Employee Monitoring Law Planner
Sources

GDPR Implementation Act (UAVG), Netherlands

Law. Placed at the Netherlands. Read 30 Sep 2026; 2 provisions cited by the planner.

UAVG Art. 33(3)Process criminal-offence data about staff only under rules adopted through the works council procedure

Criminal-offence data about personnel in the controller's service may be processed only in accordance with rules adopted following the procedure of the Works Councils Act, that is with the works council's consent under WOR art. 27(1)(k) (or the equivalent employee representation route). This covers internal fraud and theft investigations, covert camera footage used to establish an offence and incident registers about employees; the Autoriteit Persoonsgegevens' DPIA list names covert camera surveillance by employers against theft or fraud (a DPIA is required even in incidental cases) and staff blacklists (art. 33(4)(c) permit).

What a reviewer asks to see: Internal investigations or incident protocol covering criminal-offence data about staff, with the works council's consent; Register of internal investigations showing the protocol applied; DPIA for covert surveillance used in investigations
Where monitoring plans usually fall short: Internal fraud investigation carried out with no protocol ever put to the works council; Findings from covert cameras stored in personnel files outside the protocol
Source: GDPR Implementation Act (UAVG), Netherlands, read 30 Sep 2026
UAVG Art. 29Use biometric identification (fingerprint or face) only where necessary for authentication or security for a weighty public-interest access need

Under GDPR art. 9(2)(g), biometric data for uniquely identifying a person may be processed only where necessary for authentication or for security purposes, and (since the Verzamelwet gegevensbescherming, in force 1 September 2026) only insofar as necessary because of a weighty public interest in lawful access to particular places, buildings, services, products, information systems or work process systems. Convenience, cost saving and time registration are not such an access need (the AP has fined an employer for fingerprint-based time registration); outside this exception, explicit consent under art. 22(2)(a), rarely freely given by employees, is the only route. The Autoriteit Persoonsgegevens' DPIA list (Staatscourant 2019, 64418) requires a DPIA for large-scale or systematic biometric processing.

What a reviewer asks to see: Necessity assessment for each biometric system showing the access interest (for example a high-security area) and why non-biometric means do not suffice; DPIA for the biometric system; Works council consent under WOR art. 27(1)(k) or (l) where staff are enrolled
Where monitoring plans usually fall short: Fingerprint or face-recognition time clocks justified by payroll accuracy or buddy-punching prevention, which is not the access-security need art. 29 requires; Biometric access extended from a secure server room to the whole office
Source: GDPR Implementation Act (UAVG), Netherlands, read 30 Sep 2026

Open the full text on compliance.theartofservice.com

See the specimen plan run Plan your own list