On 25 May 2018 entered into general force Regulation (EU) 2016/679 to 27 April 2016 on the protection of individuals with regard to the processing of personal data and on the free movement of such data and repealing Directive 95/46/EC[1] (further: GDPR, General Data Protection Regulation). In Polish law, the basic act supplementing the GDPR is the Act with 10 May 2018 on the protection of personal data[2], However, it should be remembered that the provisions on the protection of personal data have also been regulated in other legal acts, including the Act of 26 June 1974 Labour Code[3] ((c.p.) This article presents selected legal issues concerning the protection of personal data in relation to work together with an assessment of their functioning.
1. Recruitment obligations
It is worth remembering that candidates for employees should include clauses in the CV content agreeing to the processing of data in the recruitment process. Moreover, it should be borne in mind that according to the content Article 221 The employer shall require the applicant to provide personal data covering: name(s) and surname; date of birth; contact details indicated by such person; education; professional qualifications; the course of the previous employment, except that the employer may require the provision of personal data relating to education, professional qualifications and the course of the previous employment, where necessary for the performance of a particular type of work or in a specific position.
In the opinion of the author of the article, the design of this provision is quite unfortunate, as unless a request from candidates for names, dates of birth or contact data raises no doubt, it is already a request for information on the education of a candidate, his professional qualifications, whether the course of his previous employment depends on the existence of a condition in the form of the necessity of these data to perform a particular type of work or in a specific position, which is, of course, an evaluation and relative matter.
According to this provision, not every employment relationship justifies the processing of information on education, professional qualifications or the employment of the applicant.
This solution is intended to implement the principle of minimising personal data, and while the lack of the possibility of requiring candidates to work information on their family, health, worldview, racial, ethnic or other situation, which are in fact a personal issue of the candidate is a legitimate solution, information on education, experience or qualifications, in my opinion, is the basis for a future employer when assessing candidates for work.
However, in practice, in the case of an office candidate, in the light of this provision, according to my assessment, the employer may require data on education, qualifications and employment in existing office posts, except for those posts which were not directly linked to the job application.
Importantly, employers do not have the right to require employees to submit to various types of psychological, competence or intelligence tests, unless this requirement is based on statutory standards. The employer also has no right to request recommendations from these candidates from the former employer or co-workers.
A woman applying for employment shall still not be required to provide either information on pregnancy or to undergo a test to determine whether or not she is pregnant, except where the post is covered by the work of a prohibited pregnant woman, in accordance with a regulation of the Council of Ministers of 3 April 2017 on the list of burdensome, dangerous or health-related work for pregnant and breastfeeding women[4].
Therefore, the personal data directory which the employer may request from the candidate is closed; consequently, the recruiter is not in principle entitled to request other data from the candidate. However, according to Article 221a e.g.
the consent of an applicant for employment or an employee may form the basis for the employer's processing of personal data other than those mentioned under Article 221 E.g., except for personal data referred to under Article 10 GDPR, i.e. the processing of personal data concerning convictions and criminal offences.
On the other hand, the lack of consent or withdrawal of additional data by a candidate may not give rise to adverse treatment of an applicant for employment or an employee and may not have any adverse consequences on them, in particular as a reason justifying the refusal of employment, termination of the employment contract or termination thereof without notice by the employer.
At the same time, it is worth pointing out that the processing of additional data for which a job applicant or an employee has consented relates to personal data made available by an applicant for employment or an employee at the request of the employer or personal data transferred to the employer on the initiative of an applicant for employment or an employee, so that the employer may not in principle request additional data from candidates for work than those mentioned under Article 221 k.p., however, it may ask for it, and it is up to the candidate to agree to the processing of this data by the future employer. At that time, the job notice should include a record of the need to sign a separate statement, containing consent to the processing of additional personal data for the recruitment process.
It is certainly recommended that employers indicate in the content of the announcement that candidates do not include additional self-data if they do not wish the employer to process it, which may make it easier for recruiters.
In the case of processing of specific categories of personal data referred to under Article 9(1) GDPR, revealing, among other things, racial or ethnic origin, religious beliefs, sexual orientation, or biometric data used to identify a person (formerly so-called sensitive data), consent may be the basis for their processing only if the transfer of such data takes place at the initiative of the applicant.
The processing of biometric data of a staff member shall also be permitted where it is necessary to provide them for the purpose of checking access to particularly important information, the disclosure of which may put the employer at risk or access to premises requiring special protection.
However, only persons authorised in writing to process such data issued by the employer may be allowed to process personal data of specific categories. They are obliged to keep such data confidential.
The provisions do not prejudge the form in which consent is to be granted, but where processing is carried out on the basis of consent, the employer should be able to demonstrate that the data subject has voluntarily given his consent to the processing of his personal data.
2. Other forms of recruitment
In the case of recruitment via Internet portals, the employer should sign a contract of entrustment of personal data with a portal that publishes a job notice in the mode Article 28 GDPR. Announcement portals acting as a processor process personal data on behalf of the administrator.
The agreement to entrust data for processing should be concluded in writing. If the employer orders recruitment by the employment agency, it is possible to two variants i.e. the agency may become the administrator of the candidates' personal data, or a processor, as in the case of web portals which only mediate in the recruitment process.
The agency becomes the administrator of the personal data of candidates when it selects them from its own databases or on its own behalf searches for candidates and then incorporates them into its data sets – it then decides on the purposes and ways of processing personal data.
If the agency processes the data for its own purposes, not only for its own purposes one, a dedicated recruitment is required to comply with the obligations related to the processing of personal data, including the fulfilment of the information obligation.
On the basis of a cooperation agreement with a potential employer, the agency then finds in its own resources suitable candidates for work, meeting the requirements set by the employer.
The transfer of personal data of the relevant candidate to the potential employer shall take place by making these data available on the basis of the consent expressed by the candidate. The employer, on the other hand, immediately after receiving the applicant's application documents as an administrator, is obliged to “at first the communication with the data subject” to fulfil its information obligation.
The recruitment agency becomes the so-called data processor in the case of candidates on behalf of the employer, it acts as a processor in this case, as it does not use the collected personal data for its own purposes.
The employment agency, which publishes an ad on behalf of the employer, verifies the applications of candidates, conducts recruitment talks with candidates and becomes a processor, while the employer remains the data administrator; in this case, it is necessary that the employer fulfills the obligation to inform the candidate with Article 13 GDPR, however, concluded an agreement with the agency to entrust the processing of data of applicants for employment.
A potential employer should, where he intends to entrust the agency with the performance of the information obligation on his behalf in relation to candidates, include in the cooperation agreement with the agency an appropriate provision requiring it to do so on behalf of the employer.
The Agency, as the data processor, should not process the data for its own purposes in such a case, but should remove the personal data of the candidates after the end of the cooperation in accordance with the agreement to entrust the processing of personal data.
Therefore, it should be pointed out that the way in which candidates are recruited and the purpose of processing them depends on the obligations of the employer or the recruitment entity to inform candidates about the data controller and other information obligations. At the same time, it should be borne in mind, given the absolute obligation to inform the data-processing entity that the candidate should be informed of the entity for which the recruitment is carried out.
3. Deletion of documentation after recruitment
By Sound Article 6(1) GDPR data processing is only lawful if, and to the extent that, at least one from the conditions laid down in that Article, i.e. e.g. when the data subject has agreed to the processing of his personal data In one or more specified purposes, or where the processing is necessary for the performance of the contract to which the data subject is party, or to take action at the request of the data subject, before the conclusion of the contract.
According to the author of the article, these provisions give the possibility to process data in the recruitment process until its completion, unless the candidate has agreed to the processing of data for future recruitment purposes. Otherwise, candidates' applications should be deleted by the data controller.
4. Staff data
By Sound Article 221(3) k.p.
the employer shall require the employee to provide, in addition to the data which he may request from the candidate as an employee, personal data covering: address of residence; PESEL number, and in the absence thereof, the type and number of the document proving the identity; other personal data of the worker, as well as the personal data of the children of the worker and other members of his immediate family, if such data is necessary for the purpose of using the specific rights provided for in the labour law; the education and conduct of the previous employment, if there was no basis for their request from the applicant; the payment account number if the worker has not applied for payment to his own hands.
Also based section 4 the said Article requires that personal data be provided other than those referred to above, where this is necessary for the exercise of the power or for the fulfilment of the obligation under the law.
The provision of personal data to the employer shall take the form of a statement by the data subject. The employer may request that the personal data of the persons referred to above be documented to the extent necessary to confirm them.
The provision of personal data to the employee or candidate for employment shall be made available to the employer in the form of a statement by the person concerned.
The employer's request may therefore consist in the presentation of work certificates or evidence of qualifications, education, but without the right to require the service of original documents to be annexed to the employee's file.
According to the content section 5 Regulation of the Minister of Family, Labour and Social Policy on employment documentation with 10 December 2018[5] the employer shall keep in the personal files of the employee, kept in paper form, copies or copies of documents submitted by the applicant for employment or worker, certified by the employer or person authorised by the employer for compliance with the document submitted.
In the light of these regulations, sanctions should also be applied for the provision of false information or the refusal of an employee to provide information which according to commentators depends on the type of information expected from the candidate or employee[6].
According to Krzysztof Baran, "if they fall within the scope of the legislation in question, sanctions may be imposed in breach of labour obligations, including the right to terminate employment relations".
However, considering whether an employer may require an employee to provide information not mentioned in the legislation Article 221 k.p.
or in separate regulations based on the so-called service order, in mode Article 100 k.p., it should be pointed out that in the opinion of the author of the article, such action could be regarded as circumvention of the law and thus the refusal of the employee could not constitute a basis for termination of the contract of employment without notice by the employee in the form of Article 52 k.p.
This thesis is reflected in the literature that ‘Moreover, it is appropriate to assess cases of requests for data beyond the legal scope of information.
Lying or refusing to provide information by an employee will be considered in the light of the entity's legitimate actions to protect its privacy, providing sui generis defence necessary against violation of the law.
The person asked for personal information (employee) may assess that the employer violates his personal property (especially dignity – within the meaning of Article 111 k.p.), may even be considered discriminatory within the meaning of Article 113 k.p.
The scope of the information referred to under Article 221 k.p., correspond to the sound Article 113(183a) k. in such a way that the circumstances indicated therein, which could be the cause of discrimination (e.g. concerning the family situation of the candidate), have been eliminated from it.
In this situation, it is difficult to charge a breach of the obligations of workers within the meaning of Article 100 n.e., since this obligation had no legal basis’[7].
This is also confirmed by the ruling of the Supreme Court of 5 August 2008[8], in which it indicated that ‘an employer's letter requiring an employee to provide information (personal data) not mentioned under Article 221(1) and 2 k.p. or in separate provisions (Article 221(4) k.p.) is illegal (Article 100(1) (k.p.) and therefore the refusal to execute it cannot be the basis for termination of the employment contract in the form of Article 52(1)(1) k.p.’
5. Monitoring at the workplace
By Sound Article 222 c.
if necessary to ensure the safety of workers, the protection of property, production control or behaviour in the secrecy of information the disclosure of which could put the employer in harm's way, the employer may introduce specific surveillance of the workplace or the area around the workplace in the form of technical means for recording the image, i.e.
monitoring.
Monitoring shall not include premises made available to the trade union organisation, sanitary premises, locker rooms, canteens and smoking facilities, unless the use of monitoring in those premises is necessary for the sake of the safety of workers, the protection of property, the control of production or the secrecy of information and shall not compromise the dignity and other personal property of the worker, in particular by means of techniques preventing the identification of persons present in those premises.
Monitoring of sanitary facilities requires prior approval by the trade union organisation, and if the employer does not operate the trade union organisation, the prior approval of representatives of employees selected in a manner adopted by the employer.
The employer shall process image recordings only for the purposes for which they were collected and kept for a period not exceeding 3 months after the day of the recording.
In the event that these recordings constitute evidence in a legal procedure or the employer has received a message that they may constitute evidence in the proceedings, the time limit shall be 3 the months shall be extended until the final termination of the proceedings.
At the end of that period, the video recordings containing personal data shall be destroyed, unless otherwise provided for in the separate provisions.
The objectives, scope and manner of monitoring should be determined by the employer in the collective agreement or in the working regulation or in the notice if the employer is not covered by the collective agreement or is not obliged to establish the working rules.
Moreover, it is the employer's duty to inform employees about the introduction of monitoring, in a manner adopted by the employer concerned, no later than 2 weeks before its launch and the communication of such information to the new staff member before his entry into work.
The rooms and the monitored area shall be marked in a visible and legible manner by appropriate sound signs or announcements, no later than one The day before it was launched. These regulations have introduced clear rules on the possibility of introducing and monitoring rules in the workplace.
These regulations aim to protect the right to respect for the personal life of a worker and to prevent employers from introducing classified forms of employee monitoring.
The European Court of Human Rights referred to this issue, inter alia, in its judgment of 9 January 2018[9], in which he stated that ‘it must be pointed out that secretive video monitoring of a worker at the workplace must be regarded as serious interference in the personal life of a worker as such. This interference results in a recorded and reproduced record of the behaviour of the person in the workplace, which the employee, as a person obliged under the employment contract to perform work in this (specific) place, cannot avoid.’ The Court therefore held that the measures applied concerned ‘private life’ of applicants within the meaning of Article 8(1) Convention[10].
6. Monitoring of employee e-mail
Based on Article 223 The employer may, if necessary to ensure the organisation of work which makes full use of the working time and the proper use of the work tools made available to the employee, introduce a check on the employee's official e-mail, but monitoring of e-mail must not prejudice the confidentiality of correspondence and other personal property. Those provisions shall apply mutatis mutandis to forms of monitoring other than electronic mail monitoring where their application is necessary to ensure the organisation of work which allows full use of working time and proper use of the work tools made available to the worker.
In accordance with Kazimierz Jaskowski's opinion expressed in the Commentary to the General Court,11, of the content of the legislation under consideration (Article 222(1)(2) and Article 223(1)(2)(4)) it follows that the legislator First, adopted the following rules on the scope of authorised monitoring of the staff member:
- (a) the principle of necessity;
- (b) the principle of the protection of the dignity and personal interests of the worker;
(c) the principle of freedom and independence of trade unions.
These rules correspond to the rules on the processing of personal data specified under Article 5 in conjunction with Article 6 in conjunction with Article 9 GDPR.
- Circumstances of the epidemiological situation and protection of workers concerned
The provisions do not explicitly provide for any exclusions in their use in the event of an epidemiological emergency or an outbreak, however Article 6(1) point d GDPR in relation to point 46 The preamble to the GDPR explicitly points out that the processing of personal data should be considered lawful also in cases where it is necessary to protect an interest which is essential for the life of the data subject or another natural person.
The vital interest of another natural person should, in principle, be the basis for the processing of personal data only in cases where the processing cannot clearly be based on another legal basis.
Certain types of processing may serve both the important public interest and the vital interests of the data subject, for example when processing is necessary for humanitarian purposes, including the monitoring of the epidemic and its spread or in emergency humanitarian situations, in particular in the case of natural and man-made disasters.
The interpretation of this provision may give rise to doubts as to how the term "life-like interests of a person" should be understood – whether it is a narrow approach, covering life-related interests, or whether it should be understood more broadly as "essential, important" interests for a person (for his life).
According to the commentators, the explanation set out in recital supports the wider meaning of this concept. 46 The preamble to the GDPR, which states that "the processing of personal data should be considered lawful also in cases where it is necessary to protect an interest which is essential for the life of the data subject or of another natural person"[12].
According to Paweł Fajgielski, author of the commentary on the GDPR “in the writing of the subject on the grounds of u.o.d.o.199713 It was assumed that vital interests were important interests (e.g. health, life), but that property interests should not be excluded.
It is up to the administrator to assess whether, in a given case, we are dealing with such interests and whether the person concerned is not able to protect those interests in any other way, but whether his decisions in this regard should not be of a decisive and final nature, nor should they be arbitrary and arbitrary, and should consist in balancing interests.
As a general rule, the processing of personal data should be permitted in cases where it can reasonably be assumed that the person concerned would, if possible, consent to the processing of data. In the event of a dispute, these decisions will be subject to review by the supervisory authority and judicial review (cf. J. Barta, P.
Fajgielski, R. Markiewicz, Data Protection..., p. 412). However, it is worth mentioning that the Working Group Article 29 in favour of narrow recognition of the notion of vital interests of the data subject Article 49 (Lt Guides on Article 49 of Regulation (EU) 2016/679, Adopted on 6 February 2018, WP 262, p. 13-14)”.
„In order to base the processing of data on this condition, it should be necessary to protect the vital interests of the person, i.e. the failure to process data could lead to a threat or a breach of the vital interests of that person. The determination of whether data processing is necessary should be made on a case-by-case basis, taking into account the actual circumstances of processing. Polish legislator under Article 23(3) u.o.d.o.1997 required that it be stated that it was not possible to obtain consent, and this condition authorized the controller to process the data only until it became possible to obtain consent. This provision of the Regulation does not provide for such additional requirements’[14]. It is also worth to draw attention to the guidelines of the President of the Office for Personal Data Protection, which encourage the conclusions that actions involving the processing of personal data in order to prevent the spread of epidemics are, in fact, overriding over the provisions on the protection of personal data. The wording should also be indicated here. Article 8a(5-9) Act on 14 March 1985 about the State Sanitary Inspection[15], revised Article 17 Act on 2 March 2020 specific prevention, prevention and eradication solutions COVID-19, other infectious diseases and the resulting crises[16], from which it appears that the Chief Sanitary Inspector or the Provincial Sanitary Inspector acting under his authority may issue to legal persons, natural persons and organisational units not having legal personality, in particular medical entities, employers, civil aviation entities, aircraft users, users of civil aircraft not included in the aircraft register and airport managers, decisions requiring, inter alia, certain preventive or control activities and requesting information from them.
Recommendations in the form of administrative decisions on immediate enforceability may also be issued by the Prime Minister, in accordance with the established law, may also be issued orally in cases of urgency, and subsequently immediately confirmed in writing.
In view of the above, decisions may sometimes be imposed on employers to encourage them to process employees' data which are not covered by the applicable legislation.
At the same time, in view of the above, it should be pointed out that the protection of superior goods to goods for the protection of personal data can also be used as the basis for the processing of data in connection with the spread of the epidemic. Article 9(2) point (i) GDPR, i.e.
a provision that provides that processing is necessary for reasons of public interest in the field of public health, such as protection against serious cross-border health threats or the provision of high standards of quality and safety of health care and medicinal products or medical devices, under Union or Member State law, which provide for specific measures to protect the rights and freedoms of data subjects, in particular professional secrecy.
The wording is also helpful Article 6(1) point (d) GDPR, according to which processing is necessary to protect the vital interests of the data subject or another natural person.
Despite the above-mentioned legal basis, there are doubts as to how far the activities of the services and employers can go. According to the author of the article, the employer should process employees' data only to the extent necessary to ensure the safety of workers and therefore not collect information that is not necessary to comply with the obligations imposed by the health services or recommendations to protect workers' health.
For example, it seems acceptable to measure the body temperature of an employee who is not registered in any collection, or to obtain information from the employee as to whether his health is not threatening other workers, but the employer should not continue to collect information about the employee with too much zeal when the safety rules do not require it.
8. Summary
In summary, it should be pointed out that the introduction of legislation on the protection of personal data has also been reflected in the legislation of K.P., which has resulted, inter alia, in a new catalogue of information that the employer can obtain from both an employee and an employee candidate. In this respect, the legislator has implemented solutions in accordance with the so-called principle of data minimisation, but the author of the article is critical of some of the changes introduced, since the request for information on the education of the candidate, his professional qualifications or the course of his/her previous employment now depends on the existence of a condition in the form of the necessity of such data to perform a particular type of work or in a specific position, which may raise doubts and difficulties in the assessment by the advertisers.
The entry into force of the GDPR also resulted in stricter legal regulations concerning the fulfilment of the so-called information obligation by both employers and employment agencies, which may actually become a data controller or their processor.
In addition, the required document in case of entrusting any data relating to employees or candidates for employees is a contract of entrustment for the processing of data to be concluded in writing. An important aspect introduced in K.P.
is the detailed regulation on video monitoring and monitoring of e-mails of workers, which deserves approval, because so far these issues have not been explicitly and in detail regulated, which has undoubtedly contributed to misinformation, while the existing regulations will certainly establish legal order in this matter.
In the current situation, the question of "protecting the vital interests of the data subject or of another natural person" which legitimises the processing of data under the law is likely to be more relevant.
Article 6(1) pt d GDPR, which should be understood as a condition justifying the processing of data that sometimes goes beyond the standard range of opportunities of employers.
Nevertheless, despite the possibility of referring to the so-called ‘protecting the vital interests of the person’ must not constitute grounds for abuse of that right and contribute to the demand for excessive data which, in the assessment of the situation, are not absolutely necessary for the protection and safety of the workplace.
For the above reasons, it should be considered that, despite the few not very fortunate solutions introduced against the background of personal data protection regulations, which raise doubts, the author of the article points to the conclusion that the new regulations have introduced greater legal certainty through more transparent rules for the protection of personal data in the framework of employment relations.
_________________________
1 Official Journal of the European Union L, No. 119, p. 1. 2 i.e. Journal of Laws of 2019, item 1781. 3 i.e. Journal of Laws of 2019, item 1040. 4 Journal of Laws of 2017, item 796. 5 Journal of Laws of 2018, item 2369. 6 K. Baran (ed.), Labour Code. Comment, issue IV, published: WKP 2018. 7 Ibid. 8 reference no. I PK 37/08.
9 Judgment of the European Court of Human Rights 9 January 2018, reference no. 1874/13, López Ribalda and others v. Spain. 10 Convention on the Protection of Human Rights and Fundamental Freedoms, drawn up in Rome 4 November 1950, amended by Protocols No 3, 5 and 8 and supplemented by Protocol No 2; Journal of Laws of 1993, item 284.
11 K. Jaskowski, E. Maniewska, Comment updated to the Labour Code, published: LEX/el. 2020. 12 P.
Faigielski, Comment to Regulation (EU) 2016/679 on the protection of individuals with regard to the processing of personal data and on the free movement of such data and repealing Directive 95/46 (General Data Protection Regulation) [in:] General Data Protection Regulation. Personal Data Protection Act. Published: WKP 2018.
13 Act of 29 August 1997 the protection of personal data, Journal of Laws of 1997, item 883. 14 Ibid.