What Do You Need to Consider About Data Protection When Working From Home?

To help contain the COVID-19 pandemic, companies are encouraged to let their employees work from home. Working from home isn't just an organizational challenge — it also raises questions around data protection.

Whether in the office or working from home, companies must adequately protect the data they process. Data protection law doesn't prescribe exactly which measures to take. Instead, every company is required to determine appropriate protective measures itself, based on the data it processes and in consultation with its data protection officer. The Record of Processing Activities, which companies of every size must maintain, provides important guidance.

If the data being processed includes especially sensitive data — first and foremost health data — a high level of protection is required. From a technical standpoint, it's advisable in this case to work only over a Virtual Private Network (VPN). This way, an employee working from home still operates from within the company's hopefully well-secured network. That rules out the risk of a poorly protected home internet connection becoming a gateway for hackers.

Data Protection in the Home Office — the Risks

If a company doesn't provide its employees with a VPN connection, it should at least require them to adequately secure their Wi-Fi with a WPA2 password. Factory-set default passwords are easy to find online, which means they don't offer sufficient protection. Companies are also advised to provide employees with a list of vetted software (e.g., for video conferencing) to make working from home easier. Otherwise, employees will look for suitable software on their own — and it won't always meet data protection requirements.

Technical measures alone, however, aren't enough to deploy employees in the home office in a GDPR-compliant way. Employers are also advised to enter into a formal home-office agreement with their employees. Alongside technical safeguards that employers can require, practical guidelines for working from home should also be established: Does the employee need to work alone in a room? How should they work if no separate room is available? And how are documents disposed of? If they contain personal data, throwing them in the household trash is off-limits.

Since an employee's home remains a legally protected private space even when it's used as a workplace, employers should have access rights granted to them, for example, to maintain IT equipment or check compliance with data protection requirements. Of course, such visits must be limited to absolutely necessary cases and announced in advance.

However, the legal implications of working from home go beyond just needing a home-office agreement. As always, the data protection documents every company must maintain need to be kept up to date — for example, the Record of Processing Activities (mentioned above) and the documentation of technical and organizational measures. Home-office-relevant information (such as the use of a VPN or the instruction to work in a separate room) should be added to these documents. Employee data protection training should also address the home office. After data protection authorities took a fairly hands-off approach to enforcing home-office violations in 2020, the tide appears to have turned. COVID-19, and the shift to home-office work that came with it for many companies, is (unfortunately) no longer a novelty. Fines are a real risk. Companies that haven't yet addressed the data protection implications of home-office work should therefore start doing so now.