Skip to main content
Commerce Security logo, "All 12 PCI DSS Requirements in Plain English," "Get it now for free," "Complete Survival Guide" and a button toclick to get it
HR Questionnaires and GDPR: Five Mythsgeneral
6 min readFor Compliance Officers

HR Questionnaires and GDPR: Five Myths

Your HR team's post-sick leave check-in might seem harmless. You're showing concern for returning employees, gathering information for workplace adjustments, and documenting absences for planning. Then a regulatory authority reviews your process and finds multiple GDPR violations you didn't anticipate.

These myths persist because workplace health data processing intersects with employment law, occupational health requirements, and data protection obligations. HR teams often assume their legitimate business interests or duty of care justify collecting health information. They don't. The Italian Supervisory Authority's 50,000 Euro fine against an automotive company for post-sick leave questionnaires shows how routine HR practices can trigger enforcement action when teams misunderstand the legal framework.

Myth 1: Legitimate Interest Covers Routine HR Data Collection

The Reality: Article 6(1)(f) of the General Data Protection Regulation establishes legitimate interests as a lawful basis for processing, but Article 9 imposes stricter requirements for special category data, including health information. Your legitimate interest in managing workforce attendance doesn't automatically authorize collecting details about an employee's illness or medical treatment.

The Italian authority found the company lacked any valid legal basis under Article 9 for processing health data through their questionnaires. The processing itself had no lawful foundation because the company couldn't point to explicit consent, a specific legal obligation, or one of the other narrow exceptions Article 9(2) permits for health data.

Your options for processing employee health information are limited: explicit consent (which must be freely given and isn't truly "free" in an employment context), compliance with employment law obligations, protection of vital interests, or substantial public interest grounds established in law. "We need this for HR records" doesn't appear on that list.

Myth 2: Employees Consent When They Complete Your Forms

The Reality: Consent under the General Data Protection Regulation requires four conditions: freely given, specific, informed, and unambiguous. In employment relationships, the power imbalance makes truly free consent nearly impossible. When your supervisor hands you a health questionnaire after sick leave, can you realistically refuse without fear of consequences?

The Italian case highlighted this problem. Even if employees completed the questionnaires willingly, the authority didn't consider consent valid because the company failed to provide clear, transparent information about the processing. Employees didn't understand what data would be collected, how long it would be retained, who would access it, or what decisions might result from it.

Article 7(4) explicitly states that when assessing whether consent is freely given, "utmost account shall be taken of whether, inter alia, the performance of a contract, including the provision of a service, is conditional on consent to the processing of personal data that is not necessary for the performance of that contract." Replace "contract" with "continued employment" and the problem becomes clear.

Myth 3: Occupational Health Needs Justify Extended Data Retention

The Reality: Article 5(1)(e) requires you to keep personal data "for no longer than is necessary for the purposes for which the personal data are processed." The Italian authority found the company stored workers' data for up to ten years, a retention period deemed irrelevant and disproportionate to any legitimate occupational health purpose.

Consider what you actually need the data for. If you're documenting a workplace adjustment for an employee with a temporary injury, how long does that information remain relevant? Once the employee has recovered and returned to normal duties, or once they've left the company, the original purpose has expired. Keeping detailed health questionnaires in HR files for a decade suggests you're either retaining data without a defined purpose or you've conflated different processing activities with different retention requirements.

Your data retention schedule should specify different periods for different categories of health information: current accommodation needs (active employment plus a reasonable period), occupational injury records (as required by employment law), aggregated health and safety statistics (anonymized, indefinite), and detailed medical questionnaires (minimal retention or none at all).

Myth 4: HR Can Review Health Data to Assess Performance

The Reality: Purpose limitation under Article 5(1)(b) means you can only process personal data for "specified, explicit and legitimate purposes" and can't further process it "in a manner that is incompatible with those purposes." The Italian authority noted that the company's data processing was "not relevant for assessing the professional skills of the employees."

This finding reveals a common scope creep in HR data processing. You collect health information ostensibly to support workplace adjustments or occupational health interventions. Then managers start referencing absence patterns in performance reviews, or HR includes sick leave history in promotion decisions. Each of these represents a new purpose that requires its own legal basis and its own assessment against Data Minimisation principles.

If you need absence data for workforce planning, collect absence data (dates and duration). If you need to assess performance, use performance metrics. Don't collect detailed health questionnaires and then mine them for purposes beyond the original occupational health justification.

Myth 5: Small-Scale HR Processes Don't Warrant Formal Compliance Review

The Reality: The Italian case involved routine post-sick leave questionnaires, not a massive data breach or systematic surveillance program. The authority still imposed a definitive ban on the processing, ordered deletion of all collected data, and issued a 50,000 Euro fine. The scale of your processing doesn't determine whether the General Data Protection Regulation applies; the nature of the data and the existence of a legal basis do.

Your Article 30 processing register should document every HR activity that involves personal data, including health information. For each activity, you need to identify the legal basis, the categories of data subjects and personal data, the recipients, the retention period, and the security measures. If you can't complete that documentation for a processing activity, you shouldn't be conducting it.

The Italian authority's enforcement action demonstrates that supervisory authorities will investigate workplace data processing based on complaints from trade unions or individual employees. Your questionnaires might seem routine internally, but they look different to a data protection authority reviewing them against Article 9's strict requirements.

What to Do Instead

Start with a complete inventory of every HR process that collects or uses employee health information. For each process, document the specific legal basis under Article 9(2). If you're relying on "processing is necessary for the purposes of carrying out the obligations and exercising specific rights of the controller or of the data subject in the field of employment," confirm that your processing is actually necessary under employment law, not just convenient for HR administration.

Review your employee-facing privacy notices. Article 13 requires you to inform employees about the purposes of processing, the legal basis, the retention period, and their rights. Generic privacy policies don't satisfy this requirement; you need specific information about specific processing activities at the point of data collection.

Audit your data retention practices against documented business needs and legal obligations. If you're keeping health questionnaires for ten years, identify the specific requirement that justifies that period. If you can't, implement a shorter retention schedule and delete historical data that no longer serves a legitimate purpose.

Separate occupational health data from general HR records. Consider whether your occupational health provider should hold health information directly, with HR receiving only the minimum necessary information to implement workplace adjustments. This separation limits access, reduces the risk of purpose creep, and clarifies accountability.

Finally, train your HR team and line managers on the distinction between general absence management (which may rely on legitimate interests) and health data processing (which requires an Article 9 legal basis). The questionnaire your supervisor completes after an employee returns from sick leave isn't just an HR form. It's special category data processing that triggers the strictest requirements in the General Data Protection Regulation.

Topics:general
Application Security Isn’t Optional Anymore.

You Might Also Like