[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fOucCODb_za48RsgrR9xO8yKvpedLMjPFM8WriTnrU_E":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":22,"created_at":23,"published_at":24,"article":25,"tags":29,"podcasts":42},"feefaae0-053c-4abf-b250-85ac4aa26838","austrian-dpa-rules-employee-feedback-process-unlawful-for-lacking-works-council-approval","fa41f292-5877-4056-ab4b-0b11a366c02b","Austrian DPA Rules Employee Feedback Process Unlawful for Lacking Works Council Approval","An Austrian employer implemented a 360-degree employee feedback system without obtaining the mandatory works council agreement required under the Austrian Labour Constitution Act (ArbVG), rendering the entire data processing activity unlawful. Attempting to justify the processing under GDPR's legitimate interests (Art. 6(1)(f)) or contract performance (Art. 6(1)(b)) does not override national labor law co-determination rights. This case highlights that GDPR compliance alone is insufficient — organizations must also satisfy sector-specific and national statutory requirements before processing employee data. The ruling underscores the layered nature of data protection obligations in EU member states, where local labor laws frequently impose additional constraints on workplace data processing.","**Immediate actions:**\n- Audit all existing employee data processing activities to identify any that lack required works council or employee representative agreements.\n- Suspend or pause any unlawful employee monitoring or evaluation systems until proper legal bases and co-determination approvals are secured.\n\n**Legal & compliance alignment:**\n- Engage legal counsel to map national labor law requirements (e.g., ArbVG in Austria, BetrVG in Germany) alongside GDPR obligations before deploying any HR technology.\n- Establish a mandatory pre-deployment checklist that requires sign-off from both DPO and HR legal teams before any new employee data processing begins.\n- Document works council negotiations and agreements as part of the processing records under GDPR Art. 30.\n\n**Long-term improvements:**\n- Implement a Data Protection Impact Assessment (DPIA) process specifically tailored for employee-facing systems that includes a labor law compliance gate.\n- Train HR and management teams on the intersection of GDPR and national labor co-determination rights to prevent recurring violations.\n- Establish a periodic review cycle for all HR data processing activities to ensure continued compliance with evolving national regulations.",[12,13,14,15,16,17,18,19,20,21],"GDPR Art. 6(1)(b) – Lawfulness of processing: contract performance","GDPR Art. 6(1)(f) – Lawfulness of processing: legitimate interests","GDPR Art. 30 – Records of processing activities","GDPR Art. 35 – Data Protection Impact Assessment (DPIA)","Austrian Labour Constitution Act (ArbVG) – Works council co-determination rights","NIST SP 800-53 PT-2 – Authority to Process Personally Identifiable Information","NIST SP 800-53 PM-25 – Minimize PII Used in Testing, Training, and Research","CIS Control 3 – Data Protection","ISO\u002FIEC 29101 – Privacy Architecture Framework","ITIL – Service Design: Compliance and Legal Requirements Management","published","2026-08-06T14:20:22.832683+00:00","2026-08-06T14:20:22.524+00:00",{"id":7,"url":26,"slug":27,"title":28},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=DSB_(Austria)_-_2025-0.960.016&diff=52635&oldid=0","dsb-austria-2025-0-960-016-fe02ec","DSB (Austria) - 2025-0.960.016",[30,36],{"id":31,"name":32,"slug":33,"description":34,"color":35},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":37,"name":38,"slug":39,"description":40,"color":41},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]