German Firms Told to Lock Down Staff Schedules as Privacy Rules Tighten on Sick-Day Data
Published on 07/21/2026 at 18:08 | Redaktion boerse-global.de
Cloud-based software for managing employee rotas is rapidly replacing the traditional corkboard in German workplaces. Thousands of companies have already switched to password-protected digital platforms developed in Germany that comply with the General Data Protection Regulation (GDPR). These systems allow individual access permissions, so each worker sees only their own schedule. But the shift is driven as much by legal necessity as by convenience: posting a paper duty roster is far more restricted than many employers realise.
What can — and cannot — go on a public schedule
Article 6(1)(b) of the GDPR provides the legal basis for processing employee data when planning working hours, since the activity is necessary for performing the employment contract. Yet that does not give businesses unlimited freedom over what they display. Information about sickness or other absences is strictly forbidden on any public rota. Such details are classified as particularly sensitive under the regulation.
Even the placement of a roster matters. It must be positioned so that only authorised employees can view it. Customers, suppliers or visitors must have no sight of the staffing plan. Without careful controls, a simple photograph taken by a passer-by can violate data-protection rules.
Speaking of data protection and compliance — UK employers face similar scrutiny around how they manage workplace safety documentation. A free Health & Safety Toolkit provides ready-to-use risk assessments and checklists that help you stay compliant with UK regulations. Download the free Health & Safety Toolkit
Works councils have a formal say
The German Works Constitution Act (Betriebsverfassungsgesetz) gives employee representatives a binding right of co-determination. Section 87 of the law covers not only the timing of work but also the method by which schedules are announced. Companies must consult their works council — where one exists — on both the content and the form of publication.
Firms are also expected to take measures that prevent the photographing or copying of displayed rosters. Clear internal guidelines reduce the risk of breaches. In sectors such as nursing, specialised training sessions now teach staff about the hazards of inadvertently exposing colleagues' data.
Bureaucratic hurdles slow down compliance
While many companies are moving to digital solutions, the regulatory environment remains complex. Germany's National Regulatory Control Council (Nationaler Normenkontrollrat) recently criticised the growing volume of digital legislation. More than 1,600 individual obligations and multiple supervisory authorities create a substantial administrative burden.
Navigating complex regulations is a challenge in any country. In the UK, the Health & Safety at Work Act 1974 places specific duties on employers that are easy to overlook. A free toolkit with nine practical tools, including a directors' liability guide and compliance checklists, helps you stay on the right side of the law. Get the free Health & Safety at Work Act 1974 Toolkit
The council has proposed leaving data-protection law itself untouched but consolidating all data-economy regulations into a single central Data Code (Datengesetzbuch). The aim is to help small and medium-sized enterprises especially regain an overview. For HR managers, the core task remains the same: balancing operational needs with the protection of employees' personal information.
Disclaimer regarding our articles: No investment advice, no buy or sell recommendation. Information on prices, companies, and markets is provided without guarantee; changes are possible at any time. Stock market transactions can lead to substantial losses. Our articles are created and reviewed in whole or in part automatically with the support of AI.
