
Health Data & GDPR
Which health data may HR analyze — and what does the GDPR prohibit?
Under German law, health data analysis falls under Art. 9 GDPR. Only fully anonymized data (e.g., statutory health insurer reports) is permitted. Individual medical certificates are strictly off-limits for HR analytics.
Permitted vs. prohibited data sources in BGM
| Data Source | GDPR Status | Correct Use in BGM |
|---|---|---|
| Individual medical certificates (sick notes) | Strictly prohibited for HR analytics | Remain in the personnel file — for administrative purposes only |
| Statutory health insurer reports | Legal — if anonymized | From about 20 insured employees per insurer: GDPR-compliant basis for the annual plan |
| Scientifically validated employee surveys | Legal — with the right safeguards | Anonymous external tool, no IP address storage, participation communicated as explicitly voluntary |
| Internal sick-leave statistics (aggregated, anonymous) | Legal | HR may analyze cross-department rates — never at the individual level |
| Diagnoses from medical certificates | Strictly prohibited | Diagnoses do not belong in the HR file — not even 'just for information' |
Why Rising Sick Leave Rates Put HR Under Pressure
Note: this guide explains requirements under German and EU data protection law. When sick leave rates climb, management demands immediate answers. Understandable — but the reflex to dig deeper into personnel data leads straight into a GDPR trap. Art. 9 GDPR classifies health data as a special category, giving it the highest protection level under European data protection law.
HR managers who inadvertently handle sick-note diagnoses, or who create demographic breakdowns fine-grained enough to identify individuals, risk fines of up to €20 million or 4% of global annual revenue — whichever is higher.
The GKV Prevention Guide requires a well-founded baseline analysis for GKV Phase 3 (Checks 23–35). This analysis must be GDPR-compliant and based on anonymized data. Anyone who misreads this and starts cataloging individual employees' causes of illness undermines not only GDPR compliance but also eligibility for statutory health insurer funding.
The Permitted Analysis Tools in Detail
Statutory health insurer sick-leave reports: Under §20b SGB V, statutory health and long-term care insurers are required to support workplace health management — including anonymized health reports. These show aggregated absence rates, diagnosis groups (by ICD-10 chapter), and stress hotspots without identifying individuals. The catch: each insurer generally requires at least 20 insured employees at a company before it will issue a report. At smaller companies, some insurers offer alternative solutions.
Workplace health surveys: Scientifically validated survey instruments such as the COPSOQ (psychosocial workload), SALSA (resources), or a company-adapted short questionnaire are the strongest tools for the baseline analysis. They become legally sound under three conditions: (1) complete anonymity with no IP address storage, (2) explicit voluntariness communicated before the survey, (3) results evaluated only in aggregate for groups larger than 5 people.
Aggregated sick-leave rates: HR may calculate cross-department absence rates and present them to the steering committee. The limit is identifiability: departments with fewer than 5 people may not be reported separately — this also applies to seemingly harmless combinations like 'Department X in Q3.'
The 3-Point Data Protection Safety Check for Surveys
Before an employee survey goes out, this quick check is recommended:
Check 1 — Re-identification test: Could demographic questions (department + age + gender) combine in small groups to identify individuals? Never evaluate groups of fewer than 5 people separately.
Check 2 — Voluntariness clause: Does the survey's landing page clearly state that participation is voluntary and that no IP addresses or timestamps are stored?
Check 3 — Purpose-limitation proof: Is it contractually and technically ensured that the data is used exclusively for BGM measure planning and then deleted? Linking it to performance reviews is a serious GDPR violation.
What to Do When Managers Ask About Diagnoses
A real-world scenario: a department head asks in the steering committee meeting why 'everyone in logistics always seems to be sick.' HR feels pressure to provide concrete answers. The right response is not to pull individual sick-leave data, but to channel the question toward the permitted analysis tools.
In practice: the Health Working Group commissions a short analysis using aggregated data. If available, the relevant insurer's sick-leave report is pulled. If not, a voluntary, anonymous flash survey within the department (respecting the minimum group size) can provide initial indications.
What HR can say: 'We look at the department's anonymized absence rates and compare them to the previous year. We don't look at individual data — that's not permitted under data protection law, and it isn't our goal anyway. The goal is to understand workload, not the causes of individual employees' illnesses.'
Related measures & topics
Key takeaways
- Under German data protection law, individual sick-note diagnoses are absolutely off-limits for HR analytics — not even 'just for information.'
- Statutory health insurer sick-leave reports (from about 20 insured employees) are the cleanest GDPR-compliant analysis tool.
- Surveys require: anonymity, voluntariness, purpose limitation, and works council involvement.
- Groups of fewer than 5 people may never be evaluated individually.
Frequently asked questions
May HR track the number of sick days per employee?+
Yes — under German law, the raw number of sick days (without diagnosis) may be recorded for administrative reasons, e.g., for BEM monitoring (§167 SGB IX requires tracking the 6-week threshold). However, this data may not be used for performance reviews or for analysis purposes beyond the BEM trigger.
What health data may the works council access?+
The works council (Betriebsrat) has a general right to information (§80 BetrVG), but it, too, has no claim to individual diagnosis data. It can request aggregated absence statistics. In BEM proceedings, the works council has a participation right (§167 (2) SGB IX), but the affected employee's data protection remains paramount.
Do we need the works council's approval for the health insurer survey?+
Yes. Under German law, employee surveys fall under §87 (1) No. 6 BetrVG (technical monitoring equipment) and are subject to the works council's co-determination rights. Without the works council's approval, the company risks an injunction. Involving the works council is not an obstacle, though — it typically strengthens the workforce's acceptance of the survey considerably.
Can we conduct a well-founded baseline analysis without a statutory health insurer report?+
Yes. For companies below the reporting threshold, a combination of aggregated internal sick-leave rates (HR monitoring), workplace walkthroughs by the company physician, and a voluntary flash survey is recommended. This combination covers the requirements of GKV Checks 23–35 even without an external health insurer report.
Analyze Health Data — the Right Way
EasyBGM aggregates absences, BEM triggers, and measures in a GDPR-compliant way — without HR ever seeing individual diagnosis data.
Sources
- Art. 9 GDPR — Processing of Special Categories of Personal Data (Health Data) ↗
- §20b SGB V — Workplace Health Promotion: Statutory Health Insurers' Duty to Provide Anonymized Analysis ↗
- §167 (2) SGB IX — BEM Obligation: Sick-Day Tracking as a Legally Permitted Basis ↗
- §87 BetrVG — Co-Determination in Employee Surveys (No. 6: Technical Equipment) ↗
- §80 BetrVG — General Duties of the Works Council (Right to Information) ↗
Last updated: 2026-06-24. Not legal or tax advice — have your specific case reviewed by a professional.