EU GDPR employee data is governed by the General Data Protection Regulation (EU Regulation 2016/679), which sets the rules for processing personal data of employees across the European Union. Employers process employee data daily — names, addresses, salaries, health records, performance reviews, and absence data. Each processing activity must have a lawful basis, the data must be kept accurate, secure, and no longer than necessary, and employees must be informed of how their data is used. The GDPR provides for fines of up to €20 million or 4% of annual global turnover for serious breaches. Data protection authorities in each EU member state enforce the GDPR, and each member state has enacted a national implementing law that adds country-specific provisions.

This guide covers the GDPR’s application to employee data, the lawful bases, special category data rules, employee consent, data minimisation, and the practical obligations for employers operating in the EU.

Key takeaways

  • The EU GDPR (Regulation 2016/679) applies to all processing of employee personal data in the EU.
  • Every processing activity must have a lawful basis — the most relevant for employees are contractual necessity (Art. 6(1)(b)) and legitimate interests (Art. 6(1)(f)).
  • Consent is rarely a valid basis in employment due to the power imbalance — the GDPR expressly recognises this.
  • Special category data (health, trade union membership, biometric data, etc.) requires an additional condition under Article 9.
  • The GDPR’s transparency principle requires employers to inform employees about data processing — through a privacy notice at the point of collection.
  • Cross-border transfers of employee data outside the EU require a valid transfer mechanism — standard contractual clauses, adequacy decisions, or binding corporate rules.

Lawful bases for processing employee data

Under Article 6 GDPR, every processing activity must have one of six lawful bases. In the employment context, the most relevant are:

Lawful basis When it applies
Contractual necessity (Art. 6(1)(b)) Processing necessary to perform the employment contract — paying salary, managing leave, providing benefits
Legitimate interests (Art. 6(1)(f)) Processing necessary for the employer’s legitimate interests, where those interests are not overridden by the employee’s rights — performance management, absence tracking, fraud prevention
Legal obligation (Art. 6(1)(c)) Processing required by law — tax reporting, pension contributions, right-to-work checks
Consent (Art. 6(1)(a)) Not generally appropriate in employment due to the power imbalance — consent must be freely given and can be withdrawn at any time

Legitimate interests — the balancing test

Where the employer relies on legitimate interests, it must conduct a Legitimate Interests Assessment (LIA) that balances the employer’s interest against the employee’s rights and freedoms. The assessment considers:

  1. Purpose — what is the legitimate interest being pursued?
  2. Necessity — is the processing necessary to achieve that interest?
  3. Balancing — does the employee’s interest in not having the processing occur override the employer’s interest?

Example: Monitoring employee email to prevent fraud is a legitimate interest, but monitoring every email in real time without informing employees is unlikely to pass the balancing test.

Special category data

Special category data is data revealing racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic data, biometric data, health data, or data concerning sex life or sexual orientation — Article 9 GDPR.

Processing special category data requires both a lawful basis under Article 6 and an additional condition under Article 9(2). The most relevant conditions for employers are:

Article 9 condition When it applies
Employment, social security, and social protection law (Art. 9(2)(b)) Processing necessary for the employer’s obligations under employment law — health certificates, pension contributions
Explicit consent (Art. 9(2)(a)) Where the employee has given explicit consent — but the power imbalance makes consent a weak basis
Substantial public interest (Art. 9(2)(g)) Processing necessary for reasons of substantial public interest — rarely applies to routine HR processing
Trade union membership (Art. 9(2)(d)) Processing necessary for the purposes of the employment relationship — verifying union status

Each EU member state has enacted national implementing legislation that specifies which Article 9(2)(b) and (g) conditions apply. The employer must check the national law of the member state where the employee works.

The power imbalance between employer and employee means that consent under Article 7(4) GDPR is often not freely given. The GDPR expressly states that consent is not freely given where there is a clear imbalance between the data subject and the controller.

In practice:

  • Consent for processing health data, salary data, or disciplinary records is almost never freely given.
  • Consent can be withdrawn at any time — Article 7(3) GDPR — and the employer must stop processing and delete the data if there is no other legal basis.
  • Relying on consent as the primary basis for employee data processing is a compliance risk.

The better approach is to rely on contractual necessity or legitimate interests, and to use consent only where it is genuinely free — for example, where the employee opts into a newsletter or a benefit that is entirely voluntary.

Transparency and information obligations

Under Articles 13 and 14 GDPR, the employer must inform employees about data processing at the point of collection. The privacy notice must include:

  1. The identity and contact details of the controller.
  2. The purposes and lawful basis for processing.
  3. The categories of personal data processed.
  4. The recipients or categories of recipients.
  5. The retention period or criteria for determining it.
  6. The employee’s rights — access, rectification, erasure, restriction, portability, and objection.
  7. The right to withdraw consent (where consent is the lawful basis).
  8. The right to lodge a complaint with a supervisory authority.
  9. The existence of automated decision-making, including profiling.

The privacy notice must be provided at the time the data is collected — which, for employee data, is typically at the start of the employment relationship.

Data minimisation and retention

The GDPR’s data minimisation principle — Article 5(1)(c) — means employee data should not be kept longer than necessary. The employer should:

  1. Define retention periods for each category of employee data.
  2. Delete data at the end of the retention period (unless there is a legal obligation to retain it).
  3. Anonymise data where possible — anonymised data is no longer personal data and falls outside the GDPR.

Cross-border transfers

Where the employer transfers employee data outside the EU (e.g., to a parent company in the US, or to a cloud provider outside the EU), the transfer must comply with Chapter V GDPR. Valid transfer mechanisms include:

Mechanism When it applies
Adequacy decision The European Commission has determined that the country provides an adequate level of data protection — e.g., Japan, South Korea, the UK (under the adequacy decision)
Standard Contractual Clauses (SCCs) Pre-approved contractual terms between the data exporter and importer — the most common mechanism for transfers to the US
Binding Corporate Rules (BCRs) Intra-group rules approved by a supervisory authority —适用于跨国公司集团内部
Derogations Specific exceptions — e.g., explicit consent for a specific transfer, or necessity for the performance of the contract

Following the Schrems II decision (C-311/18), transfers to the US based on SCCs require a Transfer Impact Assessment to assess whether the laws of the destination country undermine the protections provided by the SCCs.

Common pitfalls

Consent is rarely valid in the employment context. The GDPR and data protection authorities across the EU recognise that consent given in the shadow of the employment relationship is not freely given.

2. Not providing a privacy notice

Failing to inform employees about data processing at the point of collection is a breach of Articles 13 and 14. The privacy notice must be provided before the data is processed.

3. Transferring data outside the EU without a valid mechanism

Transferring employee data to a non-EU country without a valid transfer mechanism — particularly to the US — is a breach of Chapter V GDPR. SCCs and a Transfer Impact Assessment are the minimum requirements.

4. Retaining data indefinitely

Keeping employee data “just in case” breaches the storage limitation principle. Every piece of personal data should have a defined retention period.

Putting it into practice

Five steps to build GDPR compliance into your HR processes:

  1. Map your data flows — know what employee data you collect, where it is stored, who has access, and how long it is kept.
  2. Document your lawful basis — for each processing activity, record whether you rely on contractual necessity, legitimate interests, or another basis.
  3. Publish a privacy notice for employees — tell them what data you collect, why, how long you keep it, and who you share it with.
  4. Manage cross-border transfers — identify all transfers outside the EU, apply SCCs where necessary, and conduct Transfer Impact Assessments.
  5. Train your HR team on GDPR obligations — particularly the transparency principle, data minimisation, and employee rights.
You can take advantage of the free 14 days trial and explore Leave Balance.

A leave management system that stores employee data securely, applies retention schedules automatically, manages cross-border transfers, and generates reports on request reduces the compliance burden of the GDPR.

Sources

This article is general information, not legal advice. GDPR compliance depends on the specific member state’s implementing legislation and the nature of the processing — consult a data protection specialist for specific situations.