Skip to content
+370 5 212 1506 info@dat.lt

Informing employees about data processing: what to say and when

24 September 2026 · Good to know

An employer must tell an employee who processes their data, for what purposes and on what legal bases, to whom it is passed, how long it is kept and what rights the employee has. This is done when the data is obtained (Article 13(1) GDPR), usually already at hiring. The information must be concise, intelligible and easily accessible (Article 12(1) GDPR). Where the data does not come from the employee, they must be informed within a reasonable period, but at the latest within one month (Article 14(3)(a) GDPR), or earlier if the data is used to communicate with the employee and the employer contacts them first, or discloses the data to another recipient (Article 14(3)(b) and (c) GDPR).

A website privacy policy does not meet this duty: it is written for customers and visitors, while employee data is processed for other purposes and on other bases. We wrote about the website text in privacy policy: is it mandatory and when to update it, and about candidates in the article on candidate and employee data, CVs and ID copies. Here: what the law requires specifically for employees, where mistakes can happen and what they mean legally.

What the law requires

The basis is the transparency principle: data is processed lawfully, fairly and in a transparent manner (Article 5(1)(a) GDPR). The employer must also be able to demonstrate compliance (Article 5(2) GDPR). Informing is not enough: you need proof that you informed.

The mandatory content is set by Article 13(1) and (2) GDPR. In employment the following items matter most:

  • Purposes and a legal basis for each purpose (Article 13(1)(c) GDPR). Payroll, social insurance, occupational safety, access control and internal communication have different bases. One general sentence such as “we process data for employment purposes” does not list them.
  • The specific legitimate interest, if you rely on one (Article 13(1)(d) GDPR).
  • Recipients (Article 13(1)(e) GDPR): state institutions, the payroll provider, IT system suppliers, group companies.
  • Transfers outside the EEA (Article 13(1)(f) GDPR), if group or supplier systems are in third countries.
  • Retention periods (Article 13(2)(a) GDPR). How to justify them, we explained in how long to keep personal data.
  • Whether providing the data is required by law or contract, and the consequences of not providing it (Article 13(2)(e) GDPR). For an employee this is the most practical item: they need to know what they must provide and what is their choice.
  • Automated decisions, if any (Article 13(2)(f) GDPR).
  • Rights and the right to complain to VDAI (Article 13(2)(b) and (d) GDPR).

Where processing is based on legitimate interest or a public-interest task, the employee has the right to object on grounds relating to their particular situation (Article 21(1) GDPR). They must be told about this right at the latest at the first communication, clearly and separately from any other information (Article 21(4) GDPR).

Data not obtained from the employee, for example from a former employer or a recruitment agency, has its own rules. Then the source of the data must be stated too (Article 14(2)(f) GDPR). Data on a candidate’s qualifications may be collected from a former employer only after informing the candidate, and from the current employer only with the candidate’s consent (Article 5(3) ADTAĮ).

Informing is not a one-off. If you intend to use existing data for another purpose, you must tell employees before you start (Article 13(3) GDPR). Informing is not required only where and insofar as the employee already has the information (Article 13(4) GDPR). A recruitment notice given to a candidate does not cover what will happen to their data during employment.

What form, and what counts as proof

The information is provided in writing or by other means, including electronically (Article 12(1) GDPR). The Article 29 Working Party Guidelines on transparency (WP260 rev.01), endorsed by the EDPB in 2018 (Endorsement 1/2018), say that the information must be provided actively. The person must not have to search for it among other information, such as contract terms. So an employee notice hidden in an annex to the work rules may not meet this requirement.

Lithuanian law adds two things. First, the employer lets an employee start work only after making them aware, against signature, of the working conditions and the labour law rules that set the order at the workplace (Article 42(4) of the Labour Code, DK). If you have adopted your rules on processing employee data as a local normative act (local normative acts set labour-law norms, Article 3(1) DK), the employee is made aware of them at the same time. Second, about monitoring (video and audio data at the workplace, monitoring of behaviour, location or movement), employees are informed against signature or in another way that proves they were informed (Article 5(4) ADTAĮ).

An employer with an average of twenty or more employees adopts its policy on the storage of employees’ personal data after informing and consulting the works council (Article 206(1), point 7, DK).

Notice, policy and records: three different documents

A client asked why it needed an internal data protection policy when employees had already been given a privacy notice. We answered by explaining what the policy is for. The internal policy sets rules: how staff handle data, how a data breach is handled, how people’s requests are dealt with, how an impact assessment is carried out. Article 24(2) GDPR describes such a policy as one of the controller’s measures, where proportionate to the processing activities. The notice tells the employee what happens to their own data. One does not replace the other.

The third document is the record of processing activities. It is made available to VDAI on request (Article 30(4) GDPR). In one company, the purposes and retention periods of one processing operation on employee data were properly described in the records, but the employee notice did not mention that processing. The record informs nobody. If a processing operation is not in the notice, employees have not been informed about it.

What goes wrong

There is no notice, or it is generic. One sentence in the employment contract saying that the employer processes the employee’s data under the GDPR provides none of the Article 13(1) and (2) GDPR items.

The notice does not match reality. It describes systems that no longer exist and leaves out new ones: video surveillance, GPS, a new HR system or a supplier outside the EEA.

There is no proof. The notice was sent in a general e-mail years ago and never given to new staff. In a dispute or an inspection, under Article 5(2) GDPR it is the employer who must prove it.

The notice comes too late. A new monitoring or assessment tool is introduced, and employees are told afterwards. Where the line lies for employee monitoring is covered in Employee monitoring: cameras, GPS, call recording and e-mail.

The consequences are legal. The duty to inform is part of the data subject’s rights. For breaches of rights under Articles 12–22 GDPR, the GDPR provides for administrative fines of up to twenty million euros or, for an undertaking, up to 4 % of total worldwide annual turnover of the preceding financial year, whichever is higher (Article 83(5)(b) GDPR). Public authorities and bodies in Lithuania face lower caps (Article 33(2) ADTAĮ), unless they carry on commercial activity (Article 33(3) ADTAĮ). VDAI may order that processing be brought into compliance within a set period (Article 58(2)(d) GDPR). An employee who suffered damage has a right to compensation (Article 82(1) GDPR). The problem can come up, for example, in a dispute over a dismissal or a disciplinary sanction. The question then is whether the employee was told that such data was collected and what it was used for.

When to call a lawyer

  • when you draft or update the employee privacy notice and the internal data protection policy;
  • when you introduce a new HR, time-recording or monitoring system;
  • when employee data is shared with group companies or suppliers outside the EEA;
  • when an employee asks for their data or complains about how it is handled;
  • when you need to consult the works council on data processing rules.

Frequently asked questions

Does an employee have to sign the privacy notice?

The GDPR does not require a signature, but it requires the employer to be able to prove that it informed. A signature or an electronic confirmation is the simplest proof. For monitoring, Article 5(4) ADTAĮ requires informing against signature or in another way that proves it. The signature means the employee was told, not that they agreed.

Is a clause in the employment contract enough?

Usually not. A clause saying that the employer processes data under the GDPR does not list purposes, bases, recipients, periods and rights. The WP260 guidelines say a person must not have to search for the information among other terms; the same principle applies to an employment contract. It is best to have a separate notice and to state in the contract or the work rules where it can be found.

Do existing employees need to be informed again when we start using a new system?

Yes, if there is a new purpose, a new recipient or a transfer outside the EEA. A new purpose is notified before processing starts (Article 13(3) GDPR). For other material changes to the notice, the WP260 guidelines (para. 29) say the same principles apply as for the original notice. Among other things, a new purpose, a different controller or a change in how rights are exercised must always be notified; other changes are judged by their impact on the employee and how unexpected they are. In our view, a new recipient or a transfer outside the EEA usually is such a change. It is worth giving the updated notice in a way that leaves proof of who received it and when.

Do we need the employee’s consent to process their data?

Usually not. In employment, consent is rarely considered free, so data is processed on the basis of a legal obligation, the contract or legitimate interest. We explained why in the article on employee consent. Informing and consent are different things: informing is required whatever the legal basis.

How to start

Send us the notice given to employees, your internal data protection policy and a list of the systems where employee data is processed. We will compare what the documents say with what actually happens and tell you what is missing.

You can check whether your organisation needs a record of processing activities with the Privacio tool, built by Linden (in Lithuanian).

Email: info@linden.lt

More about this service: GDPR audit, compliance documents and consultations.

Get a free assessment

Related articles