Health Data & GDPR

Health Data & GDPR

What health data is HR allowed to analyze — and what does GDPR prohibit?

Analyzing health data falls under Art. 9 GDPR. Only fully anonymized data is permitted (e.g., statutory health insurer sick-leave reports). Individual sick notes are strictly off-limits for HR analytics. Note: this guidance reflects German law.

Permitted vs. prohibited data sources in workplace health management

Data sourceStatus under GDPRCorrect use in BGM
Individual sick notes (Arbeitsunfähigkeitsbescheinigungen)Strictly prohibited for HR analyticsStay in the personnel file — for administrative purposes only
Health insurer sick-leave reports (Krankenkassen-Gesundheitsberichte)Legal — provided it is anonymizedFrom roughly 20 insured employees at one insurer: a compliant basis for the annual plan
Scientifically validated employee surveysLegal — with the right safeguards in placeAnonymous external tool, no IP-address storage, voluntary participation explicitly communicated
Internal sick-leave statistics (aggregated, anonymous)LegalHR may analyze cross-departmental rates — never at the level of individual employees
Diagnoses from medical certificatesStrictly prohibitedDiagnoses do not belong in the HR file — not even 'just for information'

Why rising sick-leave rates put HR under pressure

When sick leave rises, management demands immediate explanations. Understandable — but the reflex to dig deeper into personnel data leads straight into a GDPR trap. Art. 9 GDPR classifies health data as a special category, giving it the highest level of protection under European data protection law.

An HR manager who unintentionally handles sick-note diagnoses, or produces demographic breakdowns so granular that individuals become identifiable, risks fines of up to €20 million or 4% of global annual turnover — whichever is higher.

Germany's statutory prevention guideline (GKV-Leitfaden Prävention) requires a well-founded baseline analysis for GKV phase 3 (checks 23–35). This analysis must be privacy-compliant and based on anonymized data. Anyone who misreads this and starts cataloging individual employees' causes of illness sabotages not only GDPR compliance but also eligibility for funding.

The permitted analysis tools in detail

Health insurer sick-leave reports: Under Section 20b of Book V of the German Social Code (SGB V), statutory health and long-term care insurers are required to support workplace health management — including anonymized health reports. These show aggregated absence rates, diagnosis groups (by ICD-10 chapter), and areas of strain without identifying individuals. The catch: insurers typically require at least 20 insured employees at a company before issuing a report. Some insurers offer alternative solutions for smaller companies.

Workplace health surveys: Scientifically validated survey instruments such as COPSOQ (psychological strain), SALSA (resources), or a company-adapted short questionnaire are the strongest tool for a baseline analysis. They become legally sound under three conditions: (1) full anonymity with no IP-address storage, (2) voluntary participation communicated explicitly before the survey, (3) results analyzed only in aggregate for groups larger than 5 people.

Aggregated sick-leave rates: HR may calculate cross-departmental absence rates and present them in the steering committee. The limit is identifiability: departments with fewer than 5 people may not be reported separately — this also applies to seemingly harmless combinations like 'Department X in Q3.'

The 3-point data-protection safety check for surveys

Before an employee survey goes out, this quick check is recommended:

Check 1 — Re-identification test: Could demographic questions (department + age + gender) allow individuals to be identified within small groups? Never analyze groups of fewer than 5 people separately.

Check 2 — Voluntariness clause: Does the survey's landing page clearly state that participation is voluntary and that no IP addresses or timestamps are stored?

Check 3 — Purpose-limitation proof: Is it contractually and technically ensured that the data is used exclusively for BGM measure planning and then deleted? Linking the data to performance reviews is a serious GDPR violation.

What to do when managers ask for diagnoses

A real-world scenario: a department head asks in the steering committee meeting why 'everyone in logistics always seems to be sick.' HR feels the pressure to provide concrete answers. The right response isn't to pull individual sick-note data, but to channel the request toward the permitted analysis tools.

In practice: the health working group (AK Gesundheit) commissions a short analysis using aggregated data. If available, the relevant health insurer's sick-leave report is pulled. If not, a voluntary, anonymous flash survey in the department (respecting the minimum group size) can provide initial insights.

What HR can say: 'We're looking at the department's anonymized absence rates and comparing them to last year. We do not look at individual data — that's not permitted under data protection law, and it isn't our goal either. The goal is to understand workload, not the causes of individual illnesses.'

Related measures & topics

Key takeaways

  • Individual sick-note diagnoses are absolutely off-limits for HR analytics — not even 'just for information.'
  • Health insurer sick-leave reports (from roughly 20 insured employees) are the cleanest privacy-compliant analysis tool.
  • Surveys require: anonymity, voluntary participation, purpose limitation, and works council involvement.
  • Groups of fewer than 5 people must never be analyzed individually.

Frequently asked questions

May HR track the number of sick days per employee?+

Yes — the raw number of sick days (without diagnosis) may be recorded for administrative reasons, e.g., for BEM monitoring (Section 167 SGB IX requires tracking the 6-week threshold). However, this data may not be used for performance reviews or analysis purposes beyond the BEM trigger.

What health data may the works council view?+

The works council has a general right to information (Section 80 of the Works Constitution Act, BetrVG), but it too has no claim to individual diagnosis data. It can request aggregated absence statistics. For BEM procedures, the works council has a co-determination right (Section 167(2) SGB IX), but the affected employee's data protection remains paramount.

Do we need works council approval for the health insurer survey?+

Yes. Employee surveys fall under Section 87(1) No. 6 BetrVG (technical monitoring facilities) and are subject to works council co-determination. Without works council approval, the company risks an injunction. Involving the works council is not an obstacle, though — it typically strengthens employee acceptance of the survey considerably.

Can we conduct a solid baseline analysis without a health insurer report?+

Yes. For companies below the reporting threshold, a combination of aggregated internal sick-leave rates (HR monitoring), site visits by the company physician, and a voluntary flash survey is recommended. This combination covers the requirements of GKV checks 23–35 even without an external health insurer report.

Analyze health data — the right way

EasyBGM aggregates absences, BEM triggers, and measures in a GDPR-compliant way — without HR ever seeing individual diagnosis data.

Sources

Last updated: 2026-06-24. This guide refers to German law (§ 167 SGB IX) and is not legal advice — have your specific case reviewed by a professional.

Read more