[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fsTIMi_dkACPbh36CwfBOCh3m3DjM4rlCx3oAW27dwZY":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":22,"created_at":23,"published_at":24,"article":25,"tags":29,"podcasts":42},"a0f0c79d-dd32-4d0d-a4fe-3b1302dea177","unlawful-employee-feedback-processing-missing-legal-basis-triggers-austrian-dpa-ruling","3f27530d-6410-49b9-8924-aeb97860de40","Unlawful Employee Feedback Processing: Missing Legal Basis Triggers Austrian DPA Ruling","A company conducted a 360-degree employee feedback program without securing the required works agreement mandated by Austrian labor law, rendering the personal data processing unlawful. The core failure was assuming that general internal agreements were sufficient to cover systematic, sensitive assessments of employee leadership behavior. This matters because HR data processing — especially evaluative assessments — carries heightened legal obligations under both national labor law and GDPR, and non-compliance exposes organizations to regulatory sanctions and reputational harm. The case illustrates that data protection compliance cannot be addressed generically; specific processing activities require specific, documented legal bases.","**Immediate actions:**\n- Audit all active HR data processing activities (performance reviews, feedback tools, monitoring systems) to verify each has an adequate and specific legal basis.\n- Suspend or pause any systematic employee assessment programs that lack a documented works agreement or equivalent lawful basis until compliance is confirmed.\n\n**Policy & governance improvements:**\n- Establish a mandatory Data Protection Impact Assessment (DPIA) process for all new HR technology and people-analytics initiatives before deployment.\n- Require legal and DPO sign-off on any employee monitoring or evaluation program to confirm alignment with both GDPR and applicable national labor law.\n- Maintain a granular Records of Processing Activities (RoPA) entry for each HR processing activity, distinguishing between general and specific legal bases.\n\n**Long-term culture & training measures:**\n- Train HR, Legal, and People Operations teams on the intersection of GDPR and national labor law obligations specific to employee data processing.\n- Implement a periodic review cycle (at least annually) to reassess whether existing agreements and consent frameworks still cover current data processing practices.",[12,13,14,15,16,17,18,19,20,21],"GDPR Article 6 (Lawfulness of processing)","GDPR Article 9 (Processing of special categories of data)","GDPR Article 13 & 14 (Transparency obligations)","GDPR Article 35 (Data Protection Impact Assessment)","GDPR Article 88 (Processing in the context of employment)","Austrian Data Protection Act (DSG) Section 11 (Employee data)","NIST SP 800-53 PT-2 (Authority to Process)","NIST SP 800-53 PT-3 (Personally Identifiable Information Processing Purposes)","CIS Control 3 (Data Protection)","ISO\u002FIEC 27701 Section 7.2.1 (Identify and document purpose)","published","2026-08-11T14:20:23.370079+00:00","2026-08-11T14:20:23.064+00:00",{"id":7,"url":26,"slug":27,"title":28},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=DSB_(Austria)_-_2025-0.960.016&diff=52668&oldid=52645","dsb-austria-2025-0-960-016-065664","DSB (Austria) - 2025-0.960.016",[30,36],{"id":31,"name":32,"slug":33,"description":34,"color":35},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":37,"name":38,"slug":39,"description":40,"color":41},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]