Before deploying invasive employee monitoring, HR skips Works Council consultation in a Member State that requires it. Why does that matter for CIPP/E-level compliance judgment?
Select an answer to reveal the explanation.
Short Explanation
In some EU countries, big monitoring rollouts are not a solo HR project—you talk to the Works Council first. Skipping that local gate can sink an otherwise “GDPR-looking” plan. National employment rules sit beside the GDPR here.
Full Explanation
GDPR sets a common data-protection floor, but employment monitoring often intersects with national labour and co-determination law. Where Works Council or equivalent consultation is required before introducing intrusive systems, omitting that step can render the deployment non-compliant even if some GDPR paperwork exists. Practitioners must map both EU data-protection requirements and applicable national employment procedures.