The General Data Protection Regulation (GDPR) generally prohibits the processing of data relating to, e.g., sexual orientation, religious affiliation, or ethnic backgrounds. In practice, this can be an obstacle for inclusion and diversity initiatives
In today’s challenging labor market, companies are asking themselves how they can become even more attractive to applicants and employees from diverse backgrounds. In the corporate world, this is referred to as diversity and inclusion and is often the subject of group-wide initiatives. These initiatives stem from the recognition that people belonging to minority groups historically underrepresented in the corporate world and in leadership roles often have needs that not only differ from the needs of the (relative) majority, but remain also unknown to this majority.
Equal treatment can be discriminatory
The effort to meet the individual needs of each employee, especially considering their minority background, is the subject of discussion across the globe under the term “woke” (which is defined as being actively alert to injustice and discrimination). It is increasingly recognized that treating everyone “equally” is often driven by the best of intentions, but can easily lead to forms of both unconscious and conscious discrimination. This is because equal treatment is traditionally based on the needs of the (relative) majority of the employees, ignoring that the equal treatment of substantially different groups leads to inequal treatment and, hence, to discrimination.
For example, a company retreat scheduled on the Saturday on which the Pride parade takes place would not appear to be a scheduling conflict to many employees, while members of the LGBTIQ community (and those who advocate for them) would perceive this as a discriminatory restriction on private activities. Similarly, an internal company policy on “paternity leave” would be perceived as discriminatory by mothers who do not give birth to the child – in the international context, this is referred to as “non-birthing parent”.
To better understand the extent of the challenges within their own organization, companies could consider conducting surveys among – employees – covering satisfaction levels and analyzing the results across ethnic backgrounds, sexual orientation and religious affiliation. After all, only those who know where the challenges lie can tackle them effectively. For example, if the organization loses an above-average number of Muslim employees, there are clear starting points for necessary changes. However, the right countermeasures can only be taken if the underlying cause is known.
Staff surveys and data protection
However, this inevitably means collecting information that qualifies as “sensitive” data under the GDPR. This includes, in particular, ethnic origin, religious beliefs, health data or data relating to sexual orientation. The GDPR only permits the processing (and therefore the collection) of this data in very limited cases.
One of the justifications for the processing of sensitive data under the GDPR is a legal obligation. Discrimination on the basis of ethnicity, religious beliefs or sexual orientation is prohibited under Equal Treatment Acts in various EU jurisdictions (e.g., the Equal Treatment Acts in Austria and Germany) implementing a variety of EU Directives. Yet, there is no legal obligation to actively promote diversity and inclusion as an employer. This means that there is no legal obligation as a basis for data processing. The consent of the data subject is not a valid justification either. According to the prevailing view, such consent given by employees is not sufficiently free from employment-related constraints and is therefore invalid. Asking pertinent questions may correspondingly be qualified as illegitimate, for example to applicants.
For companies that aim to comply with the GDPR, another option is to resort to a works agreement (i.e., ”collective agreements” as provided for in Art. 88(1) GDPR). According to Art. 88(1) GDPR Member States may, by law or by collective agreements, and within the guardrails of Art. 88(2) GDPR inter alia, provide for more specific rules as regards the processing of personal data in the employment context for the purposes of equality and diversity in the workplace. Insofar as employer and works council agree to allow the company to process the aforementioned sensitive data to promote diversity and inclusion, companies can indeed collect this data and respond to the associated special needs of the employees. This ranges from the consideration of religious dietary requirements in Islam or Judaism to religious fasting periods, for example in Ramadan or before Easter in Christianity, to the needs-based individualization of working hours. While this option sounds promising the ECJ has recently shown a critical attitude when it comes to Member States’ (in the specific case, Germany’s) use of the opener clause in Art. 88(1) GDPR (cf., in C-34/21 of March 30, 2023) and, moreover, a collective agreement always has to respect the employees’ fundamental rights (cf. Art. 88(2) GDPR).
That said, if no works council has been established or if the national law in the respective member state does not recognize the institution of a works council, the collection of such data about the company’s employees is, in principle, inadmissible . In addition, in countries where the processing of such ”sensitive data” is only allowed when mandated by law and there’s no such law in place, this processing would be unlawful. It is therefore fair to argue that the GDPR is based on the misconception that treating everyone equally will create a positive, inclusive working environment that values people in their individual characteristics.
A legislative amendment is needed
The lively discussion about diversity and inclusion that has been taking place around the world has shown that not taking into account the reality of the lives of people belonging to minorities is detrimental to equal opportunities and leads to companies losing valuable employees. This results not only in a disadvantage for society as a whole, but also an economic disadvantage for companies that have not yet recognized the potential of a more inclusive workplace culture.
In order to improve the current legal situation, it would be worth introducing explicit legal provisions that allow the collection of sensitive data for the purpose of promoting diversity and inclusion. In view of preventing misuse, certain data protection and data security requirements, which must be strictly defined, would have to be met. The existing rules on data processing for statistical purposes could serve as a point of reference, but require some clarification. According to the wording of the law (Art. 89 GDPR), the collection of sensitive personal data for statistical purposes is currently only permitted in limited circumstances. However, as this approach is often not realistic, improvements would have to be made here. Diversity and inclusion objectives constantly require us to question traditional structures and look for improvements. This also holds true for established legal or regulatory frameworks such as the protection of sensitive personal data under the GDPR. Without this critical examination, , we risk settling for good intentions instead of achieving genuine inclusion.
This is the second post in our three-part blog series. Links to access both preceding and subsequent installments (once they are published) are conveniently provided below:
- The protection of gender identity under the GDPR (publish date: 28 June)
The post GDPR compliance and inclusion: striking the right balance appeared first on Connect On Tech.