Unlock AI Compliance: Master the new EU AI Act with our comprehensive guide.

Roinn

4 min read

Writen by adm

Posted on: January 18, 2022

Data Protection and Corona Virus

Since vaccinations against corona virus became available, the employers have been increasingly seeking to know their employees’ vaccination status. However, the vaccination status classifies as a health data, which is a special category of personal data under the GDPR. Due to it’s sensitive nature, processing of such personal data is generally prohibited, unless an exception applies.

Employers can collect and process information about the vaccination status of their employees (as a special category of personal data) if:

  • they demonstrate a lawful basis for processing, under Article 6 of GDPR; and
  • meet a specific, separate condition, as stipulated in Article 9 of the GDPR.

Moreover, the employers have to identify the purpose of collecting and processing this kind of data. They usually rely on ensuring Health and Safety at the workplace.

Finally, they might need to conduct a DPIA (Data Protection Impact Assessments), before processing large volumes of data regarding vaccination status. The DPIA would need to consider why such data is needed and whether there is a sufficient legal basis for processing. The safest legal reasons will be compliance wit legal obligations and “substantial public interest”.

Different views across Europe

Whether there is a legal basis for the processing of vaccination data by employers under Art. 9 GDPR is viewed differently throughout Europe.

Countries such as the United Kingdom, Austria, Spain, Finland permit the employers to collect and process employees’ vaccination status data to the extent that the information is necessary to ensure the safety of the workplace (i.e., to prevent infections at the workplace).  In their view, this can be based on Art. 9 (2) (b) GDPR, which allows the processing of special category data “for the purposes of carrying out the obligations and exercising specific rights of the controller or of the data subject in the field of employment”.

Contrary, guidance from several countries, such as France, Germany, Belgium, Netherlands, and Ireland, indicate that employers are not allowed to ask employees for their vaccination status, as there is no legal basis for it. Germany provides an exemption from this strict rule: vaccination status requests by employers may be allowed in case of wage compensation claims.

Therefore, it is of utmost importance that each employer assesses national legislation and guidance on the processing of vaccination data before any data is collected and processed.

Key considerations

However, even if national laws and guidelines indicate that the collection and processing of data on your employees’ vaccination status is permissible, there are some key principles you have to consider.

First of all, you as an employer must provide employees with information about how and why their vaccination data is being processed. This could be an update to your existing Privacy Policy or could be provided as a separate document.

Second, the principle of data minimisation obliges you to limit the collection of vaccination data to employees working in an office or other facility in this case, as only this data is necessary to ensure workplace safety. Moreover, you have to limit the retention of vaccination data to the period that is strictly necessary to achieve the purpose. Therefore, your company should establish a retention schedule for employee vaccination data (and inform the employees about it)

Finally, with special category data, such as health data, security is vital. Therefore, your company should have organisational and technical safeguards in place, such as limiting access to vaccination data to persons responsible for monitoring health and safety in the workplace.

Conclusion

Due to its personal and sensitive nature, processing of employees’ vaccination status data is permitted in specific and limited cases. You should always assess your national laws to confirm if such processing is permitted. If this is not the case, you should refrain from processing employee vaccination data. If processing is considered to be permissible, you should nevertheless always keep the above mentioned key considerations and principles in mind and adhere to them.

Déan Teagmháil Linn

Tá súil agam go mbeidh sé seo úsáideach duit. Má theastaíonn Ionadaí AE uait, má tá aon cheist GDPR agat, nó má fuair tú iarratas SAR nó Rialálaí agus má theastaíonn cabhair uait, déan teagmháil linn ag am ar bith. Táimid i gcónaí sásta cabhrú ...
Foireann áitiúil GDPR.

Déan Teagmháil Linn

Recent blogs

AI in Recruitment: Balancing Innovation with GDPR Compliance


AI in recruitment is transforming the HR landscape, offering unprecedented efficiencies and imp

The Future of Finance: Adapting to AI and Data Privacy Laws

The rapidly evolving landscape of financial technology is witnessing a significant transformation w

Navigating the Contradictions: Automated Decision-Making and Regulatory Legislation in AI Systems

The Dilemma of Automated Decision-Making At the heart of AI systems lies the promise of aut

Faigh Do Chuntas Anois

Socraigh i gceann cúpla nóiméad. Cuir isteach sonraí do chuideachta agus roghnaigh na seirbhísí a theastaíonn uait.

Cruthaigh Cuntas

Téigh i dteagmháil

Níl tú cinnte cén rogha atá le roghnú? Glaoigh, ríomhphost, comhrá a dhéanamh linn
am ar bith.

Déan Teagmháil Linn
06 EOLAS GDPR

Fan Suas chun Dáta

Fág do chuid sonraí anseo agus seolfaimid nuashonruithe agus faisnéis chugat maidir le gach gné den GDPR agus d'Ionadaí an AE. Ní bheidh muid bombard tú le ríomhphoist agus beidh tú in ann a insint dúinn chun stop a chur ag am ar bith.

Tá Ainm Iomlán ag teastáil!

Tá Ríomhphost Gnó ag teastáil!

Tá cuideachta ag teastáil!

Glac leis na Téarmaí agus Coinníollacha agus an Polasaí Príobháideachais