Employee Monitoring Law Planner
Sources

Federal Data Protection Act (BDSG), Germany

Law. Placed at Germany. Read 30 Sep 2026; 8 provisions cited by the planner.

BDSG s 26(4)Where a collective or works agreement governs employee data, meet GDPR Art. 88(2) Section 26(1) sentence 1 is not a legal basis on its own (CJEU C-34/21): name the GDPR Art. 6(1) basis for the purpose, or a works agreement that meets GDPR Art. 88(2).

Collective agreements (collective bargaining agreements, works agreements and service agreements) may form the basis for processing employees' data, including special categories, for employment purposes. The negotiating parties must observe GDPR Art. 88(2): suitable and specific measures to safeguard the employees' dignity, legitimate interests and fundamental rights, with particular regard to transparency, transfers within a group, and monitoring systems at the workplace.

What a reviewer asks to see: Works agreement or collective agreement for each monitoring system, stating purposes, data, access, retention and prohibited uses; Art. 88(2) safeguard checklist signed off for each agreement; GDPR Art. 5, 6 and 9 compliance review of the agreed processing
Where monitoring plans usually fall short: Works agreement lowers GDPR standards on the assumption that the agreement itself is enough; Agreement silent on performance evaluation limits and retention; Agreement not updated when the system changes
Source: Federal Data Protection Act (BDSG), Germany, read 30 Sep 2026
BDSG s 4(2)Make video surveillance and the controller identifiable at the earliest possible point

The operator must use suitable measures, such as signs placed before the monitored area is entered, so that people can see, at the earliest possible moment, that they are being observed and who the controller is, with the controller's name and how to contact it.

What a reviewer asks to see: Signs positioned ahead of each monitored zone with the camera symbol and the controller's identity and contact route; Photographs or inspection records of signs in place; Layered notice with the full GDPR Art. 13 information available on request or online
Where monitoring plans usually fall short: Signs only inside the monitored area; Sign omits who operates the cameras or how to reach them; Signs removed or obscured after refits
Source: Federal Data Protection Act (BDSG), Germany, read 30 Sep 2026
BDSG s 26(1) sentence 2Investigate suspected crimes by employees only on documented suspicion and proportionately Section 26(1) sentence 1 is not a legal basis on its own (CJEU C-34/21): name the GDPR Art. 6(1) basis for the purpose, or a works agreement that meets GDPR Art. 88(2).

Employees' data may be processed to uncover criminal offences only where documented factual indications support a suspicion that the person committed an offence in the employment relationship, the processing is necessary to uncover it, and the employee's legitimate interest in exclusion does not prevail, in particular because the kind and extent of the measure are not disproportionate to the occasion. The rule governs covert measures such as hidden cameras, keystroke logging or targeted mailbox review in an internal investigation: blanket or suspicion-free covert monitoring does not meet it.

What a reviewer asks to see: Written record of the factual indications before the measure starts, dated and signed by the decision maker; Proportionality assessment showing why less intrusive steps were insufficient; Investigation plan limiting persons, period and data, with the end date and deletion step
Where monitoring plans usually fall short: Covert monitoring started on a vague suspicion; Suspicion documented only after the measure; Measure extended to uninvolved employees or kept running after the suspicion is resolved
Source: Federal Data Protection Act (BDSG), Germany, read 30 Sep 2026
BDSG s 26(1) sentence 1Process employee data only where necessary for the employment relationship, on a GDPR legal basis Section 26(1) sentence 1 is not a legal basis on its own (CJEU C-34/21): name the GDPR Art. 6(1) basis for the purpose, or a works agreement that meets GDPR Art. 88(2).

Section 26(1) sentence 1 describes when employees' data may be processed for employment purposes: where necessary to decide on hiring, to perform or end the employment relationship after hiring, or to exercise or meet the rights and duties of employee representation arising from statute or from collective agreements, works agreements or service agreements. The sentence does not by itself supply the legal basis: in C-34/21 (30 March 2023) the Court of Justice held that a Hesse provision worded like this sentence is not a more specific rule under GDPR Art. 88(1) where it does not meet Art. 88(2), and must then be disapplied unless it is a rule under Art. 6(3). The controller therefore identifies for every employment purpose a basis in GDPR Art. 6(1) (contract under (b), legal obligation under (c), legitimate interests under (f)) or a works agreement meeting Art. 88(2), and applies the necessity test the sentence states: no more data and no more intrusive processing than the purpose requires.

What a reviewer asks to see: Employee record of processing listing each HR and monitoring purpose with its GDPR Art. 6(1) basis (not s 26(1) alone); Necessity and proportionality assessment for each monitoring measure; Employee privacy notice naming the bases relied on
Where monitoring plans usually fall short: Notices and records still cite s 26(1) BDSG as the sole basis; Monitoring justified as necessary for the contract without assessment; No review of legal bases after C-34/21
Source: Federal Data Protection Act (BDSG), Germany, read 30 Sep 2026
BDSG s 26(5)Take measures to ensure the GDPR principles are met in employee data processing Section 26(1) sentence 1 is not a legal basis on its own (CJEU C-34/21): name the GDPR Art. 6(1) basis for the purpose, or a works agreement that meets GDPR Art. 88(2).

The controller puts suitable measures in place so that, above all, the principles of GDPR Art. 5 (lawfulness, fairness and transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality, accountability) are complied with when employees' data are processed.

What a reviewer asks to see: HR data protection policy mapping each Art. 5 principle to a control; Retention schedule for personnel records and monitoring data; Access control matrix for HR and monitoring systems
Where monitoring plans usually fall short: No deletion of applicant data after the process ends; Monitoring data retained indefinitely; Broad HR system access for managers
Source: Federal Data Protection Act (BDSG), Germany, read 30 Sep 2026
BDSG s 4(5)Delete video data without delay once no longer needed

Video data must be erased without undue delay when they are no longer necessary for the purpose or when the legitimate interests of the persons concerned stand against keeping them longer.

What a reviewer asks to see: Retention setting on each recorder with a short default overwrite period; Documented justification for any longer retention; Deletion or overwrite logs and legal-hold records for footage kept for an incident
Where monitoring plans usually fall short: Default recorder retention of weeks or months without justification; Incident footage kept indefinitely; No evidence that overwrite actually occurs
Source: Federal Data Protection Act (BDSG), Germany, read 30 Sep 2026
BDSG s 26(2)Rely on employee consent only where it is genuinely voluntary, in the required form and with text-form notice Section 26(1) sentence 1 is not a legal basis on its own (CJEU C-34/21): name the GDPR Art. 6(1) basis for the purpose, or a works agreement that meets GDPR Art. 88(2).

Where employee data are processed on consent, voluntariness is judged by how dependent the employee is on the employer and by the situation in which consent was obtained. Consent can be voluntary in particular where the employee gains a legal or economic advantage or employer and employee pursue aligned interests. Consent is given in writing or electronically unless special circumstances justify another form, and the employer informs the employee in text form (for example email) of the purpose of processing and of the right to withdraw consent under GDPR Art. 7(3).

What a reviewer asks to see: Consent form in written or electronic form stating the purpose; Text-form notice of the purpose and the withdrawal right given before consent; Assessment of voluntariness (advantage to the employee or aligned interest) and proof that refusal carries no detriment
Where monitoring plans usually fall short: Consent used for monitoring that the employee cannot realistically refuse; Consent obtained orally or buried in the employment contract; No withdrawal route or processing continues after withdrawal
Source: Federal Data Protection Act (BDSG), Germany, read 30 Sep 2026
BDSG s 4(1)Video surveillance of publicly accessible spaces only where necessary for a listed purpose

Watching publicly accessible spaces by optical-electronic means (video surveillance) is lawful only to the extent needed for a public body's tasks, for exercising the right to decide who may enter or stay (domestic authority, Hausrecht), or for legitimate interests pursued for concretely specified purposes, and only if nothing indicates that the overriding legitimate interests of those observed prevail. For large publicly accessible facilities (sports grounds, venues for assembly and entertainment, shopping centres, car parks) and for vehicles and large facilities of public rail, ship and bus transport, protecting the life, health and freedom of people present counts as a particularly important interest.

What a reviewer asks to see: Written purpose statement for each camera or camera group; Legitimate interest and necessity assessment including less intrusive alternatives; Camera site plan showing fields of view and excluded areas (staff rooms, toilets, changing areas)
Where monitoring plans usually fall short: Purpose stated only as general security; Cameras cover areas outside the stated purpose; No review whether surveillance is still necessary
Source: Federal Data Protection Act (BDSG), Germany, read 30 Sep 2026

Open the full text on compliance.theartofservice.com

See the specimen plan run Plan your own list