GDPR in HR – Focus on Poland: What Employers Can Know About Employees?

HR departments process much more than just names and contact details. Their responsibilities often include handling health information, education records, family circumstances and employment history. Improper handling of such data can result in serious privacy violations and legal consequences.

Compliance requires more than just valid consents or information clauses. It involves full implementation of key GDPR principles: accountability, data minimisation, purpose limitation and data security.

Contents:

Employees and GDPR – What Kind of Data Can Be Collected According to Polish Law?

Should an employer know everything about their employees? Definitely not. The data an employer in Poland is legally allowed to collect is clearly defined in Article 22(1) §1 and §3 of the Polish Labour Code. This includes name, surname, PESEL number, contact information, education, and employment history.

Collecting any other information—such as family situation, hobbies, or health preferences—requires a specific legal basis. If the Labour Code doesn’t provide one, GDPR’s six lawful bases for processing must apply (Article 6):

  • consent of the data subject
  • performance of a contract
  • compliance with a legal obligation
  • protection of vital interests
  • public interest task
  • legitimate interest of the controller

Even with good intentions—such as trying to better understand the team—employers must be careful. Instead of asking “Can I know this?”, a better question is “Do I need to know this?”.

Every processing activity needs a clear legal basis, whether from the Labour Code or GDPR. Responsible data processing shows not only compliance, but also respect for employee privacy.

Consent is often seen as the safest legal basis, but it should be used only when no other legal ground applies. It’s not meant to be a fallback or a routine solution.

Consent must be freely given and can be withdrawn at any time. Once withdrawn, any continued processing becomes unlawful. That’s why organisations need clear procedures and tools to handle such changes efficiently.

In many HR and recruitment situations, consent isn’t required. For example, sending a CV is considered a clear expression of interest in a job, so consent isn’t necessary to process that data for recruitment purposes.

However, if a company wants to retain CVs for future opportunities, that’s a new purpose, so consent becomes necessary.

Employee image – when can it be used?

An image is personal data, and its use requires caution. A few examples:

  • Photo on an employee badge: Requires voluntary consent. Since it’s not included in the Labour Code’s standard data set, the employee must agree to its use.
  • Security staff ID: In this case, a separate law (Act on the Protection of Persons and Property) requires a photo for identification. Consent isn’t needed.

Consent can be withdrawn at any time and can’t affect the employee’s position. That’s why using consent when another legal ground exists (like a statutory requirement) can create serious problems.

Always verify whether consent is necessary. If it’s not, don’t use it.

Website, events, business cards – where are the traps?

Publishing an employee’s photo on the company website or in marketing materials requires their consent. Being employed by the company doesn’t automatically allow public use of their image.

The same rule applies to photos from events. Even if someone posts a photo on their personal profile, it doesn’t mean the company can reuse it on official platforms.

Transparency and respect matter. Asking for consent isn’t just about following the law. It builds trust and creates a safer workplace culture.

Digital “delete” – how to effectively erase data from electronic systems?

In a digital world, deleting data doesn’t always mean it’s gone. “Delete” often just removes it from view, not from backups, logs, or storage.

GDPR requires that personal data be effectively and permanently erased when no longer needed. Companies must be able to prove this, for example, through anonymisation or secure deletion procedures.

This means having policies and tools in place to ensure data is removed from all environments: live systems, backups, cloud storage, and logs.

Regular reviews and tests of the deletion process help ensure compliance, and offer real protection for data subjects.

Human error – the weakest link in data security

Even the best IT systems can’t protect data if employees don’t know how to use them safely. Human error remains the biggest vulnerability in any security strategy.

That’s why it’s critical to provide:

  • regular employee training
  • clear internal procedures
  • well-defined access rights
  • ongoing monitoring and audits

Want to avoid mistakes and improve personal data security in your company?
Contact with us and our partner Omni Modo and learn how to effectively train your HR team in data protection.

Contact:

Rafał Nadolny
MD Poland,
Partner

Daniela Zsigmond
MD Romania,
Partner

Tamás Kovács
MD Hungary,
Partner


Related content