The Austrian Data Protection Authority weighs in on Coronavirus and GDPR:
- Employers may collect the personal contact information of employees for the purpose of efficient communication during the pandemic. This information may not be used for any other purpose and must be deleted after the pandemic is over.
- Collecting this information is permissible under Art. 6(1)(c), (d) and (f) GDPR and is subject to providing a notice of processing under Art 13 GDPR
- The legitimate interest in question is (a) the reduction of an employee’s health risks in the workplace and (b) the containment of the spread of infection.
- AT provides a sample notice to employees and a sample Art 13 notice with respect to this processing.