"Article 29 Data Protection Working Party (WP29) issued an opinion 2/2017 on data processing at work (the Opinion). The Opinion is an update/restatement of the WP29’s previous opinions (WP48 and WP55)." (lexology)
Contents
1 Executive summary ....................................................................................................................... 3
2. Introduction ................................................................................................................................... 3
3. The legal framework ..................................................................................................................... 4
3.1 Directive 95/46/EC—Data Protection Directive (“DPD”) ...................................................... 5
3.2 Regulation 2016/679—General Data Protection Regulation (“GDPR”) ................................. 8
4. Risks ............................................................................................................................................... 9
5. Proportionality assessment......................................................................................................... 10
6.
5.1 Processing operations during the recruitment process ........................................................... 11
5.2 Processing operations resulting from in-employment screening ........................................... 12
5.3 Processing operations resulting from monitoring ICT usage at the workplace ..................... 12
5.4 Processing operations resulting from monitoring ICT usage outside the workplace ............ 15
5.5 Processing operations relating to time and attendance .......................................................... 18
5.6 Processing operations using video monitoring systems ........................................................ 19
5.7 Processing operations involving vehicles used by employees .............................................. 19
5.8 Processing operations involving disclosure of employee data to third parties ...................... 21
5.9 Processing operations involving international transfers of HR and other employee data ..... 22
Conclusions and Recommendations .......................................................................................... 22
6.1 Fundamental rights ................................................................................................................ 22
6.2 Consent; legitimate interest ................................................................................................... 23
6.3 Transparency ......................................................................................................................... 23
6.4 Proportionality and data minimisation .................................................................................. 23
6.5 Cloud services, online applications and international transfers ............................................. 24