GDPR questions and answers

GDPR: QUESTIONS AND ANSWERS

Category:
GDPR at Work

Can information about one employee's pay reduction be disclosed to other employees in the company?

ANSWER

Whether a personal data breach within the meaning of Article 4(12) GDPR — understood as disclosure of personal data to an unauthorised person — occurred in the case described will depend on whether the person indicated — the direct supervisor — is authorised by the data controller (employer) to process this scope of personal data. If the supervisor's authorisation under Article 29 GDPR also covers employees' personal data relating to remuneration, there will be no personal data breach, as the person is authorised to access those data. If, however, the authorisation does not cover this scope, it may be considered that such a breach occurred. It is therefore necessary to determine the scope of the supervisor's authorisation in order to establish whether a personal data breach occurred.

Read also:

Receive a free package of 4 tutorials and 4 e-learning trainings
The controller of your data is ODO 24 sp. z o. o.
Disclosing pay information within a company — GDPR | ODO 24 | ODO 24