GDPR and social law: what are the employer's obligations?
Recruitment, payroll, monitoring of working time, professional evaluation, video surveillance, teleworking, management of absences or disciplinary procedures: the employer processes a considerable volume of personal data concerning its employees on a daily basis.
These processing operations are necessary for the operation of the company. They nevertheless remain subject to the General Data Protection Regulation (GDPR), the French Data Protection Act and the specific rules of labor law.
The intersection of GDPR and employment law has become a major issue for businesses. Excessive data collection, unjustified retention periods, or disproportionate monitoring systems can lead to sanctions from the CNIL (French Data Protection Authority), but can also jeopardize disciplinary proceedings or employment litigation.
What data can the employer collect? How should employees be informed? How far can they monitor their activity? What measures should be put in place to secure HR practices?
Why does the GDPR play a central role in employee management?
Human resources management necessarily involves the processing of personal data.
From the recruitment stage, the company collects information relating to the identity, education, and professional experience of candidates. After hiring, it processes, in particular:
- the employee's contact details and civil status information;
- his social security number and payroll data;
- his bank details;
- his schedule and his absences;
- his professional evaluations;
- his training requests;
- any possible disciplinary sanctions;
- certain data relating to his health;
- the information necessary to monitor his career;
- the traces left by the use of professional computer tools.
Some of this information is particularly sensitive. This may include health data, trade union information, biometric data, or information relating to a disability.
In most cases, the employer acts as the data controller. It is therefore up to them to determine why the data is collected, how it is used, who can access it, and how long it will be kept.
Compliance is therefore not solely the responsibility of the IT department or the data protection officer. It directly concerns HR departments, the legal department, operational managers, and anyone involved in personnel management.
What rules must the employer follow?
Determine a specific purpose
Each treatment must meet a specific, explicit and legitimate objective.
The collection of bank details may, for example, be justified by salary payments. Retaining supporting documents may be necessary to fulfill the company's social and accounting obligations. Monitoring access to certain premises may be a security imperative.
On the other hand, data should not be collected for possible future use without a clearly identified purpose.
Information initially collected to organize work cannot be freely reused for disciplinary purposes if this new use is incompatible with the stated purpose.
Identify a legal basis
All processing of personal data must be based on a legal basis as provided for by the GDPR.
In the field of human resources, the most common foundations are:
- the execution of the employment contract;
- compliance with a legal obligation imposed on the employer;
- the legitimate interest of the company, provided that it does not disproportionately infringe on the rights of employees;
- In exceptional cases, the consent of the person concerned.
Consent must be used with caution in the employment relationship. Due to the hierarchical nature of the relationship, employees are not always in a position to freely refuse the proposed treatment. Therefore, consent is not, in principle, the most appropriate basis for routine HR practices.
Collect only the necessary data
The principle of data minimization requires the employer to limit the collection of information to that which is strictly necessary for the objective pursued.
This requirement must be considered from the design stage of a form, HR software, recruitment process, or control device.
During recruitment, the questions asked must have a direct and necessary link to the job offered or the evaluation of the candidate's professional skills. Information relating to their family life, opinions, health, or personal plans cannot be collected without legitimate justification.
The same vigilance is required when a digital tool technically allows the collection of much more information than the company actually needs.
Clearly inform candidates and employees
The individuals concerned must receive information accessible at:
- the identity of the data controller;
- the objectives pursued;
- the legal basis used;
- the categories of data collected;
- the recipients of this data;
- their shelf life;
- the existence of possible transfers outside the European Union;
- their rights and the procedures for exercising them;
- the possibility of contacting the CNIL.
This information can be included in a notice for employees, in recruitment forms, on the intranet, or in an IT policy. However, it must be sufficiently precise and tailored to each processing activity.
In labor law, ArticleL. 1222-4 of the Labor Code further stipulates that no information concerning an employee personally may be collected by a device that has not been previously brought to their attention.
Limit access to HR data
Personnel files should not be accessible to all managers or employees of the company.
Each person should only have access to the information necessary for the performance of their duties. Data relating to payroll, health, disciplinary sanctions, or internal reports requires heightened vigilance.
The employer must therefore plan for:
- individualized authorizations;
- sufficiently robust authentication;
- a regular review of access rights;
- the rapid removal of access points that have become unnecessary;
- traceability of the most sensitive consultations;
- specific measures for paper files and email exchanges.
How long should employee data be kept?
Personal data cannot be stored indefinitely.
The relevant duration depends on the purpose of the processing, applicable legal obligations, and the timeframes during which the company may be required to establish or defend its legal rights.
It is generally necessary to distinguish between:
- the active database, in which information is accessible for day-to-day management;
- intermediate archiving , reserved for data that must still be kept due to a legal obligation or a risk of litigation;
- the deletion or permanent anonymization upon expiry of the useful period.
In 2026, the CNIL published a new guideline regarding the retention periods for human resources management data. It now constitutes a particularly useful tool for building a coherent data retention policy.
However, a company should not apply a single retention period indiscriminately to the entirety of an employee's file. Pay slips, unsuccessful applications, disciplinary documents, access control data, and information relating to working time are not subject to the same rules.
Employee monitoring: how far can the employer go?
The employer can control the activity of its employees, but this power is not unlimited.
All control devices must be:
- justified by the nature of the task to be performed;
- proportionate to the objective pursued;
- brought to the attention of employees beforehand;
- recorded, where applicable, in the register of processing activities;
- subject to prior information and consultation of the social and economic committee.
These rules relate in particular to video surveillance, geolocation, timekeeping, internet browsing analysis, access to professional email and activity tracking software.
Constant surveillance is, in principle, disproportionate
An employee should not be placed under permanent surveillance, except in exceptional circumstances that are clearly demonstrated.
The CNIL (French Data Protection Authority) notably sanctioned a company that used software to track supposed periods of inactivity, took regular screenshots, and imposed continuous video recording of certain employees. Such surveillance constituted an excessive infringement on their privacy.
Employers must be particularly cautious with tools that allow:
- the systematic recording of keystrokes;
- the repeated taking of screenshots;
- the permanent activation of a camera;
- continuous recording of conversations;
- automatic measurement of inactivity time;
- the establishment of an individual productivity score.
The technical possibility of activating a feature does not mean that its use is legally lawful.
Professional email and personal files
Messages and files created using the professional tool are, in principle, presumed to be professional in nature, unless they are clearly identified as personal.
The employer must respect the privacy of messages or files thus identified. Opening or using them may infringe on the confidentiality of correspondence and the employee's privacy.
The IT charter must clearly explain the conditions of use of professional tools, the controls that may be carried out and how the employee can identify their personal content.
Recruitment, algorithms and artificial intelligence: new risks
The use of artificial intelligence tools in recruitment and career management further increases the issues related to personal data.
Automated application sorting, video analysis of an interview, behavioral assessment, employee ranking or recommendation of a mobility: these systems can produce opaque decisions, reproduce biases or lead to the collection of excessive information.
Before deploying such a tool, the employer must, in particular, verify the following:
- the data actually used by the system;
- their origin and their reliability;
- the criteria taken into account by the algorithm;
- the existence of a risk of discrimination;
- the conditions for data reuse by the service provider;
- the location of the data and any potential international transfers;
- the possibility of real human intervention;
- the need to carry out a data protection impact assessment.
Furthermore, GDPR compliance must be coordinated with the requirements of the European regulation on artificial intelligence, particularly when the tool is used for recruitment, candidate selection or certain decisions affecting the employment relationship.
What are the rights of employees?
The employee retains all the rights recognized by the GDPR. In particular, they can request:
- access to his data;
- the correction of inaccurate information;
- the deletion of certain data;
- the limitation of a treatment;
- opposition to certain treatments;
- the communication of information about an automated decision.
The right of access may relate to data contained in professional emails, provided that they concern the requesting employee.
This option is now frequently used before or during employment litigation. The employer's response must comply with the deadlines set by the GDPR, while protecting the rights of third parties, trade secrets, and the confidentiality of correspondence that does not concern the applicant.
Access requests should therefore not be treated as simple IT requests. They often require a joint analysis of personal data law and social litigation strategy.
What risks does the company face?
Failure to comply with the GDPR can have multiple consequences.
The CNIL can issue a formal notice, order the restriction or cessation of processing, and impose an administrative fine. For the most serious breaches, the GDPR provides for a penalty of up to €20 million or 4% of total worldwide annual turnover, whichever is higher.
In addition to this administrative risk, there are also:
- an action for damages brought by an employee;
- a dispute relating to the infringement of privacy;
- criminal penalties in certain situations;
- an intervention by the labor inspectorate;
- an action by the social and economic committee or a trade union organization;
- a deterioration of the social climate and the company's reputation.
Non-compliance can also affect individual legal disputes. An irregular monitoring system can weaken the evidence gathered by the employer. However, its admissibility is no longer assessed in a systematically binary fashion: the judge notably weighs the right to evidence against the employee's fundamental rights, verifying whether the production of the evidence was essential and proportionate.
This development in no way exempts the employer from putting in place lawful measures. On the contrary, it underlines the importance of anticipating their justification and regulation.
How to bring the company into compliance with the GDPR in social matters?
An effective approach can be organized around ten priority actions.
1. Map HR processes
The company must list the data collected from recruitment to the employee's departure: origin, purpose, recipients, software used, retention periods and any transfers outside the European Union.
2. Update the treatment register
Processes relating to candidates, payroll, training, assessments, working time, access controls or disciplinary procedures must be properly documented.
3. Verify the legal basis
Each processing activity must be linked to an appropriate legal basis. Systematic reference to employee consent should be avoided when another basis is more relevant.
4. Review the information notices
Candidates and employees must receive clear, complete, and easily accessible information. This documentation must reflect the practices actually implemented.
5. Define a conservation policy
A retention schedule must specify, for each category of documents, the duration in active database, the duration of intermediate archiving and the methods of deletion.
6. Framework for control tools
Each video surveillance, geolocation, or digital tracking system must be subject to a necessity and proportionality analysis. Employees and the Works Council must be informed or consulted when required by law.
7. Secure sensitive data
Authorizations must be limited, access regularly monitored, and exchanges containing sensitive data protected. A procedure must also be in place for managing data breaches.
8. Audit HR service providers
Contracts concluded with software publishers, recruitment firms, payroll providers, training platforms or artificial intelligence solutions must specify their obligations regarding confidentiality, security, subcontracting, data storage and return.
9. Organize the exercise of rights
The company must have a procedure in place to quickly identify, investigate and process employee requests, especially when these involve large volumes of emails or documents.
10. Form the teams
HR departments, managers and IT managers need to be made aware of the right reflexes: limit the data collected, avoid subjective comments, secure transmissions and report any incident quickly.
GDPR and social law: compliance that must be cross-cutting
Compliance in HR processes cannot be based on standard documentation that is disconnected from company practices.
It requires a cross-analysis of data protection law, labor law, the digital tools used, and operational constraints. This approach is particularly important when implementing a control system, acquiring a new HR tool, reorganizing, conducting an internal investigation, or handling a dispute with an employee.
A targeted audit helps to identify the riskiest processes, prioritize the necessary corrections and build a compliance plan adapted to the size and activity of the company.
The Social Law and GDPR & New Technologies teams at ARST Avocats support employers in auditing their practices, drafting their documentation, consulting the CSE, overseeing control mechanisms and managing litigation related to employees' personal data.
Authors: Chaouki Gaddada and Morgan Jamet

Chaouki Gaddada
Author

Morgan Jamet
Author
Transfer of shares in predominantly real estate companies: a new formality under penalty of nullity since June 27, 2026
Since June 27, 2026, the transfer of shares in a predominantly real estate company is subject to new mandatory formalities. When it falls within the scope of Article 1865-1 of the Civil Code, it must, under penalty of nullity, be recorded in a deed...
Electricity meter fraud and reconstructed consumption figures: how to contest a claim from Enedis, EDF or Engie?
Disputes related to electricity meter fraud, under-metering, and allegedly evaded electricity consumption appear to be on the rise. For a company, contesting an Enedis claim, however, requires distinguishing between the observation of a...
Commercial leases: what the simplification law of May 26, 2026 changes in concrete terms for landlords and tenants
The 2026 reform of commercial leases, stemming from the law of May 26, 2026, modifies several essential mechanisms of the commercial lease statute, for both landlords and tenants. Key point: Right of first refusal: the law clarifies what constitutes "premises for commercial use"...
Should the franchisor require a shareholders' agreement within the franchised companies?
Introduction: The rationale for a franchise partnership agreement. A conflict between partners in a franchised company can destabilize a point of sale as surely as a breach of the franchise agreement. The franchisor therefore has a vested interest in ensuring that this risk...
Mining law in French Guiana: what the law of May 26, 2026 changes for operators
Introduction: "Mining Law in French Guiana" Law No. 2026-403 of May 26, 2026, on simplifying economic life, does not, at first glance, specifically concern mining law in French Guiana. However, Article 43 introduces several important amendments to the Code...
Electronic invoicing and assignment of receivables: from legal assignability to "digital financeability".
The widespread adoption of electronic invoicing does not change the legal rules governing the assignment of receivables. However, it could transform the practical conditions. When a receivable is assigned while the corresponding invoice continues its lifecycle...
Creating a restaurant franchise network: 9 mistakes to avoid
A restaurant is doing well, revenue is increasing, and the concept is finding its audience. At this stage, many owners wonder if their establishment is ready to become a franchise. It's often at this point that the idea of...
Does approving an electronic invoice constitute an acknowledgment of debt?
With the widespread adoption of electronic invoicing, the question of the link between electronic invoices and acknowledgments of debt has taken on new importance for businesses. Since the widespread adoption of electronic invoicing, businesses no longer...
Private labeling: a legal structure designed to build trust
Faced with the proliferation of labels, private labels offer companies a tool for differentiation and building trust. However, their creation requires defining a credible standard, control procedures, and a sufficiently robust legal framework.
Electronic invoicing: what the reform changes to companies' contractual practices
The reform of electronic invoicing does not only change the methods of issuing and receiving invoices. It also transforms companies' contractual practices, particularly regarding evidence, validation, deadlines, and dispute management.