The company social benefits fund consists of financial resources collected by the employer, intended to provide social support to individuals entitled to use the fund, namely employees of the given workplace, their families, as well as retirees, pensioners – former employees, and other individuals who may benefit from it under the regulations. By design, it aims to support those in less favorable situations, thereby, as far as possible, leveling their opportunities and providing financial assistance when needed. The forms of this assistance may vary, but the most common include holiday benefits, funding for cultural and educational activities, and material assistance (both financial and in-kind), for example, for an employee affected by a serious unforeseen event or a single parent raising children.
Receive a package of free GDPR guides and micro-trainings
Issues related to the processing of personal data within the framework of the company social benefits fund should be determined not only based on the GDPR itself but also in accordance with the Act on the Company Social Benefits Fund (Act of March 4, 1994, on company social benefits funds, consolidated text: Journal of Laws of 2019, item 1352), which was amended on May 4, 2019 (by the Act amending certain acts in connection with ensuring the application of Regulation 2016/679, i.e., the GDPR).
What changes occurred in the Act on the Company Social Benefits Fund as of May 4, 2019?
As previously mentioned, the allocation of funds from the Social Fund (ZFŚS) is dependent on the situation of the eligible person. While until now Article 8(2) of the ZFŚS Act also stipulated that "The rules and conditions for using services and benefits financed from the Fund (...) as well as the rules for allocating the Fund's resources for specific purposes and types of social activities are determined by the employer in the regulations," the amended act includes additional provisions. The following paragraphs have been added to Article 8:
- Article 8(1a) – the legislator defined the form of the declaration when providing the employer with information about the social situation of eligible persons, while maintaining the possibility of requesting documentation of personal data only to the extent necessary for its verification, particularly based on declarations and certificates regarding life circumstances (including health), family, and financial situation. Thus, employers are required to comply with the data minimization principle expressed in the GDPR, according to which data controllers should only collect data necessary for the purpose of processing. In this case, the legislator deemed that the necessary data will generally be the information declared by the employee (or another person applying for the benefit). The employer has been granted the right to verify the information provided by the employee – understood as a request to present documents confirming the information obtained from the employee, without the possibility of making copies/scans of them.
Example:
An employee applying for funding after the loss of a family member declares that the average income per family member is 800 PLN per month. The employer has the right to verify this information by requesting access to, for example, the PIT declaration and the death certificate.
- Article 8(1b) – the processing of personal data concerning health (i.e., special categories of data under Article 9(1) of the GDPR) within the framework of the ZFŚS may only be permitted for individuals who have written authorization to process such data, issued by the employer. These individuals are obliged to keep this data confidential. While until now the requirement to grant authorizations was indirectly derived from Article 29 of the GDPR (which pertains to the mere fact of allowing authorized persons to process data, rather than the official granting of written authorizations), the provisions of the ZFŚS Act now state this explicitly. As a point of interest, it can be noted that a similar obligation to grant authorizations is regulated in Article 221b § 3 of the Labor Code.
Example:
What should such authorization look like? For instance, the following paragraph can be added to the standard template for authorization to process personal data:
[YES/NO – choose the appropriate] I hereby additionally authorize you to process personal data concerning health, as referred to in Article 9(1) GDPR, in the context of handling applications for benefits from the company social benefits fund.
- Article 8(1c) – by adding this provision, the legislator specified the period during which the employer (as the data controller) may process data collected for the purposes of managing the social benefits fund. Namely, such data may be processed for the period necessary to grant the subsidized service and benefit, the subsidy from the social benefits fund, and to determine their amount, as well as for the period necessary to pursue rights or claims.
The period specified in the Social Benefits Fund Act necessary for pursuing claims should be understood as the time during which the tax authority (pension authority) may pursue claims related to the granting of benefits, i.e., 5 years from the end of the tax year in which the benefit was granted.
- Article 8(1d) – the last, but not least important, of the provisions added to Article 8 of the Social Benefits Fund Act imposes on the employer the obligation to annually (“no less than once a calendar year”) review the data processed within the social benefits fund and to delete data unnecessary for achieving the purpose specified in paragraphs 1a and 1c. It is recommended that the annual review of these documents be reflected in the data deletion policy or in the records of processing activities – we remind you that according to the principle of accountability, the data controller must be able to demonstrate compliance with data processing principles.
What is the legal basis for processing data within the social benefits fund?
In the author's opinion, the data of the person applying for funding, as well as the data of other individuals provided by them, including the data of their family members, will be processed by the data controller to fulfill the legal obligations imposed on them based on Article 6(1)(c) GDPR – in the context of managing the social benefits fund – and Article 9(2)(b) GDPR – in the context of special categories of data.
We would like to remind you that Article 3 of the Act on the Social Benefits Fund (ZFŚS) imposes an obligation on employers to establish a ZFŚS if, as of January 1 of a given year, they employ at least 50 employees in full-time equivalents or – regardless of the number of employees – if they operate as budgetary units or municipal budgetary establishments. Additionally, a ZFŚS may be established at the request of a workplace trade union if the number of employees is at least 20 and less than 50 in full-time equivalents.
What data can be processed within the framework of the ZFŚS?
Initially, the draft amendment to certain acts related to the implementation of the GDPR provided for a catalog of personal data of the entitled person (as well as their family members and persons living in the same household) that the employer may process in connection with the person's application for a subsidized service or benefit. This could include, among others, name, surname, date of birth, degree of kinship, and other data necessary to determine the life, family, and financial situation of the entitled person. However, this proposal ultimately did not hold – the Act on the ZFŚS does not specify the personal data that may be processed in connection with the operation of the ZFŚS. This issue has been left to the employer to regulate in the ZFŚS regulations.
The employer may specify in the ZFŚS regulations the documents that the applicant for the benefit may be asked to present for inspection (for example, tax declarations or birth/death certificates). We recommend that this list not be exhaustive, as it is difficult to predict all possible documents that will be necessary to confirm the life, family, and financial situation of the person applying for the benefit when drafting the regulations.
What should the employer include in the ZFŚS regulations?
What obligations arise for the employer in the process of adapting the Social Benefits Fund (ZFŚS) to the requirements of the GDPR and the amended Act on the Social Benefits Fund? First and foremost, the regulations of the ZFŚS must be supplemented with provisions regarding personal data. In principle, this will involve including a paragraph with a privacy notice directed to the person applying for the benefit and to third parties whose data has been obtained through the applicant for funding (which means that the information obligation should be fulfilled in accordance with the content of Article 14 of the GDPR).
The second issue is the verification of the application for a discounted service/benefit/subsidy from the ZFŚS in terms of the principle of data minimization. It should be structured in such a way that the employee (or another person applying for the benefit) only needs to fill in the relevant fields. This way, only the data necessary for processing the application will be collected – and nothing more.
Additionally, it is advisable to state in the regulations that, in principle, the data necessary for processing the application will be collected in the form of declarations from the employee (or another person applying for the benefit); however, the employer has the right to verify the submitted declarations and request access to documents that confirm the information provided by the employee. It should also be remembered that the retention period for data collected under the ZFŚS should be reflected in the data deletion procedure or another document based on which the organization deletes personal data after the purpose of processing personal data has ceased.
To whom may the data of individuals entitled to benefit from the ZFŚS be disclosed?
Do you like to keep order in GDPR?
So do we!
In the course of fulfilling the obligations arising from the operation of the Employee Social Benefits Fund (ZFŚS), the employer may share data obtained in this regard with external entities. For example, such data may be disclosed to entities authorized to receive it under legal provisions, such as the Social Insurance Institution (ZUS) or the tax office. Information about the data recipients should be included in the privacy notice, in accordance with Article 13 (or 14) of the GDPR.
Trade unions play a significant role in the process of providing benefits from the ZFŚS (Article 27(2) of the Trade Unions Act in conjunction with Article 8(2) of the ZFŚS Act). Primarily, the ZFŚS regulations must be consulted with the unions. Furthermore, the granting of benefits from the ZFŚS is also done in agreement with the trade union. In this situation, the trade union should be considered a recipient of personal data within the meaning of Article 4(9) of the GDPR, i.e., an entity to which the data is disclosed.
Summary
Recent changes to the ZFŚS Act are significant for the shape of the ZFŚS regulations and the manner of processing personal data collected within the framework of the ZFŚS. To adapt the process of managing the ZFŚS, the employer should primarily introduce appropriate changes to the regulations, verify the scope of data collected through the benefit application, ensure compliance with the information obligation towards the individuals whose data is processed, and also ensure that no data is processed in the organization for which the purpose of processing has ceased and which, according to the ZFŚS Act, should be deleted.
Do you want to clarify any doubts regarding the provisions of the GDPR? Contact Marcin Kuźniak. He will provide you with support and the necessary information.


