Belgian DPA Publishes Statement Regarding COVID-19 and Workplace-Related Processing of Personal Data
Time 3 Minute Read

On March 13, 2020, the Belgian Data Protection Authority (the “Belgian DPA”) released a statement regarding workplace-related processing of personal data in the context of the COVID-19 crisis (the “Statement”).

The key takeaways from Statement are:

Lawfulness

  • Under the EU General Data Protection Regulation (the “GDPR”), every processing activity must be lawful, even where such processing activities relate to preventive health measures. The Belgian DPA indicated that the “vital interests” legal basis should not be used systematically and cannot be interpreted broadly, even under the current circumstances.
  • The Belgian DPA explained that the lawfulness principle also applies to the processing of sensitive data related to employees’ health. In this respect, companies and employers must keep in mind that the legal basis set forth under Article 9.2 (i) of the GDPR (i.e., the necessity of the processing for reasons of public interest in the area of public health) can only be relied on when acting upon explicit directives imposed by public authorities.
  • The Belgian DPA stated that an assessment of health-related risks should only be performed by the business’ corporate doctor, who is competent to detect infections and inform the employer and the individuals who may have been in contact with the infected employee. Such information can be shared by the doctor with the employer based on Articles 6.1 (c) and 9.2 (b) of the GDPR (i.e., the necessity of the processing to protect the vital interests of the data subjects and for preventive medicine purposes).

Safeguards and General Principles

  • The GDPR’s general data processing principles must be complied with when processing personal data to implement preventive measures related to COVID-19. In particular, companies and employers must ensure that their processing activities are proportionate and that they only collect data that is necessary to achieve the processing purpose (i.e., data minimization).
  • Appropriate information must also be provided to data subjects such as employees or visitors regarding the processing of their personal data, the purposes of the processing and relevant retention period(s) (i.e., transparency).
  • The personal data collected must be adequately protected (i.e., integrity and confidentiality).

FAQ

The Belgian DPA also answered questions it recently received from Belgian citizens and companies. Notably, the Belgian DPA stated that:

  • Companies can conduct body temperature controls with respect to their employees to the extent such checks are voluntary and the employer does not record the data generated by the checks (i.e., which therefore does not constitute a data processing activity within the meaning of the GDPR).
  • Companies cannot force their employees to complete medical questionnaires or questionnaires related to employee’s recent travels. The Belgian DPA recommends that companies encourage their employees to voluntarily report any travels to risky areas or symptoms of the virus.
  • Based on the principles of confidentiality and data minimization, companies cannot reveal names of infected employees but only inform other employees about an infection (without identifying those infected).

Any additional questions regarding the implementation of preventive measures related to COVID-19 can be sent to the Belgian DPA at contact@apd-gba.be.

You May Also Be Interested In

Time 3 Minute Read

The Connecticut Attorney General recently issued a legal memorandum regarding the application of existing Connecticut laws, such as the Connecticut Data Privacy Act, to the use of artificial intelligence.

Time 3 Minute Read

On March 20, 2026, Oklahoma Governor Kevin Stitt signed SB 546 into law, enacting the Oklahoma Consumer Data Privacy Act, which will take effect on January 1, 2027.

Time 2 Minute Read

On March 23, 2026, the UK Information Commissioner's Office released new guidance clarifying the use of the new recognized legitimate interest lawful basis for processing personal information under UK data protection law.

Time 4 Minute Read

Recent changes to 42 CFR Part 2 mean many covered entities must update their HIPAA Notices of Privacy Practices by February 16, 2026.

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Archives

Jump to Page