Jan Dop

partner

Jan is a specialist in employment law and corporate law

jan.dop@russell.nl
+31 20 301 55 55

Is your staff management ready for the GDPR?

Publication date 23 mei 2018

At the end of the week, on 25 May 2018, the General Data Protection Regulation (GDPR) comes into force. This does not just have consequences for your website or online shop but also for your staff management. Is it ready for the GDPR?

persoonsgegevens - ubo

You may have heard a lot about the General Data Protection Regulation (GDPR) and the necessary changes you have to make to your website, the mandatory privacy statement, and the processing agreements you have to conclude. But even if you don’t have a website or web store, you will have to deal with the GDPR.

General Data Protection Regulation

The GDPR will give citizens more control over their personal data, such as name, address, bank account number, etc. The GDPR requires organisations to make transparent in advance which personal data they process, for what purpose, what the legal basis is for the processing, and how the data are processed. This does not just apply to personal data of customers and suppliers, but also to the personal details of your employees.

Personnel data are personal data

The data an organisation collects and processes of its employees are certainly personal data which fall under the GDPR: wages, pension, leave, etc. In addition, special category personal data will be processed, such as citizen service numbers and sick leave. Also, data used in the application process are personal data within the meaning of the GDPR.

Usually, the processing of personal data is based on a legal requirement under fiscal or social legislation, or labour law and pension law. There is no legal requirement for an in-company “face book”, for instance, or a birthday calendar and the legal basis for the processing must be a legitimate interest (employees must be able to identify each other for the purpose of security) or the processing has to be based on the informed consent of the individual employees.

Sharing data with third parties

Employees have to be informed of what happens with their personal data, for instance, that part of the data will be shared with a payroller, a pension fund, and – in the event of sickness – with the occupational health and safety service and/or employee insurance agency. You also have to conclude processing agreements with the external parties you involve in your staff management, where they declare to comply with the GDPR and your privacy policy.

Employee rights

In addition, make your employees aware of their rights, such as the right to be forgotten, the right to obtain restriction of data processing, and the right to object to processing. These rights cannot be invoked where you are legally required to process data. The storage period of salary details for fiscal purposes is, for instance, 7 years from the termination of employment. During this period, the (former) employee cannot require you to delete these data from your files.

Conclusion

The GDPR does not just have consequences for the relationship with your customers or suppliers but it does also affect the internal relationship with your employees. We recommend you draft a separate privacy policy for your employees and conclude the required processing agreements.

More information

Would you like to learn more about the GDPR and what you, as an organisation have to do for a “GDPR-proof” staff management? Would you like to make changes to your privacy statement, or would you like us to draft a processing agreement? Please contact us at:

    We process the personal data above with your permission. You can withdraw your permission at any time. For more information please see our Privacy Statement.

    Related publications

    Is your staff management ready for the GDPR?

    At the end of the week, on 25 May 2018, the General Data Protection Regulation (GDPR) comes into force. This does not just have consequences for your website or online shop but also for your staff management. Is it ready for the GDPR?

    Read more

    Privacy: New European Data Protection Regulation

    In this newsletter Russell Advocaten will inform you, in short, about the most important changes to be expected in the European data protection regulations. More detailed information on this topic can be found in our previous newsletters.

    Read more

    24 November: Equal Pay Day: wage transparency for women and men

    24 November 2025 was Equal Pay Day in the Netherlands: the day of the year when men have earned on average as much as women in a whole year. How can the European Directive on wage transparency ensure that men and women are paid equally?

    Read more

    Prevent the AI Act from taking you by surprise: how to limit the risks

    Almost all companies now use some form of AI. This means that they may be subject to the prohibitions and regulations set out in the European AI Act. How can you ensure that you comply with these rules?

    Read more

    Statutory minimum hourly wage

    The statutory minimum hourly wage changes every six months. What are the new amounts as of 1 January 2026?

    Read more

    11 November 2025: Wtta (Labour Supply Act) passed

    The new Labour Supply Act (Wtta) imposes stricter requirements on temporary employment agencies, payroll companies and secondment agencies. But the Wtta also has major consequences for companies that use their services. What does this mean for their personnel policy and administration?

    Read more