GDPR and social law: what are the employer's obligations?
Recruitment, payroll, monitoring of working time, professional evaluation, video surveillance, teleworking, management of absences or disciplinary procedures: the employer processes a considerable volume of personal data concerning its employees on a daily basis.
These processing operations are necessary for the operation of the company. They nevertheless remain subject to the General Data Protection Regulation (GDPR), the French Data Protection Act and the specific rules of labor law.
The intersection of GDPR and employment law has become a major issue for businesses. Excessive data collection, unjustified retention periods, or disproportionate monitoring systems can lead to sanctions from the CNIL (French Data Protection Authority), but can also jeopardize disciplinary proceedings or employment litigation.
What data can the employer collect? How should employees be informed? How far can they monitor their activity? What measures should be put in place to secure HR practices?
Why does the GDPR play a central role in employee management?
Human resources management necessarily involves the processing of personal data.
From the recruitment stage, the company collects information relating to the identity, education, and professional experience of candidates. After hiring, it processes, in particular:
- the employee's contact details and civil status information;
- his social security number and payroll data;
- his bank details;
- his schedule and his absences;
- his professional evaluations;
- his training requests;
- any possible disciplinary sanctions;
- certain data relating to his health;
- the information necessary to monitor his career;
- the traces left by the use of professional computer tools.
Some of this information is particularly sensitive. This may include health data, trade union information, biometric data, or information relating to a disability.
In most cases, the employer acts as the data controller. It is therefore up to them to determine why the data is collected, how it is used, who can access it, and how long it will be kept.
Compliance is therefore not solely the responsibility of the IT department or the data protection officer. It directly concerns HR departments, the legal department, operational managers, and anyone involved in personnel management.
What rules must the employer follow?
Determine a specific purpose
Each treatment must meet a specific, explicit and legitimate objective.
The collection of bank details may, for example, be justified by salary payments. Retaining supporting documents may be necessary to fulfill the company's social and accounting obligations. Monitoring access to certain premises may be a security imperative.
On the other hand, data should not be collected for possible future use without a clearly identified purpose.
Information initially collected to organize work cannot be freely reused for disciplinary purposes if this new use is incompatible with the stated purpose.
Identify a legal basis
All processing of personal data must be based on a legal basis as provided for by the GDPR.
In the field of human resources, the most common foundations are:
- the execution of the employment contract;
- compliance with a legal obligation imposed on the employer;
- the legitimate interest of the company, provided that it does not disproportionately infringe on the rights of employees;
- In exceptional cases, the consent of the person concerned.
Consent must be used with caution in the employment relationship. Due to the hierarchical nature of the relationship, employees are not always in a position to freely refuse the proposed treatment. Therefore, consent is not, in principle, the most appropriate basis for routine HR practices.
Collect only the necessary data
The principle of data minimization requires the employer to limit the collection of information to that which is strictly necessary for the objective pursued.
This requirement must be considered from the design stage of a form, HR software, recruitment process, or control device.
During recruitment, the questions asked must have a direct and necessary link to the job offered or the evaluation of the candidate's professional skills. Information relating to their family life, opinions, health, or personal plans cannot be collected without legitimate justification.
The same vigilance is required when a digital tool technically allows the collection of much more information than the company actually needs.
Clearly inform candidates and employees
The individuals concerned must receive information accessible at:
- the identity of the data controller;
- the objectives pursued;
- the legal basis used;
- the categories of data collected;
- the recipients of this data;
- their shelf life;
- the existence of possible transfers outside the European Union;
- their rights and the procedures for exercising them;
- the possibility of contacting the CNIL.
This information can be included in a notice for employees, in recruitment forms, on the intranet, or in an IT policy. However, it must be sufficiently precise and tailored to each processing activity.
In labor law, ArticleL. 1222-4 of the Labor Code further stipulates that no information concerning an employee personally may be collected by a device that has not been previously brought to their attention.
Limit access to HR data
Personnel files should not be accessible to all managers or employees of the company.
Each person should only have access to the information necessary for the performance of their duties. Data relating to payroll, health, disciplinary sanctions, or internal reports requires heightened vigilance.
The employer must therefore plan for:
- individualized authorizations;
- sufficiently robust authentication;
- a regular review of access rights;
- the rapid removal of access points that have become unnecessary;
- traceability of the most sensitive consultations;
- specific measures for paper files and email exchanges.
How long should employee data be kept?
Personal data cannot be stored indefinitely.
The relevant duration depends on the purpose of the processing, applicable legal obligations, and the timeframes during which the company may be required to establish or defend its legal rights.
It is generally necessary to distinguish between:
- the active database, in which information is accessible for day-to-day management;
- intermediate archiving , reserved for data that must still be kept due to a legal obligation or a risk of litigation;
- the deletion or permanent anonymization upon expiry of the useful period.
In 2026, the CNIL published a new guideline regarding the retention periods for human resources management data. It now constitutes a particularly useful tool for building a coherent data retention policy.
However, a company should not apply a single retention period indiscriminately to the entirety of an employee's file. Pay slips, unsuccessful applications, disciplinary documents, access control data, and information relating to working time are not subject to the same rules.
Employee monitoring: how far can the employer go?
The employer can control the activity of its employees, but this power is not unlimited.
All control devices must be:
- justified by the nature of the task to be performed;
- proportionate to the objective pursued;
- brought to the attention of employees beforehand;
- recorded, where applicable, in the register of processing activities;
- subject to prior information and consultation of the social and economic committee.
These rules relate in particular to video surveillance, geolocation, timekeeping, internet browsing analysis, access to professional email and activity tracking software.
Constant surveillance is, in principle, disproportionate
An employee should not be placed under permanent surveillance, except in exceptional circumstances that are clearly demonstrated.
The CNIL (French Data Protection Authority) notably sanctioned a company that used software to track supposed periods of inactivity, took regular screenshots, and imposed continuous video recording of certain employees. Such surveillance constituted an excessive infringement on their privacy.
Employers must be particularly cautious with tools that allow:
- the systematic recording of keystrokes;
- the repeated taking of screenshots;
- the permanent activation of a camera;
- continuous recording of conversations;
- automatic measurement of inactivity time;
- the establishment of an individual productivity score.
The technical possibility of activating a feature does not mean that its use is legally lawful.
Professional email and personal files
Messages and files created using the professional tool are, in principle, presumed to be professional in nature, unless they are clearly identified as personal.
The employer must respect the privacy of messages or files thus identified. Opening or using them may infringe on the confidentiality of correspondence and the employee's privacy.
The IT charter must clearly explain the conditions of use of professional tools, the controls that may be carried out and how the employee can identify their personal content.
Recruitment, algorithms and artificial intelligence: new risks
The use of artificial intelligence tools in recruitment and career management further increases the issues related to personal data.
Automated application sorting, video analysis of an interview, behavioral assessment, employee ranking or recommendation of a mobility: these systems can produce opaque decisions, reproduce biases or lead to the collection of excessive information.
Before deploying such a tool, the employer must, in particular, verify the following:
- the data actually used by the system;
- their origin and their reliability;
- the criteria taken into account by the algorithm;
- the existence of a risk of discrimination;
- the conditions for data reuse by the service provider;
- the location of the data and any potential international transfers;
- the possibility of real human intervention;
- the need to carry out a data protection impact assessment.
Furthermore, GDPR compliance must be coordinated with the requirements of the European regulation on artificial intelligence, particularly when the tool is used for recruitment, candidate selection or certain decisions affecting the employment relationship.
What are the rights of employees?
The employee retains all the rights recognized by the GDPR. In particular, they can request:
- access to his data;
- the correction of inaccurate information;
- the deletion of certain data;
- the limitation of a treatment;
- opposition to certain treatments;
- the communication of information about an automated decision.
The right of access may relate to data contained in professional emails, provided that they concern the requesting employee.
This option is now frequently used before or during employment litigation. The employer's response must comply with the deadlines set by the GDPR, while protecting the rights of third parties, trade secrets, and the confidentiality of correspondence that does not concern the applicant.
Access requests should therefore not be treated as simple IT requests. They often require a joint analysis of personal data law and social litigation strategy.
What risks does the company face?
Failure to comply with the GDPR can have multiple consequences.
The CNIL can issue a formal notice, order the restriction or cessation of processing, and impose an administrative fine. For the most serious breaches, the GDPR provides for a penalty of up to €20 million or 4% of total worldwide annual turnover, whichever is higher.
In addition to this administrative risk, there are also:
- an action for damages brought by an employee;
- a dispute relating to the infringement of privacy;
- criminal penalties in certain situations;
- an intervention by the labor inspectorate;
- an action by the social and economic committee or a trade union organization;
- a deterioration of the social climate and the company's reputation.
Non-compliance can also affect individual legal disputes. An irregular monitoring system can weaken the evidence gathered by the employer. However, its admissibility is no longer assessed in a systematically binary fashion: the judge notably weighs the right to evidence against the employee's fundamental rights, verifying whether the production of the evidence was essential and proportionate.
This development in no way exempts the employer from putting in place lawful measures. On the contrary, it underlines the importance of anticipating their justification and regulation.
How to bring the company into compliance with the GDPR in social matters?
An effective approach can be organized around ten priority actions.
1. Map HR processes
The company must list the data collected from recruitment to the employee's departure: origin, purpose, recipients, software used, retention periods and any transfers outside the European Union.
2. Update the treatment register
Processes relating to candidates, payroll, training, assessments, working time, access controls or disciplinary procedures must be properly documented.
3. Verify the legal basis
Each processing activity must be linked to an appropriate legal basis. Systematic reference to employee consent should be avoided when another basis is more relevant.
4. Review the information notices
Candidates and employees must receive clear, complete, and easily accessible information. This documentation must reflect the practices actually implemented.
5. Define a conservation policy
A retention schedule must specify, for each category of documents, the duration in active database, the duration of intermediate archiving and the methods of deletion.
6. Framework for control tools
Each video surveillance, geolocation, or digital tracking system must be subject to a necessity and proportionality analysis. Employees and the Works Council must be informed or consulted when required by law.
7. Secure sensitive data
Authorizations must be limited, access regularly monitored, and exchanges containing sensitive data protected. A procedure must also be in place for managing data breaches.
8. Audit HR service providers
Contracts concluded with software publishers, recruitment firms, payroll providers, training platforms or artificial intelligence solutions must specify their obligations regarding confidentiality, security, subcontracting, data storage and return.
9. Organize the exercise of rights
The company must have a procedure in place to quickly identify, investigate and process employee requests, especially when these involve large volumes of emails or documents.
10. Form the teams
HR departments, managers and IT managers need to be made aware of the right reflexes: limit the data collected, avoid subjective comments, secure transmissions and report any incident quickly.
GDPR and social law: compliance that must be cross-cutting
Compliance in HR processes cannot be based on standard documentation that is disconnected from company practices.
It requires a cross-analysis of data protection law, labor law, the digital tools used, and operational constraints. This approach is particularly important when implementing a control system, acquiring a new HR tool, reorganizing, conducting an internal investigation, or handling a dispute with an employee.
A targeted audit helps to identify the riskiest processes, prioritize the necessary corrections and build a compliance plan adapted to the size and activity of the company.
The Social Law and GDPR & New Technologies teams at ARST Avocats support employers in auditing their practices, drafting their documentation, consulting the CSE, overseeing control mechanisms and managing litigation related to employees' personal data.
Authors: Chaouki Gaddada and Morgan Jamet

Chaouki Gaddada
Author

Morgan Jamet
Author
The seizure of the life insurance contract by the public accountant
Jefferson Larue, partner at Arst Avocats, presents the seizure of a life insurance contract by the public accountant
Video – The manager's duty to inform his partners
Jefferson Larue, partner at Arst Avocats, presents the duty of disclosure of a company director towards its partners
Civil Procedure Reform – Focus on the main upcoming measures – Law of 23 March 2019 on programming 2018-2022 and reform for justice
Simplifying civil procedure is a key focus of the Law of March 23, 2019, on the 2018-2022 programming and reform for justice. This reform of civil procedure aims to be synonymous with speed and simplicity for litigants.
Obligation to employ disabled workers: new rules from January 1, 2020
Law No. 2018-771 of September 5, 2018, for the freedom to choose one's professional future, known as the Future Law, reformed the obligation to employ disabled workers (OETH), with the objective of increasing the employment rate of disabled workers. The...
The SAS (simplified joint-stock company) has definitively become the most attractive corporate form following the reform of statutory auditing!
The PACTE Law (Law No. 2019-486 of May 22, 2019) significantly reformed the statutory auditing regime for simplified joint-stock companies (SAS), thereby further increasing the attractiveness of this corporate form. It was quickly supplemented by an implementing decree on May 24, 2019. A...
The so-called Macron scales have been validated by the Court of Cassation
In an opinion issued on July 17, 2019, the Court of Cassation held that the pay scales provided for in Article L. 1235-3 of the French Labor Code, known as the Macron scales, were not contrary to international conventions and treaties, specifically Articles 6 and 1 of the...
Acknowledgment of termination of the employment contract and reform of contract law
According to established case law, an employee may terminate their employment contract due to breaches they attribute to their employer. Upon application by the employee, the judge must then rule on the attribution of the termination and determine whether...
Regulation of commercial relations between professionals – New provisions of the order of April 24, 2019
On April 25, 2019, Ordinance No. 2019-359, recasting Title IV of Book IV of the French Commercial Code relating to transparency, restrictive practices of competition, and other prohibited practices, was published in the Official Journal [1]. Issued pursuant to...
Consider explicitly waiving the application of the non-competition clause!
Paying a negotiated termination indemnity that is significantly higher than the statutory termination indemnity does not in any way prevent the employee from making further claims, as confirmed by the French Supreme Court ruling of February 6, 2019 (Cass. soc. February 6, 2019, No. 17-28188)...
Brexit – the fate of British nationals present on French territory
March 29, 2019, the date of an event that will undoubtedly mark a turning point in the history of the European Union: Brexit. It was on this date that the two-year period stipulated by Article 50 of the Treaty on European Union, since the...