GDPR in employment
governs how employers process employee data: lawful bases beyond consent (contract, legal obligation, legitimate interest), transparency notices, minimisation, security, and strict limits on monitoring. HR data flows to payroll and EOR providers require processor agreements and transfer safeguards.
The employment-specific rules that matter
- Consent rarely works: the power imbalance invalidates most employee consent — process on contract, legal-obligation and legitimate-interest bases with documented balancing.
- Monitoring is bounded: covert or blanket surveillance fails; works councils co-determine tools in Germany; proportionality and notice are the tests.
- Providers are processors: payroll, EOR and benefits vendors sign Article 28 agreements; cross-border flows need SCCs or adequacy.
- Rights requests reach HR: access requests cover emails and files about the person — retention and structure decide whether responses are feasible.
- Retention is per purpose: payroll records keep for statutory years; applicant data does not.
FAQ
Can we transfer employee data to group companies abroad?
With safeguards: adequacy decisions where they exist, standard contractual clauses plus transfer assessments otherwise, and binding corporate rules for mature groups. Intra-group transfers are transfers — ‘same company family’ is not a legal basis.
What data can an EOR or payroll provider hold?
What the service needs: identity, contract, bank, tax and social data — under an Article 28 processor agreement, with sub-processor transparency and deletion at exit. Client-side HR should not mirror the full payroll file back without purpose; minimisation runs both directions.