21 December 2018

Employee privacy: the GDPR in practice

Stelt u zich eens voor: u werkt al jaren met dezelfde zelfstandige. Hij stuurt facturen, factureert btw en heeft een eigen kvk-nummer. Toch krijgt u in 2026 ineens vragen van de Belastingdienst over de aard van uw samenwerking. Hoe heeft het zo ver kunnen komen?

An organisation with employees, by definition, processes personal data of employees. Think of the usual data such as name, address, phone number, citizen service number (BSN), etc. In addition to this usual data, other personal data is often processed, such as psychological assessment reports, GPS tracking overviews, photos in the staff directory, time registration systems, etc. From 25 May 2018, one will have to reconsider, with regard to all that data, whether all the processing complies with the General Data Protection Regulation (hereinafter GDPR). Failure to comply with the GDPR can, after all, result in high fines, reputational damage and claims from employees. It can also have unpleasant effects in illness files and dismissal cases. So what are the most important obligations and changes for the employer under the GDPR?

Right of access

Under the Dutch Data Protection Act (Wbp), privacy rights already existed for the employee. A number of these rights have been expanded under the GDPR. For example, employees have the right to inspect the personal data that the employer processes about them, even if this data has already been provided previously.

This is based on one of the most important privacy principles, the so-called transparency principle. Everyone must be able to inspect, at any time, the personal data that has been collected about them. That right must also be easy to exercise, so that they can inform themselves of the processing and check its lawfulness. The fact that the employee is already familiar with this data, or that this data has already been provided before, is not a reason not to provide the documents. Simply put, this means that the employee may request their complete personnel file and that the employer must also provide this to the employee. This must then be done as quickly as possible and, at the latest, within the GDPR term of one month after the request has been submitted.

Right to erasure

A new personal right under the GDPR is the right to erasure. This right means that the employee can ask the employer to erase certain personal data. This is, however, not an absolute right. If, for example, there is a statutory retention period for the employer, this right cannot be exercised as long as the statutory retention period is still running.

Duty to inform

What further follows from the transparency principle is the duty to inform. As an employer, you must proactively, i.e. of your own accord, inform your job applicants and employees about the processing of personal data taking place within the organisation. The most common way to do this is by posting a privacy statement on the website and having an internal privacy policy that forms part of the employment documentation. It must be clearly stated what data is being collected, for what purposes this is done, and where the employee can, if applicable, submit a complaint or request regarding the processing.

Camera surveillance, GPS and fingerprint scan

What about camera surveillance at work, the use of a fingerprint scan to gain access or clock in, and the GPS system in the employee’s car? Are you allowed to collect all this as long as you inform the employee about it? Or must you ask for consent? And are you then also allowed to use that data to monitor the employee and detect irregularities?

GDPR steps

In all these cases, one must first establish whether there is a legal basis for the processing at all. Next, one must weigh the interest of the employer in processing and collecting the data against the interest of the employee in keeping that data confidential. The question the employer must always ask themselves in this regard is whether there is an alternative way of obtaining the data that is less intrusive with regard to the employee’s privacy.

GDPR applied too strictly

These questions are not always easy to answer. In practice, we therefore regularly see that employers, due to a lack of knowledge, make far too strict an assessment. Choices are then made with the thought “that’s no longer allowed under the GDPR”, while it could actually still have been done, just differently. For example, sending payslips by email. That is still allowed, but then black out the BSN number and other data that is not relevant to the recipient.

Make sure you have the right knowledge about the practical application of the GDPR

It is a very diverse range of situations that one, as an employer, is repeatedly confronted with. It is therefore important to acquire the right practical knowledge regarding what the correct general steps and considerations are in the most common employee situations.

To make the correct practical application possible within your organisation, we are organising the Privacy and Employees Masterclass on 16 June 2019. In one half-day session we will guide you through this topic, and you will also receive a handy reference work as part of it. You can also order this reference work separately for 95 euros (excl. VAT). For more information, visit our website www.thelegalprivacycompany.com/trainingen, email info@thelegalprivacycompany.com or call 020-3450152.

De afgelopen jaren stonden in het teken van de Wet VBAR, het wetsvoorstel dat een einde moest maken aan onduidelijkheid over de zzp’er. Het kabinet heeft delen van dat voorstel inmiddels geschrapt. Op het eerste gezicht is dat goed nieuws: minder regels, minder administratieve last. Maar in de praktijk blijven dezelfde toetsen overeind.

“De inhoud van de samenwerking is leidend, niet wat er op papier staat.”

De Belastingdienst handhaaft sinds 1 januari 2025 weer actief op schijnzelfstandigheid. En recente uitspraken van de Hoge Raad bevestigen dat rechters strikt toetsen of er sprake is van ondergeschiktheid en gezagsverhouding.

Voor uw praktijk betekent dit drie dingen. Een: leg de samenwerking duidelijk vast, met aandacht voor de inhoud. Twee: voorkom dat een zzp’er feitelijk werkt als werknemer. Drie: wees voorbereid op een controle, en weet hoe u de relatie kunt herzien als dat moet.

Heeft u vragen over uw concrete situatie? Wij sparren dagelijks met opdrachtgevers over hun zzp-relaties. Vraag een offerte op of bekijk onze Legal Safe abonnementen.

Hella Vercammen LL.M.
Bente Brouwer LL.M.
Niels Terlouw LL.M.
Puck de Jong LL.M.

Read more