Data Protection

Subscribe to Data Protection RSS Feed

Belgian Ministry of Employment blows hot and cold on pre-return temperature checks

In an attempt to keep Covid-19 out of the workplace, many employers have been inquiring about the possibility of performing temperature checks before employees enter their premises each day. The Belgian Ministry of Employment’s position until last week was fairly relaxed: its FAQ document referred to the stance taken by the Belgian Data Protection Authority, … Continue Reading

The Australian Government wants workplaces to be “COVID-safe”, but this doesn’t mean employers can require employees to download the COVIDSafe App

In a bid to reawaken the Australian economy, the Federal Government is developing a return to work health and safety “toolkit” and is encouraging workplaces to become “COVID-safe”. At the same time, the Government is continuing to encourage the public to download its COVIDSafe digital contact-tracing App.… Continue Reading

New York Strengthens Data Privacy and Security Protections: Employers Must Adopt Safeguards (US)

Joining the growing list of states enacting privacy and data security laws, on July 25, 2019, New York’s governor signed into law the “Stop Hacks and Improve Electronic Data Security” Act (the “SHIELD Act”), amending the state’s data breach notification and cybersecurity law. The SHIELD Act applies to “any person or business that owns … … Continue Reading

When employee consent is the start of the problem, not the end – the GDPR shows some teeth

The Greek Data Protection Authority has imposed a 150,000 EUR fine on PriceWaterhouseCoopers Business Solutions SA for – get this – asking their employees’ consent to process their personal data. It may strike you as counterintuitive (and going against everything your mother ever told you) that asking consent could get you into trouble, but where … Continue Reading

Employee Data Subject Access Requests in the UK: Part 4 – how to deal with mixed data

In part 1 of this blog series, we asked how employers facing a Data Subject Access Request (DSAR) should be dealing with ‘mixed data’ cases, i.e. when a third party’s personal data is intertwined with that of the requester? Mixed data comes in many forms; for example, an email from John to a colleague saying … Continue Reading

Employee Data Subject Access Requests: Part 3 – DSARs and proportionality – limiting the search (UK)

Some DSARs can be wonderfully straightforward: “Can I have a copy of my personnel file?” “Absolutely, here you go” “Can I have a copy of the notes from my appeal hearing?” “Of course, all yours. Any time” However, a large number of DSARs submitted by employees are far more taxing: “Can I have all personal … Continue Reading

Employee Data Subject Access Requests: Part 2 – It’s complicated – extending the DSAR deadline (UK)

In the second of our five part blog series on Data Subject Access Requests (DSARs), we examine the notion of “complexity” and how that might affect the way you respond as an employer to a DSAR. What is “complex”? Under the General Data Protection Regulation (GDPR), data controllers must respond to DSARs “without undue delay … Continue Reading

Employee Data Subject Access Requests: Part 1 – where are we now and what questions remain? (UK)

Just when we thought we were getting to grips with some of the stickier issues around Data Subject Access Requests (DSARs), then along comes the EU General Data Protection Regulation (GDPR) and numerous new ambiguities over how its DSAR provisions might work in practice.  We are waiting for the ICO’s guidance and update on its … Continue Reading

Practical Guide to the GDPR – Part 8

Part 7 of this series looked at how far an employer might be exposed if employees whose images were used in internal or external marketing or other corporate communications then withdraw their consent to that processing. Our Global IP and Technology team has now provided some useful further thoughts on this risk, accepting that the … Continue Reading

What’s Your Number? Be Careful When Asking Your Japanese Employees.

In many countries, individuals are identified by a unique number issued by the government. Probably the most ubiquitous example is the Social Security Number in the United States, which is generally necessary to obtain employment, open a bank account or obtain a driver’s license, and is used for credit monitoring and other private sector purposes. … Continue Reading

Employee Wellbeing Programmes (UK)

With a clear link between increased employee wellbeing (both in terms of physical and mental health) and reduced sickness absence, many employers may use renewed New Year ambitions to adopt or promote employee wellbeing programmes. Businesses have introduced measures including step challenges with free pedometers, fruit ‘desk drops’ and health monitoring stations in the workplace. … Continue Reading

ECHR keeps an eye on covert workplace surveillance, but for whose benefit?

Judge Dedov is the one to watch here.  He was the only one out of the European Court of Human Rights panel not responsible for a recent decision on employee surveillance which many may feel tilts European law around workplace monitoring altogether too far towards the interests of the employee. Ms Ribalda and her four … Continue Reading

Illinois Employers Face A Recent Rash of Class Action Lawsuits Filed Under State Biometric Information Privacy Law

Illinois enacted its Biometric Information Privacy Act (“BIPA”) in 2008 to regulate, among other things, employer collection and use of employee biometric information.  Biometrics is defined as the measurement and analysis of physical and behavioral characteristics.  This analysis produces biometric identifiers that include things like fingerprints, iris or face scans, and voiceprints, all of which … Continue Reading

How to make time fly – HR preparation for the GDPR

Exactly one year from today, Brexit notwithstanding, the EU General Data Protection Regulation comes into effect. This is aimed primarily at commercial progressing of customer data but still has significant ramifications for HR’s handling of employee data. Compliance with the Data Protection Act as it stands will not be enough to protect against breaches of … Continue Reading

Key new rules for employers posting staff to France

Foreign employers posting employees to France temporarily, whether to provide services for a client based in France or for their own sake or as part of an intra-group mobility programme, must comply with strict legal requirements.  These relate in particular to providing for those staff a set of mandatory employment rules applicable while they are … Continue Reading
LexBlog