Jan Dop

partner

Jan is a specialist in employment law and corporate law

jan.dop@russell.nl
+31 20 301 55 55

Is your staff management ready for the GDPR?

Publication date 23 mei 2018

At the end of the week, on 25 May 2018, the General Data Protection Regulation (GDPR) comes into force. This does not just have consequences for your website or online shop but also for your staff management. Is it ready for the GDPR?

persoonsgegevens - ubo

You may have heard a lot about the General Data Protection Regulation (GDPR) and the necessary changes you have to make to your website, the mandatory privacy statement, and the processing agreements you have to conclude. But even if you don’t have a website or web store, you will have to deal with the GDPR.

General Data Protection Regulation

The GDPR will give citizens more control over their personal data, such as name, address, bank account number, etc. The GDPR requires organisations to make transparent in advance which personal data they process, for what purpose, what the legal basis is for the processing, and how the data are processed. This does not just apply to personal data of customers and suppliers, but also to the personal details of your employees.

Personnel data are personal data

The data an organisation collects and processes of its employees are certainly personal data which fall under the GDPR: wages, pension, leave, etc. In addition, special category personal data will be processed, such as citizen service numbers and sick leave. Also, data used in the application process are personal data within the meaning of the GDPR.

Usually, the processing of personal data is based on a legal requirement under fiscal or social legislation, or labour law and pension law. There is no legal requirement for an in-company “face book”, for instance, or a birthday calendar and the legal basis for the processing must be a legitimate interest (employees must be able to identify each other for the purpose of security) or the processing has to be based on the informed consent of the individual employees.

Sharing data with third parties

Employees have to be informed of what happens with their personal data, for instance, that part of the data will be shared with a payroller, a pension fund, and – in the event of sickness – with the occupational health and safety service and/or employee insurance agency. You also have to conclude processing agreements with the external parties you involve in your staff management, where they declare to comply with the GDPR and your privacy policy.

Employee rights

In addition, make your employees aware of their rights, such as the right to be forgotten, the right to obtain restriction of data processing, and the right to object to processing. These rights cannot be invoked where you are legally required to process data. The storage period of salary details for fiscal purposes is, for instance, 7 years from the termination of employment. During this period, the (former) employee cannot require you to delete these data from your files.

Conclusion

The GDPR does not just have consequences for the relationship with your customers or suppliers but it does also affect the internal relationship with your employees. We recommend you draft a separate privacy policy for your employees and conclude the required processing agreements.

More information

Would you like to learn more about the GDPR and what you, as an organisation have to do for a “GDPR-proof” staff management? Would you like to make changes to your privacy statement, or would you like us to draft a processing agreement? Please contact us at:

    We process the personal data above with your permission. You can withdraw your permission at any time. For more information please see our Privacy Statement.

    Related publications

    Is your staff management ready for the GDPR?

    At the end of the week, on 25 May 2018, the General Data Protection Regulation (GDPR) comes into force. This does not just have consequences for your website or online shop but also for your staff management. Is it ready for the GDPR?

    Read more

    Privacy: New European Data Protection Regulation

    In this newsletter Russell Advocaten will inform you, in short, about the most important changes to be expected in the European data protection regulations. More detailed information on this topic can be found in our previous newsletters.

    Read more

    Amendment or termination of the share scheme: is the consent of the works council required?

    The works council has the right of consent when establishing, amending or withdrawing a remuneration system. Is an amendment to a share scheme an amendment to the remuneration system?

    Read more

    Digital General Meeting for Private Law Legal Entities Act adopted

    On 16 December 2025, the House of Representatives of the Netherlands adopted the Digital General Meeting for Private Law Legal Entities Act. This Act makes it possible to hold general meetings entirely digitally. What does this mean for directors and shareholders of private limited companies, public limited companies and other legal entities?

    Read more

    Highly skilled migrants: salary thresholds for 2026 and possible stricter rules

    The salary thresholds for highly skilled migrants and European Blue Card holders are adjusted annually. What will be the amounts for 2026? Also, stricter rules for the highly skilled migrant scheme are proposed. What might change?

    Read more

    On-call employees

    On-call contracts offer many advantages for both employers and on-call employees. However, there are also a few rules that they need to take into account. What are they?

    Read more