The central - and probably most well-known - norm in German employee data protection law is Section 26 German Dazta Protection Act (BDSG). According to Section 26 (1) BDSG, personal data may be processed if this is necessary for the establishment, implementation or termination of an employment relationship or for the exercise or fulfillment of other rights and obligations under employment law. With this standard, the German legislator has made use of the opening clause of Article 88 (1) GDPR and thus of the possibility of establishing more specific regulations for employee data protection, which are intended to take into account the national particularities of working life. The European Court of Justice (ECJ) has now put Section 26 (1) BDSG to the test and ruled on March 30, 2023 (Case C-34/21) that this standard does not meet the requirements of the GDPR and is therefore no longer applicable.
What happened?
The case occurred in the context of the Corona pandemic: Hessian students who were unable to attend classes in person due to the Corona pandemic were given the opportunity to follow the lessons via video conference. To ensure that this was done in compliance with data protection regulations, parents were asked to give their consent to the associated data processing - but not the teachers concerned.
In this respect, the Hessian Minister of Education based the processing of personal data on the legal basis of Section 23 (1) sentence 1 HDSIG, a state law provision which...
Read Full Story:
https://news.google.com/rss/articles/CBMiU2h0dHBzOi8vd3d3LmxleG9sb2d5LmNvbS9s...