Data protection at the company medical service: What information can the company doctor share with the employer?

Last updated:
14.02.2023
Many employees are worried about being honest with their company doctor. What information are they actually allowed to share with your employer? We’ll clear things up.
Data protection at the company medical service: What information can the company doctor share with the employer?
Key Takeaways
  • Occupational physicians are subject to medical confidentiality in accordance with Section 8 (1) sentence 3 of the German Occupational Safety Act (ASiG).
  • Health data is highly protected and requires consent under Article 9 (2) of the GDPR.
  • Exceptions to confidentiality apply in cases of occupational diseases, notifiable diseases, and risks to third parties.
  • Occupational physicians may inform employers about fitness for work, but not about specific details without consent.
  • External occupational physicians are not considered data processors, and their files do not constitute personnel records.

The good news first: Occupational physicians are subject to medical confidentiality, just like any other doctor. The duty of confidentiality for occupational physicians is established in Section 8 (1) sentence 3 of the Occupational Safety Act. Occupational physicians are also liable to prosecution under Section 203 of the German Criminal Code (StGB) if they violate this duty. That is the simplified, short answer. However, there are exceptions to medical confidentiality regarding patient data, as an occupational physician has obligations that do not apply to a "regular" doctor.

What data is processed by occupational physicians?

To understand how your information is also protected under data protection law (i.e., not just through the doctor's duty of confidentiality), we must clarify what type of data is processed by doctors. The data you provide to your (occupational) physician is health data and, as a so-called "special category of personal data," enjoys an extra high level of protection because it is highly sensitive information.

The GDPR defines health data in Art. 4 (15) as "[...] personal data related to the physical or mental health of a natural person, including the provision of health care services, which reveal information about his or her health status."

As a special category of personal data, its processing is generally prohibited under Art. 9 (1) GDPR, unless a legal basis such as consent from the data subject under Art. 9 (2) (a) GDPR applies. It is therefore a "prohibition with the possibility of exemption." Another possible legal basis exists under Art. 9 (2) (h) in conjunction with Art. 88 GDPR and Section 22 (1) no. 1 (b) of the Federal Data Protection Act (BDSG) if the processing is "for the purpose of preventive medicine, for the assessment of the working capacity of the employee, for medical diagnosis, the provision of care or treatment in the health or social sector necessary for the management of health or social care systems and services, or pursuant to a contract between the data subject and a health professional.”

What are the duties of company doctors?

Company doctors have specific duties, for example, they must prevent risks to third parties in the workplace . Many employees view the company doctor as a kind of informant for their boss, but this is not the case. On the contrary, their main task is to protect employees from work-related physical and mental health issues. For instance, they are required to report to the employer if they believe workplace safety measures are inadequate, making them a key part of improving working conditions.

These specific duties also come with special rights. For example, company doctors have an exemption from confidentialityif:

  • … they have a well-founded suspicion of an occupational disease. In this case, they must notify the accident insurance provider, but not the employer.
  • … the employee is suffering from a notifiable disease. In this case, like any other doctor, they are permitted and required to report this information to the public health department.
  • … a risk to the life or physical safety of third parties in the workplace outweighs the employee's interest in confidentiality.
  • … they learn of a planned criminal act that endangers the health or life of third parties.

What rights do employees have when visiting a company doctor?

Employees have many rights under employee data protection laws. However, they also have obligations: while an employee generally does not have to consent to an examination requested by a company doctor, according to the BMAS and the BGW (Institution for Statutory Accident Insurance and Prevention in the Health and Welfare Services), the employee is not under an obligation to tolerate it, unless it involves mandatory examinations for risk assessment in the workplace, which only apply to certain professional groups.

A distinction must be made between preventive and fitness-for-work examinations. Preventive examinations are further subdivided into mandatory, offered, and requested check-ups. As the terms suggest, proof of mandatory preventive care is a prerequisite for an employee to perform their duties. This generally applies to preventive examinations for those in the nursing sector who are advised on vaccination options. Participation in offered and requested check-ups is voluntary, meaning the employee's consent must be obtained. If they provide their consent, the preventive care certificate from the company doctor may only contain the following information :

  • Reason for the check-up
  • Date of the examination
  • Medical assessment of when the next check-up would be appropriate

Fitness-for-work examinations are in some cases prescribed by law or regulation. In addition, the employer may, within the scope of their (ancillary) duty of care are entitled and obligated to order an occupational medical examination. In these cases, consent generally does not need to be obtained. Following a fitness-for-work examination, the company physician may only inform the employer whether the individual is fit, fit with restrictions, or unfit for a specific job task. The employer may only receive further information from the company physician if the employee has consented to this.

Sometimes, employers attempt to obtain a blanket waiver of medical confidentiality for the company physician as part of the employment contract. This is not permitted. Only a case-specific waiver of confidentiality by the employee is permissible.

What should employers know?

Only physicians who hold a certificate from the competent medical association confirming that they are entitled to use the specialist designation "Occupational Medicine" or the additional designation "Company Medicine" may be appointed as company physicians.

Contracting an external company physician does not constitute data processing on behalf of a controller under Art. 28 GDPR, but rather the utilization of external professional services from an independent controller. Therefore, the company physician's records are not employer documents and are not part of the personnel file. In the event of a change of company physician, the records must be stored securely (without the possibility of access by the employer or other unauthorized persons) and then transferred to the custody of the new physician. However, the new physician may also only access the records of their predecessor with the consent of the data subject .

For upcoming examinations, it may also be useful to involve the Data Protection Officer if one has been appointed. They can help you assess whether the specific examination is a mandatory requirement for performing your duties or not.

Is my employer allowed to ask about my vaccination status?

Do I have to inform my employer about my vaccination status? This is a tricky question, and the legal situation is constantly evolving – Proliance explains what is and isn't permitted when it comes to requesting vaccination status.

  • Employers may request vaccination status under specific circumstances.
  • Vaccination status is afforded special protection under Art. 9 (1) GDPR.
  • Section 26 (3) of the Federal Data Protection Act (BDSG) permits inquiries when there is a specific right to information.
  • Inquiries regarding vaccination status are only permitted in the healthcare sector.
  • Employees are not required to proactively disclose their vaccination status.

Do you have further questions on this topic? Our experts will be happy to advise you free of charge.

If you're looking for a partner to support you on your journey to data protection and information security, feel free to contact our team of experienced experts.
60+ Expertinnen und Experten
Book a consultation
Topics
Editorial
Alexander Ingelheim
Co-Founder & CEO
Alexander Ingelheim is Co-founder and CEO of Proliance. His driving force from day one has been to support companies with the hurdles and challenges of data protection and GDPR. He brings extensive experience from his work in international consulting, including positions at Bregal Unternehmerkapital GmbH and McKinsey & Company. He is also a certified Data Protection Officer (TÜV & DEKRA).
Zum Autorenprofil
Zum Expertenprofil
About Proliance
Proliance stands for Professional Compliance for businesses. We are a digitally driven Legal Tech company based in Munich, established in 2017 and now with over 90 privacy enthusiasts. Our more than 2,500 clients include start-ups, medium-sized businesses, and corporate groups from almost all industries.
About us
Latest Articles

Topics you might be interested in