Datos de salud de empleados y confidencialidad en la empresa

Few types of processing cause so much trouble with so little data. Employee health data is a special category under Article 9 GDPR, and its regime is not resolved by a consent form signed on the first day of employment. It is resolved by knowing what the employer may know, what must never reach them, and who answers for each piece.

The rule is prohibition

Article 9(1) GDPR prohibits the processing of data concerning health. It may only be processed where one of the exceptions in Article 9(2) applies. Three are relevant in the employment context:

  • Article 9(2)(b): processing necessary for carrying out obligations and exercising rights in the field of employment and social security and social protection law, insofar as it is authorised by Union or Member State law or a collective agreement providing for appropriate safeguards.
  • Article 9(2)(h): preventive or occupational medicine, assessment of the working capacity of the employee and medical diagnosis, subject to the safeguards of paragraph 3 — that is, professional secrecy.
  • Article 9(2)(i): reasons of public interest in the area of public health.

Article 9 of the Spanish Data Protection Act adds two points worth keeping in mind. First: the data subject’s consent alone does not lift the prohibition where the main purpose of the processing is discriminatory. Second: processing under points (g), (h) and (i) grounded in Spanish law must be based on a provision having the force of law.

The practical consequence is blunt: the employee’s consent is the worst possible basis in this area. It does not work for what is prohibited, and it is not freely given in a relationship of subordination.

Fit or unfit: the line drawn by Article 22

Article 22 of the Spanish Occupational Risk Prevention Act is the provision most often breached without meaning to. It says two things.

First, health surveillance may only be carried out with the employee’s consent. That voluntary character admits exceptions only — and after a report from the workers’ representatives — where the examination is indispensable to assess the effects of working conditions on health, to verify whether the employee’s state of health may pose a danger to themselves or to others, or where a legal provision so establishes.

Second, and here is the line: access to personal medical information is limited to medical staff and the health authorities, and may not be provided to the employer without the employee’s express consent. The employer and those with prevention responsibilities are informed only of the conclusions as to fitness for the post and of any need to introduce or improve protective measures.

Fit, unfit, fit with restrictions. Never the diagnosis, never the test, never the reason.

Sick leave: what the employer may know

Since 1 April 2023, with the entry into force of Royal Decree 1060/2022 and its implementing order, employees no longer have to hand a copy of the sick note to their employer. The doctor gives it to the employee; the National Social Security Institute communicates to the employer the purely administrative identifying data of the leave, confirmation and discharge notes, at the latest on the following working day. The employer, in turn, transmits the corresponding data to the Institute within three working days.

The effect is precisely what the reform intended: the employer knows dates and administrative data, not the clinical contingency or the diagnosis. If someone in your organisation still files sick notes showing the reason for the absence, they are retaining data they should no longer be receiving.

Who is responsible for what

This is where documentation gets tangled most often. Where a company engages an external prevention service or a clinic to carry out examinations under its prevention plan, the healthcare centre performing the tests and generating clinical records acts as controller in respect of those records, because of the obligations that health legislation places on it. It is not a mere processor executing instructions.

That classification has consequences: signing a generic processing agreement and treating the matter as closed is not enough. What information flows in each direction must be set out in writing — and the information flowing to the employer must be limited to fitness.

What getting it wrong has cost

In December 2021 the Spanish Data Protection Agency imposed a fine of 50,000 euros on a construction company that disclosed to a third party the dates and reasons for an employee’s sick leave, for infringement of Articles 6 and 9 GDPR.

In another file, it fined 40,000 euros — reduced to 32,000 for voluntary payment — for a breach of the confidentiality principle in Article 5(1)(f): one employee’s medical report was scanned into another employee’s file and uploaded to the prevention service portal.

Look closely at the second case. There was no bad faith, no deliberate disclosure, no intent to harm. There was a scanning error. Health data has that characteristic: the most trivial administrative slip becomes a special-category infringement.

The review worth doing

  1. Check that no fitness certificate filed in HR contains a diagnosis or test results.
  2. Review who has access to the folders holding fitness certificates and sick notes, and cut that list to the minimum.
  3. Stop the practice of keeping sick notes showing a clinical reason.
  4. Document the allocation of roles with the prevention service and with the clinic.
  5. Record the health surveillance processing activity with its legal basis, retention period and recipients.
  6. Train whoever processes sick leave: they touch this data most often and usually have the least training.

None of those six points is expensive. All are easy to evidence if they are done, and impossible to improvise if they are not. It is part of what we review within our advice on data protection when we look at the employment side of a company.

0 replies

Leave a Reply

Want to join the discussion?
Feel free to contribute!

Leave a Reply

Your email address will not be published. Required fields are marked *