Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Note that GDPR does have some carveouts for workplaces (meaning, it doesn't always apply in full as you'd expect).

As always, it really leans heavily on why people are recorded and how that data is used.



I'm not sure what would people expect for GDPR to apply in "full" in the workplace. (TBH I'm not even sure what would most people expect from GDPR, apart from being annoyed with cookie questions while browsing the web, but let's concentrate on people who know their rights and would potentially want to exercice them.) And even then, GDPR applies, and in a good amount of cases require even more strict measures than "baseline" GDPR. E.g. employees are considered "vulnerable" because of the employee / employer relationship, and that often implies that Privacy Impact Assessments are required (fulfil one criteria and as soon as 2 are presents, PIAs are needed).

That you can't use GDPR to e.g. delete random company data just because you are somehow associated to it is only logical, but I would not really count that as "GDPR not applying in full". That was understandably never the intent of the law, and it is detailed enough to avoid silly scenarios.


> GDPR does have some carveouts for workplaces

Can you point me to any? IMHO it does not have any explicit clauses mentioning more lax conditions for consent in case of employment relationships, and there have been multiple cases of GDPR enforcement re-asserting that anything that you require from all employees doesn't count as consent. An employer might assert a "legitimate need" basis for processing (in which case you need to only inform the employee, not their consent), but that is inherently limited and there have been large fines assessed for employees trying to push constant monitoring with this justification; the employer has a duty to minimize the invasiveness of achieving that legitimate need (e.g. surveillance for theft prevention can monitor only places relevant for that, and doesn't permit using the same videos for any other purpose e.g. measuring employee activity).




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: