Employee Consent: When It Holds Up, When It Does Not

7 min readLast updated By Philipp Staiger

What this is about: consent in the employment relationship

Many Swiss employers have employees sign a blanket consent to the processing of their personal data, often directly in the employment contract. This practice rarely holds up legally. Both the FDPIC (Federal Data Protection and Information Commissioner) and the European Data Protection Board (EDPB) have repeatedly held that consent in the employment relationship can generally not be given freely because of the power imbalance. The correct question is therefore not primarily "How do we obtain consent" but "On what legal basis are we processing employee personal data at all". This guide situates the Swiss DSG (Federal Act on Data Protection / FADP), in force since 1 September 2023, Art. 328b of the Swiss Code of Obligations (OR) and the GDPR, to the extent the latter applies extraterritorially. It shows which legal bases hold up, when consent is nevertheless sensible, and which special rules apply to employee monitoring, applicant selection and health data. For deeper reading we refer to the DSG guide (German-language pillar) and the GDPR guide.

A double regime: DSG and Art. 328b OR

Data processing in the employment relationship is subject in Switzerland to two parallel regimes. The DSG contains the general duties: processing principles under Art. 6 DSG, the duty to inform under Art. 19 DSG, the Records of Processing Activities (ROPA) under Art. 12 DSG, as well as the special duties for automated individual decisions under Art. 21 DSG. Alongside this, Art. 328b OR protects employees' personality rights specifically within the employment relationship. Under this provision, the employer may only process data that either concerns the employee's suitability for the employment relationship or is necessary for performance of the employment contract. This restriction applies on top of the DSG and significantly narrows the employer's room for manoeuvre. For example, processing that could in principle be justified under the DSG is impermissible under Art. 328b OR if it is not suitability- or contract-related. Where employees have a nexus to the European Economic Area, the GDPR additionally comes into play. Art. 88 GDPR allows Member States to enact specific rules for the employment context; the law of the employee's place of work is therefore frequently decisive. Swiss employers must factor in this multi-level structure for every new data processing.

Why consent is rarely freely given

Consent must, under Art. 6(6) DSG, be given freely, for one or more specific processing operations and after adequate information. For personal data requiring particular protection or for profiling with a high risk, express consent is required. In the employment relationship, the freely given character is in doubt. Employees are economically dependent on their employment and fear disadvantages if they refuse to agree. The FDPIC has clarified in several statements that consent in the employment relationship is in principle only effective if its refusal genuinely has no consequences. The EDPB Guidelines 05/2020 on consent formulate the same for the GDPR: consent is "problematic in most cases" in the employment context. The practical consequence: anyone who inserts a blanket consent clause into the employment contract cannot later rely on it. Anyone who obtains a specific consent for a single project must be able to demonstrate that refusal had no professional consequence. Effective consent therefore remains the exception, not the rule. In case of doubt, another legal basis should be chosen or the processing avoided.

The viable legal bases at a glance

Instead of relying on consent, employers should examine the following bases. First, contract performance: data that is necessary for the conclusion or performance of the employment contract may be processed without consent. Under the DSG, this follows from proportionality (Art. 6 DSG) and, in private law, from Art. 328b OR; under the GDPR, Art. 6(1)(b) covers the same situation. This includes payroll, working-time management, expense accounting and the granting of access rights. Second, the legal obligation: social security contributions, withholding tax, pension fund or accident insurance require data processing by operation of law. Third, the overriding legitimate interests, under the DSG Art. 31(1) as a justifying ground and under the GDPR Art. 6(1)(f). This basis supports, for example, information security measures, log file analyses or fraud prevention, but only after a documented balancing of interests. For sensitive personal data (health, religion, biometric data) stricter requirements apply; the GDPR additionally requires an exemption under Art. 9, such as employment and social law. For every HR processing activity we recommend documenting the chosen legal basis in the ROPA and making it transparent to employees in the privacy notice.

When consent is nevertheless the right choice

In clearly delimited cases, consent remains the right choice. The precondition is always that the processing is not necessary for performance of the contract and that employees have a genuine choice. Typical use cases are voluntary wellness or health programmes, such as a step-count contest or a voluntary health check. Likewise, the publication of photo and video material on the website, in brochures or on LinkedIn. Optional benefits such as an employee share programme, a private insurance component or participation in a referral programme also fall within this category. In each of these cases the consent must be specific, informed, freely given and revocable at any time. Withdrawal must not trigger any disadvantage under labour law. In practice this means: a separate consent declaration instead of a contractual clause, a clear description of the purpose, the data and the recipients, separate tick boxes instead of bundled consents, and a low-threshold withdrawal option, for example by email to HR. We also recommend documenting every consent with date, version and content; only then can the legal basis later be evidenced. Anyone employing an international team must verify whether national employment law under Art. 88 GDPR sets additional requirements, such as co-determination or a particular form.

Employee monitoring and HR tools

Workplace monitoring is particularly sensitive. Under Art. 26 of Ordinance 3 to the Swiss Labour Act (ArGV 3), monitoring and control systems intended to monitor employees' behaviour at the workplace are not permitted. Such systems are permitted only if they are necessary for other reasons (such as safety or performance measurement) and are designed so that the health and freedom of movement of employees are not impaired. This labour-protection limit applies on top of the DSG and cannot be overridden by consent. Three tool categories are particularly relevant in practice. First, monitoring software on end-user devices (keystroke tracking, screenshot tools): generally not permitted. Second, communication tools with analytics functions (email analysis, Microsoft 365 Productivity Score at individual level): only permissible in strongly anonymised form. Third, HR analytics platforms with predictions on attrition or performance: where automated decisions are involved, Art. 21 DSG applies, with duties to inform and to be heard. From a security perspective, the risk of data exfiltration is added, since HR systems centrally hold social security numbers, salaries and health data. Technical safeguards with access logging, role-based access control and regular penetration tests are standard. Before introducing any HR tool we recommend a combined review covering labour law, data protection law and security.

Applicant selection, health data, international constellations

Three common constellations deserve dedicated treatment. In the recruitment process, under Art. 328b OR only data necessary for assessing suitability may be collected. Questions on pregnancy, on health without job relevance, or on memberships are not permitted; the applicant may answer such questions untruthfully. Background checks are only permitted to the extent they are suitability-relevant and are carried out after prior information. AI-assisted screening falls within Art. 21 DSG as soon as the pre-selection takes place without human involvement. Health data is sensitive personal data under Art. 5(c) DSG and Art. 9 GDPR. In the employment relationship it may only be processed insofar as it is necessary for fitness for work, the protection of employees or legal obligations (accident insurance, disability insurance notifications). Medical certificates belong in a separate, restrictively accessible personnel file. For international teams: employees in the EU and EEA bring the GDPR into play regardless of the employer's seat. Swiss parent companies that centrally administer personnel data of their EU subsidiaries require Standard Contractual Clauses or another appropriate safeguard, complemented by a Transfer Impact Assessment. EU representation under Art. 27 is frequently required; details are set out in our GDPR guide.

Practical recommendation and support

Our recommendation to HR and management is: work with a documented HR data map instead of relying on blanket consents. Four steps in our experience deliver the greatest impact. First: capture all HR processing activities in the ROPA, with purpose, legal basis, data categories, retention period and recipients. Second: revise the employee privacy notice. It replaces the consent clause and fulfils the duty to inform under Art. 19 DSG and Art. 13 GDPR. Third: cleanly separate consent into its own form for the few cases in which it is genuinely necessary (photos, voluntary programmes, optional benefits). Fourth: train managers and HR officers so that data protection becomes part of day-to-day thinking. This preparation protects against complaints, FDPIC investigations and employment disputes. Those seeking support will find three matching services with us: Swiss data protection advisor for DSG- and OR-compliant HR practice, external EU Data Protection Officer for GDPR constellations, and the data protection workshop for SMEs to upskill your HR team. Foundational depth is provided by our DSG guide (German-language pillar) and the GDPR guide. A clean choice of legal basis protects employees and companies alike.

Employee Consent: When It Holds Up, When It Does Not

INSIGHT

All
5 May 2026
Philipp Staiger
Consent in the employment relationship means the explicit agreement by employees to the processing of their personal data. Because of the power imbalance, it is rarely the right legal basis in Switzerland.

Subscribe to our newsletter for free here

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.