an authorized receiver of the communication. There are several cases denying relief
to employees fired on the grounds of the content of communications made available
on electronic social networks.
96
Sectoral legislation may, however, offer some protection to employees in certain
specific areas and under specific statutes, such as the protection of their credit card
information, under the FACTA, medical records, genetic information and
disabilities.
97
At the state level, there are no significant additional protections for employees in
the context of personal data processed by electronic means. It is, therefore, a fact that
the United States’ legal framework, both at the federal level and at the state level,
does not grant employees significant protection in that context.
In contrast with the United States, the European Union Member States have
developed a very strict legal framework that affords employees a considerable
level of protection to their personal data, whenever processed by electronic
means.
98 While in the United States there are many exceptions to the protection of
the personal data of employees, processed by electronic means, in the European
Union such exceptions are much less extensive and numerous, and they are mainly
justified by the legitimate interests of the employer.
Although the GDPR does not contain specific rules concerning this topic,
99
Member States have a considerable level of freedom to accommodate their own
solutions and, in particular, they may provide protections beyond the minimum
requirements set forth in that legal instrument.
100 This is true in general and
specifically in this case, since the GDPR contains a general clause allowing Member
States to provide for specific rules to ensure the protection of rights and freedoms in
respect of the processing of personal data of employees in the employment context.
101 Additionally, collective agreements may provide for specific rules for
personal data processing in the employment context, including the conditions for
processing based on the consent of the employee.
102
The exercise of the right to exceed the minimum requirements set forth in the
European Union’s legal framework is particularly noticeable in what concerns the
processing of personal data of employees through electronic means. Member States
have specific legislation, administrative guidance and, in some cases, abundant case
law on this subject.
96 It is noteworthy that, since 2012, 25 states have enacted legislation preventing employers from
forcing their employees to disclose the respective passwords. See the United States of America’s
National Report, Sect. 2.5.3.
97 See the United States of America’s National Report, Sect. 2.5.
98 See van der Sype et al. (2017).
99 See the European Union Special Report, Sect. 2.4.
100 See, for instance, article 5 of the GDPR, which sets out the main principles applicable to the
processing of personal data, such as lawfulness, fairness and transparency, purpose limitation,
minimization, accuracy, storage limitation, integrity, confidentiality and accountability.
101 See article 88(1) of the GDPR.
102 See recital 155 of the GDPR.
Data Protection in the Internet: General Report
21
to employees fired on the grounds of the content of communications made available
on electronic social networks.
96
Sectoral legislation may, however, offer some protection to employees in certain
specific areas and under specific statutes, such as the protection of their credit card
information, under the FACTA, medical records, genetic information and
disabilities.
97
At the state level, there are no significant additional protections for employees in
the context of personal data processed by electronic means. It is, therefore, a fact that
the United States’ legal framework, both at the federal level and at the state level,
does not grant employees significant protection in that context.
In contrast with the United States, the European Union Member States have
developed a very strict legal framework that affords employees a considerable
level of protection to their personal data, whenever processed by electronic
means.
98 While in the United States there are many exceptions to the protection of
the personal data of employees, processed by electronic means, in the European
Union such exceptions are much less extensive and numerous, and they are mainly
justified by the legitimate interests of the employer.
Although the GDPR does not contain specific rules concerning this topic,
99
Member States have a considerable level of freedom to accommodate their own
solutions and, in particular, they may provide protections beyond the minimum
requirements set forth in that legal instrument.
100 This is true in general and
specifically in this case, since the GDPR contains a general clause allowing Member
States to provide for specific rules to ensure the protection of rights and freedoms in
respect of the processing of personal data of employees in the employment context.
101 Additionally, collective agreements may provide for specific rules for
personal data processing in the employment context, including the conditions for
processing based on the consent of the employee.
102
The exercise of the right to exceed the minimum requirements set forth in the
European Union’s legal framework is particularly noticeable in what concerns the
processing of personal data of employees through electronic means. Member States
have specific legislation, administrative guidance and, in some cases, abundant case
law on this subject.
96 It is noteworthy that, since 2012, 25 states have enacted legislation preventing employers from
forcing their employees to disclose the respective passwords. See the United States of America’s
National Report, Sect. 2.5.3.
97 See the United States of America’s National Report, Sect. 2.5.
98 See van der Sype et al. (2017).
99 See the European Union Special Report, Sect. 2.4.
100 See, for instance, article 5 of the GDPR, which sets out the main principles applicable to the
processing of personal data, such as lawfulness, fairness and transparency, purpose limitation,
minimization, accuracy, storage limitation, integrity, confidentiality and accountability.
101 See article 88(1) of the GDPR.
102 See recital 155 of the GDPR.
Data Protection in the Internet: General Report
21
