• Contact
  • Newsletter
  • linkedin_a955101832.webpinstagram_c89d1c13f3.webpTikTok.svgyoutube_b9af0f4a2e.webp
  • Product
    • All-In-One Compliance Solution

      All-In-One Compliance Solution

    • GDPR

    • nFADP

    • ISO 27001

    • EU AI Act

    • NIS2

    • UK GDPR

    • Whistleblowing

  • Services
    • Data Protection Documentation

      Data Protection Documentation

    • External Data Protection Officer

    • Data Protection Consultation

  • Prices
  • Resources
    • Data Protection Basics

    • Compliance Blog

    • Whitepapers

    • Studies

    • Customer Stories

    • FAQs

  • Company
    • About Us

    • Partner

    • Careers

    • Contact

    • Press

Data Protection and Home Office
Data ProtectionCybersecurity & Risk Management

What do you need to know about data protection when working from home?

252x252_arthur_heydata_882dfef0fd_c07468184b.webp
Arthur
27.01.2023
Share via LinkedIn

What do you need to know about data protection when working from home?

To contain the COVID-19 pandemic, companies are forced to let their employees work from home. Working from home is not only an organizational challenge but also raises data protection issues. 

Whether in the office or at home, companies must protect the data they process. However, data protection legislation does not prescribe which specific measures are to be taken. Rather, each company is required to determine the appropriate protective measures based on the data processed and in consultation with its data protection officer. The processing directory to be maintained by companies of any size offers important guidance.

If the data processed includes sensitive data - especially health data - high protection measures must be taken. From a technical point of view, it is advisable in this case to work exclusively via a virtual private network (VPN). Here, an employee works from his home office on the hopefully well-secured company network. This eliminates the risk that the poorly protected home Internet connection becomes an entry point for hackers.

Data protection in the home office - the risks:

If a company does not provide its employees with a VPN connection, it should at least encourage them to protect their WLANs with a WPA2 password. Default passwords are easy to find on the Internet. They therefore do not offer sufficient protection. Companies are also advised to provide their employees with a list of tested software (e.g. for video conferencing) that makes working from home easier. Otherwise, employees will look for suitable software themselves. This will not always comply with data protection regulations. 

However, purely technical means are not sufficient to enable employees to work from home in a data-compliant manner. It is also advisable for employers to conclude an agreement with their employees on working from home. In addition to the technical measures that employers can require their employees to take, they should also lay down practical guidelines for working from home: Must the employee sit alone in a room when working? How should he work if there is no separate room available? And how should documents be disposed of? If they contain personal data, they are off-limits. 

Since an employee's home is still a legally protected place of retreat even if he or she is working there, employers should have access rights, e.g. to maintain IT equipment or to check compliance with data protection regulations. Of course, visits must be limited to necessary cases and must be announced in advance.

However, the legal implications of the home office are not limited to the need for a home office agreement. As always, the data protection documents that every company has to maintain must be kept up to date, e.g. the (already mentioned) data processing directory and the documentation of the technical and organizational measures. Information relevant to the home office (e.g., the use of a VPN or the instruction to work in a separate room) should be included in these documents. In 2020, the data protection authorities were reluctant to pursue data protection violations in the home office, but the tide may have turned. COVID-19 and the associated move to the home office for many companies is (unfortunately) no longer a novelty. Fines are looming. Companies that have not yet reacted to home office work from a data protection perspective should start doing so now.

Compliance Newsletter

Subscribe to our newsletter now and stay updated with the latest insights on data protection, GDPR, cybersecurity, and other important compliance frameworks like revDSG, NIS 2, and ISO 27001. Get expert tips, exclusive resources, and access to regular webinars. Don’t miss out on crucial news and developments!

Follow us on social media to stay up to date

  • Instagram
  • Linkedin
  • TikTok
  • YouTube

Product
  • All-in-one compliance solution
    • Document Vault
    • Vendor Risk Management
    • Data Protection Audit
    • Compliance Trainings
    • HR Integration
  • GDPR
  • nFADP
  • ISO 27001
  • EU AI Act
  • NIS2
  • UK GDPR
  • Whistleblowing Tool
Services
  • Data protection documentation
    • Data Privacy Policy
    • Technical and Organizational Measures
    • Data Protection Impact Assessment
    • Record of Processing Activities
    • Data Processing Agreement
  • External data protection
  • Data protection consultation
Prices & Packages
  • Prices & Packages
Resources
  • Data Protection Basics
  • Compliance Blog
  • Whitepapers
  • Studies
  • Customer Stories
  • FAQs
Company
  • About us
  • Partner
  • Careers
  • Press
  • Contact
  • Proven Expert Logo
  • Marktplatz Mittelstand Logo
  • Bundesverband  IT Mittelstand Logo
  • Bitkom Logo
  • BvD e.V. Mitglied Logo
  • Type=Startup Verband.svg
  • Type=German Accelerator.svg
  • heyData-GDPR.svg
  • heyData-EU_AI_Act.svg
  • heyData-Whistleblowing.svg

Social
Icon to view our LinkedIn profile
Icon to view our Instagram profile
TikTok.svg
Icon to view our YouTube profile

© 2025 heyData. Alle Rechte vorbehalten.

  • Imprint
  • Privacy Policy