment history, health data for the occupational mutual, trade-union information in some cases, and geolocation data if a company vehicle is used. The temptation to treat that data with the same freedom as any other internal resource is understandable, but it is a costly mistake. Regulation (EU) 2016/679 (GDPR) and Spain's Organic Law 3/2018 on Data Protection and Digital Rights Guarantee (LOPDGDD) establish a specific framework for the employment context that every company — regardless of size — is required to respect.

This guide answers, in question-and-answer format, the most frequent queries raised by companies in Castilla y León and the Canary Islands when trying to understand what they may and may not do with their employees' data.

What data may be processed, and on what legal basis?

Article 6 of the GDPR requires every processing activity to have a legal basis. In the employment context, the three most commonly applicable bases are:

Consent is rarely the appropriate basis in the employment relationship. The AEPD has stated in numerous resolutions that the power imbalance between employer and employee means that consent given in that context can hardly be considered freely given, rendering it invalid as a legal basis.

What information must employees receive?

The GDPR (Arts. 13–14) requires the controller to inform the data subject before processing begins. In practice, this means the company must provide each employee — at the time of hiring and in writing — an information notice covering:

This information may not be buried in the employment contract or drafted in generic terms. Failure to comply with the information obligation is itself a sanctionable infringement.

What rights do employees have over their data?

Articles 15 to 22 of the GDPR recognise for employees the same rights as for any other individual, with some specificities in the employment context:

The company must respond to all these rights within one month. Failing to respond, or responding late, is a directly sanctionable infringement.

Can the company monitor employees' email and devices?

This is one of the most frequently asked questions — and the one that has generated the most AEPD resolutions and Supreme Court judgments. The answer is neither a simple yes nor a simple no: it depends on how it is done.

Article 87 of the LOPDGDD recognises employees' right to privacy when using digital devices provided by the company. It establishes that employers may set usage rules — including access to content to verify compliance with labour obligations — but only if employees have been clearly informed in advance of what use is permitted and that monitoring is possible.

The consolidated case law of the European Court of Human Rights (Barbulescu II, 2017) and Spain's Constitutional Court requires that employer monitoring meet three requirements:

  1. Suitability: the measure is appropriate for a legitimate control purpose.
  2. Necessity: no less invasive measure would achieve the same result.
  3. Strict proportionality: the benefit to the company outweighs the cost to the employee's privacy.

Without prior information and a documented usage policy, monitoring of devices or corporate email may be declared invalid as evidence in disciplinary or judicial proceedings.

When is workplace video surveillance lawful?

Article 89 of the LOPDGDD governs the use of cameras for labour control purposes. The requirements are cumulative: the company must inform employees and their representatives in advance of the existence of cameras, their purpose and location; cameras may not be installed in rest areas, changing rooms, toilets or other private spaces; and recordings may only be retained for the time necessary, with a maximum of one month unless they relate to an ongoing disciplinary or judicial investigation.

A visible warning sign is mandatory even where employees have already been individually informed. The AEPD has sanctioned companies that had cameras without signage, even when those cameras were used solely for access control and not for performance monitoring.

May the company use geolocation systems in vehicles or devices?

Article 90 of the LOPDGDD permits the use of geolocation systems to monitor employees' work activity, but with conditions equivalent to those for video surveillance: clear prior information (purpose, retention period, access to data), limitation to working hours, and proportionality with the objective pursued.

A transport or home-care company may geolocate its vehicles to manage routes and verify timings. What it may not do is use that data to sanction an employee for conduct occurring outside their working hours, or without having informed them of that possibility.

What about the right to digital disconnection?

Article 88 of the LOPDGDD recognises the right to digital disconnection outside working hours. This means the company cannot — directly or indirectly — demand availability outside the employee's working day or process data relating to the employee's connectivity or activity during that period. Companies with more than 250 employees or those required to negotiate an equality plan must draw up an internal disconnection policy, preferably agreed with employee representatives.

Can employees' health data be processed?

Health data is a special category (Art. 9 GDPR) that may only be processed in specific cases. In the employment context, the usual bases are:

The HR manager has no right to access an employee's diagnosis. They may only know the fitness verdict (fit/unfit, with or without restrictions) issued by the occupational health service. Sharing more information between internal departments constitutes a breach of special-category data rules, with the aggravating circumstances that entails under the sanctions framework in Article 83 of the GDPR.

What sanctions may the AEPD impose?

Article 83 of the GDPR establishes a two-tier sanctions framework, without setting automatic amounts: the severity of the infringement, intent, number of individuals affected, measures taken to mitigate damage, and cooperation with the supervisory authority are all factors the AEPD weighs in each case. The most serious infringements — such as processing data without a legal basis, failing to respect data subjects' rights, or breaching special-category data safeguards — fall into the higher tier. The AEPD publishes its resolutions openly, creating a reputational risk that goes beyond the purely financial.

How should the company manage data when the employment relationship ends?

When a contract is terminated, the company may not retain the former employee's data indefinitely. The general rule is to retain only what statutory obligations require — four years for tax and social security obligations, one year for labour inspection records, the applicable limitation period for potential claims — and to erase or block the rest. The former employee's corporate email account must be deactivated within a reasonable time, and stored messages may not be accessed without justified cause.

Where a video surveillance system is in use, recordings featuring the former employee are subject to the maximum one-month retention period, unless they relate to an ongoing proceeding.

What role does the payroll firm or external adviser play?

When a company outsources payroll management to an advisory firm or accountancy practice, that firm becomes a processor within the meaning of Article 28 of the GDPR. This means the relationship must be formalised through a data processing agreement covering, as a minimum: the controller's instructions, confidentiality obligations for the processor's staff, required security measures, prohibition on sub-processing without prior authorisation, assistance with the exercise of data subjects' rights, and return or destruction of data on termination of the service. Without that agreement, both parties are in breach of the GDPR.

Can Summum Consultoría help?

GDPR compliance in the employment context combines data protection law, labour law, and in many cases collective bargaining. It cannot be resolved with a template clause downloaded from the internet. At Summum Consultoría, we accompany companies through GDPR and LOPDGDD compliance: we review existing processing activities, draft the necessary documentation — records of processing activities, information notices, data processing agreements, device usage policies — and train HR teams in their specific obligations. Our work is to help companies comply; the final decision on each processing activity always rests with the company as the data controller. For data protection questions that require a dedicated function, you may also be interested in our external Data Protection Officer service.