Data protection in remote work
Data protection in remote work covers the technical and organisational measures with which a controller maintains the level of security required by Art. 32 GDPR outside its own premises – from encrypted devices and VPN access to binding rules for paper records.
The GDPR contains no separate regime for working from home: the employer remains the controller within the meaning of Art. 4(7) GDPR even when the processing happens at a kitchen table. Employees do not become processors; they act as persons under the authority of the controller pursuant to Art. 29 and Art. 32(4) GDPR, which is why a data processing agreement is neither required nor legally possible. German employment law distinguishes two situations that carry different obligations. A "Telearbeitsplatz" under Section 2(7) of the Workplace Ordinance (ArbStättV) is a display screen workstation permanently installed by the employer in the employee's home for an agreed duration and weekly working time, and it falls under Annex No. 6 of that ordinance. Mobile working – on a train, in a hotel, occasionally at home – is outside the ArbStättV but fully inside the scope of data protection law. For the risk assessment the difference still matters: the more variable the place of work, the higher the risk of unauthorised viewing and of device loss.
Technically, Art. 32(1) GDPR requires a level of security appropriate to the risk, preserving the availability, integrity and above all the confidentiality of data outside the controlled office environment. Today's baseline includes full disk encryption on all endpoints, encrypted remote access via VPN or a zero-trust architecture, multi-factor authentication, centrally managed devices with mobile device management, enforced screen lock and remote wipe, current patch levels, and storage exclusively on company systems rather than local drives or private cloud accounts. The home router and wireless network are part of the attack surface and should be covered by minimum requirements: WPA2 or WPA3, a changed default password, current firmware. The analogue side is routinely underestimated: printouts, notes and files need a lockable storage place, a rule for transport and destruction in line with DIN 66399 rather than the household bin. Privacy filters, screen positioning, a ban on use by family members and a deliberate approach to voice assistants and video calls in living spaces complete the picture. Germany's BSI IT-Grundschutz provides a workable control set in its modules OPS.1.2.4 (teleworking), INF.8 (home workplace) and INF.9 (mobile workplace).
Organisationally, the controller carries the accountability obligation of Art. 5(2) and Art. 24 GDPR: measures must not only work, they must be demonstrable. That means a written remote-work policy with clear rules on device use, data storage, paper records and incident reporting, a confidentiality commitment signed by staff, recurring training, and inclusion of the remote-work scenario in the description of technical and organisational measures accompanying the record of processing activities. Art. 32(1)(d) GDPR calls for regular testing of effectiveness – and this runs into a constitutional limit at the front door, because Art. 13 of the German Basic Law protects the inviolability of the home. A right of access exists only where it has been agreed individually or in a works agreement and is exercised with prior notice; self-assessments, checklists and technical evidence from device management are the more practical route. Works council co-determination also applies: Section 87(1) no. 14 of the Works Constitution Act covers the arrangement of mobile work, and Section 87(1) no. 6 covers any technical system capable of monitoring behaviour or performance – which regularly includes attendance, monitoring and productivity tooling. For employee data itself, Section 26 BDSG remains the relevant national provision; a dedicated employee data protection act has been announced several times but has not entered into force.
Legal Basis
Art. 5(1)(f), Art. 5(2), Art. 24, Art. 29, Art. 32, Art. 33 GDPR; Section 26 BDSG; Section 2(7) and Annex No. 6 ArbStättV (German Workplace Ordinance); Section 87(1) nos. 6 and 14 BetrVG (Works Constitution Act); BSI IT-Grundschutz OPS.1.2.4, INF.8, INF.9
Practical Example
A tax advisory firm with 90 employees introduces two fixed remote-work days per week. The data protection officer treats this not as a new processing activity but as a change of processing environment, and updates the documentation of technical and organisational measures attached to the record of processing activities. Technically the firm moves to encrypted laptops under mobile device management, VPN access with multi-factor authentication, a five-minute screen lock and a complete ban on local storage; client files stay in the document management system. Because paper documents still arrive at the office, taking original records home is prohibited and replaced by a scanning workflow – the single exception for field staff is tied to a lockable document case and a transport log. On the organisational side the firm produces a six-page remote-work policy, a renewed confidentiality commitment referencing the professional secrecy provision of Section 203 of the Criminal Code, and a 45-minute mandatory training. A works agreement under Section 87(1) no. 14 BetrVG is concluded with the works council and states explicitly that attendance data will not be evaluated for performance monitoring. The firm deliberately forgoes a right of access to employees' homes and replaces it with an annual self-assessment including photographic evidence of the lockable cabinet.