The Data Privacy Law No. 22/11, June 17 governs Angolan data privacy and determines, in general terms, how to collect, use, disclose, store and give access to "personal information."
There is no specific regulation on employee data privacy.
The Argentine Data Privacy Law No. 25,326 (Ley de Protección de los Datos Personales or LPDP) protects the personal data stored in files, registers, data banks or other technical storage of data processing, whether public or private, in order to guarantee the right to honor and privacy of the data of individuals, as well as to restrict the access to such information, in accordance with the provisions set out in Article No. 43, third paragraph of the Argentine National Constitution.
Australia has stringent data privacy obligations. As a general rule, personally identifiable data may only be processed if it is required for the performance of the employment contract and constitutes an employee record. Certain acts and practices are exempt from the application of Australia's data privacy laws, but there are strict criteria which must be met for an exemption to apply. Employee records are generally exempt, but this exemption will not apply to documents that come into existence prior to the employment relationship (eg, pre-employment or hire documentation) or to documents relating to any contractors engaged by the business. At the time it collects personal information, the employer is required to provide the individual with a statement setting out the company's obligations under Australia's data privacy laws and the individual's rights. Further restrictions apply for sensitive personal data.
Employee records – with the exception of tax file numbers – are not covered by the Australian notifiable data breach regime, which requires notification to the Office of the Australian Information Commissioner (OAIC) and to affected individuals of any data breach that could result in serious harm. However, the OAIC advises that it is good practice for employers to notify employees affected by a data breach so that they may take protective action.
The monitoring of individuals and their data is covered by various surveillance legislation in each state or territory. Essentially, surveillance of employees is prohibited in sensitive areas, such as washrooms and change rooms, unless the surveillance device is installed pursuant to a warrant or authorization. Surveillance is permitted in public areas if it conforms with relevant legislation. The monitoring of an employee's use of a work computer (ie, emails and internet browsing) is governed by specific laws in some states.
Employees must be generally notified of personal data processing – and, in certain cases, must give consent. Strict rules apply to data transfer outside the EEA. Monitoring employees usually requires an agreement with the works council, if any, or an individual agreement with each employee. Since May 2018, Austria has been subject to the General Data Protection Regulation (GDPR), which has introduced significant new obligations and onerous sanctions for employers.
Personal data privacy is protected under Law No. 30 of 2018 with respect to Personal Data Protection (PDPL). Employees must be notified prior to processing their personal data, and their prior written consent should be obtained (unless exceptions stipulated under the relevant legislation are present) for such processing and transfer of their personal data.
Transfers of personal data out of Bahrain is prohibited unless the transfer is made to a country or region that provides sufficient protection to personal data. Those countries have yet to be listed by the Personal Data Protection Authority or published in the Official Gazette.
Employees generally must be informed of personal data processing and, in certain cases, give prior and explicit consent. Special rules apply to data transfer outside the EEA. Significant and local-specific restrictions apply on monitoring email and internet use and use of cameras at the workplace. The personal data processing must occur in line with the General Data Protection Regulation (GDPR) and the Belgian data protection laws.
The new General Data Protection Law (Lei Geral de Proteção de Dados or LGPD) came into force on September 18, 2021. The LGPD is Brazil´s first comprehensive data protection regulation and applies to any processing operation carried out by a natural person or a legal entity, of public or private law, irrespective of the means used for the processing, the country in which its headquarters are located or the country where the data is located, provided that:
- The processing operation is carried out in Brazil
- The purpose of the processing activity is aimed at the offering or provision of goods or services, or at the processing of data of individuals located in Brazil, or
- The personal data was collected in Brazil.
The LGPD does not contain specific employment provisions, but its provisions cover employment data.
The monitoring of corporate email and internet use is allowed, but employees should be notified that they cannot expect privacy in the use of these work tools.
Legislative requirements vary by jurisdiction. Where privacy laws apply, personal information must only be collected with consent and may only be used for the purposes for which it was collected. In most jurisdictions, email and internet use may be monitored where notice has been given through clear employer policies.
The employer is obliged to maintain the privacy of the information and personal data related to its employees. The right to personal data protection has the status of constitutional right, and, therefore, any breach may lead to litigation for impairment of fundamental rights.
The Regulations on Employment Services and Employment Management require that an employee's personal data is kept confidential and not made public without the employee's consent.
The PRC Cyber Security Law imposes new security and data protection obligations on "network operators," puts restrictions on transfers of data outside China by "key information infrastructure operators" and introduces new restrictions on critical network and cybersecurity products.
The Civil Code strengthens protection on individuals’ privacy and personal information. It improves the legal definition of personal information and clarifies the connotation, principles and conditions of handling personal information as well as strengthens the information security obligations of processors.
The Personal Information Protection Law (PIPL) came into effect on November 1, 2021, setting out the first comprehensive legal regime regulating the protection of personal information in China. There are requirements on notification and obtaining separate consent when collecting, processing and transferring personal information. Additional legal grounds for processing personal information in addition to the general “consent-based” approach are included in the PIPL.
To process personal data, data controllers must provide a privacy notice to the affected employees prior to the collection and processing of personal data. In the case of data transfers, the privacy notice must contain the name of the transferee or the person to whom the information is transferred. All transfers of personal data to domestic or foreign third parties must be pre-approved by the data subject/employee.
Employees have the right to know, update and correct their personal data. This right may be exercised in relation to partial, inaccurate, incomplete, split or deceptive data, and/or data that is prohibited from or not authorized for processing, such as race or ethnic origin, political orientation, religious or philosophical orientation and enrollment to unions or social organizations, among other items considered sensitive information.
Employees may revoke the authorization granted for the processing of their personal data and may request to remove their personal information from the employers or subcontractor's databases by filing a formal claim, save for information directly related to their employment (eg, HR core data, recruitment, performance, global compensation learning and training-related data and master data). This possibility is only applicable in the case of wrongful use of the employee's information.
Generally, employees must be notified of personal data processing (eg, camera recordings) and, in certain limited cases, give their consent (eg, for use of the employee’s personal data for marketing purposes). Significant restrictions on monitoring employees, including email and internet use.
The Czech Republic is subject to the General Data Protection Regulation (GDPR). The local law implementing the GDPR was issued in 2019.
Employers must comply with the General Data Protection Regulation (GDPR) as of May 25, 2018 as well as the Danish Data Protection Act.
Employees have the right to detailed information about the processing of their data. All information provided must be concise, transparent, easily accessible and in plain language. Employers must provide information on the legal basis for processing and, if the data is sensitive, which of the conditions for processing special categories of personal data on which the employer relies. The notice must also advise the employees of their rights under the GDPR.
Employees must usually be notified about personal data processing and give consent to this when necessary. Only necessary data may be processed. Special rules apply to data transfers outside of the EEA. There are significant restrictions on monitoring email and internet use.
From May 2018, Finland has been subject to the General Data Protection Regulation (GDPR) which introduced significant new obligations and onerous sanctions for employers.
The General Data Protection Regulation (GDPR) came into force on May 25, 2018. It applies to any processing of personal data within the EU. The GDPR implements new rights for data subjects, such as right to access, data erasure, data portability and consent.
Where data processors/controllers process operations which require regular and systematic monitoring of data subjects on a large scale or of special categories of data, a Data Protection Officer (DPO) must be appointed.
Data transfers outside of the EU are subject to additional requirements. Significant restriction on monitoring internet and e-mail use even when on company's IT device.
Covered by the EU-wide General Data Protection Regulation (Datenschutzgrundverordnung, or GDPR) entered into force in May 2018 and the complementing Federal Data Protection Act. Processing of personal data is generally unlawful except as listed by the Act and the General Data Protection Regulation, a works council agreement or free and individual consent. Appointment of data protection officers is required if more than 9 individuals deal with electronically saved personal data. Special rules apply to data transfer outside the EEA. Significant restrictions on monitoring email and internet use exist.
Hong Kong, SAR
The PDPO is principally concerned with 6 data protection principles (DPPs). Broadly, these require:
- That personal data is only collected for a lawful purpose, that only personal data that is necessary and not excessive for that purpose is collected and that individuals are informed of certain things before data is collected or used (DPP 1)
- That all reasonably practicable steps are taken to ensure that personal data is accurate and that it is only retained for as long as is necessary to fulfill its purpose (DPP 2)
- That personal data is not, without the prescribed consent of the job applicant or employee, used for a purpose other than the purpose for which it was collected (DPP 3)
- That all reasonably practicable steps are taken to ensure that the personal data is secure and protected against unauthorized or accidental access, processing, erasure or other use (DPP 4)
- That all reasonably practicable steps are taken to ensure that an individual may access information about the data user's policies and practices in relation to personal data, the kind of personal data about them that is being held and the purposes for which it will be used (DPP 5) and
- That, with some exceptions, an individual is entitled to request access to all personal data held by a data user and to correct that data if it is inaccurate (DPP 6).
There are provisions in the PDPO that restrict the transfer of personal data outside of Hong Kong, but these are not currently in force.
Employers must balance their need to obtain, use, store and disclose information for effective management and business purposes with their employees' right to privacy. The law distinguishes between ''personal data'' and ''sensitive personal data.'' Special rules apply for the transfer of personal data within and outside of the EEA. The National Authority for Data Protection and Freedom of Information is responsible for ensuring compliance and enforcing data protection.
Since May 2018, Hungary has been subject to the General Data Protection Regulation (GDPR), which introduced significant new obligations and onerous sanctions for employers.
Employee records and employee access to data
The Information Technology Act, 2000 (IT Act) covers data protection and violation of personal privacy. This statute safeguards against certain breaches in relation to data from computer systems, prevents unauthorized use of computers and creates liability for damage suffered in the event of unauthorized access, downloading, extraction and copying of data from a computer system or network. It stipulates the penalty for breaches of confidentiality and privacy.
The storage, management and handling of sensitive personal data or information belonging to persons located in India is regulated by the Information Technology (Reasonable security practices and procedures and sensitive personal data or information) Rules, 2011 (Sensitive Information Rules) enacted under the IT Act. The government of India has also released the Personal Data Protection Bill, 2019 (Data Protection Bill), which is being considered by the Indian government to replace the Sensitive Information Rules.
Sensitive personal data or information is defined under the Sensitive Information Rules to include passwords, financial information, physical, psychological and mental health conditions, sexual orientation, medical records and history, and biometric information.
Any body corporate receiving any of the above types of information as a result of either using the services of an individual or employing an individual must comply with the Sensitive Information Rules regarding processing and storing such information.
Law No. 11 of 2008 on Electronic Information and Transactions, as amended, restricts the electronic use of private data without the data subject's consent. Under Law No. 39/1999 on Human Rights, each individual has the right to their own privacy and cannot be subjected to an investigation in relation to personal data without their agreement, except on the order of a court or other legitimate authority under prevailing legislation. A new draft of the Data Privacy Law has been prepared, but it is not clear when it will be introduced.
Ireland is subject to the General Data Protection Regulation (GDPR), which places significant obligations and onerous sanctions for employers. GDPR requires employers to identify a legal basis for their processing of personal data, and it is unlikely that a catch-all consent will enable processing of employee data by an employer. Employers must ensure that they have GDPR-compliant documentation and that they are able to deal with the new rules on subject access requests. There continue to be significant restrictions on monitoring employees, including email and internet use.
Employees generally must be notified of the terms of the employer's personal data processing policy, and must consent to it. Registrations in the Databases Register may be required. Special rules apply to data transfer outside Israel. Significant restrictions on monitoring email and Internet use. Monitoring personal email is restricted.
Employees generally must be notified of personal data processing – and, in certain cases, give consent. Special rules apply to data transfer outside the European Economic Area (EEA). Not possible to control or monitor employees remotely with devices unless upon agreement with works council or authorization of the Labor Office, with the exception of the instruments used by the employee to carry out their work or to detect access or attendance.
Since May 2018, Italy has been subject to the General Data Protection Regulation (GDPR), which introduced significant new obligations and onerous sanctions for employers.
The receipt, maintenance of and access to personal information relating to an individual is regulated by the Act of Protection of Personal Information. Broadly, upon the collection of such information, the collector must notify the person of the purpose of the use of such information and thereafter must take necessary and proper measures to prevent leakage, loss or damage of that information, and take other reasonable steps to control the security of the personal information. In addition, the party maintaining such information is required to adopt internal regulations designed to ensure the confidential and secure maintenance of such information as long as it is held. Disclosure of personal information to third parties (parent and affiliated companies are considered third parties) is strictly limited.
The Data Protection Act, 2019 gives effect to Article 31(c) and (d) of the Constitution on the right to privacy. The Act establishes the Office of the Data Protection Commissioner, makes provision for the regulation of the processing of personal data and provides for the rights of data subjects and obligations of data controllers and processors, among others. The Act is modeled along the lines of the EU General Data Protection Regulations (GDPR).
The Constitution guarantees the right to privacy.
The Computer Misuse and Cyber Crimes Act, 2018 creates various offenses, including the right to privacy, in relation to computer systems.
There are no clear laws in Kuwait comparable with those in the US or Europe concerning the handling and transmission of employees' personal information, nor do any provisions address the cross-border flow of data. However, it is advisable to seek prior written consent to the processing of personal data from the employee to the extent necessary to address the various privacy protections set out in Kuwait law, including the protections set out in the Kuwait Penal Code and the Kuwait Constitution.
The General Data Protection Regulation (GDPR) has been in force since May 25, 2018. It has been complemented by the Luxembourg law of August 1, 2018 on the organization of the CNPD.
Since then, the processing of personal data is no longer subject to a prior notification to/authorization from the National Data Protection Commission (Commission Nationale pour la Protection des Données or CNPD). However, the processing of personal data for the purpose of supervising employees in the context of employment relationships may only be carried out by the employer under certain conditions.
The employee's consent does not legitimize the processing of data.
In case of conducting employee monitoring, the employer must first notify:
- The employees concerned
- All persons external to the company who may also be concerned (eg, customers, suppliers or visitors) and
- If a surveillance system is used in the workplace, the staff delegation or, failing this, the Inspectorate of Labor and Mines (Inspection du travail et des mines or ITM).
Please note that a number of strict requirements apply in this context according to the Labor Code.
Data subjects have the right to lodge a complaint with the CNPD.
Collection and processing of personal data is governed by the Personal Data Protection Act 2010 (PDPA). Employers must obtain employees' consent (implied or express) before collecting and processing employees' personal data, and explicit consent is required if "sensitive personal data" is being collected. Employers must notify their employees of the nature and purpose of information being collected, to whom it is being disclosed, and that the employees have the right to access such data. Employee consent is also required before employee personal data is shared with third parties (for example, external payroll service providers).
As a result of the PDPA, an employee consent/notice document is required. This document has to be bilingual – in both English and Bahasa Malaysia – and is usually a separate document and referenced in the employment contract.
To process personal data, data controllers must provide a privacy notice to the affected employees prior to the collection and processing of such personal data. In the case of data transfers, the privacy notice must contain the name of the transferee or the person to whom the information is transferred. All transfers of personal data to domestic or foreign third parties must be pre-approved by the data subject (ie, the employee).
Employees must be notified of data processing in accordance with law No 09-08 on data protection. Employees' consent to the processing of their data is required. Employees should be given the right to have access to and modify/amend their personal data.
Employers must declare data processing to the National Control Commission for the Protection of Personal Data (Commission Nationale de protection des Données Personnelles).
The Constitution of the Republic of Mozambique, as well as the recently enacted Electronic Transactions Law (The Law No. 3/2017, of January 9), prohibits access to data bases or to computerized archives, files and records for obtaining information on the personal data of third parties, as well as the transfer of personal data from one computerized file to another that belongs to a distinct service or institution, except in cases provided for by law or by judicial decision.
The Labor Law establishes that employers may not require an employee to supply information regarding their private life, except when particular requirements inherent to the nature of the professional activity so require. In addition, employees' personal data obtained by an employer is subject to a duty of confidentiality, and information where the release of which would violate that employee's privacy rights may not be given to a third party without the consent of the employee, unless it is required by law.
There are not currently any specific laws or regulations in Myanmar relating to data privacy. However, per the Law Protecting the Privacy and Security of Citizens enacted on March 8, 2017, a person is not allowed to do the following without permission of the relevant authorities:
- Request or acquire any private call data, electronic communications data and information from operators or supply such information
- Open, search, seize, destroy or damage any envelope, parcel or correspondence communicated that are the personal affairs of other individuals and
- Criticize or interfere in the personal affairs and family affairs of any citizen or engage in conduct that may be detrimental to the good name, standing or dignity of an individual
Other than the above, there are currently no other laws or regulations on data privacy.
Employees generally must be notified of personal data processing – and, in certain cases, give consent. Registrations with the Information Commissioner are required. Special rules apply to data transfer outside the EEA. Significant restrictions on monitoring email and internet use.
From May 2018, the country is subject to the General Data Protection Regulation (GDPR), which introduces significant new obligations and onerous sanctions for employers. In general, the GDPR aims at empowering individuals (including temporary employees, job applicants, contractors, trainees and other workers) with regard to controlling the use of their personal data and at harmonizing the data protection legislation across the EU.
The Privacy Act 2020 controls New Zealand data privacy and determines how employers collect, use, disclose, store and give access to ''personal information.''
The National Information Technology Development Agency published the Nigeria Data Protection Regulation, 2019 which safeguards the rights of natural persons to data privacy.
Notification to the employee is required. An obligation to notify the Data Inspectorate may apply. Significant restrictions on monitoring and control of employees. Special provisions apply for transmission of data outside the EEA.
There are no clear laws in Oman comparable to those in the US or Europe concerning the handling and transmission of employees' personal information. However, the Electronic Transactions Law, RD 69/2008 (ETL) provides for the protection of personal data and regulates the transfer of personal data outside of Oman.
The Cyber Crime Law, Royal Decree no. 12 /2011 (Cybercrime Law) provides that it is an offense to violate the privacy of individuals through technology and prohibits the collection of private data.
It is advisable to seek prior written consent from employees to the processing of their personal data to the extent necessary to overcome the various privacy protections set out in the applicable civil and criminal laws.
During the employment relationship, companies collect employee personal data. The processing of personal data must be done in accordance with the guiding principles provided by the law.
According to the Peruvian Data Protection Law, consent and privacy notices must be obtained/given before the personal data is obtained/processed. Pursuant to the law, personal data may only be processed and/or transferred with prior consent. Such consent must be free, informed, express and unequivocal. However, a company does not need the express consent of the employee to obtain personal data if this information is necessary for the operation of the employment relationship, but it must comply with the duty of inform about the processing of personal data.
When an employer collects and processes personal information of its employees, especially sensitive personal information, the employer must comply with applicable guidelines on the adoption of organizational, physical and technical security measures and the registration thereof with the National Privacy Commission. The data subject must have given their consent prior to the collection, or as soon as practicable and reasonable. An employer's collection of personal information from its own employees does not require the employee's prior written consent, provided the personal information collected and the processes applied to such information are only to the extent necessary for compliance with legal requirements prescribed for an employer-employee relationship.
An employer is obliged to respect its employees' dignity and other personal rights, including their privacy and the confidentiality of the content of employees' private correspondence. There are statutory rules which forbid the secret monitoring of employees, and there are specific rules to introduce camera monitoring and other forms of employee monitoring, including monitoring of software and the internet, among others.
The Polish Labor Code sets forth specific rules regarding collecting and processing personal data of the candidates and the employees and, in particular, lists the types of data that may be requested by the employer. In matters not regulated by the Labor Code, general rules on data protection provided for in the Act on the Protection of Personal Data and the General Data Protection Regulation (GDPR) apply.
Since May 2018, Portugal is subject to the General Data Protection Regulation (GDPR), which introduced significant new obligations and onerous sanctions for employers.
The local privacy law under the GDPR (Law no. 58/2019) entered into force on August 9, 2019. Limitations to the use of consent within a working relationship and video surveillance were introduced by this law.
On November 2016, Qatar issued a stand-alone data protection law No. 13 of 2016 on Protection of Personal Data Privacy (Data Protection Law). Businesses must take action to protect the privacy of personal data or risk fines of up to QAR 5 million. Key features of the law include:
- Personal data is defined as data relating to an individual whose identity is determined, or able to be reasonably determined, either through the data or through linking this data with other data
- The Data Protection Law applies to personal data when it is processed electronically, or when it is accessed or collected or extracted otherwise in preparation for its electronic processing, or when it is processed in a traditional and electronic way together
- The processing of personal data will be regulated in a way which bears similarities with existing data protection regulations elsewhere in the world
- Particular protection will be provided to certain types of personal data, such as data relevant to children, to physical and mental health and to crimes referred to as sensitive personal data
- For example, parental consent will be required in connection with the online collection and processing of the personal data of children
- Businesses will need to implement suitable measures, including training, to protect personal data from loss, damage, modification, disclosure or illegal access
- Direct marketing will require the prior consent of the intended recipient and, amongst other requirements, the relevant communication must include a means by which the recipient may opt-out of future communications
This law may sit alongside the Qatar Financial Centre data protection regulations. It is also important to note that as per the Qatar Penal Code it is advisable to seek prior written consent to the processing of personal data from the employee to the extent necessary to overcome the various privacy protections.
Employees must be informed of personal data processing – and in certain limited cases, must give consent.
Since May 2018, Romania has been subject to the General Data Protection Regulation (GDPR), which introduced significant new obligations and onerous sanctions for employers. Under the GDPR, specific rules apply to any personal data transferred outside the European Economic Area aimed at ensuring that appropriate safeguards are provided for the transferred personal data and that enforceable data subject rights and effective legal remedies for data subjects are available.
Monitoring of employees, including email and internet use, may be performed under very specific circumstances, provided that the legal provisions which impose restrictions on interference with the protection of private life, data privacy and electronic communications are complied with.
In certain cases, employers are required to obtain the prior written consent of their employees in order to process their personal data (eg, transfer personal data to third parties including cross-border transfers).
Transfer of employee data outside of the KSA is not regulated under Saudi law. However, general Shariah principles provide for personal data protection rules which imply that employers should include provisions in employment contracts where the employee's consent is required for the employer to use or disclose the employee's data to third parties, to the extent that such disclosures may be required.
Generally, employers are required to at least notify applicants of the purposes for which their personal data is being used in connection with the management and termination of employment and/or obtain their consent where collecting, using or disclosing their personal data.
However, under the PDPA, an employer is permitted to collect, use and disclose the employees' personal data for purposes of managing or terminating an employment relationship without the need to seek employee's consent, so long as the employee has been notified of the purposes of such collection, use and disclosure and/or provides their consent prior to such collection, use and disclosure. Further, employers may collect, use and disclose personal data without obtaining the employees' consent or notifying them where it is necessary for evaluative purposes, including the determination of the suitability or eligibility of an individual to whom the data relates for employment, continuance in employment or promotion.
Note that employers must seek consent for purposes that are not related to, or for the collection of personal data that is not relevant to, the management or termination of an employment relationship or that are not relevant for evaluative purposes, unless any other exception under the PDPA applies.
Covered by the national data protection laws and EU rules. Processing of personal data is generally unlawful except as allowed by the applicable legislation or based on consent of the individual. Special rules apply to data transfers outside the EEA.
In general, an employer may collect personal data about its employees which relates to their qualifications and professional experience, and other information which is relevant to the work carried out by the employees.
As of May 2018, Slovakia is subject to the General Data Protection Regulation (GDPR), the local introduced significant new obligations and onerous sanctions for breach of personal data rules. In specific cases, also Act No. 18/2018 Coll. on Personal Data Protection, as amended, applies.
The right to privacy is protected under the Constitution of the Republic of South Africa, 1996, the common law and the Protection of Personal Information Act, 2013 (POPIA), which came into effect on July 1, 2020. Case law recognizes that the right to privacy is not absolute and may be limited where it is reasonable and justifiable to do so. Personal information may be processed on the basis of one of the justifications for processing personal information under POPIA. These justifications include consent and where it is necessary for pursuing the legitimate interests of the responsible party or employer or third party to whom it is disclosed.
Under the PIPA, an employee is entitled to request the employer to allow access to, correct or delete their personal information. The PIPA requires an employer to obtain the consent of the individual employee when their personal information is obtained or provided to third parties.
Spain is subject to the General Data Protection Regulation of the European Union (GDPR). The Spanish legislation that implements the GDPR is the Organic Law 3/2018 on data protection and guarantee of digital rights (Ley Orgánica 3/2018 de protección de datos y garantía de los derechos digitales). Employees must generally be notified of personal data processing (and, in certain cases, must give consent). Registration of databases with the Spanish Data Protection Commissioner (AEPD) is no longer required. Special rules apply to data transfers, even between companies belonging to the same group. Prior stringent restrictions on international data transfers, on monitoring email and internet use in the workplace and on video surveillance at work, have been eased and aligned with the GDPR, although significant compliance requirements remain.
The General Data Protection Regulation (Regulation (EU) 2016/679) (GDPR), applicable since May 25, 2018, applies to the processing of employees' personal data. The employer must ensure that the fundamental requirements for processing of the employees' personal data are fulfilled (eg, personal data must be correct, adequate and relevant in relation to the purposes of the processing and may not be retained for a longer period than is necessary in light of the purposes of the processing); there must be a legal basis for the processing, such as performance/administration of the employment agreement and relationship; and the employee must receive adequate information regarding the processing. Special rules apply to data transfers outside the EEA. Sweden has also issued national laws and regulations in addition to the GDPR including the Swedish Data Protection Act (2018:218) and the Data Protection Ordinance (2018:19) (the DPA). The DPA regulates general aspects of data protection where the GDPR allows (eg, processing of social security numbers and processing of data pertaining to criminal offenses. The DPA entered into force on May 25, 2018.
In general, employees should be notified of any processing of their personal data (and, in certain cases, give consent). Registrations with the Federal Data Protection Commissioner are required in certain circumstances. Special rules apply to data transfers outside of Switzerland. Significant restrictions on monitoring email and internet use.
Taiwan, Republic of China
The collection, processing and use of employee personal information is governed by the Personal Data Protection Act. The Act has notice and consent requirements that may be applicable to the collection, processing and use of employee information. This applies to cross-border transmission of the information or any use outside of the norms of a domestic employment relationship.
Under amendments to the Employment Service Act that came into force in late 2012, the amount of personal information that an employer may request from an employee or prospective employee has been severely restricted. Prohibited or restricted requests for personal information include physiological information (eg, medical tests and fingerprints), psychological information (eg, psychiatric tests and polygraph tests) and personal lifestyle information (eg, financial records, criminal records, family information/plans and background checks).
The Personal Data Protection Act B.E. 2562 (2019) (PDPA) was enacted on May 28, 2019 and has full effect from June 1, 2022. The PDPA is the first-ever law relating to personal data protection in Thailand. Essentially, consent is required for the collection, use and/or disclosure of personal data. Under the PDPA, the term “personal data” is defined as any data pertaining to a person that enables the identification of that person, whether directly or indirectly, but specifically excludes data of someone who is deceased.
Under Tunisian law, all people have the right to the protection of personal data related to their private life and this applies to both automated and non-automated treatment of data. Personal data is defined as information that directly or indirectly permits the identification of a physical person, except for data linked to public life or defined as such under the law. In general, any organization planning to use personal data must make a declaration of the data to be used to the National Authority for the Protection of Personal Data, though there are exceptions for employers using employee data. In addition, express written consent from the data subject is required in most cases.
Employees must be notified of personal data processing, and their prior written consent should be obtained (unless exceptions stipulated under the relevant legislation are present) for such processing and transfer of their personal data. Personal data should be processed:
- In accordance with the law
- In good faith
- For definite, clear and legitimate purposes
- In a relevant and measured manner
Data controllers (ie, individuals or legal entities that determine the purposes and means of processing personal data – for example, employers) are required to be registered with the Data Controllers Registry provided that they meet certain criteria.
The Data Protection and Privacy Act, 2019 was passed into law to supplement constitutional privacy protections under Article 27 of the Constitution of the Republic of Uganda. The Act regulates personal data collection, processing, use and disclosure, and applies to any person, entity or public body within or outside of Uganda who collects, processes, holds or uses personal data.
The Act requires an employer to obtain informed consent prior to collecting or processing an employee’s personal data. The Act permits processing or storage of personal data outside Uganda if adequate measures are in place in the country in which the data is processed or stored, at least equivalent to protections under the Act, or with the data subject’s consent.
In most cases, the processing of personal data requires the consent of the respective data subject. However, employers are allowed to process an employee's basic personal data without consent to the extent required to perform the employer's statutory obligations (eg, pay salary or statutory reporting).
Processing of sensitive data (eg, health status data, data related to religious beliefs or political views) is prohibited, unless the individual provides explicit consent or there is a statutory ground for processing these categories of data. The processing of sensitive data requires notification to the Ukrainian Parliament Commissioner for Human Rights.
Cross-border personal data transfers require documents such as an intercompany agreement on the transfer of data in addition to the data subject's consent.
United Arab Emirates
2021 saw a new data privacy law issued in the UAE, which borrows certain concepts from the GDPR.
As of the end of the transition period following the UK's exit from the EU, the UK is subject to the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, which impose significant obligations and onerous sanctions for employers. Under this regime, it is extremely difficult for employers to rely on consent as a basis for processing employee data, and other legitimate grounds generally must be identified.
Certain states restrict the use of employees' social security numbers for any identifying purposes. Medical information must be maintained separately from personnel files and kept confidential. Otherwise, employers generally are entitled to monitor or search corporate emails of their employees and internet traffic accessed by their computer systems, on the premise that employees do not have an expectation of privacy in the use of their employer's computer systems or corporate emails, especially with a policy that says so. Jurisdictions vary as to an employer's ability to search or monitor personal email addresses and websites accessed from an employer's computer or premises.
State laws may provide for additional individual data rights, including data breach notifications, or obligations on businesses processing personal data.
Although there is no specific regulation regarding data privacy, employers have a general duty to uphold employees’ right to privacy and must observe the data protection principles determined by the Supreme Court (DP Principles).
The DP Principles apply to systems, registers or compilations of data that allow the creation of a complete or partial profile of an individual forming part of such system, register or compilation (in this case, an employee, for example). There is no clear outline of what a “complete or partial profile” involves.
This means that, in general, employee consent is required to process personal data. Venezuelan case law does not draw a distinction between forms of personal data. Therefore, there are no separate standards for the protection of sensitive data.
Pursuant to the DP Principles, employers must (i) inform the employee what data has been collected, (ii) inform the employee of the purpose(s) of the collection of their personal data, (iii) inform the employee who will be the final users of the data (ie, whether any third parties will have access to the data) and (iv) allow the employee to correct any erroneous data or delete any data that may be incomplete, inadequate or excessive in relation to the purpose(s) for which they were gathered (and this must be communicated to any third party who has been given access to the personal data).
Venezuelan law also provides for the protection of private communications, and employers have a strict obligation to keep employee health information and records confidential.
The Civil Code requires any person to seek the consent of an individual before collecting, storing, using or publishing their personal data. The parties to a contract are not permitted to disclose any information about each other’s private life or personal affairs of which they became aware in the course of entering into and performance of the contract.
The 2018 Law on Cyber Security covers any domestic or foreign enterprise that provides services on telecommunications networks, the internet or value-added services in Vietnam's cyberspace. The law governs the collection, exploitation, analysis and processing of personal data, data about service users' relationships and data generated by them in Vietnam. Under this law, any such data must be stored in Vietnam under the terms stipulated by the government.