Skip to content
+370 5 212 1506 info@dat.lt

Health data at work: what an employer may know

25 September 2026 · Good to know

An employer may process an employee’s health data only where an exception in Article 9(2) GDPR applies. In employment this is most often a duty or right under employment or workplace safety law (Article 9(2)(b) GDPR). Health is assessed not by the employer but by a health care institution, whose conclusion the employer receives (Articles 21(5) and 25(1)(10) DSSĮ). For such processing the GDPR requires the data to be handled by, or under the responsibility of, a professional bound by professional secrecy, or by another person bound by secrecy (Article 9(2)(h) and 9(3) GDPR). In practice this means the employer needs to know that the employee is unfit for work, that a mandatory health check has been done and what the medical conclusion says about the work. It almost never needs the diagnosis.

Problems start not with what the employer does not know, but with what it collects “just in case”: the cause of an illness in an email to a manager, copies of medical certificates in the general personnel file, a spreadsheet of vaccinations. This article covers what the law lets an employer know in each common situation, who may see it and what collecting too much can lead to.

Why health data is a separate category

Data concerning health means personal data related to a person’s physical or mental health, including the provision of health care services, which reveal information about their health status (Article 4(15) GDPR). The concept is broad: it covers information about a disease, a disability, a risk of disease or medical history, whatever the source – a doctor or the person themselves (Recital 35 GDPR). So a manager’s note that “the employee has back problems” is already health data.

Processing such data is prohibited (Article 9(1) GDPR) unless one of the exceptions in Article 9(2) applies. Two usually fit an employer: obligations in the field of employment and social security law (point (b)) and occupational medicine, where a professional assesses working capacity (point (h)). Both need a legal basis: for (b), a law or a collective agreement under national law with appropriate safeguards; for (h), a law or a contract with a health professional bound by professional secrecy. Where there is no such basis, explicit consent is left, and in employment it is rarely freely given – we explain why in our article on employee consent.

Data minimisation also applies: collect only what the purpose needs (Article 5(1)(c) GDPR). The Labour Code adds a general duty to respect employees’ rights to private life and to the protection of personal data (Article 27(1) DK).

What an employer may know: the common situations

Sick leave. The Labour Code attaches consequences to incapacity for work, not to a diagnosis. For example, if the employee is temporarily unfit for work when a notice period ends, the end of the notice period is postponed (Article 64(4) DK), and in certain cases the last day of employment is postponed too (Article 65(6) DK). The employer needs the fact and the period. The employer has no lawful use for the answer to “what are you ill with?”, and once written down it becomes health data without a purpose. How the employer learns about incapacity for work is set by social insurance legislation; we do not analyse it in this article.

Mandatory health checks. The employer approves the list of employees who must have their health checked and the schedule of checks, informs employees of it against signature and monitors compliance (Article 21(1) DSSĮ). An employee who refuses to have a health check at the set time is suspended from work (Article 21(4) DSSĮ). If the employer suspects that an employee’s health may endanger them or others, it may send them for a check outside the schedule (Article 21(2) DSSĮ). The employer transfers an employee to other work, with their consent, taking into account the conclusion of the health care institution that checked their health (Article 25(1)(10) DSSĮ), and the employee has the right to see the results of the checks (Article 34, point 3 DSSĮ). The procedure for the checks is set by the Minister of Health (Article 21(5) DSSĮ); we do not analyse that order in this article. The logic of the law is clear: the employer needs a conclusion about the work, not a medical record. In a health care institution, all information about a patient’s health status and diagnosis is confidential (Article 8(3) PTŽSAĮ), it may be given to other persons only with the patient’s written consent, except where a law provides otherwise (Articles 8(4) and 9(1) PTŽSAĮ), and health care professionals are prohibited from breaching the confidentiality of health secrets (Article 52(3) SSĮ).

DSSĮ has new editions coming into force on 1 October 2026 and 1 January 2027. The provisions of Articles 21, 25, 29, 34 and 37 discussed here do not change in them.

Pregnancy. The fact of pregnancy is confirmed to the employer by a doctor’s certificate (Article 61(1) DK), and protection against dismissal starts on the day the employer learns of the pregnancy (Article 61(2) DK). The employee decides when to tell. Once it knows, the employer must provide safe and healthy working conditions (Article 37(1) DSSĮ), so it keeps the certificate lawfully. Asking about an intention to have children is not allowed: discrimination on this ground and on the ground of health status is prohibited (Article 26(1) DK). What may be asked during recruitment is covered in our article on candidate and employee data.

Disability and chronic illness. The initiative usually comes from the employee. On the basis of a health care institution’s conclusion, they may ask for part-time work without the limits in Article 40(4) DK (Article 40(5) DK), remote work (Article 52(2) DK) or a working time arrangement that suits them (Article 113(1) DK). From 1 November 2026 (Law No XV-1058 of 25 June 2026), all three provisions refer to a health care institution’s document instead of its conclusion (Articles 40(5), 52(2) and 113(1) DK as in force from 1 November 2026). From the same date, the remote-work and working-time provisions also change when the employer may refuse: instead of excessive costs, where the request cannot be met because of how work or production is organised. For remote work, a collective agreement may provide otherwise (Article 52(2) DK as in force from 1 November 2026). For data purposes the substance does not change: the request is supported by a document from a health care institution, not by an employer’s questionnaire. For employees with a disability, the notice period for dismissal without fault on their part is tripled (Article 57(7) DK). The employer processes what the employee provided, for the purpose it was provided for.

Vaccination and tests. The law provides that employees at risk of catching a communicable disease are vaccinated at the employer’s expense, and the lists of such professions are approved by the Minister of Health (Article 29(5) DSSĮ). In those jobs the employer may process as much data as it needs to organise and pay for the vaccination; the provision does not make vaccination compulsory or give a right to demand a certificate. Other laws may set additional requirements for certain activities, for example in communicable disease control; we do not analyse them here. Where neither a law nor a collective agreement under it provides for this, the exception in Article 9(2)(b) GDPR does not apply, and usually only consent is left. By analogy: the Article 29 Working Party, in an opinion adopted before the GDPR applied and assessing health-monitoring devices handed out by employers, said that because of the imbalance between employer and employee it is highly unlikely that an employee’s consent to monitoring of health data would be valid (Opinion WP 249, section 5.4.4).

Accidents at work. Reports of accidents at work and the investigation material are kept at the company for the document retention periods set by the Office of the Chief Archivist of Lithuania (Article 45(4) DSSĮ). From 1 January 2027 the same rule will be in Article 45(8).

Who may see it and who may be told

Health data should be seen only by those who need it for their work: usually the HR specialist and the occupational safety specialist. The line manager usually only needs to know that the employee will be absent and until when, or which tasks they must not be given. Colleagues need to know only that their colleague is not working. There is no basis for telling the team what someone is ill with, even with good intentions.

Our suggestion (not a legal requirement): keep certificates and conclusions separately from the general personnel file, with restricted access. What security measures the GDPR requires is covered in our article on Article 32.

What happens when an employer knows too much

The first risk is a fine. Infringing the conditions for processing special categories of data (Article 9 GDPR) and the basic principles falls in the highest tier of fines: up to twenty million euros or, for an undertaking, up to 4 % of its total worldwide annual turnover of the preceding financial year, whichever is higher (Article 83(5)(a) GDPR). VDAI can also impose a temporary or definitive limitation on processing, including a ban (Article 58(2)(f) GDPR).

The second risk is damage. An employee who has suffered material or non-material damage as a result of an infringement has the right to compensation (Article 82(1) GDPR). A diagnosis made known to the team may be exactly such a case.

The third risk is a discrimination dispute. If the employer knew about an illness or a pregnancy and then dismissed or did not promote the employee, it is enough for the employee to point to circumstances from which it may be presumed that they were discriminated against, and the employer must prove there was no discrimination (Article 26(5) DK). The more health data sits in the employer’s files, the harder it is to prove that a decision had nothing to do with it.

When to call a lawyer

  • when you want to introduce a health, vaccination or test requirement that the law does not provide for;
  • when an employee refuses a health check and you are considering suspension;
  • when health data has reached the wrong people;
  • when an employee asks for working conditions based on a doctor’s conclusion and you do not know what you may check;
  • when you are dismissing an employee whose illness, disability or pregnancy you know about;
  • when VDAI or an employee asks why you keep their health data.

Frequently asked questions

Does an employer need to know what an employee is ill with?

Usually not: the consequences in the Labour Code are tied to the fact and period of incapacity for work, not to the illness (Articles 64(4) and 65(6) DK). A diagnosis collected without a purpose breaches data minimisation (Article 5(1)(c) GDPR). If the employee told you themselves, do not write it down where others can see it.

Can an employer get the results of a medical check from the clinic?

The employer takes into account the conclusion about the work from the institution that checked the employee’s health (Article 25(1)(10) DSSĮ); how it reaches the employer is set by the procedure approved by the Minister of Health (Article 21(5) DSSĮ). Other confidential information about a patient may be given by a health care institution to other persons only with the patient’s written consent, except where a law provides otherwise (Articles 8(4) and 9(1) PTŽSAĮ). The employee has the right to see the results of the checks.

Can we require proof of vaccination?

Article 29(5) DSSĮ only provides that employees in risk groups are vaccinated at the employer’s expense. A certificate may be required only where another law directly provides for vaccination, or proof of it, for the job. In other cases there is no general basis, and relying on the employee’s consent is risky, because in employment it is rarely freely given.

Is it enough that the employee signed a consent?

Usually not. Health data needs explicit consent (Article 9(2)(a) GDPR), and an employee who depends on the employer can rarely refuse freely. If a law provides for the processing, consent is not needed. If it does not, consent usually does not solve the problem.

How to start

List the health data you hold today: certificates, health check conclusions, emails about illnesses, vaccination lists. Next to each, write which law requires it and who can see it. Where you cannot find a law, send us the list – we will tell you what to keep, what to delete and how to restrict access.

You can check whether your organisation needs a record of processing activities with the Privacio tool, built by Linden (in Lithuanian).

Email: info@linden.lt

More about this service: GDPR audit, compliance documents and consultations.

Get a free assessment

Related articles