Skip to content
Call, +49 511 47 55 58 10
lexICT GmbH, Home

Point of law

Special categories of personal data

Art. 9(1) GDPR prohibits the processing, and a permission under paragraph 2 sits alongside the legal basis in Art. 6 GDPR rather than replacing it. Anyone relying on a permission in section 22(1) BDSG additionally owes the suitable and specific measures set out in paragraph 2.

Health data, scattered across the filing

The personnel file holds a certificate about a phased return to work, the post room an envelope from the company doctor, the ticketing system a request for an ergonomic chair. In the record of processing activities none of the three carries any note about special categories.

Health data arises without anyone collecting it

Where health data arises in the employment relationship is usually answered with the company doctor. The definition in Art. 4(15) GDPR reaches further. It covers any information relating to physical or mental health from which information about that state of health can be derived.

Five places where it regularly arises

Incapacity for work and its duration

The fact of incapacity concerns the state of health, even without a diagnosis. Duration and frequency say something in addition, so an analysis of absence figures processes special categories.

Occupational integration management

Section 167(2) SGB IX obliges the employer, after six weeks of incapacity in a year, to explore options together with the employee representation and with the data subject’s consent. What arises there is particularly sensitive and does not belong in the general personnel file.

Occupational health examinations

Findings are subject to the duty of confidentiality under section 203 StGB and stay with the medical staff. What the employer receives is the outcome, so fitness, and not the route to it.

Severe disability and equal status

Status as a severely disabled person is health data. It is necessary for the compensatory levy and for involving the representative body and may therefore be processed, but not everywhere.

Incidental entries in free-text fields

The finding no record knows about. A note in the ticketing system about an ergonomic chair, an entry on parental leave because of a child’s illness, a remark in the minutes of a meeting.

Which permission covers the processing is a question with two answers at once. Art. 9(1) GDPR sets out a prohibition of its own. An exception in paragraph 2 lifts it, and alongside that the lawfulness under Art. 6(1) GDPR still has to be established.

Two assessments, one after the other

  1. First stage, the prohibition

    Does an exception in Art. 9(2) GDPR apply, or a national provision based on it? For the employment relationship that is section 26(3) BDSG, resting on Art. 9(2)(b) GDPR.

  2. Second stage, the legal basis

    Which condition in Art. 6(1) GDPR is met? In the employment relationship regularly section 26(1) BDSG, so necessity for the employment relationship.

  3. Third stage, the measures

    Both provisions named stand under the condition in section 22(2) BDSG. Without the measures required there, the permission has not been fully relied upon.

3 von 3

Consent is the weakest option here too. Art. 9(2)(a) GDPR requires explicit consent, and section 26(2) BDSG imposes additional requirements on freedom of choice for employees.

Suitable and specific measures are the second half of the permission

Which additional measures have to be taken is set out in section 22(2) BDSG, and this provision is the most frequently overlooked part of the framework. Sentence 1 requires them, sentence 2 names ten examples.

General security and specific measure

Art. 32 GDPRMerkmalSection 22(2) BDSG
Every processing activityA level of security appropriate to the risk.TriggerOnly special categoriesA condition of the permission and not merely a security duty.
Appropriate to the riskState of the art, cost, nature and purpose.YardstickSuitable and specificSpecific means tailored to this category of data.
Role conceptAccess by function.Example, accessA tighter restrictionNo. 5 names restricting access separately, so beyond the role concept.
As neededIn so far as necessary for security.Example, loggingExpressly namedNo. 2 requires that entry, amendment and removal remain subsequently verifiable.

The measures in section 22(2) BDSG are not a tightening of Art. 32 GDPR but a condition of the permission. Where they are missing, the permission lacks one of its elements.

Four measures that can almost always be implemented

Liste zu erledigender Punkte

  • A separate area for health data in the HR system, kept apart from the general file
  • An access group named by person and not defined by department
  • Logging of entry, amendment and removal, with a report that somebody reads
  • A briefing for the access group that names the difference from ordinary personnel data

How we support you with special categories of data

The starting point is the record of processing activities. Art. 30(1)(c) GDPR calls for the categories of personal data, and that is where special categories have to be flagged. From that list follows which permission has to be assessed and which measures have to be taken. Where processing is on a large scale, an impact assessment under Art. 35(3)(b) GDPR applies on top.

Frequently asked questions

Are sickness notifications health data?

The statement that someone is unfit for work concerns their state of health and therefore falls under Art. 9(1) GDPR. The diagnosis is not for the employer to receive, and since electronic certificates of incapacity were introduced it regularly no longer does.

Do I still need a legal basis alongside Art. 9 GDPR?

Yes. Art. 9(1) GDPR sets out a prohibition of its own that an exception in paragraph 2 lifts. Lawfulness under Art. 6(1) GDPR is unaffected by that and has to be assessed in addition.

What does section 22(2) BDSG require in concrete terms?

Suitable and specific measures to safeguard the interests of the data subject. Sentence 2 names ten examples, among them restricting access, logging entry and amendment, raising awareness among those involved, and pseudonymisation and encryption.

Who in the organisation may see the data?

As few people as possible. Section 22(2) sentence 2 no. 5 BDSG names restricting access within the controller expressly as a measure. For the company doctor the duty of confidentiality under section 203 StGB applies on top, so findings stay there and only the outcome is communicated.

Get in touch!

Have we sparked your interest? Do you have questions? Would you like a quote without obligation? We look forward to hearing from you!

Contact us

Alternatively you can request a call back.