Skip to main content
ExplainerGDPR ComplianceRegulatory Explainer· 5 min read· in Careers & Work

How the GDPR Restricts Employee Data Processing: Navigating Contract, Legal Obligation, and Legitimate Interest

European data protection authorities effectively invalidate employee consent due to workplace power dynamics, forcing companies to rely on stricter legal bases for HR data operations.

By Alexei Morozov

Data Protection Authorities 45%Corporate Compliance Officers 35%Privacy Advocates 20%
Data Protection Authorities
Argue that the inherent power imbalance in employment makes freely given consent impossible, requiring strict adherence to alternative legal bases.
Corporate Compliance Officers
Focus on the administrative complexity of conducting legitimate interest assessments and mapping hundreds of data points to specific legal obligations.
Privacy Advocates
Emphasize the necessity of these strict legal boundaries to prevent workplace surveillance creep and protect fundamental worker rights.

Perspectives this story doesn't cover

  • Enterprise HR Software Vendors
  • Labor Union Representatives

Corporate compliance officers view employee consent as the ultimate legal shield—a signed document proving the worker agreed to biometric timekeeping or email monitoring. European data protection authorities view that same signature as legally void. They argue that a subordinate relying on a company for their livelihood cannot freely say no to the person who signs their paycheck, rendering the agreement inherently coercive.[1][2]

The stakes for misclassifying this data are measured in enforcement actions. Since the General Data Protection Regulation (GDPR) took effect in May 2018, data protection authorities have levied fines exceeding €1.5 million against individual employers who improperly relied on employee consent. The core mechanism of the regulation requires a lawful basis for every data operation, and modern human resources systems typically process between 400 and 600 distinct data points per employee.[3][6]

The Jackson Lewis analysis from May 2026 highlights this exact friction. "Employers often default to consent because it feels intuitive and transparent," the firm notes, but the European Data Protection Board explicitly warns against it. Article 7 of the GDPR requires consent to be freely given, specific, informed, and unambiguous. In an employer-employee dynamic, the inherent power imbalance means a worker might fear retaliation or career stagnation if they refuse to let the company process their data.[3][4]

The Dutch data protection authority, Autoriteit Persoonsgegevens (AP), issued updated guidance in April 2025 reinforcing this boundary. The AP explicitly states that because of the hierarchical relationship, employees are rarely in a position to refuse without consequence. Therefore, employers must pivot away from consent and anchor their data processing in one of the other available legal bases provided by the regulation.[2]

Regulatory enforcement effectively reduces the six GDPR legal bases to three functional pathways for employers.

The first viable alternative is contractual necessity, defined under Article 6(1)(b). When an individual signs an employment contract, the company must process certain data simply to fulfill that agreement. This covers the foundational mechanics of employment: bank details for payroll processing, home addresses for tax forms, and basic contact information required to manage the working relationship.[1][5]

However, contractual necessity is strictly bounded. The UK Information Commissioner's Office (ICO) emphasizes that the processing must be objectively necessary to deliver the contract. An employer cannot use this basis to justify monitoring an employee's internet usage or tracking their location via a company vehicle, as neither action is strictly required to pay the worker their agreed salary.[1]

When the contract falls short, legal obligation—codified in Article 6(1)(c)—often steps in. Employers operate under hundreds of statutory requirements across different jurisdictions. If a national law mandates that a company track working hours to ensure compliance with the European Working Time Directive, the employer processes that timekeeping data under a legal obligation.[1][5]

When the contract falls short, legal obligation—codified in Article 6(1)(c)—often steps in.

This basis also covers workplace safety and tax reporting. The GDPRLedger compliance guide from April 2026 notes that processing sick leave data or workplace accident reports is not a choice for the employer; it is a statutory mandate. The employee does not need to consent, and the employer does not need to prove legitimate interest, because the state has already required the data collection.[5]

The most flexible, and therefore most scrutinized, pathway is legitimate interest, found in Article 6(1)(f). This basis applies when an employer needs to process data for a valid business reason that is not strictly required by law or contract, provided that this need is not overridden by the employee's fundamental rights and freedoms.[1][2]

The majority of routine employee data processing falls under contractual necessity or legal obligation.

Relying on legitimate interest requires a documented balancing test known as a Legitimate Interest Assessment (LIA). If a company wants to deploy data loss prevention software to scan outgoing emails for proprietary code, it must weigh its right to protect intellectual property against the worker's right to privacy. The ICO requires organizations to prove the processing is purposeful, necessary, and balanced.[1]

The calculus changes entirely when dealing with special category data, such as biometric information, health records, or union membership. Article 9 of the GDPR prohibits processing this data unless a specific exception applies. Standard legitimate interest is insufficient here, forcing employers to find explicit authorization in national employment law.[3][5]

Consider a warehouse implementing fingerprint scanners for timekeeping. Because consent is invalid in the employment context, and legitimate interest cannot authorize biometric processing, the employer must find a specific national law authorizing biometric timekeeping. Without it, the system violates the regulation, a reality that has triggered numerous six-figure fines across the European Union.[2][6]

Processing biometric data requires specific national legal authorization, as standard legitimate interest is insufficient.

Regardless of which of the three viable bases an employer selects, the transparency requirement remains absolute. Workers must be informed exactly which legal basis applies to which data point before the processing begins. This is typically executed through a comprehensive employee privacy notice distributed during onboarding, detailing standard 30-day retention periods and data subject rights.[1][5]

This regulatory architecture is forcing a redesign of human resources technology. Enterprise software vendors are now building compliance mapping directly into their platforms, requiring administrators to tag every new data field with its corresponding legal basis. A system that defaults to asking for user consent is now recognized as a liability rather than a feature.[4][6]

The enforcement landscape continues to tighten around these distinctions. As workplace surveillance tools become more sophisticated, regulators are demanding more rigorous documentation of the legitimate interest balancing tests. The burden of proof rests entirely on the employer to demonstrate that their data practices respect the boundaries of the employment relationship.[1][2][6]

What to know

  1. Employee consent is generally considered invalid under the GDPR due to the inherent power imbalance in the workplace.
  2. Employers must rely on contractual necessity for core employment functions like payroll and benefits administration.
  3. Statutory requirements, such as tax reporting and workplace safety, fall under the legal obligation basis.
  4. Optional processing, like network monitoring, requires a documented Legitimate Interest Assessment.
  5. Special category data, including biometrics, requires specific authorization under national employment law.

Key terms

Data Controller
The entity (in this case, the employer) that determines the purposes and means of processing personal data.
Legitimate Interest Assessment (LIA)
A documented three-part test used to ensure an employer's business need to process data does not override the employee's privacy rights.
Special Category Data
Highly sensitive personal information, such as biometric data, health records, or racial origin, which requires explicit legal authorization to process.

Sources

Source coverage

6 outlets

3 viewpoints surfaced

Data Protection Authorities 45%Corporate Compliance Officers 35%Privacy Advocates 20%
  1. [1]ICOData Protection Authorities

    A guide to lawful basis

    Read on ICO
  2. [2]Autoriteit PersoonsgegevensData Protection Authorities

    Legal bases from the GDPR explained

    Read on Autoriteit Persoonsgegevens
  3. [3]GDPR.euPrivacy Advocates

    Consent

    Read on GDPR.eu
  4. [4]Jackson LewisCorporate Compliance Officers

    Is Employee Consent under EU Data Protection Regulation Possible?

    Read on Jackson Lewis
  5. [5]GDPRLedgerCorporate Compliance Officers

    GDPR for HR and Employers — EU Employee Data Compliance Guide

    Read on GDPRLedger
  6. [6]Factlen Editorial Team

    Synthesis by Factlen editorial team

    Read on Factlen Editorial Team

Comments

Stay informed

Every angle. Every day.

Get Careers & Work stories with full source coverage and perspective breakdowns delivered to your inbox.