Skip to content

GDPR compliant processing of employee health data

Processing employees’ health data is permitted only under strict GDPR conditions, and employers must establish a lawful purpose and legal basis for the processing. For example, recording sick leave generally does not require access to a diagnosis, while a workplace accident may justify more detailed information. The article explains data minimisation, access controls, retention periods and the limited role of employee consent.

Professional discussing GDPR-compliant processing of employee health data.

Key takeaways

The processing of employees' health data is strictly prohibited. Employers may not collect information about illnesses or diagnoses unless they have a clear legal basis and a legal title that meets the conditions of both Article 6 and Article 9 of the GDPR.
To process health data, you need a dual legal basis. In addition to a general legal basis under Article 6 of the GDPR (e.g., compliance with a legal obligation), you must also meet a special condition for sensitive data under Article 9 of the GDPR, which permits the processing of this strictly protected data.
Recording sick leave is legal, but only for specific purposes. An employer may process health data if it is necessary for fulfilling obligations in the field of employment law and occupational health and safety, for example, to record temporary incapacity for work for the purpose of paying sickness benefits.
Medical examinations and assessments are permitted to evaluate fitness for work. An employer may process data from medical examinations, reports on fitness for work, or test results if they are necessary to assess an employee's medical fitness to perform their job.
ARROWS law firm

Key Legal Requirements

The General Data Protection Regulation (GDPR) prohibits the processing of special categories of personal data, which includes data concerning the health of a natural person, unless one of the exceptions specified directly in the regulation is met.

In other words, an employer may not collect or record information about an employee's illnesses, diagnoses, or disabilities unless there is a clear legal reason and a corresponding legal basis for doing so. In addition to the general processing principles (such as lawfulness, fairness, data minimisation, etc.), the employer must therefore meet two levels of conditions for any processing of health data:

1. An "ordinary" legal basis under Article 6 of the GDPR:

There must be one of the grounds for processing that the GDPR recognises for personal data in general (e.g., performance of a legal obligation, legitimate interest, or, exceptionally, the data subject's consent, etc.).

2. An exception for sensitive data under Article 9 of the GDPR:

In addition to the standard legal basis, a special condition must also be met that permits the processing of health data. The GDPR protects such data more strictly – it is a priori prohibited unless the controller can demonstrate that it falls under one of the exhaustively listed exceptions (e.g., processing is necessary for the purposes of healthcare, employment law obligations, etc.).

Typical exceptions that allow an employer to legally process an employee's health data include:

1. Fulfilling obligations in the field of employment law and OHS: 

If the processing of health data is required by a special law or is necessary for the employer to fulfil an obligation under the Czech Labour Code or social security regulations. This includes, for example, recording temporary incapacity for work for the purpose of paying sickness benefits, keeping records of work-related accidents or occupational diseases, etc.

2. Preventive and occupational medical care: 

Data from medical examinations, medical fitness for work assessments, or test results, if they are necessary to assess an employee's fitness for work. This data may generally be processed by an occupational health service provider or another healthcare professional bound by professional secrecy. The employer should only receive the conclusion about fitness ("fit/unfit for work"), not detailed diagnoses.

3. Protection of vital interests: 

For example, providing health information in a situation where it is a matter of saving the life or health of an employee or another person and the employee is unable to give consent (typically an acute medical intervention at the workplace).

4. Public interest in the area of public health: 

Extraordinary situations such as epidemics may justify certain processing – e.g., temperature checks, recording of infectious disease test results, etc., if it is in the interest of protecting public health and is based on legal regulations or the employer's legitimate interest in fulfilling its duty to ensure a safe working environment.

5. Explicit consent of the employee:

Only exceptionally, if no other legal basis can be applied, may an employee voluntarily give explicit consent to the processing of specific health data for a given purpose. Consent must be freely given and informed, it cannot be merely "assumed" or coerced, and the employee can withdraw it at any time.

In the employment context, however, caution is advised – due to the relationship of subordination and dependence, it is considered that an employee's consent may often not be given entirely voluntarily, and regulators question the validity of such consents. Therefore, consent should be used rather exceptionally, for example, for completely voluntary benefits or above-standard services that the employee is not required to use.

DO YOU NEED LEGAL HELP?

Get in touch — we're happy to help.

ARROWS law firm

In addition to choosing the correct legal basis, it is crucial to adhere to the principles of data minimisation and purpose limitation. In practice, this means collecting only such health information about an employee as is necessary to fulfil a legitimate purpose, and not using it further in a manner incompatible with the original purpose.

As the Czech Data Protection Authority aptly stated in the aforementioned Berlin case – if an employer cannot demonstrate that it genuinely needs certain health data for a legitimate purpose or legal obligation, it violates the principles of necessity and minimisation under Article 5 of the GDPR.

A company should therefore always be able to justify why it requests and processes specific health information.

Practical Steps for Companies

From the perspective of daily HR and human resources management practice, many situations arise where working with employees' health data may be necessary. Below are common scenarios, correct procedures, and recommendations on how to ensure compliance with the GDPR:

Typical situations requiring the processing of health data:

1. Sick leave (temporary incapacity for work)

When an employee falls ill, they usually have to provide a doctor's certificate. The standard "sick note" given to the employer only contains information that the employee is temporarily unable to work and for how long; it does not state a diagnosis or details about the illness. 

Such a certificate does not contain sensitive health data within the meaning of the GDPR, so its acceptance and recording are in order. The employer should insist on this form. 

Conversely, the employer is not entitled to demand a detailed medical report with a diagnosis from the employee (e.g., a description of a work accident report or test results beyond what is necessary to assess fitness for work). If an employer were to collect such detailed health documents without a legal obligation, it would violate the prohibition on processing special categories of sensitive data.

Current opinions suggest that employers should be advised to always accept only a standard certificate of incapacity for work that does not contain a diagnosis as proof of illness – accepting documents with specific health data (e.g., the cause of illness) may be assessed as an administrative offence in the area of personal data protection. (An exception is situations where another legal regulation directly requires the submission of details – see the recording of work-related accidents below.)

2. Work-related accidents and occupational diseases

In the event of an accident at the workplace or the discovery of an occupational disease, the employer has a legal duty to record and report these events (e.g., to the Labour Inspectorate, insurance company). As part of the record of work-related accidents, a description of the injury or illness, the circumstances of the event, and other health information necessary to assess the employee's claims are usually included.

Here, therefore, a legal basis exists for processing even more detailed data about health status – it is a matter of fulfilling the employer's legal obligation in the area of occupational safety. However, these records must be protected as carefully as other sensitive data, and access to them should be restricted to authorised persons only (see below).

Furthermore, it is necessary to remember that the law sets special retention periods for accident documentation: under Czech labour law, records of work-related accidents and occupational diseases are kept for 30 years (for pension insurance purposes). The company must therefore ensure the secure archiving of this data for this period and its subsequent secure destruction.

3. Pre-employment and periodic medical examinations

The Czech Labour Code and related regulations require the employer to ensure that employees perform work corresponding to their medical fitness. Before starting employment and at certain intervals during the employment relationship, employees must therefore undergo occupational medical examinations. The medical fitness assessment is issued by a contracted physician, and the employer generally receives only the result: fit/unfit for work (possibly with restrictions). The details of the examination or diagnosis remain confidential between the employee and the doctor.

For the HR department, the recommendation is therefore to retain only the medical assessments themselves (or confirmation of the result), not the complete medical documentation. The processing of this data is based on a legal obligation (fulfilling OHS requirements) and the exception under Article 9(2)(h) of the GDPR (preventive medicine, assessment of working capacity). The obligation to secure these documents against unauthorised access applies here as well.

Our specialists will help you

Mgr. Jakub Oliva, LL.M., MSc.

Mgr. Jakub Oliva, LL.M., MSc.

advokát, partner

oliva@arws.cz
ARROWS law firm

4. COVID-19 testing and other health screenings

The extraordinary situation during the pandemic confronted many employers with the question of whether they could ascertain health information such as COVID-19 test results, vaccination status, or measure temperatures at the entrance to the workplace. The Czech Data Protection Authority confirmed during the pandemic that measuring temperature or recording a negative test could be justified under strict conditions – especially if it is justified by the employer's duty to ensure a safe and healthy working environment.

The legal basis here can be legitimate interest and the fulfilment of a legal obligation (OHS), while also meeting the exception for processing health data for reasons of public interest in the area of public health or the protection of life and health (Article 9(2)(i) or (b) of the GDPR).

In practice, this means carrying out only necessary actions (e.g., not measuring temperatures across the board if the situation does not require it, not retaining data for longer than necessary) and ensuring the maximum security of the data obtained. For example, if a company records that an employee had a positive test on a certain day, it must treat this record as strictly confidential and delete it once the purpose has passed.

Which Legal Bases to Choose

In each of the situations described above, the employer should clarify on what basis (reason) it is processing health data. As a rule, it will be:

1. to fulfil a legal obligation (legal basis under Article 6(1)(c) of the GDPR – e.g., the duty to keep accident records, allow sick leave checks, arrange medical examinations, etc.), or

2. the employer's legitimate interest (Article 6(1)(f) – typically ensuring safety at the workplace, protecting the health of other employees, controlling the abuse of sick days, etc.).

3. less often, it may be the employee's consent (Article 6(1)(a)), but use this only in cases where it is not truly an obligation or a necessary step (e.g., an employee voluntarily discloses information about their health limitation so that the employer can accommodate them – even here, the basis is often more about fulfilling the duty not to discriminate against them).

It is important not to combine multiple bases unclearly at once – for each processing purpose, choose the most appropriate one and state this reason in the records of processing activities and in the information provided to employees. Also, do not forget the requirement of Article 9 of the GDPR, so in addition to the chosen basis from Article 6, you must also have a corresponding exception for sensitive data (see above). For example: if you are storing a certificate of incapacity for work, the legal basis is the fulfilment of a legal obligation (records for the Czech Social Security Administration - ČSSZ) and the special exception is Article 9(2)(b) of the GDPR (necessary for fulfilling obligations in the employment field).

Correctly Obtaining and Storing Consent 

If a situation arises where you are genuinely relying on an employee's consent to process health data, pay close attention to the form and content. The consent must be explicit, preferably in writing or electronically signed, and definitely not implied. State specifically what data the employee is consenting to and for what purpose (e.g., a one-off biometric data examination for a voluntary health program).

Consent must not be hidden in an employment contract or General Terms and Conditions – it must be a separate document or a clearly separate clause.

Also, inform the employee that they can withdraw their consent at any time and provide them with a simple way to do so (e.g., contact the HR department or the DPO). Never make standard employment-related actions conditional on consent – for example, do not consider signing a consent form as mandatory upon starting a job. This would make the consent involuntary and legally invalid.

Records of granted consents should be meticulous; ideally, maintain a register of consents with details of who, when, and for what purpose consent was given, so you can prove it in case of an inspection.

Setting Up Internal Processes to Ensure Data Protection

A key practical measure is to establish clear rules within the company about who can handle employees' health data and how. Health documents and information should be accessible only to a limited circle of people – typically HR staff, payroll department employees (for sick leave), or a line manager, but only to the necessary extent. Sensitive medical reports or assessments should be stored separately from the employee's regular personnel file, for example, in a sealed envelope or in an electronic HR system with restricted access rights.

Technical security must match the nature of the data: health data in electronic form should be encrypted or at least protected by a strong password, with access to folders logged and conditional on authorisation. Keep paper documents in locked cabinets with controlled access. Any digital record of health data must be part of internal security measures – inadequate technical and organisational security (e.g., storing data in unencrypted form, lack of controlled procedures for access and user authentication) constitutes a serious breach of the GDPR. Therefore, train employees who come into contact with sensitive data about their duty of confidentiality and correct procedures.

An internal policy should define how health data is recorded, who approves access, how to proceed with a request for sensitive data (e.g., who is allowed to see the diagnosis from an accident report), and what to do in the event of a potential incident (loss of a document, unauthorised access, etc.).

Also, do not forget the duty of confidentiality – for example, if the company has its own corporate doctor or healthcare professional, this person must be contractually bound to secrecy. Last but not least, it is advisable to anonymise or pseudonymise data wherever detailed identification is not necessary – for example, aggregated data without names is sufficient for sickness statistics.

DO YOU NEED LEGAL HELP?

Get in touch — we're happy to help.

ARROWS law firm

Retention Period for Health Data

The GDPR requires that personal data be kept only for as long as is necessary for the purpose. This is doubly true for health data – a company should not archive it for longer than necessary. Therefore, set disposal periods for different types of documents:

  • A standard certificate of incapacity for work or an absence record can be disposed of after the statutory period for potential inspections or the statute of limitations for claims has expired (usually several years). To be safe, it is often recommended to retain them for 3–4 years after the end of employment, due to possible disputes, but then the data should be destroyed.

  • Keep medical fitness assessments for the duration of the employment relationship (or the validity of the assessment) and for the period stipulated by law thereafter. Some regulations may require archiving for several years after the employee's departure (e.g., for potential claims related to occupational diseases).

  • Documentation on work-related accidents and occupational diseases, as mentioned above, has a special long retention period – 30 years from the date of the event. Therefore, archive these records separately and securely for this period and only then carry out their disposal.

  • If you have obtained an employee's consent for a one-off action (e.g., a screening), and the action has taken place, you have no reason to keep the data any longer – delete the data immediately after the purpose has been fulfilled. Remember that if an employee withdraws their consent, you must stop processing and delete the data (unless you have another legal reason).

To make things easier, you can include an overview of document types containing employees' personal data in an internal policy or a filing and disposal plan, and assign retention periods to them according to legal regulations or internal needs. After the given period expires, securely destroy the data (shredding paper, deleting and anonymising electronic records). This will prevent the unnecessary accumulation of sensitive data and reduce the risk of someone gaining unauthorised access to it in the future.

Do you have doubts about the correct retention period for your employees' health records? We can help you set up internal rules.

Typical Mistakes and How to Avoid Them

Even with the best intentions, companies sometimes make mistakes when processing employees' health data.

Here are four common missteps, supplemented with practical examples and tips on how to eliminate them:

1. Collecting unnecessarily detailed information: 

Sometimes employers record more health data than they actually need – for example, requiring a detailed medical report with a diagnosis from an employee instead of a sufficient certificate of incapacity. This violates the principle of minimisation and may constitute unlawful processing of sensitive data.

How to avoid it: Always ask whether you really need to know the information in question. Take only what is necessary to fulfil an obligation (e.g., the start and end date of incapacity for work). Leave medical details (diagnoses, descriptions of illnesses) to doctors and do not request them from employees.

2. Unclear or invalid employee consent: 

A common mistake is to try to "cover all bases" with a universal consent from the employee that covers very broad processing (all possible data) or is obtained formally without a real choice. Such a blanket consent is contrary to the GDPR – it is neither specific nor freely given. Moreover, the employee can withdraw consent at any time, which puts the company in a difficult position if it has based necessary processes on it.

How to avoid it: Do not rely on consent where you can base the processing on another legal basis (legal obligation, legitimate interest). If you do need consent, formulate it narrowly for the specific purpose and genuinely give the employee a choice (no sanctions or disadvantages if they do not consent). An example of good practice is a voluntary health program – offer employees participation, but do not force them. Archive the consent and regularly check that it is still valid and necessary.

3. Inadequate security and confidentiality: 

Even the best legal basis is of no help if the company neglects organisational and technical measures to protect the data. In practice, there have been cases where sensitive files with employee data were freely accessible to a wider group of people due to a system misconfiguration – this happened, for example, in the H&M case, where internal records on employees' health and private lives were temporarily made accessible to the entire company, which subsequently led to a record fine. 

How to avoid it: Implement strict access rights – only authorised persons should have access to health data. Encrypt files and use secure storage. Consistently communicate internally that health information is confidential. Everyone who works with it should be bound by a duty of confidentiality. Conduct regular audits to ensure no unauthorised access is occurring. In the case of IT systems, pay attention to updates and security features (encryption, two-factor authentication, access logging). This will prevent data leaks and misuse.

4. Misuse of health data for improper purposes: 

The most serious situation is when an employer uses the sensitive data obtained against employees or for discriminatory decisions. For example, the aforementioned case in Berlin revealed that the company kept a list of "critical" employees based on mental illnesses and other personal information, and used it during layoffs. This is a gross violation of the law and ethics – the GDPR clearly states that health data cannot be processed for the purpose of unfairly assessing or discriminating against employees.

How to avoid it: Establish a zero-tolerance policy in your organisational culture for any misuse of personal data. Health data serves exclusively for lawful purposes (e.g., health protection, fulfilling obligations) and never for deciding who gets a raise, a promotion, or is laid off, unless it is directly related to the information in question.

Decisions on work matters must be based on performance, qualifications, and objective criteria – never on the fact that someone has health problems or is caring for a sick family member. Review your internal processes (recruitment, performance reviews, termination of employment) and make sure they do not include any questions or criteria related to health that are not supported by the employer's obligations.

If you are unsure whether fulfilling a legal obligation or obtaining consent is more appropriate in your case, we will be happy to assess your situation individually.

FAQ – Most Common Legal Questions on Processing Employee Health Data

1. Can an employer require an employee to disclose their diagnosis on a sick note?

No, the employer does not have this right. For the purposes of excusing absence and administering benefits, information that the incapacity for work has begun, is ongoing, and when it ended is sufficient. The diagnosis itself is highly sensitive data that the employer does not need for its purposes and must not request. If you are unsure which documents you can request from employees, contact our experts.

2. What health information can we request from a job applicant before they start?

You may only request health information to the extent strictly necessary to assess the applicant's fitness to perform the specific job. This scope is defined within the pre-employment medical examination, the content and obligation of which depend on the job category and risk level. Broad and general health questions in questionnaires are not permissible. Do not hesitate to contact us for a review of your recruitment processes.

3. How long can we archive the medical assessments of former employees?

You must retain medical assessments and related documentation for the period specified by specific legal regulations (e.g., the Act on Specific Health Services). After these statutory retention periods expire, it is your duty to ensure their secure and irreversible destruction. We will be happy to help you set up internal rules for archiving and disposal.

4. What should we do if an employee requests a copy of all the health data we hold about them?

This is an exercise of the right of access under Article 15 of the GDPR. You are obliged to provide them with a copy of the processed data without undue delay (within one month at the latest) and also to inform them about the purpose, legal basis, retention period, and their other rights.

5. In the context of OHS, can we monitor employees' health beyond the statutory medical examinations?

Any further monitoring (e.g., temperature checks, testing) is only possible if it is necessary for the protection of public health or the health of other employees and there is a legal basis for it (e.g., extraordinary measures from the Ministry of Health). The processing must always be proportionate and as non-invasive as possible.

DO YOU HAVE MORE QUESTIONS? GET IN TOUCH

ARROWS law firm

About the author

JUDr. Jakub Dohnal, Ph.D., LL.M.
JUDr. Jakub Dohnal, Ph.D., LL.M.

Associate, managing partner

Jakub Dohnal is an attorney-at-law and managing partner of ARROWS. He focuses on company sales, investor entries into private companies and real estate transactions — most often acting for the owner who is selling a business built over many years and needs the deal to close on the agreed terms.

Disclaimer:

The information contained in this article is for general informational purposes only and serves as a basic guide to the issue as of 2026. Although we strive for maximum accuracy, laws and their interpretation evolve over time. We are ARROWS Law Firm, a member of the Czech Bar Association (our supervisory authority), and for the maximum security of our clients, we are insured for professional liability with a limit of CZK 350,000,000. To verify the current wording of the regulations and their application to your specific situation, it is necessary to contact ARROWS Law Firm directly (consultation@arws.cz). We are not liable for any damages arising from the independent use of the information in this article without prior individual legal consultation.