Your company just got fined €80,000 for using employee personal phones as work tools. I analyzed a fresh GDPR enforcement case from Spain (Agencia Española de Protección de Datos - AEPD) that every HR and privacy leader needs to understand. Majorel SP SOLUTIONS required employees to provide personal mobile numbers for two-factor authentication to access a client's platform. No corporate devices offered. No real choice given. The Spanish DPA ruled this unlawful. Here's why: The company argued "contract performance" as legal basis under Article 6(1)(b). The authority rejected this completely. Three critical failures: 1. Employers must provide work tools - personal devices cannot substitute corporate infrastructure when less intrusive alternatives exist 2. The ***Data Protection Officer warned against *** this practice months earlier - management ignored the advice 3. 203 of 364 employees had personal numbers exposed to a third party without valid consent The National Court had already established this principle: if two-factor authentication is required, the employer provides the necessary tools. Period. What makes this case significant for businesses? India's DPDP Act implementation is approaching. Similar principles around employer-employee data handling will apply. Organizations using personal devices for work authentication need to reassess their practices now. The fine was reduced to €48,000 after voluntary payment and acknowledgment. But the reputational damage? That stays. Is your organization using employee personal phones for work authentication? What's your legal basis?
GDPR in HR Practices
Explore top LinkedIn content from expert professionals.
Summary
GDPR, or the General Data Protection Regulation, sets strict rules on how organizations handle personal data—including sensitive employee information—within HR practices. It requires employers to ensure lawful, transparent, and fair data processing, protecting staff privacy and preventing unauthorized data sharing.
- Rethink device policies: Always provide employees with secure, company-managed devices for work-related tasks instead of requiring personal phones or computers.
- Secure data sharing: Never share or expose employee CVs or personal data online or with third parties unless you have explicit, written consent from the individual.
- Review agreements thoroughly: Internal works agreements cannot replace GDPR requirements, so always check that your HR data processing activities meet legal standards independently of such arrangements.
-
-
👨⚖️ 𝗚𝗲𝗿𝗺𝗮𝗻 𝗙𝗲𝗱𝗲𝗿𝗮𝗹 𝗟𝗮𝗯𝗼𝘂𝗿 𝗖𝗼𝘂𝗿𝘁: 𝗚𝗗𝗣𝗥 𝗥𝗲𝗾𝘂𝗶𝗿𝗲𝗺𝗲𝗻𝘁𝘀 𝗳𝗼𝗿 𝗧𝗲𝘀𝘁𝗶𝗻𝗴 𝗣𝗵𝗮𝘀𝗲 𝗼𝗳 𝗮 𝗻𝗲𝘄 𝗣𝗲𝗿𝘀𝗼𝗻𝗻𝗲𝗹 𝗠𝗮𝗻𝗮𝗴𝗲𝗺𝗲𝗻𝘁 𝗦𝗼𝗳𝘁𝘄𝗮𝗿𝗲 In a decision dated May 8th, 2025, the Federal Labour Court (BAG, Az. 8 AZR 209/21) had to deal with the legality of data processing in the testing phase of a new software solution for personnel management. - The Case - The plaintiff, works council chairman and employee of the defendant, claimed non-material damages in the amount of 3.000 Euro under Art. 82 (1) GDPR. The claim arose from the transfer of actual personal data, including sensitive details such as salary, home address, date of birth, social security number, and tax ID, to the parent company for the purpose of testing the new “Workday” HR software. Not all of the transferred information was covered by the works council agreement concluded in preparation for the data transfer. - The Ruling - The BAG held that the company had committed a GDPR violation by transferring real personal data for testing purposes. The court further ruled that Sec. 26 (1) of the Federal Data Protection Act (BDSG) could not serve as a legal basis, as it does not meet the requirements of Art. 88 GDPR, a position previously confirmed by the CJEU for a similar provision in state data protection law. According to the BAG, the only potentially relevant legal basis in this case was Art. 6(1)(f) GDPR. Justification for the processing of personal data in the preliminary operation of Workday for “testing purposes” is not ruled out from the outset if depersonalized “dummy” test data is not sufficient to achieve the testing purpose. Provisional testing with personal data may be necessary in individual cases to protect the legitimate interests of the employer in order to prepare for a software changeover. While using real data instead of dummy data may, in principle, be permissible if necessary for testing purposes, this was not applicable here, as the volume of data transferred exceeded what had been authorized in the works council agreement. Since the processing also could not be justified under Art. 6(1)(b) GDPR, the court found it to be unlawful. According to the BAG and in line with the current CJEU position, even a short-term loss of control can lead to a compensation claim. In this case, the court found 200 Euro to be sufficient to compensate the plaintiff for this loss of control. Decision (in German): https://lnkd.in/eyJJjDwm #DSGVO #GDPR #Dataprotection #privacy
-
Would you post someone’s ID card online to “help them”? Then why share their CV? A worrying trend is popping up again: Well-meaning people post full CVs of job seekers on LinkedIn or mass-email them to their network — thinking they’re doing a good deed. Here’s the truth: 📄 A CV is not just a piece of paper. It’s a bundle of personal data — name, phone number, address, education, job history, sometimes even ID numbers and photos. 💥 That makes it a GDPR time bomb. You are not authorized to circulate someone else’s personal data unless they gave explicit, informed, written consent. One click can lead to: • A data breach • Identity theft or fraud • Legal risks for you and your company Even if you cover the phone number or email — that’s not enough. Would you want your CV online for thousands to see, without your control? 💡 So how can we really help job seekers? ✅ Share their LinkedIn profile (with permission) ✅ Encourage them to apply directly via career pages or future talent pool applications ✅ Refer them privately, respectfully, and securely ✅ Offer guidance, feedback, or connections — not public exposure ⚠️ “Good intentions” don’t protect data. Responsible support does. #GDPR #PrivacyMatters #RecruitmentEthics #CVConfidentiality #LinkedInBestPractices #DataProtection #JobSearchHelp #FutureTalentPool #HRCompliance
-
Would you trust your employer with your medical records, biometrics, and behavioural data? Now ask the harder question: is your organisation protecting employee data the way regulators expect? HR teams process the most sensitive data in the enterprise, including health records, biometrics, payroll, performance analytics, background checks, and monitoring data. Yet HR privacy is still treated as an internal admin issue. Regulators strongly disagree. In 2023, global privacy fines crossed $2.9B, with 18% tied to employee and HR data violations. Enforcement is accelerating across the EU, US, Canada, Singapore, and the UAE. What HR & compliance leaders must know: GDPR / UK GDPR • Lawful basis is mandatory; consent rarely applies in employment • Health, biometric, union data = special category data • Enforceable employee rights + 30-day response timelines US State Laws (CCPA/CPRA, CDPA, CPA) • Employee exemptions are largely gone • Rights to access, delete, correct & limit sensitive data • Algorithmic HR decisions require disclosures and human review • Risk assessments for monitoring & profiling Canada (PIPEDA & Quebec Law 25) • Purpose limitation, data minimisation, meaningful consent • Monitoring must be necessary, proportionate, and least intrusive • Cross-border safeguards + breach reporting • Quebec mandates privacy-by-design Singapore (PDPA) • Employment exception only where reasonably necessary • Mandatory breach notification • Cross-border transfers require comparable protection UAE Data Protection Law • GDPR-style employee rights • Strong safeguards for sensitive HR data • Transfer controls apply • Fines up to AED 10M HR data privacy is no longer a compliance checkbox. Multinational employers need a highest-common-denominator privacy program, strong governance, secure HR tech, vendor controls, and continuous monitoring. Get HR privacy wrong, and the cost isn’t just fines. It’s employee trust, brand reputation, and operational resilience. DLA Piper IAPP Bird & Bird KPMG US KPMG au Québec Bird & Bird - Privacy & Data Protection cander Eastridge Workforce Solutions HR Grapevine KPMG Canada #PIPEDA #PCND #GDPR #CCPA #DPDPA #Privacy
-
🔍 𝐂𝐚𝐧 𝐚 𝐖𝐨𝐫𝐤𝐬 𝐀𝐠𝐫𝐞𝐞𝐦𝐞𝐧𝐭 𝐉𝐮𝐬𝐭𝐢𝐟𝐲 𝐄𝐦𝐩𝐥𝐨𝐲𝐞𝐞 𝐃𝐚𝐭𝐚 𝐏𝐫𝐨𝐜𝐞𝐬𝐬𝐢𝐧𝐠 𝐔𝐧𝐝𝐞𝐫 𝐆𝐃𝐏𝐑? The ECJ Says NO. It may sound surprising to some, but the European Court of Justice has just made it crystal clear: 𝐚 𝐰𝐨𝐫𝐤𝐬 𝐚𝐠𝐫𝐞𝐞𝐦𝐞𝐧𝐭 𝐜𝐚𝐧𝐧𝐨𝐭 𝐬𝐞𝐫𝐯𝐞 𝐚𝐬 𝐚 𝐬𝐭𝐚𝐧𝐝𝐚𝐥𝐨𝐧𝐞 𝐥𝐞𝐠𝐚𝐥 𝐛𝐚𝐬𝐢𝐬 𝐟𝐨𝐫 𝐩𝐫𝐨𝐜𝐞𝐬𝐬𝐢𝐧𝐠 𝐞𝐦𝐩𝐥𝐨𝐲𝐞𝐞 𝐝𝐚𝐭𝐚 𝐮𝐧𝐝𝐞𝐫 𝐭𝐡𝐞 𝐆𝐃𝐏𝐑. The ruling in Case C-65/23 (MK v K GmbH) marks a decisive moment for HR compliance in the EU. The case involved a German employer rolling out an HR platform via a works agreement—transferring sensitive employee data to the US in the process. The ECJ rejected this practice outright. 💥 The Court’s message? ➡️ 𝘐𝘯𝘵𝘦𝘳𝘯𝘢𝘭 𝘢𝘨𝘳𝘦𝘦𝘮𝘦𝘯𝘵𝘴—𝘯𝘰 𝘮𝘢𝘵𝘵𝘦𝘳 𝘩𝘰𝘸 𝘭𝘦𝘨𝘪𝘵𝘪𝘮𝘢𝘵𝘦 𝘶𝘯𝘥𝘦𝘳 𝘯𝘢𝘵𝘪𝘰𝘯𝘢𝘭 𝘭𝘢𝘸—𝘤𝘢𝘯 𝘯𝘦𝘷𝘦𝘳 𝘣𝘦 𝘢 𝘭𝘦𝘨𝘢𝘭 𝘣𝘢𝘴𝘪𝘴 𝘶𝘯𝘥𝘦𝘳 𝘵𝘩𝘦 𝘎𝘋𝘗𝘙. And the implications go far beyond Germany. In Italy, for instance, even 𝐜𝐨𝐥𝐥𝐞𝐜𝐭𝐢𝐯𝐞 𝐛𝐚𝐫𝐠𝐚𝐢𝐧𝐢𝐧𝐠 𝐚𝐠𝐫𝐞𝐞𝐦𝐞𝐧𝐭𝐬 can't make non-compliant data processing lawful according to an arguable position of the Italian data protection authority. The Garante has already sanctioned similar attempts in the past. Here are a few takeaways for all employers: ✅ Do not rely on works agreements as a legal basis for employee data processing ✅ Assess the necessity of every HR-related data flow ✅ Avoid third-country transfers without robust safeguards ✅ Update your documentation to reflect independent GDPR compliance—not just internal arrangements 👉 I wrote a full article unpacking the ECJ's judgment, practical implications for HR platforms, and what Italian employers need to know. You can read it on my blog here: https://lnkd.in/dupaFPPg 📩 What do you think? Are companies underestimating the limits of works agreements under GDPR? Let's discuss in the comments. #GDPR #DataProtection #HRCompliance #EUCourt #PrivacyLaw #WorksAgreement #DPO #LegalUpdate #EmploymentLaw #AIandPrivacy #Cybersecurity #DirittoAlDigitale #ECJ #DataTransfers #CloudCompliance
-
🇦🇹📑Background checks are important for companies, but conducting them requires strict adherence to the #GDPR. The recent decision of the Austrian DPA (DSB) of 11 November 2025 offers valuable guidance on how employers should handle information about criminal convictions during recruitment and how they must respond to deletion requests from applicants. ❌The case concerned a candidate who, during a hiring process, informed the employer that she had a criminal conviction and submitted an official extract from the criminal register. The HR department then forwarded the conviction details to several managers involved in assessing whether she could be hired. Shortly afterwards, the candidate was rejected. She then asked the company to delete all her personal data. Although the employer later confirmed that the deletion had occurred, an internal HR email containing the details of the conviction remained in the system. ❌The DPA upheld the complaint about the right to erasure. It found that the employer had not fully complied with the August 2024 deletion request. The justification offered by the company, namely that the email had to be retained in case of potential future legal disputes, was rejected. Under the GDPR, controllers may retain personal data for the purpose of defending legal claims only when litigation is already underway or clearly foreseeable. A vague possibility of a dispute in the future is not enough. The DPA therefore ordered the company to delete the remaining email within two weeks. ❌However, the DPA dismissed the complaint regarding the alleged breach of confidentiality. It held that the employer had a legitimate interest under Article 6(1)(f) GDPR, supported by the relevant provisions of Austrian national law, in examining whether the candidate’s conviction affected her suitability for the role. The DPA considered internal sharing of this information necessary and proportionate. ❌The reasoning emphasised that the candidate had herself disclosed the existence of the conviction and had submitted the criminal-record extract, so it was objectively foreseeable that managers directly involved in the hiring decision would need to review it. The DPA also clarified that criminal-conviction data falls within a special category of personal data regulated by Article 10 of the GDPR, meaning that private employers may process such data only when national law expressly allows it and when strong safeguards are in place. #privacy #HR #employees
-
Recent from the Italian DPA - fine of EUR 420,000 for the unlawful processing of an #employee's #personaldata during disciplinary proceedings. The company used screenshots of an unnamed employee's Messenger and WhatsApp messages, as well as Facebook content, in disciplinary action that led to the employee's termination. The Italian DPA found that this constituted unlawful and excessive processing of #personaldata, violating Articles 5(1)(a)(b)(c), 6, and 88 of the GDPR. Key takeaways from the Italian DPA's holding include: - Broad interpretation of "#processing" concept: Of course, #receiving and #using #personaldata, even if not actively collected by the employer, represents #processing under #GDPR - Lack of #legalbasis and #accountability: The company failed to demonstrate a #legitimateinterest for processing the data, particularly by not providing evidence of a #balancingtest as required under #GDPR - #Necessity and #proportionality: The processing was deemed unnecessary for the stated purpose, as disciplinary proceedings could have been pursued without the #socialmedia and #privatecommunication screenshots. #HR #employeespersonaldata #processing #personaldataprocessing #GDPR #legalbasis #legitimateinterest #LIA #privatecommunication https://lnkd.in/dkGxve3W
-
𝗖𝗼𝗻𝘁𝗲𝘅𝘁 𝗶𝘀 𝘁𝗵𝗲 𝗱𝗶𝗳𝗳𝗲𝗿𝗲𝗻𝗰𝗲 𝗯𝗲𝘁𝘄𝗲𝗲𝗻 𝗽𝗿𝗼𝘁𝗲𝗰𝘁𝗶𝗼𝗻 𝗮𝗻𝗱 𝘁𝗵𝗲𝗮𝘁𝗿𝗲. Most teams secure content - few secure context. That gap is where breaches become headlines and compliance turns into fines. What do I mean by context? Not just “what is the data”, but: who it belongs to, why it exists, who is using it, where it lives, how sensitive it is, when it should be deleted, and what it’s linked to. Miss any one of these and you are optimising the wrong control. 𝗧𝘄𝗼 𝗲𝘅𝗮𝗺𝗽𝗹𝗲𝘀 𝘁𝗵𝗮𝘁 𝗹𝗼𝗼𝗸 𝘁𝗵𝗲 𝘀𝗮𝗺𝗲 𝗯𝘂𝘁 𝗮𝗿𝗲 𝗻𝗼𝘁 • A passport image in HR’s payroll system for right-to-work checks - legitimate purpose, restricted access, defined retention. • The same passport image in a random OneDrive folder - no lawful purpose, overshared, no retention, high blast radius. 𝗦𝗮𝗺𝗲 𝗰𝗼𝗻𝘁𝗲𝗻𝘁 - 𝗱𝗶𝗳𝗳𝗲𝗿𝗲𝗻𝘁 𝗰𝗼𝗻𝘁𝗲𝘅𝘁 - 𝘁𝗼𝘁𝗮𝗹𝗹𝘆 𝗱𝗶𝗳𝗳𝗲𝗿𝗲𝗻𝘁 𝗿𝗶𝘀𝗸. 𝗔 𝘀𝗶𝗺𝗽𝗹𝗲 𝗳𝗿𝗮𝗺𝗲𝘄𝗼𝗿𝗸 𝘆𝗼𝘂 𝗰𝗮𝗻 𝘀𝗵𝗶𝗽 Treat context as 6 signals your controls must read in real time: • 𝗜𝗱𝗲𝗻𝘁𝗶𝘁𝘆 - who is the data about and who is touching it • 𝗣𝘂𝗿𝗽𝗼𝘀𝗲 - why you collected it and whether current use matches that purpose • 𝗦𝗲𝗻𝘀𝗶𝘁𝗶𝘃𝗶𝘁𝘆 - classification tied to harm, not just regex or file type • 𝗟𝗼𝗰𝗮𝘁𝗶𝗼𝗻 - systems, jurisdictions, vendors, and cross-border flows • 𝗘𝘅𝗽𝗼𝘀𝘂𝗿𝗲 - who can access it and via which paths or tokens • 𝗧𝗶𝗺𝗲 - collection date, last use, and deletion due date If your DLP, DSPM, IAM, and SIEM cannot evaluate these signals together, you are guessing. 𝗪𝗵𝘆 𝘁𝗵𝗶𝘀 𝗺𝗮𝘁𝘁𝗲𝗿𝘀 𝗿𝗶𝗴𝗵𝘁 𝗻𝗼𝘄 • The average breach is still measured in millions - IBM’s 2025 study puts the global average at 4.4M USD, down from 4.88M in 2024, but hardly comforting. Context-rich detection and response drove the drop. • Humans remain the soft edge - the 2024 Verizon DBIR attributes 68% of breaches to a human element. Context-aware controls reduce the fallout when someone clicks. • Regulators are codifying context - GDPR’s purpose limitation requires use to match the stated purpose, forcing financial entities to prove operational resilience across vendors and data flows. 𝗔 𝟮-𝗺𝗶𝗻𝘂𝘁𝗲 𝗮𝘂𝗱𝗶𝘁 𝘁𝗼 𝘁𝗲𝘀𝘁 𝘄𝗵𝗲𝘁𝗵𝗲𝗿 𝘆𝗼𝘂 𝗵𝗮𝘃𝗲 𝗰𝗼𝗻𝘁𝗲𝘅𝘁 𝗼𝗿 𝗷𝘂𝘀𝘁 𝗮 𝗱𝗮𝘁𝗮 𝗶𝗻𝘃𝗲𝗻𝘁𝗼𝗿𝘆 1. Show me every candidate CV older than 24 months, where it lives, and the deletion queue. 2. Show me who accessed customer IDs in the last 30 days and whether that matched a documented purpose. 3. Show me which regulated records traverse non-EU locations. 𝗜𝗳 𝘆𝗼𝘂 𝗰𝗮𝗻𝗻𝗼𝘁 𝗮𝗻𝘀𝘄𝗲𝗿 𝗶𝗻 𝟮 𝗺𝗶𝗻𝘂𝘁𝗲𝘀, 𝘆𝗼𝘂 𝗵𝗮𝘃𝗲 𝗮 𝗹𝗶𝘀𝘁, 𝗻𝗼𝘁 𝗴𝗼𝘃𝗲𝗿𝗻𝗮𝗻𝗰𝗲. If your controls cannot deny a legitimate-looking request because the purpose is wrong, you are doing privacy and security by appearance, not by design. #DataProtection #DataSecurity #DSPM #DataGovernance #DataClassification #GDPR #DORA #InfoSec #CPO #CISO #CYERA
-
HR Software Handles Your Most Sensitive Data, So Why Is It Your Least Defended System? As of 2024, over 51% of corporate data breaches originate from vulnerabilities in third-party SaaS systems, and among them, HR software ranks in the top three most targeted platforms, according to IBM’s “X-Force Threat Intelligence Index.” Yet shockingly, less than 30% of HR vendors today offer enterprise-grade data residency controls, real-time compliance tracking, or end-to-end encryption. “The irony is brutal, companies spend millions securing their customer data but leave payroll, PII, and internal records wide open through under-secured HR platforms,” says Dr. Karolina Beck, Director of Cyber Risk at Stanford’s Center for Digital Trust. In an era of escalating regulatory scrutiny, where GDPR fines now exceed €2.1 billion annually and U.S. SEC enforcement is targeting board-level accountability, HR systems are no longer administrative tools. They are risk surface areas, often neglected, rarely audited, and dangerously centralized. WebHR flips that script. It delivers: 100% employee data encryption at rest and in motion Customizable jurisdictional data storage for GDPR, CPRA, and Middle East data laws Real-time compliance alerts across 100+ legal zones AI anomaly detection for payroll fraud and access abuse "HR isn’t just a compliance obligation, it’s your legal exposure in waiting,” notes Marcus Dorne, Lead Compliance Advisor at BDO Global. “If your system isn’t sovereign-ready and breach-resilient, it’s not future-proof, it’s a ticking liability.” This article exposes the hidden risks in HR stacks, why WebHR is engineered like financial infrastructure, and how enterprise leaders are redefining HR software as a strategic line of defense, not just a workflow tool. Because in 2025, you won’t be asked if you knew your HR vendor posed a risk. You’ll be asked why you didn’t fix it.