GDPR and social law: what are the employer's obligations?
Recruitment, payroll, monitoring of working time, professional evaluation, video surveillance, teleworking, management of absences or disciplinary procedures: the employer processes a considerable volume of personal data concerning its employees on a daily basis.
These processing operations are necessary for the operation of the company. They nevertheless remain subject to the General Data Protection Regulation (GDPR), the French Data Protection Act and the specific rules of labor law.
The intersection of GDPR and employment law has become a major issue for businesses. Excessive data collection, unjustified retention periods, or disproportionate monitoring systems can lead to sanctions from the CNIL (French Data Protection Authority), but can also jeopardize disciplinary proceedings or employment litigation.
What data can the employer collect? How should employees be informed? How far can they monitor their activity? What measures should be put in place to secure HR practices?
Why does the GDPR play a central role in employee management?
Human resources management necessarily involves the processing of personal data.
From the recruitment stage, the company collects information relating to the identity, education, and professional experience of candidates. After hiring, it processes, in particular:
- the employee's contact details and civil status information;
- his social security number and payroll data;
- his bank details;
- his schedule and his absences;
- his professional evaluations;
- his training requests;
- any possible disciplinary sanctions;
- certain data relating to his health;
- the information necessary to monitor his career;
- the traces left by the use of professional computer tools.
Some of this information is particularly sensitive. This may include health data, trade union information, biometric data, or information relating to a disability.
In most cases, the employer acts as the data controller. It is therefore up to them to determine why the data is collected, how it is used, who can access it, and how long it will be kept.
Compliance is therefore not solely the responsibility of the IT department or the data protection officer. It directly concerns HR departments, the legal department, operational managers, and anyone involved in personnel management.
What rules must the employer follow?
Determine a specific purpose
Each treatment must meet a specific, explicit and legitimate objective.
The collection of bank details may, for example, be justified by salary payments. Retaining supporting documents may be necessary to fulfill the company's social and accounting obligations. Monitoring access to certain premises may be a security imperative.
On the other hand, data should not be collected for possible future use without a clearly identified purpose.
Information initially collected to organize work cannot be freely reused for disciplinary purposes if this new use is incompatible with the stated purpose.
Identify a legal basis
All processing of personal data must be based on a legal basis as provided for by the GDPR.
In the field of human resources, the most common foundations are:
- the execution of the employment contract;
- compliance with a legal obligation imposed on the employer;
- the legitimate interest of the company, provided that it does not disproportionately infringe on the rights of employees;
- In exceptional cases, the consent of the person concerned.
Consent must be used with caution in the employment relationship. Due to the hierarchical nature of the relationship, employees are not always in a position to freely refuse the proposed treatment. Therefore, consent is not, in principle, the most appropriate basis for routine HR practices.
Collect only the necessary data
The principle of data minimization requires the employer to limit the collection of information to that which is strictly necessary for the objective pursued.
This requirement must be considered from the design stage of a form, HR software, recruitment process, or control device.
During recruitment, the questions asked must have a direct and necessary link to the job offered or the evaluation of the candidate's professional skills. Information relating to their family life, opinions, health, or personal plans cannot be collected without legitimate justification.
The same vigilance is required when a digital tool technically allows the collection of much more information than the company actually needs.
Clearly inform candidates and employees
The individuals concerned must receive information accessible at:
- the identity of the data controller;
- the objectives pursued;
- the legal basis used;
- the categories of data collected;
- the recipients of this data;
- their shelf life;
- the existence of possible transfers outside the European Union;
- their rights and the procedures for exercising them;
- the possibility of contacting the CNIL.
This information can be included in a notice for employees, in recruitment forms, on the intranet, or in an IT policy. However, it must be sufficiently precise and tailored to each processing activity.
In labor law, ArticleL. 1222-4 of the Labor Code further stipulates that no information concerning an employee personally may be collected by a device that has not been previously brought to their attention.
Limit access to HR data
Personnel files should not be accessible to all managers or employees of the company.
Each person should only have access to the information necessary for the performance of their duties. Data relating to payroll, health, disciplinary sanctions, or internal reports requires heightened vigilance.
The employer must therefore plan for:
- individualized authorizations;
- sufficiently robust authentication;
- a regular review of access rights;
- the rapid removal of access points that have become unnecessary;
- traceability of the most sensitive consultations;
- specific measures for paper files and email exchanges.
How long should employee data be kept?
Personal data cannot be stored indefinitely.
The relevant duration depends on the purpose of the processing, applicable legal obligations, and the timeframes during which the company may be required to establish or defend its legal rights.
It is generally necessary to distinguish between:
- the active database, in which information is accessible for day-to-day management;
- intermediate archiving , reserved for data that must still be kept due to a legal obligation or a risk of litigation;
- the deletion or permanent anonymization upon expiry of the useful period.
In 2026, the CNIL published a new guideline regarding the retention periods for human resources management data. It now constitutes a particularly useful tool for building a coherent data retention policy.
However, a company should not apply a single retention period indiscriminately to the entirety of an employee's file. Pay slips, unsuccessful applications, disciplinary documents, access control data, and information relating to working time are not subject to the same rules.
Employee monitoring: how far can the employer go?
The employer can control the activity of its employees, but this power is not unlimited.
All control devices must be:
- justified by the nature of the task to be performed;
- proportionate to the objective pursued;
- brought to the attention of employees beforehand;
- recorded, where applicable, in the register of processing activities;
- subject to prior information and consultation of the social and economic committee.
These rules relate in particular to video surveillance, geolocation, timekeeping, internet browsing analysis, access to professional email and activity tracking software.
Constant surveillance is, in principle, disproportionate
An employee should not be placed under permanent surveillance, except in exceptional circumstances that are clearly demonstrated.
The CNIL (French Data Protection Authority) notably sanctioned a company that used software to track supposed periods of inactivity, took regular screenshots, and imposed continuous video recording of certain employees. Such surveillance constituted an excessive infringement on their privacy.
Employers must be particularly cautious with tools that allow:
- the systematic recording of keystrokes;
- the repeated taking of screenshots;
- the permanent activation of a camera;
- continuous recording of conversations;
- automatic measurement of inactivity time;
- the establishment of an individual productivity score.
The technical possibility of activating a feature does not mean that its use is legally lawful.
Professional email and personal files
Messages and files created using the professional tool are, in principle, presumed to be professional in nature, unless they are clearly identified as personal.
The employer must respect the privacy of messages or files thus identified. Opening or using them may infringe on the confidentiality of correspondence and the employee's privacy.
The IT charter must clearly explain the conditions of use of professional tools, the controls that may be carried out and how the employee can identify their personal content.
Recruitment, algorithms and artificial intelligence: new risks
The use of artificial intelligence tools in recruitment and career management further increases the issues related to personal data.
Automated application sorting, video analysis of an interview, behavioral assessment, employee ranking or recommendation of a mobility: these systems can produce opaque decisions, reproduce biases or lead to the collection of excessive information.
Before deploying such a tool, the employer must, in particular, verify the following:
- the data actually used by the system;
- their origin and their reliability;
- the criteria taken into account by the algorithm;
- the existence of a risk of discrimination;
- the conditions for data reuse by the service provider;
- the location of the data and any potential international transfers;
- the possibility of real human intervention;
- the need to carry out a data protection impact assessment.
Furthermore, GDPR compliance must be coordinated with the requirements of the European regulation on artificial intelligence, particularly when the tool is used for recruitment, candidate selection or certain decisions affecting the employment relationship.
What are the rights of employees?
The employee retains all the rights recognized by the GDPR. In particular, they can request:
- access to his data;
- the correction of inaccurate information;
- the deletion of certain data;
- the limitation of a treatment;
- opposition to certain treatments;
- the communication of information about an automated decision.
The right of access may relate to data contained in professional emails, provided that they concern the requesting employee.
This option is now frequently used before or during employment litigation. The employer's response must comply with the deadlines set by the GDPR, while protecting the rights of third parties, trade secrets, and the confidentiality of correspondence that does not concern the applicant.
Access requests should therefore not be treated as simple IT requests. They often require a joint analysis of personal data law and social litigation strategy.
What risks does the company face?
Failure to comply with the GDPR can have multiple consequences.
The CNIL can issue a formal notice, order the restriction or cessation of processing, and impose an administrative fine. For the most serious breaches, the GDPR provides for a penalty of up to €20 million or 4% of total worldwide annual turnover, whichever is higher.
In addition to this administrative risk, there are also:
- an action for damages brought by an employee;
- a dispute relating to the infringement of privacy;
- criminal penalties in certain situations;
- an intervention by the labor inspectorate;
- an action by the social and economic committee or a trade union organization;
- a deterioration of the social climate and the company's reputation.
Non-compliance can also affect individual legal disputes. An irregular monitoring system can weaken the evidence gathered by the employer. However, its admissibility is no longer assessed in a systematically binary fashion: the judge notably weighs the right to evidence against the employee's fundamental rights, verifying whether the production of the evidence was essential and proportionate.
This development in no way exempts the employer from putting in place lawful measures. On the contrary, it underlines the importance of anticipating their justification and regulation.
How to bring the company into compliance with the GDPR in social matters?
An effective approach can be organized around ten priority actions.
1. Map HR processes
The company must list the data collected from recruitment to the employee's departure: origin, purpose, recipients, software used, retention periods and any transfers outside the European Union.
2. Update the treatment register
Processes relating to candidates, payroll, training, assessments, working time, access controls or disciplinary procedures must be properly documented.
3. Verify the legal basis
Each processing activity must be linked to an appropriate legal basis. Systematic reference to employee consent should be avoided when another basis is more relevant.
4. Review the information notices
Candidates and employees must receive clear, complete, and easily accessible information. This documentation must reflect the practices actually implemented.
5. Define a conservation policy
A retention schedule must specify, for each category of documents, the duration in active database, the duration of intermediate archiving and the methods of deletion.
6. Framework for control tools
Each video surveillance, geolocation, or digital tracking system must be subject to a necessity and proportionality analysis. Employees and the Works Council must be informed or consulted when required by law.
7. Secure sensitive data
Authorizations must be limited, access regularly monitored, and exchanges containing sensitive data protected. A procedure must also be in place for managing data breaches.
8. Audit HR service providers
Contracts concluded with software publishers, recruitment firms, payroll providers, training platforms or artificial intelligence solutions must specify their obligations regarding confidentiality, security, subcontracting, data storage and return.
9. Organize the exercise of rights
The company must have a procedure in place to quickly identify, investigate and process employee requests, especially when these involve large volumes of emails or documents.
10. Form the teams
HR departments, managers and IT managers need to be made aware of the right reflexes: limit the data collected, avoid subjective comments, secure transmissions and report any incident quickly.
GDPR and social law: compliance that must be cross-cutting
Compliance in HR processes cannot be based on standard documentation that is disconnected from company practices.
It requires a cross-analysis of data protection law, labor law, the digital tools used, and operational constraints. This approach is particularly important when implementing a control system, acquiring a new HR tool, reorganizing, conducting an internal investigation, or handling a dispute with an employee.
A targeted audit helps to identify the riskiest processes, prioritize the necessary corrections and build a compliance plan adapted to the size and activity of the company.
The Social Law and GDPR & New Technologies teams at ARST Avocats support employers in auditing their practices, drafting their documentation, consulting the CSE, overseeing control mechanisms and managing litigation related to employees' personal data.
Authors: Chaouki Gaddada and Morgan Jamet

Chaouki Gaddada
Author

Morgan Jamet
Author
Mergers and acquisitions and public action against the acquired company
Court of Cassation, Criminal Chamber, November 25, 2020, No. 18-86.955 FS PBI, Société Iron Mountain France. By a judgment dated November 25...
The status of commercial agent and the power to negotiate prices
Court of Cassation, Civil Division, Commercial Chamber, December 2, 2020, 18-20.231, Published in the CJEU Bulletin...
Registration of electronically signed documents
Registration of electronically signed documents: rules and precautions. The registration of electronically signed documents has been accepted by the tax authorities since January 1, 2021. Privately signed documents can therefore be submitted for registration...
Termination clause and landlord's waiver
A landlord who has requested and obtained the acquisition of a termination clause under a final judgment may no longer, in the event of non-compliance by the tenant with the payment deadlines conditioning the suspension of the effects of the termination clause,...
Brexit and existing insurance contracts
The combined interpretation of Article L....
The complete closure of the business and force majeure
The total closure of the business as part of the state of health emergency and lockdown may constitute force majeure
Covid-19 – New tightening of restrictions imposed on French insurers!
During the first lockdown related to the health crisis triggered by the spread of Covid-19, the government called upon a number of stakeholders to contribute to the national effort to support the French economy. In his speech on the 13th...
Covid-19 – Focus on the fate of commercial rents
Presentation of Article 14 of Law No. 2020-1379 of November 14, 2020, authorizing the extension of the state of health emergency and enacting various measures for managing the health crisis. The context of the establishment of Law 2020-1379 of November 14, 2020...
Inter-company lending: a little-known solution
Inter-company lending: a little-known solution. Article updated in September 2026. Can a company with surplus cash grant a loan to a supplier, subcontractor, franchisee, or other business partner? For a long time...
Focus on the ruling of the Plenary Assembly of the Court of Cassation of January 20, 2020
Why discuss this decision, which is already over six months old? The ripple effect of this decision was abruptly halted by the emergence of Covid-19, but the easing of lockdown measures is finally leading practitioners to give it the attention it deserves. Because this decision deserves...