There is no discussion so far on the question, to whom the values drawn from the
employees’ personal data shall be attributed under German labour law. Following
general rules such questions might be dealt with by collective agreements.
2.1.7 Use of Electronic Means by Employees and Disciplinary
Proceedings
The use of electronic means (also of social networks) by employees is not subject to
particular legislation. The usage of such means is governed by general sources of
employment law, namely collective employment law, including tariff agreements
and works agreements, and individual employment law, determined by the employment contract. It thus depends on the individual case whether and to what extent the
(private) use of electronic means by employees is allowed.
Due to his right of freedom of speech, Art. 5 para. 1 GG, the employee may
criticize the employer on social networks. However, he also has a duty of loyalty to
the employer and may deal out criticism only in an appropriate way. The Federal
Labour Court held that a termination without notice due to a gross affront on
Facebook can be justified.
49 Information gained from social media may be used
within disciplinary proceedings. Even if it was gained infringing data protection
rules, there from does not necessarily result an exclusion of that evidence.
50
2.1.8 Obligations in Order to Protect Personal Data Conveyed
and Stored Through Electronic Means
There are additional obligations in order to protect personal data conveyed and
stored through electronic means laid down in the Act on the Federal Office for
Information Security (“BSIG”) adopted in 2015. The BSIG has been adapted to
implement the provisions of the NIS-Directive.
51 It now contains increased demands
on technical and organizational security measures to protect customer data and
IT-systems used by them. A general digital product security law has not been
established yet.
The GDPR also foresees the implementation of appropriate technical and organizational measures like pseudonymisation and encryption to ensure a high level of
security, Art. 32 GDPR. Furthermore, it provides a set of rules concerning processors to safeguard that a high security level is also guaranteed where the
processing is to be carried out on behalf of a controller, Art. 28 GDPR. The
introduction of the principles of data protection by design and by default, Art.
49 Federal Labour Court (BAG), judgment of 10 December 2009, 2 AZR 534/08 ¼ NZA 2010, 698.
50 Further elaboration on the use of social media by employees: Kort (2012), p. 1321; Bauer and
Günther (2013), p. 67.
51 Directive on security of network and information systems (EU) 2016/1148.
194
C. Breunig and M. Schmidt-Kessel
employees’ personal data shall be attributed under German labour law. Following
general rules such questions might be dealt with by collective agreements.
2.1.7 Use of Electronic Means by Employees and Disciplinary
Proceedings
The use of electronic means (also of social networks) by employees is not subject to
particular legislation. The usage of such means is governed by general sources of
employment law, namely collective employment law, including tariff agreements
and works agreements, and individual employment law, determined by the employment contract. It thus depends on the individual case whether and to what extent the
(private) use of electronic means by employees is allowed.
Due to his right of freedom of speech, Art. 5 para. 1 GG, the employee may
criticize the employer on social networks. However, he also has a duty of loyalty to
the employer and may deal out criticism only in an appropriate way. The Federal
Labour Court held that a termination without notice due to a gross affront on
Facebook can be justified.
49 Information gained from social media may be used
within disciplinary proceedings. Even if it was gained infringing data protection
rules, there from does not necessarily result an exclusion of that evidence.
50
2.1.8 Obligations in Order to Protect Personal Data Conveyed
and Stored Through Electronic Means
There are additional obligations in order to protect personal data conveyed and
stored through electronic means laid down in the Act on the Federal Office for
Information Security (“BSIG”) adopted in 2015. The BSIG has been adapted to
implement the provisions of the NIS-Directive.
51 It now contains increased demands
on technical and organizational security measures to protect customer data and
IT-systems used by them. A general digital product security law has not been
established yet.
The GDPR also foresees the implementation of appropriate technical and organizational measures like pseudonymisation and encryption to ensure a high level of
security, Art. 32 GDPR. Furthermore, it provides a set of rules concerning processors to safeguard that a high security level is also guaranteed where the
processing is to be carried out on behalf of a controller, Art. 28 GDPR. The
introduction of the principles of data protection by design and by default, Art.
49 Federal Labour Court (BAG), judgment of 10 December 2009, 2 AZR 534/08 ¼ NZA 2010, 698.
50 Further elaboration on the use of social media by employees: Kort (2012), p. 1321; Bauer and
Günther (2013), p. 67.
51 Directive on security of network and information systems (EU) 2016/1148.
194
C. Breunig and M. Schmidt-Kessel
