When an employee leaves, the work mailbox, files and accounts stay with the employer, but the data in them does not become free to use. The employer may keep what it needs to continue the work and to meet legal obligations. At the same time it must revoke the former employee’s access, must not read their personal correspondence (Article 2.23(2) of the Civil Code, CK; Article 27(2) of the Labour Code, DK) and must not keep their mailbox running indefinitely (Article 5(1)(e) GDPR). Documents whose preparation is required by law are kept for the set periods; other data only for as long as it is needed.
Most mistakes are made not on the last working day but months later. The address still receives mail that a manager reads. Access to the cloud still works. Files sit on a shared drive with no owner. Below: what the law requires, where things usually go wrong and what can follow.
What stays with the employer, and what does not
The work email mailbox, work files and accounts are the employer’s tools. But they contain the employee’s own personal data: their name in the address, their correspondence, sometimes personal messages and files. They also contain data about customers, partners and colleagues.
The fact that the tool belongs to the employer does not remove the employee’s rights. When the employer exercises its rights of ownership or management over the technologies used at the workplace, the secrecy of employees’ personal correspondence may not be breached (Article 27(2) DK). In our view, this also applies after the employment ends: personal messages remain personal. The general GDPR principles also apply:
- Purpose. Data is collected for specified, explicit purposes and not further processed in a manner incompatible with them (Article 5(1)(b) GDPR). A mailbox kept for business continuity is not an archive in which to search for information about the person at any time.
- Amount. Only what is necessary for the purpose is processed (Article 5(1)(c) GDPR).
- Period. Data is kept no longer than necessary for the purpose (Article 5(1)(e) GDPR).
- Proof. The employer must be able to demonstrate that it complies with these principles (Article 5(2) GDPR).
The basis for business continuity is usually legitimate interest (Article 6(1)(f) GDPR). Who may open an employee’s mailbox, and on what grounds, must be set in advance, not invented on the day the person leaves. The general rules for checking work email are set out in our article on employee monitoring.
The mailbox: auto-reply, forwarding or closing
Neither the GDPR nor the Labour Code sets how many days a former employee’s mailbox may stay active. So the decision has to be justified by the same principles. In our view, the risk differs as follows:
- Auto-reply. The sender is told that the person no longer works here and is given a colleague’s or a general address. New messages are read by no one, so this is the least intrusive option. It is worth using for a limited time, until customers and partners learn the new contact.
- Forwarding all mail to a colleague. Personal messages keep arriving: from the bank, a doctor, friends, other employers. Another person will read them. This is hard to reconcile with the confidentiality of correspondence (Article 2.23(2) CK), in our view also with Article 27(2) DK, and with the data minimisation principle. If you do forward, do it briefly and tell the employee in advance.
- The mailbox runs indefinitely. After a few months the purpose for which it was kept disappears, but the mailbox remains. This no longer meets the storage limitation principle. Set a period after which the mailbox is closed, and move the work messages still needed to a shared workspace.
It is best to agree on this before the person leaves: the employee hands over current matters, marks or saves their personal messages and files themselves, and you know what stays and with whom.
Reviewing old email and files
After an employee leaves, a specific work message is often needed: a customer order, a contract negotiation, a promise made. You may find it, but:
- search for the specific item, rather than going through the whole mailbox;
- do not open or read obviously personal messages;
- record who searched, when and why, because the employer bears the burden of proof (Article 5(2) GDPR).
The line is not a formality. A breach of the confidentiality of correspondence or other communications is deemed a breach of private life (Article 2.23(2) CK). It is a ground for a claim for pecuniary and non-pecuniary damages (Article 2.23(4) CK).
Accounts and access
On the last working day, access is revoked: email, the customer system, cloud storage, remote access, shared passwords. Devices are collected. The employer must ensure that persons acting under its authority process data only on its instructions (Article 32(4) GDPR). A person who has left is no longer under that authority and no longer receives instructions. In our view, their access is then unauthorised access: data must be protected against unauthorised processing (Article 5(1)(f) GDPR), and a breach of security leading to unauthorised access to personal data is a personal data breach (Article 4(12) GDPR).
If a former employee nevertheless logged in or downloaded data, this may be a personal data breach. The controller must then assess the risk and, unless the breach is unlikely to result in a risk to people’s rights and freedoms, notify VDAI without undue delay and, where feasible, not later than 72 hours after becoming aware of it (Article 33(1) GDPR).
The former employee’s data and personnel file
Mandatory documents. Retention periods follow from laws and other legal acts (Article 13(1) of the Law on Documents and Archives, DAĮ). Retention schedules for mandatory internal administration documents are approved by the Chief Archivist of Lithuania (Article 13(2) DAĮ), so look up the period for personnel documents there rather than relying on a general rule. Such documents may not be destroyed early: they must be kept for the required time (Article 12(1)(2) DAĮ) and may be destroyed, after an appraisal of their value, once the periods set by law have expired (Article 14(1) DAĮ).
Other data. Where the law sets no period, the employer sets the retention period for documents, taking into account its own obligations and legitimate interests and those of other persons concerned, including the employee (Article 13(1) DAĮ). Personal data is in any case kept no longer than necessary (Article 5(1)(e) GDPR). In an employment file this usually means a possible dispute. The general limitation period for employment relations is three years, unless a shorter one is set (Article 15(2) DK). A claim for unlawful dismissal must be brought to the labour disputes commission within one month, and other disputes over rights within three months, of the time the employee learned or should have learned of the breach (Article 220(1) DK). This helps to justify a period. It is not a reason to keep everything for years. How to set and enforce retention periods is covered in How long to keep personal data.
Works council. An employer with an average of twenty or more employees informs and consults the works council when adopting or changing its rules on the use of information technologies and employee monitoring and its policy on the retention of employees’ personal data (Article 206(1)(5) and (7) DK).
The former employee’s rights. A person who has left has the same rights as any other data subject. They may ask for confirmation of whether their data is processed and for access to it (Article 15(1) GDPR). How to answer such a request is covered in our article on subject access requests. They may also ask for erasure, but what the law requires you to keep stays (Article 17(3)(b) GDPR).
What happens when you get it wrong
Personal messages read. This breaches the confidentiality of correspondence and so private life (Article 2.23(2) CK) and, for messages received while the person was still employed, the secrecy of personal correspondence (Article 27(2) DK). It is a ground for claiming damages (Article 2.23(4) CK). Under the GDPR, a person who has suffered damage also has the right to compensation (Article 82(1) GDPR). Such messages often surface in a dismissal dispute when the employer tries to rely on them.
The mailbox runs for a year, mail forwarded to a manager. This breaches the purpose, minimisation and storage limitation principles. Infringing the basic principles of processing can lead to fines of up to twenty million euros or, for an undertaking, up to 4 % of its total worldwide annual turnover of the preceding financial year, whichever is higher (Article 83(5)(a) GDPR).
Access not revoked. A former employee downloads a customer list or reads correspondence. Apart from the incident itself, this shows inadequate security measures. Infringing the obligations under Articles 25–39 GDPR can lead to fines of up to ten million euros or, for an undertaking, up to 2 % of its total worldwide annual turnover of the preceding financial year, whichever is higher (Article 83(4)(a) GDPR).
Everything deleted on day one. With it go the customer correspondence needed for the work, the evidence for a possible dispute and the documents that had to be kept (Article 12(1)(2) DAĮ). The mistake in the other direction is no smaller.
When to call a lawyer
- when a manager or someone with access to customer or financial data leaves;
- when the dismissal is for misconduct and a dispute is likely;
- when you need to review a former employee’s mailbox or files;
- when a former employee logged in or downloaded data after leaving;
- when a former employee asks for their data or its erasure;
- when you want to set rules for retaining employee data.
Frequently asked questions
May a former employee’s mailbox stay active?
For a limited time and for a clear purpose. In our view, the safest option is an auto-reply with the new contact, rather than forwarding all mail to a colleague. Set a period after which the mailbox is closed, because data may not be kept longer than necessary (Article 5(1)(e) GDPR).
May we read a former employee’s email?
Work messages needed to continue the work may be found and read, if such a procedure was set in advance and employees knew about it. Where the check amounts to monitoring employees’ behaviour, they must be informed against signature or in another way that proves they were informed (Article 5(4) ADTAĮ). Personal messages may not be read: this breaches the confidentiality of correspondence (Article 2.23(2) CK), and the secrecy of personal correspondence is protected on work tools too (Article 27(2) DK). Search for the specific item and record who searched, when and why.
How long should a former employee’s personnel file be kept?
Periods follow from laws and other legal acts (Article 13(1) DAĮ). Retention schedules for mandatory internal administration documents are approved by the Chief Archivist of Lithuania (Article 13(2) DAĮ). Where the law sets no period, the employer sets the retention period for documents, taking into account its own obligations and legitimate interests and those of other persons concerned, including the employee (Article 13(1) DAĮ). There is no single period for the whole file.
Can a former employee demand erasure of their data?
Yes, and data that is no longer needed must be erased. But what the law requires you to keep stays until the period ends (Article 17(3)(b) GDPR). Data needed for an existing or likely dispute may be kept for as long as it is needed to defend legal claims (Article 17(3)(e) GDPR).
How to start
Write down what you do when someone leaves: who revokes access, who decides on the mailbox, how long it stays active and who reads its mail. Send us this description and your work rules or IT use policy, if you have one. We will tell you where the risk lies and what needs to change.
You can check whether your organisation needs a record of processing activities with the Privacio tool, built by Linden (in Lithuanian).
Email: info@linden.lt
More about this service: GDPR audit, compliance documents and consultations.