Employee Data Collection
Purpose first, then fields. A staff form is processing too.
What Is Employee Data Collection?
Over-collection happens internally, because nobody thinks of a staff form as data processing. A quick favour for a manager asks hundreds of colleagues for tax numbers, family birthdays and health conditions before anyone writes down the purpose, and it reaches archived profiles too. By lunchtime the Data Protection Officer has stepped in, former employees have sent in sensitive data, and the supervisory authority has written. You then rerun the request properly: establish the purpose, test six fields against it, split the legal bases, and mail only the people it covers.
What You'll Learn in Employee Data Collection
- Establish and record the purpose of a collection before any data is requested, and ask when the purpose exists only in someone's head
- Apply data minimisation under Article 5(1)(c) by testing each field against the stated purpose rather than against usefulness
- Recognise that marking an unnecessary field optional does not satisfy minimisation, and remove it instead
- Identify dietary, religious and health information as special category data under Article 9 and collect it behind separate explicit consent
- Explain why wording such as mandatory or urgent invalidates consent in an employment relationship, where the power imbalance is already a risk
- List the Article 13 information a collection notice must carry: purpose, legal basis, retention period, recipients, rights and DPO contact
- Involve Legal and the Data Protection Officer while a communication is still a draft rather than after it has been sent
- Scope an internal audience deliberately, and recognise that former employees should not receive staff communications at all
Employee Data Collection — Training Steps
-
A Favour for Dagny
Monday, twenty past nine. Dagny Sorheim, who runs People Operations and has been in back to back meetings since eight, sends over a form and asks you to get it out to everyone today. It is a two minute job. You would rather clear it now than let it sit in your inbox while you work on the things you actually planned for the day.
-
The Attachment
The form came from Dagny, so there is no reason to doubt it. Download it and get it moving.
-
A Quick Look
You give it the glance you give anything a manager forwards: is it the right document, does it have a title, is there anything obviously broken.
-
Rather a Lot of Fields
It is longer than you expected. Nothing about it looks wrong exactly, it is just a lot of boxes for something that was described as a quick favour.
-
Off to the Platform
It is a lot of questions, but Dagny asked for it and Dagny presumably knows why. You have four other things waiting. Her email links straight to Almvik People, the platform that sends anything company wide.
-
Signing In
Almvik People holds a profile for everyone the company has ever paid, and it is the only tool that can reach all of them at once.
-
Everyone Means Everyone
Dagny said everyone. The platform splits its profiles into groups, and picking through them one at a time is exactly the kind of fiddling that turns a two minute job into twenty. There is a button that takes all of them at once.
-
Attaching the Form
The mailing has its people. It still needs the thing you are actually asking them to fill in. Almvik People will not send a broadcast with nothing on it, so the form goes on before anything else happens.
-
Sent
One thing left: the note that goes above the form. People ignore internal mailings, and you have a Friday deadline to hit, so you make it sound like it matters. Then you send it and get on with your morning.
-
The Phone Rings
You are halfway through the onboarding pack for next week's starters when your phone goes. It is Ines Kovar, the Data Protection Officer, and she has not rung you before.
Security Framework Coverage
CIS Controls
- CIS 3 Data Protection
NIST CSF
- PR.AT-01 Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind
- PR.DS Data Security
GDPR
- Art. 5 Principles relating to processing of personal data
- Art. 9 Processing of special categories of personal data
- Art. 13 Information to be provided where personal data are collected