77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide
§ 26 BDSG: Implement employee data protection correctly and document it in an audit-proof manner
Platform & Strategy

§ 26 BDSG: Implement employee data protection correctly and document it in an audit-proof manner

5 August 202612 min readBy Dr. Henrik Bauer
CIVAC

Section 26 BDSG regulates employee data protection in the employment relationship. We explain the permissible purposes, the consent requirements, the limits when solving crimes and how you can document the implementation in the CIVAC workspace in an audit-proof manner.

§ 26 BDSG regulates data processing in the employment context since the new BDSG came into force on May 25, 2018 and specifies the opening clause from Art. 88 GDPR for German labour law. The standard applies to all phases of the employment relationship: initiation, implementation, termination and subsequent contract. Anyone responsible for processing employee data without a sufficient legal basis risks fines of up to 20 million euros or 4 percent of global annual turnover in accordance with Art. 83 Para. 5 GDPR as well as claims for damages in accordance with Art. 82 GDPR. In addition, there are co-determination rights of the works council in accordance with Section 87 Paragraph 1 No. 6 BetrVG, which apply to every new processing as soon as technical monitoring devices are involved. The clock starts on awareness.

This article explains the structure of Section 26 BDSG, the typical applications in practice, the limits in solving crimes according to Section 26 Paragraph 1 Sentence 2 BDSG and the requirements for effective consent according to Section 26 Paragraph 2 BDSG. You will find out how the duties are mapped in the CIVAC workspace, which templates are available for applicant management, employee monitoring and termination and how the reporting line between external data protection officer and the works council works. CIVAC is a compliance platform and officer-as-a-service with EU data residency. Licence the workspace for your internal representatives, or have our representatives order it.

Key Takeaways

  • Section 26 BDSG allows the processing of employee data to establish, implement or terminate the employment relationship, but only to the extent necessary.
  • Solving crimes requires actual evidence, a proportionality test and complete documentation of the suspicion.
  • Consent in the employment context is only effective under strict conditions, in writing or electronically and with the right to withdraw.

Structure of Section 26 BDSG: What the standard regulates and what it does not

§ 26 BDSG is divided into eight paragraphs. Paragraph 1 contains the central permission: Employee data may be processed to the extent that this is necessary for the decision on the establishment of an employment relationship, its implementation or termination. Sentence 2 supplements the processing to detect criminal offenses under strict conditions. Paragraph 2 regulates consent in the employment context, in particular the question of voluntariness. Paragraph 3 concerns the processing of special categories of data in accordance with Article 9 GDPR. Paragraph 4 contains the opening for collective agreements, in particular company agreements in accordance with Section 77 BetrVG. Paragraphs 5 to 8 regulate procedural questions, such as the obligation to provide information and the definition of the term employee.

The standard does not displace the GDPR, but rather specifies it for the German employment context. Anyone who applies Section 26 BDSG must also comply with the principles set out in Article 5 GDPR: legality, purpose limitation, data minimization, accuracy, storage limitation, integrity and confidentiality as well as accountability. The Federal Labour Court has made it clear in several decisions that necessity must be interpreted narrowly and that milder means should be given priority. In the CIVAC workspace, the necessity check is stored as a structured checklist: purpose, data category, milder means, storage period, responsibility. This makes the accountability requirement in accordance with Article 5 Para. 2 GDPR operationally implementable and directly verifiable in the audit. Others run compliance like a filing cabinet. We run it like software. The appointment certificate, signed, filed, verifiable. Anyone who wants to apply Section 26 BDSG in a structured manner should also consider the interaction with the Works Constitution Act, because many HR processing processes also trigger co-determination issues and thus require a double check. This double check is managed as a uniform view in the workspace, so that the data protection officer and the human resources department have the same assessment status in mind and no contradictory information is given to the works council.

Applicant management: What is permitted according to Section 26 Paragraph 1 BDSG

Data processing is necessary in the application process if it serves to decide on the establishment of an employment relationship. As a rule, it is permissible to collect your CV, certificates, proof of qualifications and structured interview notes. Questions about pregnancy, religious affiliation without a tendency to work, trade union membership, financial circumstances or previous convictions that are not related to the advertised position are not permitted. According to Section 15 Paragraph 4 AGG, the storage of the application documents of rejected applicants is permitted for 2 months from receipt of the rejection; if there is a threat of legal action, this is extended until the legally binding conclusion of the procedure. Storage beyond this requires the applicant's express consent, for example for inclusion in a talent pool.

Background checks are only permitted if they are necessary for the specific position, for example for positions with asset management, access to sensitive data or a special position of trust. The review must be proportionate, documented and transparent to the applicant. A template is stored in the CIVAC workspace that defines the permissible check profile for each position: identity check, qualification check, certificate of good conduct if legally required, solvency check only for cash responsibility. This template also addresses the obligation to provide information in accordance with Art. 13 GDPR in the application process, the retention periods and the procedure for deletion after the AGG deadline has expired. This allows applicant management processes to be structured uniformly via career portals, headhunter interfaces and HR systems. You can find an overview of further templates for HR processing at CIVAC-FAQ. Anyone who involves headhunters or external personnel service providers concludes an order processing agreement with them in accordance with Art. 28 GDPR and documents the data flows in the processing directory in accordance with Art. 30 GDPR, including recipient categories, storage period and third-country reference. For platforms based outside the EU, a third country assessment must also be carried out in accordance with Chapter V of the GDPR and secured with standard contractual clauses.

Implementation of the employment relationship: personnel files, performance and behaviour monitoring

During the employment relationship, the employer regularly processes a large amount of employee data. Classic fields are the personnel file with master data, contract documents, pay slips and appraisals. There are also access logs in IT systems, time recording, illness reports, absence planning and company training. According to Section 26 Paragraph 1 BDSG, each of this processing must be necessary for the implementation of the employment relationship. The necessity should not be assessed abstractly, but rather specifically for each data category. For example, the storage of bank details is necessary for salary payments, but the storage of the private mobile number is only necessary if there is a business need or effective consent has been given.

Performance and behavioral monitoring are only permitted under strict conditions. The capture of keystrokes, the evaluation of screen activity or secret video surveillance are generally not permitted. Event-related, proportionate controls are permitted, which are regulated in a works agreement in accordance with Section 87 Paragraph 1 No. 6 BetrVG. In the CIVAC workspace, all ongoing HR processing is kept in a directory in accordance with Art. 30 GDPR, with the person responsible, purpose, data category, recipients, deletion periods and technical-organisational measures in accordance with Art. 32 GDPR. This documentation is the basis for reports to the works council, for statements to the supervisory authority and for internal audits. The auditor calls, the evidence is ready. Licence the workspace for your internal representatives, or have our representatives order it. In practice, it is advisable to keep the personnel file digitally and to assign access rights strictly according to function and need-to-know principle, for example separately for personnel administration, payroll and supervisor evaluation. This operationally implements data minimization in accordance with Article 5 Paragraph 1 Letter c of the GDPR and reduces the risk of unauthorized access.

Investigation of crimes in accordance with Section 26 Paragraph 1 Sentence 2 BDSG

According to Section 26 Paragraph 1 Sentence 2 BDSG, the investigation of crimes in the employment relationship is only permissible under four cumulative conditions: There must be actual evidence to be documented that substantiates the suspicion, the suspicion must relate to a crime in the employment relationship, the processing must be necessary for detection and the employee's legitimate interest in excluding the processing must not outweigh. Necessity in particular requires a proportionality test: milder means must be exhausted, the measure must be suitable, necessary and appropriate. Covert measures are only permitted as a last resort and must be disclosed after completion.

In practice, this means: Before any measure to investigate crimes, such as the evaluation of email inboxes, the evaluation of access logs or a covert surveillance, the proportionality test must be documented in writing. A template is stored in the CIVAC workspace that records the suspicion, the milder means tested, the planned measure, the expected intensity of the intervention and the escalation decision. This submission becomes the key piece of evidence in the event of a supervisory audit or labour court proceedings. The appointment certificate, signed, filed, verifiable. Audit-proof, documented, § 26-BDSG-proof. Without this documentation, there is a risk of a ban on the use of evidence in labour court proceedings, which can jeopardize the success of a dismissal under labour law. Further information on the interface with whistleblower protection can be found at Whistleblower Protection Reporting Office. The interface between the tip according to the HinSchG and the suspicion according to Section 26 Paragraph 1 Sentence 2 BDSG requires a clear separation of the procedures because the processing of the tip has different confidentiality requirements than the examination of suspicion under labour law. The templates stored in the workspace mark the transition between the two procedures with clear responsibilities and prevent the traces of evidence from being accidentally mixed up.

Consent according to Section 26 Paragraph 2 BDSG: When it is really voluntary

Section 26 Paragraph 2 BDSG confirms the possibility of consent in the employment context, but makes it voluntary. Voluntariness is to be affirmed in particular if a legal or economic advantage is achieved for the employee or if the employer and employee pursue similar interests. Examples from case law: Consent to participate in a voluntary company health program is usually effective. Consent to the publication of employee photos on the company website can be voluntary, but can be revoked at any time. Consent to comprehensive keyboard monitoring, on the other hand, would hardly be voluntary because the asymmetry is too great.

According to Section 26 Paragraph 2 Sentence 3 BDSG, consent must be in writing unless a different form is appropriate due to special circumstances. In practice, this means a written or electronic statement with a clear affirmative action. The consent can be revoked at any time and the revocation must not have any disadvantages. In the CIVAC workspace, consents are recorded with version status, date, content text, right of revocation and revocation history. For each new processing, it is checked whether consent is actually required or whether another legal basis would take precedence, such as Section 26 Paragraph 1 BDSG, Article 6 Paragraph 1 Letters b or f GDPR or a works agreement in accordance with Section 87 BetrVG. This reduces the number of consents to the cases that are actually necessary and the risk of ineffective consents decreases significantly. Anyone who relies on consent as a legal basis should also specifically describe the procedure for revocation, including the body to which the revocation should be addressed and the consequences for ongoing processing. Deadline expires as soon as we become aware of it.

Special data categories, company agreements and co-determination

§ 26 Paragraph 3 BDSG regulates the processing of special categories of data in accordance with Article 9 GDPR in the employment context. This includes health data, data on ethnic origin, religious beliefs, trade union membership, genetic and biometric data and data on sexual life. Processing is only permitted to the extent that it is necessary to exercise rights or fulfil legal obligations under labour law, social security law and social protection. Example: Processing of social security number and health insurance is required. The collection of religious affiliation is only necessary to calculate church tax, not for other purposes.

§ 26 Para. 4 BDSG opens the processing for collective agreements, in particular company agreements and collective agreements. A works agreement can serve as an independent legal basis within the meaning of Article 88 GDPR, provided it meets the requirements for transparency, purpose limitation and data minimization. The participation of the works council in accordance with Section 87 Paragraph 1 No. 6 BetrVG is mandatory if technical devices are to be introduced to monitor the behaviour or performance of employees. A template for the data protection assessment of works agreements is stored in the CIVAC workspace, which records the scope, purpose, data categories, recipient group, storage periods, rights of those affected and reporting obligations to the works council. This means that company agreements and data protection impact assessments in accordance with Art. 35 GDPR can be carried out in an interlinked manner. You can find an overview of other representative roles at CIVAC Roles. Important in group associations: A group works agreement can set uniform standards according to Section 58 BetrVG, provided that the respective co-determination responsibilities are taken into account; However, the data protection assessment remains to be carried out by each subsidiary as an independent responsible party. In the workspace, this separation can be clearly represented by separate directory spaces for each company with a consolidated group view if desired.

Termination of the employment relationship: deletion periods and retention obligations

With the termination of the employment relationship, the obligation to check, archive or delete employee data arises. Art. 17 GDPR is relevant in conjunction with the retention periods under tax, commercial and social security law. According to Section 41 EStG and Section 28f SGB IV, income tax and social security documents must generally be retained for 6 years, and documents relevant to commercial law must be retained for 10 years in accordance with Section 257 of the German Commercial Code (HGB). Personnel files as such do not have a general legal retention period and must be checked after the end of the employment relationship. A flat 10-year retention period for all personnel documents is not covered by data protection law.

In the CIVAC workspace, a separate deletion period is defined for each data category in the personnel file. Payslips follow the payroll tax deadline, application documents follow the AGG deadline of 2 months, warnings follow the labour law repayment deadline, draft certificates of the applicant-related necessity. After the respective deadline has expired, the data category is automatically marked for deletion, documented and deleted after approval. This means that the principle of storage limitation according to Article 5 Paragraph 1 Letter e of the GDPR has been operationally implemented. Audit-proof, documented, Art. 5 GDPR-proof. For group structures with a central HR system, the configuration is uniform throughout the company, with local deviations only if there are mandatory legal requirements in the respective subsidiary. This configurability significantly reduces the number of manual deletion processes and closes the most common gap in HR data sets, namely the undeleted residual data of former employees. The appointment certificate, signed, filed, verifiable. An additional component is the deletion concept as an independent document that consolidates data categories, deadlines, solution paths and responsibilities and can be presented immediately during supervisory audits. The concept is reviewed annually and adapted to new retention periods, for example if the legislature shortens or extends tax or social security deadlines.

Inspections, fines and labour court consequences

Violations of Section 26 BDSG are sanctioned from both sides. Firstly, through the data protection supervisory authority, which can impose fines of up to 20 million euros or 4 percent of global annual turnover in accordance with Article 83 of the GDPR. Examples from practice: Fines in the six-figure range for disproportionate video surveillance in storage rooms, fines in the low seven-figure range for the evaluation of employee email accounts without an effective legal basis. Secondly, through the labour courts: Evidence obtained in violation of data protection law is often subject to a ban on the use of evidence, which can destroy the success of a termination under labour law in individual cases. In addition, there are claims for damages according to Art. 82 GDPR and non-material damages according to the case law of the ECJ and the BAG.

A template is stored in the CIVAC workspace that records every incident in the employee context in a structured manner: facts, examined legal basis, proportionality check, reporting line to management, involvement of the works council, statement of the data protection officer. This template forms the basis for defence against supervisory authorities and labour courts. The auditor calls, the evidence is ready. In addition, a risk traffic light is maintained that classifies HR processing according to its intensity of intervention: green for non-critical routine processing, yellow for processing with a codetermination obligation, red for processing with a data protection impact assessment in accordance with Art. 35 GDPR. This traffic light is the basis for the annual HR risk assessment and for setting the topic for the next internal audit. Licence the workspace for your internal representatives, or have our representatives order it. Audit-proof, documented, § 26-BDSG-proof. The structured storage of this information significantly reduces the response time to supervisory authorities for random requests for information in accordance with Art. 58 GDPR. It is also the basis for the annual reporting obligation to management in accordance with Art. 38 Para. 3 GDPR and for updating the training plan.

From paragraph to practice: Implementing Section 26 BDSG with CIVAC

If you want to structure the implementation of Section 26 BDSG, three steps are helpful. First: Create a complete register of all HR-related processing activities in accordance with Art. 30 GDPR. Secondly: Check the legal basis for each processing in accordance with Section 26 BDSG and, if necessary, add company agreements, consent or other bases. Third: Set a specific deletion period for each data category and define the procedure for exercising the rights of those affected in accordance with Articles 15 to 22 of the GDPR. These three steps form the foundation on which ongoing adjustments, such as new HR tools or new co-determination requirements, are based.

CIVAC is a compliance platform and officer-as-a-service with EU data residency. In the workspace you will find 490 audit templates, including templates for applicant management, personnel files, time recording, video surveillance, obtaining evidence in the event of suspicion, company agreements and deletion concepts. The external data protection officer will be appointed within 2 working days, with an appointment certificate, list of tasks and reporting line to the management. Licence the workspace for your internal representatives, or have our representatives order it. Turn reading into an assignment. Write to info@civac.de or use the contact form on civac.de. We will send you a binding offer with a list of services, draft contract and appointment certificate within 2 working days. Anyone who has to cover information security, whistleblower protection or money laundering prevention in parallel bundles the roles in the same workspace and leverages synergies between the officer functions. The typical process takes around 4 weeks from the initial contact to the productive platform, including the HR focus, depending on how structured the existing processing directory is and whether company agreements are already in writing. The external appointment of the data protection officer is made in parallel within 2 working days and is fully effective from the time of signature.

FAQ

Does Section 26 BDSG also apply to managing directors and board members?

The term employee according to Section 26 Paragraph 8 BDSG also includes civil servants, trainees, interns and temporary workers. Board members such as managing directors and board members are generally not recorded; their data processing is governed by Art. 6 GDPR and the provisions of the service contract. In group structures, it is advisable to have a separate legal basis, a separate obligation to provide information in accordance with Art. 13 GDPR and clear responsibility for maintaining these data sets.

Can I save application documents from rejected applicants for a talent pool?

The statutory retention period according to Section 15 Paragraph 4 AGG ends 2 months after receipt of the rejection. Any storage beyond this for a talent pool requires the applicant's express, written consent in accordance with Section 26 Paragraph 2 BDSG with a clear description of the purpose, storage period and right of withdrawal at any time. Without this consent, storage is not permitted.

What role does the works council play in the implementation of Section 26 BDSG?

According to Section 87 Paragraph 1 No. 6 BetrVG, the works council has a mandatory right of co-determination in the introduction and use of technical equipment that is suitable for monitoring behaviour or performance. A works agreement can also serve as a legal basis for data protection in accordance with Section 26 (4) BDSG, provided it meets the requirements for transparency and data minimization.

How long can I keep the personnel files of former employees?

There is no general legal deadline for personnel files. The relevant retention periods for each data category are decisive: income tax documents 6 years according to Section 41 EStG, commercial law-relevant documents 10 years according to Section 257 HGB. Data categories without a legal deadline must be checked after termination and usually deleted within a few years. Audit-proof, documented, Art. 5 GDPR-proof.

Can I evaluate employee email accounts if crimes are suspected?

According to Section 26 Paragraph 1 Sentence 2 BDSG, an evaluation is only permitted if there are actual indications of a criminal offense in the employment relationship, milder means have been exhausted and proportionality is documented. If private use is permitted, the requirements become significantly more stringent because telecommunications secrecy according to Section 88 TKG can also apply. A written evaluation is mandatory.

Which templates does CIVAC support for the implementation of Section 26 BDSG?

The CIVAC workspace contains templates for applicant management, personnel files, time recording, video surveillance, suspected case processing, company agreements, declarations of consent, deletion concept and data protection impact assessment. All templates are versioned, stored with the person responsible and the test date and can be exported immediately during the audit. Licence the workspace for your internal representatives, or have our representatives order it. A two-page list of services is available upon request via info@civac.de.

No obligation

Sounds like a lot of work?

Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.

Turn this into a mandate.

Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.

Related articles