(69) Even if personal data can be processed lawfully, when the processing is necessary for the performance of a task carried out in the public interest or in the exercise of public authority vested in the controller, or due to legitimate interests of the controller or a third party, any data subject should have the right to object to the processing of personal data concerning his or her particular situation. It should be the controller's responsibility to demonstrate that the controller's important legitimate interests override the interests or fundamental rights and freedoms of the data subject
„GDPR covers one of our employees, it's just a few documents"
Are you sure about that?

