Tricky topic: staff scheduling and data privacy? This trick keeps posting your shift plans compliant

Last updated:
21.06.2022
Data protection and staff scheduling can be a tricky combination: as a general rule, duty rosters containing full names may no longer be posted in the workplace. However, there are simple ways to ensure that schedules remain accessible to all employees.
Tricky topic: staff scheduling and data privacy? This trick keeps posting your shift plans compliant
Key Takeaways
  • Duty rosters containing full names must not be posted openly in the workplace.
  • Duty rosters contain personal data that is protected under the GDPR.
  • Anonymized or pseudonymized duty rosters may continue to be posted.
  • Employee consent still allows for duty rosters to be posted.
  • Duty rosters may only be posted in areas accessible to employees.

Erkan is working with Ursula Schicht, Tanja is on vacation, and Martin is sick again? These and many other details can be found on staff rosters. These rosters contain personal data as defined by Article 4(1) of the GDPR, which, from a data protection perspective, can no longer simply be posted for everyone to see. However, you do not have to stop posting staff rosters if you follow the appropriate rules. We have compiled an overview of what is permitted under data protection law regarding staff rosters and how you can most easily implement these requirements.

Posting staff rosters – does data protection get in the way?

A look at the staff roster is very revealing, and not just regarding shift times. It often contains other personal data, such as absences, vacation periods, or dates of birth. One of the fundamental principles of the General Data Protection Regulation (GDPR) is data minimization. This means that not every employee needs—or is allowed—to know when and how often someone is working, on vacation, or sick. Since all this information is usually found on a staff roster, it is no longer permissible to post them openly or make them available online to everyone. It is obvious that this causes problems for many employees in practice, as they no longer know who they are working with or who they might be able to swap shifts with.

Publishing staff rosters: Are they subject to data protection?

Staff rosters and the data they contain are subject to data protection if they involve personal data. It is important to know that, legally speaking, employees have no right to view the entire staff roster of all employees. For example, the reason for someone's absence or the duration of a colleague's vacation must not be disclosed to all other employees via a roster. Nevertheless, staff rosters are essential for the smooth operation of many companies and facilities. Citing the Bavarian State Office for Data Protection Supervision (BayLDA), the view is (partially) held that viewing staff rosters is "in itself only necessary for those employees who are directly affected and rely on the information." The challenge is to find a practical compromise between the requirements of data protection authorities and the demands of everyday work. We have several suggestions for how you can implement data protection and staff rosters in practice.

How to handle staff rosters and data protection in your daily work

Companies can continue to post staff rosters if they keep data protection in mind:

  • Anonymized or pseudonymized staff rosters: Staff and shift rosters can continue to be posted openly and published digitally if they are anonymized or pseudonymized. This could be implemented, for example, by assigning each employee a symbol known only to them, which is then used in the shift plan instead of their name. Third parties cannot make sense of this information, but the affected employees are informed. 
  • Obtaining consent: Staff rosters with real names may continue to be posted (only) in staff rooms (areas to which no unauthorized persons have access) and sent online to the relevant employees if those employees have been informed in advance and have provided written consent. This is only possible with the explicit consent of the affected employees; if an employee does not consent to the publication, this must be respected accordingly.
  • Works agreements: Large companies or facilities in particular can conclude works agreements regarding the posting of staff rosters. It is advisable to work closely with the works council to ensure their right of co-determination is upheld.

Important: Even when all the aforementioned measures are taken, staff rosters must not be photographed or copied. According to the BayLDA, it is also impermissible for "staff rosters to be posted in areas where external parties, such as customers or suppliers, or in hospitals, patients, in nursing homes, residents, or in daycare centers, parents of the children, can become aware of the content of the plans." In short: third parties must not be able to view staff rosters. It is therefore advisable to place staff rosters only in rooms accessible to employees, such as the staff break room. However, care must be taken to ensure that the rosters do not contain reasons for absence. If you are unsure how to reconcile the design of staff rosters with data protection, we are happy to help. Contact us no obligation!

Do you have further questions on this topic? Our experts will be happy to advise you free of charge.

If you're looking for a partner to support you on your journey to data protection and information security, feel free to contact our team of experienced experts.
60+ Expertinnen und Experten
Book a consultation
Topics
Editorial
Alexander Ingelheim
Co-Founder & CEO
Alexander Ingelheim is Co-founder and CEO of Proliance. His driving force from day one has been to support companies with the hurdles and challenges of data protection and GDPR. He brings extensive experience from his work in international consulting, including positions at Bregal Unternehmerkapital GmbH and McKinsey & Company. He is also a certified Data Protection Officer (TÜV & DEKRA).
Zum Autorenprofil
Zum Expertenprofil
About Proliance
Proliance stands for Professional Compliance for businesses. We are a digitally driven Legal Tech company based in Munich, established in 2017 and now with over 90 privacy enthusiasts. Our more than 2,500 clients include start-ups, medium-sized businesses, and corporate groups from almost all industries.
About us
Latest Articles

Topics you might be interested in