EU GDPR employee data is governed by the General Data Protection Regulation (EU Regulation 2016/679), which sets the rules for processing personal data of employees across the European Union. Employers process employee data daily — names, addresses, salaries, health records, performance reviews, and absence data. Each processing activity must have a lawful basis, the data must be kept accurate, secure, and no longer than necessary, and employees must be informed of how their data is used. The GDPR provides for fines of up to €20 million or 4% of annual global turnover for serious breaches. Data protection authorities in each EU member state enforce the GDPR, and each member state has enacted a national implementing law that adds country-specific provisions.
This guide covers the GDPR’s application to employee data, the lawful bases, special category data rules, employee consent, data minimisation, and the practical obligations for employers operating in the EU.
Key takeaways
- The EU GDPR (Regulation 2016/679) applies to all processing of employee personal data in the EU.
- Every processing activity must have a lawful basis — the most relevant for employees are contractual necessity (Art. 6(1)(b)) and legitimate interests (Art. 6(1)(f)).
- Consent is rarely a valid basis in employment due to the power imbalance — the GDPR expressly recognises this.
- Special category data (health, trade union membership, biometric data, etc.) requires an additional condition under Article 9.
- The GDPR’s transparency principle requires employers to inform employees about data processing — through a privacy notice at the point of collection.
- Cross-border transfers of employee data outside the EU require a valid transfer mechanism — standard contractual clauses, adequacy decisions, or binding corporate rules.
Lawful bases for processing employee data
Under Article 6 GDPR, every processing activity must have one of six lawful bases. In the employment context, the most relevant are:
| Lawful basis | When it applies |
|---|---|
| Contractual necessity (Art. 6(1)(b)) | Processing necessary to perform the employment contract — paying salary, managing leave, providing benefits |
| Legitimate interests (Art. 6(1)(f)) | Processing necessary for the employer’s legitimate interests, where those interests are not overridden by the employee’s rights — performance management, absence tracking, fraud prevention |
| Legal obligation (Art. 6(1)(c)) | Processing required by law — tax reporting, pension contributions, right-to-work checks |
| Consent (Art. 6(1)(a)) | Not generally appropriate in employment due to the power imbalance — consent must be freely given and can be withdrawn at any time |
Legitimate interests — the balancing test
Where the employer relies on legitimate interests, it must conduct a Legitimate Interests Assessment (LIA) that balances the employer’s interest against the employee’s rights and freedoms. The assessment considers:
- Purpose — what is the legitimate interest being pursued?
- Necessity — is the processing necessary to achieve that interest?
- Balancing — does the employee’s interest in not having the processing occur override the employer’s interest?
Example: Monitoring employee email to prevent fraud is a legitimate interest, but monitoring every email in real time without informing employees is unlikely to pass the balancing test.
Special category data
Special category data is data revealing racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic data, biometric data, health data, or data concerning sex life or sexual orientation — Article 9 GDPR.
Processing special category data requires both a lawful basis under Article 6 and an additional condition under Article 9(2). The most relevant conditions for employers are:
| Article 9 condition | When it applies |
|---|---|
| Employment, social security, and social protection law (Art. 9(2)(b)) | Processing necessary for the employer’s obligations under employment law — health certificates, pension contributions |
| Explicit consent (Art. 9(2)(a)) | Where the employee has given explicit consent — but the power imbalance makes consent a weak basis |
| Substantial public interest (Art. 9(2)(g)) | Processing necessary for reasons of substantial public interest — rarely applies to routine HR processing |
| Trade union membership (Art. 9(2)(d)) | Processing necessary for the purposes of the employment relationship — verifying union status |
Each EU member state has enacted national implementing legislation that specifies which Article 9(2)(b) and (g) conditions apply. The employer must check the national law of the member state where the employee works.
Employee consent — the problem
The power imbalance between employer and employee means that consent under Article 7(4) GDPR is often not freely given. The GDPR expressly states that consent is not freely given where there is a clear imbalance between the data subject and the controller.
In practice:
- Consent for processing health data, salary data, or disciplinary records is almost never freely given.
- Consent can be withdrawn at any time — Article 7(3) GDPR — and the employer must stop processing and delete the data if there is no other legal basis.
- Relying on consent as the primary basis for employee data processing is a compliance risk.
The better approach is to rely on contractual necessity or legitimate interests, and to use consent only where it is genuinely free — for example, where the employee opts into a newsletter or a benefit that is entirely voluntary.
Transparency and information obligations
Under Articles 13 and 14 GDPR, the employer must inform employees about data processing at the point of collection. The privacy notice must include:
- The identity and contact details of the controller.
- The purposes and lawful basis for processing.
- The categories of personal data processed.
- The recipients or categories of recipients.
- The retention period or criteria for determining it.
- The employee’s rights — access, rectification, erasure, restriction, portability, and objection.
- The right to withdraw consent (where consent is the lawful basis).
- The right to lodge a complaint with a supervisory authority.
- The existence of automated decision-making, including profiling.
The privacy notice must be provided at the time the data is collected — which, for employee data, is typically at the start of the employment relationship.
Data minimisation and retention
The GDPR’s data minimisation principle — Article 5(1)(c) — means employee data should not be kept longer than necessary. The employer should:
- Define retention periods for each category of employee data.
- Delete data at the end of the retention period (unless there is a legal obligation to retain it).
- Anonymise data where possible — anonymised data is no longer personal data and falls outside the GDPR.
Cross-border transfers
Where the employer transfers employee data outside the EU (e.g., to a parent company in the US, or to a cloud provider outside the EU), the transfer must comply with Chapter V GDPR. Valid transfer mechanisms include:
| Mechanism | When it applies |
|---|---|
| Adequacy decision | The European Commission has determined that the country provides an adequate level of data protection — e.g., Japan, South Korea, the UK (under the adequacy decision) |
| Standard Contractual Clauses (SCCs) | Pre-approved contractual terms between the data exporter and importer — the most common mechanism for transfers to the US |
| Binding Corporate Rules (BCRs) | Intra-group rules approved by a supervisory authority —适用于跨国公司集团内部 |
| Derogations | Specific exceptions — e.g., explicit consent for a specific transfer, or necessity for the performance of the contract |
Following the Schrems II decision (C-311/18), transfers to the US based on SCCs require a Transfer Impact Assessment to assess whether the laws of the destination country undermine the protections provided by the SCCs.
Common pitfalls
1. Relying on consent as the primary basis
Consent is rarely valid in the employment context. The GDPR and data protection authorities across the EU recognise that consent given in the shadow of the employment relationship is not freely given.
2. Not providing a privacy notice
Failing to inform employees about data processing at the point of collection is a breach of Articles 13 and 14. The privacy notice must be provided before the data is processed.
3. Transferring data outside the EU without a valid mechanism
Transferring employee data to a non-EU country without a valid transfer mechanism — particularly to the US — is a breach of Chapter V GDPR. SCCs and a Transfer Impact Assessment are the minimum requirements.
4. Retaining data indefinitely
Keeping employee data “just in case” breaches the storage limitation principle. Every piece of personal data should have a defined retention period.
Putting it into practice
Five steps to build GDPR compliance into your HR processes:
- Map your data flows — know what employee data you collect, where it is stored, who has access, and how long it is kept.
- Document your lawful basis — for each processing activity, record whether you rely on contractual necessity, legitimate interests, or another basis.
- Publish a privacy notice for employees — tell them what data you collect, why, how long you keep it, and who you share it with.
- Manage cross-border transfers — identify all transfers outside the EU, apply SCCs where necessary, and conduct Transfer Impact Assessments.
- Train your HR team on GDPR obligations — particularly the transparency principle, data minimisation, and employee rights.
A leave management system that stores employee data securely, applies retention schedules automatically, manages cross-border transfers, and generates reports on request reduces the compliance burden of the GDPR.
Sources
- EU General Data Protection Regulation (GDPR) (primary source)
- European Data Protection Board (EDPB) (guidance)
- European Data Protection Supervisor (EDPS) (EU institutions guidance)
- Schrems II decision (C-311/18) (cross-border transfers)
This article is general information, not legal advice. GDPR compliance depends on the specific member state’s implementing legislation and the nature of the processing — consult a data protection specialist for specific situations.