AI & Health Data
May AI analyze my employees' health data — what do the GDPR and the AI Act allow?
Under German law, AI may analyze employee health data only under strict conditions: explicit consent (Art. 9 GDPR), aggregation for the employer starting at 5 people, no emotion recognition (banned since Feb. 2025), reintegration-management (BEM) data off-limits, works council and DPIA required before rollout.
The legal framework for AI in workplace health management at a glance
| Rule | What it requires | Consequence for AI in workplace health management (BGM) |
|---|---|---|
| Art. 9 GDPR | Fundamental prohibition on processing health data, with only narrow exceptions | No personal AI analysis without explicit, voluntary, and revocable consent |
| CJEU C-413/23 P (2025) | Data without a realistic means of re-identification is anonymous for the recipient | Evaluations only in aggregate, for groups of 5 or more — then the employer's view falls outside GDPR scope |
| Art. 5 AI Act (in effect since Feb. 2, 2025) | Ban on emotion recognition in the workplace | No inferring stress or mood from heart-rate variability, speech, camera, or behavior |
| Annex III AI Act | AI assessment of individual employees = high-risk system | Avoid individual scores — or meet the full compliance catalog (risk management, logging, human oversight) |
| Section 87(1) No. 6 BetrVG (Works Constitution Act) | Co-determination for technical systems capable of monitoring | No AI rollout without works council involvement — otherwise risk of an injunction claim |
| Section 167(2) SGB IX | Special confidentiality of the reintegration-management (BEM) process | Technically exclude BEM data from any AI analysis — no exceptions |
| Art. 35 GDPR | Data protection impact assessment for high-risk processing | AI + health data + employees triggers several mandatory criteria on the DPA list — a DPIA is mandatory before go-live |
Why more and more companies are banning internal AI analysis of health data
At many companies, internal agreements or policies now categorically exclude AI from processing health data — often initiated by the works council, data protection officers, or reintegration-management (BEM) leads. This is not an isolated case: according to the Cisco Data Privacy Benchmark 2024, 35% of German companies have banned generative AI outright, and 76% restrict what data may be entered — mainly out of data-protection concerns.
The skepticism runs through every level. A representative Bitkom survey (November 2025) shows that 71% of people in Germany worry about data misuse when AI is used in a health context. At the same time, 46% would be willing to provide their health data for AI use — trust exists, but only under demonstrable conditions.
Views among decision-makers are similarly split: in the 2025 #whatsnext study (IFBG/Techniker Krankenkasse), only 50.5% of respondents consider AI helpful in health management — among health managers it's 62.4%, but only 34.0% among executive leadership. The lesson: the problem isn't the AI itself, but the lack of demonstrable control over what it can see. Whoever can prove that control turns an internal ban into informed consent.
What the GDPR allows — and where the red line runs
Under Art. 9 GDPR, health data is a special category of personal data subject to a fundamental prohibition on processing. In voluntary workplace health management, practically only one exception carries weight: employees' explicit, informed, and voluntary consent (Art. 9(2)(a)). It must be revocable at any time, and non-participation must not result in any disadvantage. The legislative rationale for the German Federal Data Protection Act (BDSG) explicitly cites workplace health management as a case where the recognizable benefit to employees supports voluntariness.
The Court of Justice of the EU has cleared up two common misconceptions. First, Section 26 BDSG has become uncertain as a sole legal basis since the CJEU (C-34/21, 2023) declared a structurally similar provision incompatible with EU law. Second, a works agreement cannot substitute for consent: under CJEU C-65/23 (2024), collective agreements must themselves be fully GDPR-compliant and cannot lower the level of protection. A works agreement governs the process — it does not supply the legal basis for processing the data.
The decisive lever in practice is anonymization through aggregation: in 2025 (C-413/23 P), the CJEU confirmed the concept of relative personal reference. Data that the recipient cannot, using reasonable means, attribute to any individual is not personal data for that recipient. Concretely: if the company sees only aggregated evaluations from a minimum group size of 5 people — without access to raw data or a mapping key — that view falls outside the scope of the GDPR. Aggregation at a group size of 5 is therefore not a cosmetic measure but a different legal category altogether.
In every case, before launch: a data protection impact assessment under Art. 35 GDPR is mandatory. The German Data Protection Conference's (DSK) mandatory list covers AI used to assess individuals, extensive processing of health data, and analysis of employee data — an AI-driven BGM scenario meets several of these criteria at once.
What the EU AI Act additionally regulates — including an outright ban
Since February 2, 2025, Art. 5 of the AI Act has banned AI systems that infer emotions in the workplace, with narrow exceptions only for medical or safety purposes. This covers exactly the features some BGM providers currently advertise: systems that 'detect stressors' from heart-rate variability, camera-based vital-sign measurement, speech, or behavioral data and then intervene move dangerously close to — or squarely inside — this prohibited zone. Violations of Art. 5 can cost up to €35 million or 7% of global annual turnover.
In addition, Annex III of the AI Act classifies AI systems as high-risk if they evaluate individual employees' performance or behavior, or influence decisions about working conditions. An AI that produces individual health or absence forecasts for employer decisions very likely falls into this category — triggering the full compliance catalog: risk management, technical documentation, logging, human oversight, and informing employee representatives before deployment.
Important for planning: the high-risk obligations were originally meant to take effect in August 2026; in May 2026, the Council and Parliament agreed in the Digital Omnibus to postpone the deadline for stand-alone Annex III systems to December 2027 — the substantive requirements remain unchanged. The emotion-recognition ban is unaffected and already applies. The architectural decision is therefore on the table now: companies that limit AI to aggregated organizational analysis without evaluating individuals can avoid the high-risk classification altogether.
Works council and BEM: the two special zones
Under settled case law, AI analytics on employee data is practically always a technical system objectively capable of monitoring behavior or performance — which triggers mandatory co-determination under Section 87(1) No. 6 BetrVG, regardless of whether any monitoring intent actually exists. Without a works agreement, the company risks an injunction claim. The constructive path is to involve the works council early and use the agreement as a quality feature. Bitkom's guide "AI and Co-Determination" (2026) provides the cornerstones for this.
One zone remains completely off-limits: workplace reintegration management (BEM). Under Section 167(2) SGB IX, BEM data enjoys heightened confidentiality — a strictly separate file, narrow purpose limitation, and staged consent at each procedural step. Any AI analysis of BEM content would be a purpose-changing processing of highly sensitive data without a legal basis and would destroy the trust that BEM depends on. The only permissible exception is diagnosis-free deadline tracking: detecting the 42-sick-day threshold that triggers a BEM offer is monitoring required by law — the substance of the process itself belongs behind a technical barrier that even AI cannot open.
Employees themselves are further along than many assume: according to the WIdO/AOK Absence Report 2025, 42% of employees already experience AI at their own workplace — yet fewer than 40% of employees at AI-using companies have received training. Training and transparency are therefore not optional extras but the lever for acceptance.
Best practice: the 4-tier model for AI data access
The legal landscape and practical experience point to a clear architectural pattern that is becoming best practice: instead of switching AI on or off wholesale, each data category is individually assigned a level of visibility the AI may have — and these rules are technically enforced before the data ever reaches the AI model.
The crucial point is the last one: an instruction to the AI ("respect data protection") is not a technical and organizational measure within the meaning of the GDPR. Enforcement must happen in the data layer — whatever the AI must not see is filtered out or aggregated before it reaches the request. Internal AI policies and works agreements can then be encoded as machine-readable rules: the prohibition isn't just on paper, it's enforced in the system.
EasyBGM works exactly according to this pattern: raw health data such as sick days, diagnoses, or BEM status are technically hard-locked from the AI, survey results are only evaluated in aggregate for groups of 5 or more, and AI data access is controllable and documented per data category — including a transparency view showing what the AI can and cannot see. That makes the DPIA defensible and gives the works council verifiable evidence instead of a promise.
- Tier 1 — Full access: only for non-critical data (e.g., program catalog, budgets, deadlines), never for health data
- Tier 2 — Pseudonymized: names and identifiers are replaced before AI processing; the mapping key stays outside the AI
- Tier 3 — Aggregated (k ≥ 5): the AI sees only group values from 5 people or more — per CJEU C-413/23 P, this view falls outside the GDPR
- Tier 4 — Locked: the data category never reaches the AI; for BEM data, this is the only permissible setting
- Enforcement happens in the data layer, not via prompt — plus logging of every AI data access
Related measures & topics
Key takeaways
- This guide reflects German law. Personal AI analysis of health data requires explicit, voluntary consent — Section 26 BDSG and a works agreement alone are not sufficient.
- Aggregation at a group size of 5 is the legal game-changer: per CJEU C-413/23 P, the employer's view falls outside the scope of the GDPR.
- Emotion recognition in the workplace has been banned since February 2025 — inferring stress from HRV, camera, or speech is not a gray area.
- Works council involvement (Section 87 BetrVG) and a DPIA (Art. 35 GDPR) come before rollout, not after; BEM data remains fully locked from AI.
- Best practice is the 4-tier model (full / pseudonymized / aggregated / locked) — technically enforced in the data layer, not by instructing the AI.
Frequently asked questions
Can we simply evaluate sick-leave data with ChatGPT?+
No. Entering personal health data into a public AI chatbot is a transfer to a third party without a legal basis and without a data processing agreement — a clear Art. 9 violation. Evaluation is only permitted in a controlled environment with a data processing agreement and EU-based processing, and even there only anonymized and aggregated (groups of 5 or more) or with the explicit consent of the individuals concerned.
Is AI-based stress detection via wearable or camera allowed?+
As a rule, not in the workplace. Since February 2025, Art. 5 of the AI Act has banned AI systems that infer emotions in the workplace; the exceptions for medical or safety purposes are narrow and do not cover general wellbeing monitoring by the employer. Anyone inferring stress levels from heart-rate variability, camera-based vital-sign measurement, or speech behavior risks fines of up to €35 million or 7% of annual turnover.
Is a works agreement sufficient as a legal basis for AI analysis?+
No. Under CJEU C-65/23, works agreements must themselves be fully GDPR-compliant and cannot lower the level of protection. A works agreement governs process, limits, and oversight rights — the legal basis for processing personal health data remains employees' explicit, voluntary consent. Anonymized, aggregated evaluations without personal reference, however, require no consent.
Does the works council have to approve AI use in workplace health management?+
Yes. AI systems that process employee data are practically always objectively capable of monitoring behavior or performance and are therefore subject to mandatory co-determination under Section 87(1) No. 6 BetrVG — regardless of any actual monitoring intent. There are also information rights that apply as early as the planning phase (Section 90 BetrVG). Without involvement, the company risks an injunction claim from the works council.
Can AI support the BEM process at all?+
Only outside the confidential content: diagnosis-free detection of the 42-sick-day threshold (Section 167(2) SGB IX), deadline tracking, and template generation are permitted. The substance of the BEM process itself — meeting notes, diagnoses, and action plans in the BEM file — is off-limits to any AI analysis and should be technically locked, not just organizationally restricted.
AI in Workplace Health Management — with Demonstrable Control
EasyBGM technically locks raw health data away from the AI, evaluates data only in aggregate for groups of 5 or more, and makes AI data access controllable per data category — the verifiable basis for the works council and DPIA.
Sources
- Art. 9 GDPR — Processing of Special Categories of Personal Data ↗
- Art. 35 GDPR — Data Protection Impact Assessment ↗
- Section 26 BDSG — Data Processing for Employment Purposes ↗
- Art. 5 AI Act — Prohibited Practices (incl. Emotion Recognition in the Workplace) ↗
- DSK Guidance "AI and Data Protection" (June 2025 edition, PDF) ↗
- HBDI Hesse on CJEU Ruling C-413/23 P (Anonymity of Pseudonymized Data) ↗
- SKW Schwarz on CJEU Ruling C-65/23 (Works Agreements and GDPR) ↗
- Gibson Dunn: Digital Omnibus — Postponement of AI Act High-Risk Deadlines ↗
- Bitkom Press Release "Dr. AI" (November 2025): Concern About Data Misuse, Willingness to Donate Data ↗
- #whatsnext Study 2025 (IFBG/Techniker Krankenkasse, PDF): AI in Health Management ↗
- Cisco Data Privacy Benchmark 2024: GenAI Bans and Input Restrictions at German Companies ↗
- WIdO/AOK Absence Report 2025: AI and Health in the World of Work ↗
- Bitkom Guide "AI and Co-Determination — Cornerstones of a Works Agreement" (2026, PDF) ↗
- Section 167(2) SGB IX — Workplace Reintegration Management ↗
- Section 87 BetrVG — Works Council Co-Determination Rights ↗
Last updated: 2026-07-06. Not legal or tax advice — have your specific case reviewed by a professional.