SOCIAL HOUSING UPDATE

DECEMBER 2019



Another GDPR fine and important considerations for housing associations

by Eugene Wojciechowski

A recent decision of the Hellenic Data Protection Agency (HDPA), the Greek equivalent of the Information Commissioner’s Office (ICO) confirms that employers who seek to rely on employee consent as the basis for processing employee data risk being in breach of the GDPR, and potentially liable to fines and enforcement action.


Personal data must be processed in accordance with one or more of the conditions for processing, and in line with the data protection principles, including transparency, fairness and accountability.  Although consent is one of several potential processing conditions, it is problematic for employers, because where there is an imbalance of power between the data controller (employer) and data subject (employee), consent may not be able to be freely given, and might cause difficulties if withdrawn.  Employers, however, can rely on other legitimate conditions for processing employee data, such as it being necessary for the performance of the employment contract, being processed in compliance with legal obligations, and/or being necessary for the legitimate interests of the data controller (in the private sector: slightly different rules apply for public authorities).  The ICO has already made its position clear on this front and since the inception of the GDPR employers have been advised not to use consent as the basis for processing employee data.


In this case, the Big Four consultancy firm, PwC was held to have breached its GDPR obligations and received a fine of 150,000 Euros.  It relied on employee consent in order to process employee data, and asked employees to sign their agreement to this effect.  Although PwC could have processed the data lawfully, on the grounds suggested above, it was held to have given employees a false impression as to the basis of processing their data, and violated the principles of accountability and transparency.


Housing employers should check what information is given to employees about the basis for processing their data and update their privacy notices and employment contracts and/or handbooks to reflect the true reasons for processing, if consent is relied on, either solely or as a “sweep up” reason.


Finally – a brief update on time limits for responding to data subject access requests.  The ICO has clarified that the “one month” for responding to a request should be counted from the date of receipt of the request, rather than the following day (which had previously been their position): eg a request made on 3 September needs to be responded to by 3 October.  Ideally requests should be dealt with as expeditiously as possible, but housing employers should be aware that there is now slightly less time to comply.

 

Contact Eugene Wojciechowski

KEY CONTACTS

RELATED LINKS

Expertise


Meet the team

 

News & publications

 

USEFUL RESOURCES

VIEW our privacy policy for details on how we handle your personal data

 

OUR OFFICES


London

Basingstoke

Birmingham

Cambridge

Guildford

Oxford

 

Reading

Madrid

Paris

Piraeus

San Francisco

São Paulo 

Singapore 

Penningtons Manches Cooper LLP is a limited liability partnership registered in England and Wales (Registered No. OC311575) and authorised and regulated by the Solicitors Regulation Authority. References to ‘partner’ include members and employees/consultants of equivalent standing within the LLP and its associated undertakings or businesses operating overseas.  A list of the members is open to inspection at its registered office, 125 Wood Street, London, EC2V 7AW.


You can read the full text about your rights as a data subject and our data privacy statement on our website at www.penningtonslaw.com/privacy-policy.

To view our privacy policy, please click here.