U.S. companies with employees located in the European Union (EU) need to ensure their policies are in compliance with EU privacy laws.
This article explains what U.S. employers need to know to protect EU employee rights, including what the EU's main privacy law requires and a list of practical compliance tips.
- 1. What Is the Main Privacy Law That Protects EU Employees?
- 1.1. What Does the GDPR Require from U.S. businesses?
- 2. What Happens When U.S. Employer Policies Clash with EU Employee Rights?
- 3. How U.S. Employers Can Comply With the GDPR
- 3.1. 1. Create a Data Map
- 3.2. 2. Choose a Legal Basis (or Bases) for Processing Employee Data
- 3.3. 3. Notify Employees Before Processing Their Data
- 3.4. 4. Protect EU Employee Data When Transferring Data to the U.S.
- 3.4.1. GDPR Record-Keeping Requirements
- 3.4.2. GDPR Data Breach Notification Requirements
- 3.5. 5. Provide a Way for Employees to Exercise Their Rights
- 3.6. 6. Conduct a Data Protection Impact Assessment (DPIA)
- 3.7. 7. Establish a Data Processing Agreement (DPA) With Third Parties
- 3.8. 8. Appoint a Data Protection Officer (DPO)
- 3.9. 9. Assign an EU Representative
- 4. Summary
What Is the Main Privacy Law That Protects EU Employees?
The General Data Protection Regulation (GDPR) is the EU's primary privacy law. It protects personal data belonging to individuals located in the EU.
Personal data is defined by the GDPR as information that can be used–directly or indirectly–to identify an individual, such as names, Social Security numbers, location data, and usernames.
Article 4 of the GDPR includes names, ID numbers, and location data in its definition of personal data.
The GDPR applies to:
- Organizations that collect or process (use) EU individuals' personal data
- Organizations operating outside of the EU that offer goods or services to EU individuals
- Organizations based outside of the EU that monitor EU individuals' behavior
Employees located in the EU are considered data subjects (people to whom personal data belongs) and are afforded the same rights under the GDPR as non-employees.
The GDPR gives data subjects (including employees) the following rights:
- The right to know what data is collected about them and why, how long the data is retained, and whether it is shared with third parties
- The right to access their personal data
- The right to correct their personal data
- The right to delete their personal data
- The right to restrict processing
- The right to data portability
- The right to object to data processing
- The right to not be subject to automated decision-making (including profiling)
What Does the GDPR Require from U.S. businesses?
U.S. businesses that process data belonging to EU employees must comply with the GDPR's requirements, including the following:
- Have a legitimate basis (or bases) for processing personal data
- Inform individuals about their data processing activities
- Provide a way for data subjects to exercise their rights
- Minimize data–only use it for stated purposes and limit your retention period to what is necessary to fulfill your purposes
- Appoint a Data Protection Officer (DPO) if required
- Keep data secure
- Maintain a Data Processing Agreement (DPA) with third-party data processors
- Assign an EU representative
- Ensure cross-border data transfers are adequately protected
Article 5 of the GDPR explains that personal data must be processed in a manner that is lawful, fair, and transparent, and that processing must be limited to fulfilling specified and legitimate purposes, among other requirements.
What Happens When U.S. Employer Policies Clash with EU Employee Rights?
If U.S. employers with EU employees don't respect EU employee privacy rights, they can face significant fines and public scrutiny.
Let's look at some examples of what can happen when U.S. employers violate the GDPR.
On December 27, 2023, the French Data Protection Authority (CNIL) fined Amazon €32 million for breaching the GDPR. Amazon had required its French warehouse employees to document their tasks via a handheld scanner as a way to monitor their productivity.
CNIL determined that this system was excessive, in part because the scanners tracked periods of inactivity, requiring workers to justify breaks and interruptions, and the data and statistical indicators were retained for 31 days, violating the GDPR's data minimization and lawful processing principles.
Another example of when a U.S. company violated the GDPR was when Uber transferred its EU drivers' sensitive information, such as taxi licenses, location data, ID documents, and criminal and medical data, to U.S. servers without implementing appropriate safeguards.
The Dutch Data Protection Authority (DPA) claimed that Uber violated the GDPR, and imposed a fine of €290 million on Uber.
As these examples show, violating the GDPR can result in massive fines, not to mention damage to your company's reputation.
Next, we'll look at how U.S. employers can avoid penalties and loss of credibility by taking practical steps to comply with the GDPR.
How U.S. Employers Can Comply With the GDPR
If your business is based in the U.S. and you have EU employees, these ten steps can help you comply with the GDPR.
1. Create a Data Map
It's important to understand what EU employee data you intend to process, transfer, store, and disclose to third parties in order to comply with GDPR notification and security requirements.
A data map can be used to identify what types of personal data you collect and process from EU employees and show how data flows through your business.
A data map that contains the following information can help you comply with the GDPR:
- The categories of personal data you collect
- Your data processing activities
- Your reasons for processing personal data
- How you transfer and store data
- How long you retain data
- How you keep data secure
Smaller businesses may be able to use a simple spreadsheet to map data; larger organizations can benefit from data-mapping software that automates the process.
2. Choose a Legal Basis (or Bases) for Processing Employee Data
You need to have a legal basis (or bases) for processing personal data belonging to EU employees.
The GDPR's six legal bases are as follows:
- Consent. The data subject consents to the processing of their data for a specific reason.
- Contract. The processing is necessary to fulfill a data subject's request in relation to preparing a contract or to carry out a contract.
- Legal obligation. The processing is required by law.
- Vital interests. The processing is necessary to protect someone's life.
- Public interest. The processing is necessary to carry out a task in the public interest or to exercise official authority.
- Legitimate interests. The processing is necessary to fulfill a party's legitimate interests–as long as the data subject's rights and freedoms don't override those interests.
Article 6 of the GDPR lists the six legal bases applicable organizations must choose from before processing personal data, including consent, contract, and legitimate interests.
Many businesses may be used to asking for consent before processing personal data, but consent isn't the best choice under the GDPR due to the power imbalance between employer and employee.
Relying on legitimate interests or a contractual basis for processing personal data is a better bet under the GDPR.
3. Notify Employees Before Processing Their Data
Whether you're sharing employee data with a third-party paycheck processor or monitoring employee behavior, it's essential that you notify EU employees before processing their personal data.
One way you can do this is by creating an accessible Privacy Policy that describes how you handle personal data and how EU employees can exercise their privacy rights. You will need to ensure that EU employees have access to your Privacy Policy at the point of data collection.
A GDPR-compliant Privacy Policy should contain the following clauses:
- The data controller's (individual who makes decisions about how or why to process personal data), representative's, and DPO's identity and contact information
- The reasons for processing personal data
- The legal basis for processing personal data and, if the processing is based on legitimate interests, the legitimate interests of the controller or a third party
- The categories of third parties personal data is disclosed to
- Whether the controller will transfer personal data to a third country or international organization and the safeguards taken
- Whether automated decision-making or profiling is involved in the data processing, as well as potential consequences
The table of contents of Airbnb's Privacy Policy contains clauses about the types of personal information it collects, how it uses, shares, and discloses data, and individuals' privacy rights, among others.
4. Protect EU Employee Data When Transferring Data to the U.S.
While the GDPR requires that organizations take steps to protect all data they collect and process, special care must be taken with personal data transferred to the U.S.
You can transfer EU employee data to the U.S. if your business is in the Data Privacy Framework list, a public list of U.S. companies that have committed to comply with the EU-U.S. Data Privacy Framework.
If your company is not in the Data Privacy Framework list, then you will need to use certain transfer tools, such as standard data protection clauses and binding corporate rules, to ensure the security of EU employees' personal information when transferring their data to the U.S. You must ensure that EU data subjects have enforceable rights and effective legal remedies.
The EU-U.S. Data Privacy Framework enables companies to transfer personal data between the EU and the U.S. It replaced the EU-U.S. Privacy Shield in 2023. The EU-U.S. Privacy Shield was invalidated in the Court of Justice of the European Union (CJEU) Schrems II ruling in 2020, when the court found that the framework didn't adequately protect EU users' personal data from access by U.S. authorities.
Standard Contractual Clauses (SCCs) and Binding Corporate Rules (BCRs) are now the primary tools used to transfer personal data between the EU and the U.S. under the EU-U.S. Data Privacy Framework.
SCCs are pre-approved legal contracts issued by the European Commission that businesses can use to transfer data from the EU to the U.S.
BCRs are legally enforceable data protection policies that multinational companies can implement to ensure compliance with the GDPR when conducting data transfers internally. The supervisory authority can approve a BCR as long as it is legally binding and enforceable, grants enforceable rights to data subjects, and fulfills the GDPR's requirements.
Article 47 of the GDPR lists the criteria BCRs must meet in order to be approved by a supervisory authority, including providing enforceable rights to data subjects concerning the processing of their personal data.
If you transfer data between the EU and the U.S. based on SCCs or BCRs, you must ensure that the data subject receives essentially equivalent protection as provided by the GDPR and the EU Charter of Fundamental Rights (CFR). You may need to take additional steps–such as encrypting data or restricting access to personal data–to make up for lacunae (gaps) in U.S. privacy laws.
Article 46 of the GDPR explains that personal data can be transferred from the EU to the U.S. as long as appropriate safeguards have been implemented, such as legally binding contracts and standard data protection clauses.
You should also be aware of the GDPR's record-keeping and breach notification requirements.
GDPR Record-Keeping Requirements
The GDPR requires data controllers and their representatives to maintain a record of their data processing activities.
Data processing records should contain the following information:
- The names and contact information of the data controller, and, if applicable, the joint controller, representative, and the DPO
- The reasons for processing data
- The categories of data subjects and personal data
- Any third parties that will receive or have received personal data (including those located in third countries and international organizations)
- A description of transfers of personal data to third countries or international organizations that includes the identification of the recipient and the safeguards that will be implemented
- The retention period for different categories of personal data
- A description of the technical and organizational security measures used to protect personal data
You will need to provide this record upon request by a supervisory authority.
Organizations with fewer than 250 employees are not obligated to comply with this requirement, unless they engage in high-risk data processing activities, the data processing is carried out on a regular basis, or they process special categories of data or personal data related to criminal convictions or offenses.
Article 30 of the GDPR lists the information a data processing record should contain, including documentation of your purposes for processing personal data and the categories of data subjects and personal data involved in the processing.
GDPR Data Breach Notification Requirements
If you are subject to the GDPR, you will need to have a process in place for notifying employees if their personal data is affected by a data breach.
A data breach in the context of protected employee data is when an unauthorized individual or entity accesses an employee's personal data. A data breach can occur intentionally–in the case of hacking or theft of a device containing confidential information–or unintentionally, such as if someone accidentally sends an email containing sensitive information to the wrong recipient.
If a data breach occurs and it is likely to result in a risk to your employees' rights and freedoms, you'll need to notify the supervisory authority of the breach within 72 hours of becoming aware of the unauthorized access.
The notification needs to contain the following information:
- The nature of the data breach, including the categories and approximate number of data subjects and personal data records concerned
- The name and contact information of the DPO
- The likely consequences of the data breach
- What you will do to address the breach and mitigate potential negative effects
Article 33 of the GDPR lists the information a personal data breach notification should contain, including the nature of the data breach and the DPO's contact details.
5. Provide a Way for Employees to Exercise Their Rights
The GDPR requires applicable organizations to give data subjects a way to exercise their rights. You must respond to EU employees' privacy requests within one month of receiving a request but can extend the response period by an additional two months if necessary (as long as you inform the employee of your reason for the extension).
Airbnb enables users to exercise their rights via its How to exercise your data subject rights, which explains how data subjects can access their data, object to processing, and opt out of receiving marketing communications, among other actions.
Article 12 of the GDPR states that data controllers must respond to data subjects' privacy requests within one month of receipt of a request.
6. Conduct a Data Protection Impact Assessment (DPIA)
The GDPR requires data controllers to conduct a DPIA if their data processing uses new technologies or poses a high risk to data subjects' rights and freedoms. Examples of data processing that require a DPIA include tracking employees' location or behavior or processing special categories of data (such as employees' race, ethnicity, biometric data, or health information).
Data processing activities that specifically require a DPIA include those that involve:
- The systematic evaluation of data subjects' information based on automated processing (including profiling)
- Large-scale processing of special categories of data or personal data related to criminal convictions and offenses
- Large-scale, systematic monitoring of publicly accessible areas
A DPIA should contain the following information:
- A description of the data processing activities
- The reasons for the processing
- The controller's legitimate interest (if applicable)
- An assessment of the necessity and proportionality of the data processing activities
- An assessment of the risks to the data subjects' rights and freedoms
- What security measures will be taken to address those risks and protect data subjects' personal data
You can use the United Kingdom (UK) Information Commissioner Office's sample DPIA template as an example of how to create a DPIA.
7. Establish a Data Processing Agreement (DPA) With Third Parties
The GDPR requires data controllers to sign an agreement with any parties that process personal data on their behalf.
A data processing agreement (DPA) is a contract that explains the rights and responsibilities of controllers and processors.
To comply with the GDPR, your DPA must include the following information:
- The processor agrees to process personal data in accordance with the controller's written instructions.
- All individuals who handle personal data agree to keep the data confidential.
- Technical and organizational security measures are implemented to keep personal data safe.
- The processor won't subcontract unless requested in writing to do so by the controller. In that case, the subprocessor will need to sign a separate DPA.
- The processor will help the controller maintain compliance with the GDPR, especially in regard to data subjects' privacy rights.
- The processor agrees to delete or return personal data to the controller when the services end.
- The processor will allow the controller to conduct audits and will provide requested information as needed.
Article 28 of the GDPR explains that controllers must enter into a legally binding contract with third parties who process personal data on their behalf.
You can use GDPR.eu's Data Processing Agreement template to help you create a GDPR-compliant DPA.
8. Appoint a Data Protection Officer (DPO)
A DPO is an individual who is highly knowledgeable about data protection law and best practices.
A DPO is responsible for fulfilling the following tasks:
- Advises the data controller or processor and staff who carry out processing activities about how to comply with the GDPR and other relevant data protection laws
- Monitors compliance with applicable data protection laws
- Conducts audits of data processing operations
- Serves as the point of contact for the supervisory authority
Businesses that meet the following criteria must appoint a DPO to comply with the GDPR:
- The data processing is carried out by a public authority (except for courts operating in a judicial role)
- The business's core activities consist of data processing that requires large-scale, ongoing, and systematic monitoring of data subjects or
- The business's core activities involve large-scale processing of special categories of data (such as health or biometric data) or data related to criminal convictions and offenses
Article 37 of the GDPR describes the conditions under which organizations must assign a DPO, including if the organization is a public authority or body (other than courts) or if the organization's core activities involve large-scale monitoring of data subjects or processing of special category data.
9. Assign an EU Representative
Unless they meet exemption criteria, companies that are based outside of the EU and offer goods or services to individuals located in the EU or track EU data subjects' behavior are required by the GDPR to have a representative located within the EU.
However, companies are exempt from this requirement if they are a public authority or body or if their data processing is occasional, doesn't involve large-scale processing of special categories of data or personal data related to criminal convictions or offenses, and isn't likely to risk data subjects' rights and freedoms.
Article 27 of the GDPR explains that organizations outside of the EU that meet its criteria are required to appoint a representative in one of the Member States where their data subjects are located.
Summary
The GDPR is the EU's main privacy law. It protects personal data belonging to EU data subjects, including employees located in the EU.
The GDPR requires employers who process EU employees' personal data to take steps to comply with the law, including determining a legal basis for processing data, notifying employees before processing their data, and honoring their privacy rights.
U.S. employer policies that could clash with EU employee rights include employee monitoring, getting consent to process employees' personal data instead of relying on a more appropriate legal basis, and not using adequate safeguards when transferring data to the U.S.
U.S. employers with EU employees can comply with the GDPR by:
- Creating a data map
- Choosing an appropriate legal basis (or bases) for processing EU employee data
- Notifying employees before collecting or processing their data
- Protecting employee data
- Implementing safeguards to protect data that is transferred to the US
- Maintaining a clearly written, easily accessible, and up-to-date Privacy Policy
- Providing a way for EU employees to exercise their privacy rights
- Conducting a DPIA
- Maintaining a Data Processing Agreement with third parties
- Appointing a DPO
- Assigning an EU representative
The first step to compliance: A Privacy Policy.
Stay compliant with our agreements, policies, and consent banners — everything you need, all in one place.