In such a case, the GDPR comes to our aid.
The employer – the data controller of our personal data – is obliged to keep the information they have collected about you confidential. Is it only the employer who is bound by this obligation? Not at all. Anyone who has come to know our personal data in a professional capacity, such as information about our health status, should keep it secret.
Our origin, political views, religious beliefs, worldview, health status (both mental and physical), sexual orientation, etc., are referred to as sensitive data, which pertains to our private life. For this reason, the GDPR protects them in a special way – it prohibits their processing (with certain exceptions). Such data may only be processed by individuals who have written authorization from the employer to process them. They must keep the entrusted data confidential – they cannot share it, for example, with a colleague at work, nor after leaving the job.
Let us remember that sensitive data deeply intrudes into our privacy, and disclosing it to colleagues at work can lead to a multitude of consequences, such as negatively affecting the work atmosphere, adversely impacting the perception of the person whose data has been disclosed, becoming a reason for discrimination, or even leading to identity theft. For this reason, it is extremely important that sensitive data is adequately secured so that it does not fall into unauthorized hands.
It has happened – the data has been disclosed, everyone already knows, for example, what is ailing us. What now?
Once you realize that your data has leaked, in addition to your right to request explanations from the employer regarding this matter, you should inform the Data Protection Officer (DPO) who operates at the employer's premises. The Data Protection Officer is the person who assists the employer (the data controller of our data) in all matters related to personal data protection. They are also the contact person for employees regarding the processing of their personal data. The Data Protection Officer, among other things:
- will analyze our case and provide us with answers to our questions,
- will explain our rights under the GDPR,
- will advise us on what actions we should take,
- will verify compliance with personal data regulations at the employer's premises,
- when a data breach is detected, will recommend specific actions to the employer and then investigate whether they have been implemented.


