Point of law
Special categories of personal data
Art. 9(1) GDPR prohibits the processing, and a permission under paragraph 2 sits alongside the legal basis in Art. 6 GDPR rather than replacing it. Anyone relying on a permission in section 22(1) BDSG additionally owes the suitable and specific measures set out in paragraph 2.
Health data, scattered across the filing
The personnel file holds a certificate about a phased return to work, the post room an envelope from the company doctor, the ticketing system a request for an ergonomic chair. In the record of processing activities none of the three carries any note about special categories.
Health data arises without anyone collecting it
Where health data arises in the employment relationship is usually answered with the company doctor. The definition in Art. 4(15) GDPR reaches further. It covers any information relating to physical or mental health from which information about that state of health can be derived.
Five places where it regularly arises
Incapacity for work and its duration
The fact of incapacity concerns the state of health, even without a diagnosis. Duration and frequency say something in addition, so an analysis of absence figures processes special categories.
Occupational integration management
Section 167(2) SGB IX obliges the employer, after six weeks of incapacity in a year, to explore options together with the employee representation and with the data subject’s consent. What arises there is particularly sensitive and does not belong in the general personnel file.
Occupational health examinations
Findings are subject to the duty of confidentiality under section 203 StGB and stay with the medical staff. What the employer receives is the outcome, so fitness, and not the route to it.
Severe disability and equal status
Status as a severely disabled person is health data. It is necessary for the compensatory levy and for involving the representative body and may therefore be processed, but not everywhere.
Incidental entries in free-text fields
The finding no record knows about. A note in the ticketing system about an ergonomic chair, an entry on parental leave because of a child’s illness, a remark in the minutes of a meeting.
The permission sits alongside the legal basis and does not replace it
Which permission covers the processing is a question with two answers at once. Art. 9(1) GDPR sets out a prohibition of its own. An exception in paragraph 2 lifts it, and alongside that the lawfulness under Art. 6(1) GDPR still has to be established.
Two assessments, one after the other
First stage, the prohibition
Does an exception in Art. 9(2) GDPR apply, or a national provision based on it? For the employment relationship that is section 26(3) BDSG, resting on Art. 9(2)(b) GDPR.
Second stage, the legal basis
Which condition in Art. 6(1) GDPR is met? In the employment relationship regularly section 26(1) BDSG, so necessity for the employment relationship.
Third stage, the measures
Both provisions named stand under the condition in section 22(2) BDSG. Without the measures required there, the permission has not been fully relied upon.
3 von 3
Consent is the weakest option here too. Art. 9(2)(a) GDPR requires explicit consent, and section 26(2) BDSG imposes additional requirements on freedom of choice for employees.
Suitable and specific measures are the second half of the permission
Which additional measures have to be taken is set out in section 22(2) BDSG, and this provision is the most frequently overlooked part of the framework. Sentence 1 requires them, sentence 2 names ten examples.
General security and specific measure
| Art. 32 GDPR | Merkmal | Section 22(2) BDSG |
|---|---|---|
| Every processing activityA level of security appropriate to the risk. | Trigger | Only special categoriesA condition of the permission and not merely a security duty. |
| Appropriate to the riskState of the art, cost, nature and purpose. | Yardstick | Suitable and specificSpecific means tailored to this category of data. |
| Role conceptAccess by function. | Example, access | A tighter restrictionNo. 5 names restricting access separately, so beyond the role concept. |
| As neededIn so far as necessary for security. | Example, logging | Expressly namedNo. 2 requires that entry, amendment and removal remain subsequently verifiable. |
The measures in section 22(2) BDSG are not a tightening of Art. 32 GDPR but a condition of the permission. Where they are missing, the permission lacks one of its elements.
Four measures that can almost always be implemented
Liste zu erledigender Punkte
- A separate area for health data in the HR system, kept apart from the general file
- An access group named by person and not defined by department
- Logging of entry, amendment and removal, with a report that somebody reads
- A briefing for the access group that names the difference from ordinary personnel data
How we support you with special categories of data
The starting point is the record of processing activities. Art. 30(1)(c) GDPR calls for the categories of personal data, and that is where special categories have to be flagged. From that list follows which permission has to be assessed and which measures have to be taken. Where processing is on a large scale, an impact assessment under Art. 35(3)(b) GDPR applies on top.
Frequently asked questions
Are sickness notifications health data?
The statement that someone is unfit for work concerns their state of health and therefore falls under Art. 9(1) GDPR. The diagnosis is not for the employer to receive, and since electronic certificates of incapacity were introduced it regularly no longer does.
Do I still need a legal basis alongside Art. 9 GDPR?
Yes. Art. 9(1) GDPR sets out a prohibition of its own that an exception in paragraph 2 lifts. Lawfulness under Art. 6(1) GDPR is unaffected by that and has to be assessed in addition.
What does section 22(2) BDSG require in concrete terms?
Suitable and specific measures to safeguard the interests of the data subject. Sentence 2 names ten examples, among them restricting access, logging entry and amendment, raising awareness among those involved, and pseudonymisation and encryption.
Who in the organisation may see the data?
As few people as possible. Section 22(2) sentence 2 no. 5 BDSG names restricting access within the controller expressly as a measure. For the company doctor the duty of confidentiality under section 203 StGB applies on top, so findings stay there and only the outcome is communicated.
More questions from this area
We are planning something
Data protection belongs in a new project from the outset and not in the acceptance test.
Automated individual decisions
Pre-selection is not a preliminary stage of the decision where the selection follows it to a significant degree.
Transfer impact assessment
The regulation does not know the term transfer impact assessment.
Data protection impact assessment
An impact assessment under Art. 35 GDPR is not a formality at the end of a project.
Get in touch!
Have we sparked your interest? Do you have questions? Would you like a quote without obligation? We look forward to hearing from you!
Contact usAlternatively you can request a call back.