BEM Records & Data Protection

BEM Records & Data Protection

BEM Records and Data Protection: How Do You Manage BEM Data Legally?

BEM data is health data (Art. 9 GDPR). The legal basis is the employee's consent. The BEM record is kept strictly separate from the personnel file, and access is limited to a minimal circle. The personnel file may only contain the offer, its date, and acceptance/rejection.

What Belongs in Which File?

InformationBEM Record (kept separately)Personnel File
BEM offer with date and proof of deliveryYes — the initiating document of the processYes — as proof that the statutory obligation was met (Section 167 SGB IX)
Acceptance or rejection (only the fact, with date)YesYes — without reasons, without comments
Meeting minutes and discussed contentYes — only hereNo — never
Action plan and effectiveness reviewYes — only hereNo
Diagnoses, medical certificates, medical opinionsOnly to the extent the employee voluntarily provides themNo — never, not even "for information only"
Speculation about causes of illness or reasons for rejectionNo — belongs in no fileNo

BEM Data Is Health Data — What Art. 9 GDPR Requires

Everything documented in the BEM process about an employee's health status — conversation content, limitations, action plans, and especially diagnoses — is health data in the special category under Art. 9 GDPR. It is subject to a fundamental processing ban with narrow exceptions. This is the highest protection level in European data protection law: violations can be sanctioned with fines of up to 20 million euros or 4% of global annual turnover (Art. 83 GDPR).

The valid legal basis for processing BEM data is the employee's consent (Art. 9(2)(a) GDPR). Since BEM itself is voluntary (Section 167(2) SGB IX), the consent logic fits naturally into the process: the employee decides whether to participate — and decides which health-related information to disclose. Consent is only valid if it is informed, freely given, and can be withdrawn at any time (Art. 7 GDPR).

This is why the Federal Labor Court (BAG, case 7 AZR 698/14) requires that the BEM invitation itself already explain the data protection implications: what data is collected, who has access to the results, and how long it will be stored. An invitation without a data protection notice is formally incomplete — the data protection concept is therefore not a downstream administrative matter, but a validity requirement of the BEM process itself.

Important in practice: the employer does not need diagnoses for the BEM process. To determine which workplace accommodations would preserve the employee's ability to work, the effects of the illness on the job are sufficient. Employers who do not collect diagnoses minimize the data protection risk at its root — data minimization is the most effective compliance measure in BEM.

Strict Separation: BEM Record vs. Personnel File

The BEM record is kept separately from the personnel file — a consequence of Art. 9 GDPR and Federal Labor Court case law (ruling of February 7, 2012, case 6 AZR 78/11). The reason: the personnel file is routinely accessed by people who have no business with BEM content — supervisors, payroll, future HR staff. Health-related BEM content in the personnel file is both a data protection violation and an evidentiary problem, because it undermines the defensibility of proper process management.

The personnel file should contain only the procedural record: that a BEM offer was made, on what date, and whether the employee accepted or declined. No meeting content, no details of measures, no reasons for rejection, no health-related information. This lean record is sufficient to prove, in a wrongful-termination proceeding, that the initiation obligation under Section 167(2) SGB IX was met.

Access to the BEM record must be kept to a minimum: only the BEM team or the BEM/BGM coordination — not the direct supervisor, not payroll, not the general HR file. The supervisor only learns what is necessary to implement agreed measures (e.g., changed working hours), not the underlying reasons.

The works council also has no claim to the contents of the BEM record. It is involved in the process only at the employee's request (Section 167(2) SGB IX) and has a general right to information (Section 80 BetrVG) — but the affected employee's data protection takes precedence. The employee, not the works council, decides who participates in the discussion.

Retention, Deletion, and the Role of Systems

BEM records are retained for the duration of the employment relationship and beyond, for the period during which wrongful-termination proceedings remain possible. As a general guideline: at least until the end of the employment relationship plus the three-year statute of limitations for labor court claims; five years from the conclusion of the BEM process is the safer benchmark. Proof of a properly conducted BEM is the employer's central line of defense — it must not be destroyed prematurely.

After this period expires, the opposite applies: BEM data must be actively deleted. Unlimited retention of health data violates the GDPR principle of storage limitation. Deletion deadlines therefore belong in the BEM data protection concept from the outset — and in the data protection notice included with the invitation.

When the BEM record is maintained digitally, the system must deliver three things: role-based access rights (only the BEM team can see content, and the personnel file remains technically separate), an access log (who viewed which record, and when), and audit-proof documentation (invitations, deadlines, responses, and minutes with timestamps that cannot be altered undetected afterward). A shared HR folder or a spreadsheet meets none of these requirements.

In practice, the choice of system determines legal defensibility: paper files in a lockable cabinet are permissible but do not scale — deadline monitoring, follow-ups, and deletion runs remain manual work. A dedicated BEM case management system handles separation, access restriction, and deadline tracking structurally, rather than leaving them to the discipline of individual staff members.

Related measures & topics

Key takeaways

  • BEM data is health data under Art. 9 GDPR — the legal basis is the employee's informed, revocable consent
  • Keep the BEM record strictly separate from the personnel file — the personnel file should contain only the offer, date, and acceptance/rejection
  • Keep the access circle minimal: only the BEM team — not supervisors, not payroll, not the works council unless the employee requests it
  • Retain records until the end of the employment relationship plus the litigation-risk period (3–5 years) — then delete actively
  • Digital BEM records need role-based access rights, an access log, and audit-proof documentation

Frequently asked questions

Does BEM require explicit data protection consent from the employee?+

Yes. BEM data is health data under Art. 9 GDPR — its processing relies on explicit consent (Art. 9(2)(a) GDPR). Consent must be informed: the employee must know in advance what data will be collected, who has access, and how long it will be stored. Under BAG case 7 AZR 698/14, this explanation must already be part of the BEM invitation.

Who is allowed to view the BEM record?+

Only a minimal, pre-defined circle: the BEM team or the BEM/BGM coordination. Not the direct supervisor, not payroll, not the general HR file. The supervisor only learns what is necessary to implement agreed measures. The works council also has no claim to the record's contents — it is involved only at the employee's request.

What may go in the personnel file — and what may not?+

Only the procedural record: the BEM offer, date, acceptance or rejection. No meeting minutes, no details of measures, no diagnoses, no reasons for rejection. This lean entry is sufficient to prove, in a wrongful-termination proceeding, that the offer obligation under Section 167(2) SGB IX was met — everything substantive stays in the separate BEM record.

How long must BEM records be retained — and when must they be deleted?+

For the duration of the employment relationship plus the period during which wrongful-termination proceedings remain possible; in practice at least three years, five years from the conclusion of the process is safer. After that, the data must be actively deleted — health data (Art. 9 GDPR) may not be retained indefinitely. The deletion deadline belongs in the data protection notice included with the invitation.

Can the employee withdraw consent — and what happens then?+

Yes, at any time (Art. 7(3) GDPR). The withdrawal takes effect going forward: further processing of the BEM health data must stop, and the ongoing BEM process cannot continue as before. The procedural record (offer, date, discontinuation) remains documented — as with a rejection, the employer needs this evidence for a possible later wrongful-termination proceeding.

Manage BEM Records Digitally — Separate, Logged, Traceable

EasyBGM manages BEM cases separately from the personnel file, with role-based access rights, deadline monitoring, and traceable documentation — GDPR-compliant.

Sources

Last updated: 2026-07-07. This guide refers to German law (§ 167 SGB IX) and is not legal advice — have your specific case reviewed by a professional.

Read more