Workplace Investigations

Contributing Editors


Workplace investigations are growing in number, size and complexity. Employers are under greater scrutiny as of the importance of ESG rises. Regulated industries such as finance, healthcare and legal face additional hurdles, but public scrutiny of businesses and how they treat their people across the board has never been higher. Conducting a fair and thorough workplace investigation is therefore critical to the optimal operation, governance and legal exposure of every business.

IEL’s Guide to Workplace Investigations examines key issues that organisations need to consider as they initiate, conduct and conclude investigations in 29 major jurisdictions around the world.  

Learn more about the response taken in specific countries or build your own report to compare approaches taken around the world.

Choose countries

 

Choose questions

Choose the questions you would like answering, or choose all for the full picture.

07. What data protection or other regulations apply when gathering physical evidence?

07. What data protection or other regulations apply when gathering physical evidence?

Flag / Icon
Finland

Finland

  • at Roschier
  • at Roschier

Generally, the basic principles set out by the GDPR and the Finnish Data Protection Act apply to data processing in connection with investigations, including evidence gathering: there must be a legal basis for processing, personal data may only be processed and stored when and for as long as necessary considering the purposes of processing, etc.

Additionally, if physical evidence concerns the electronic communications (such as emails and online chats) of an employee, gathering evidence is subject to certain restrictions based on Finnish ePrivacy and employee privacy laws. As a general rule, an employee’s electronic communications accounts, including those provided by the employer for work purposes, may not be accessed and electronic communications may not be searched or reviewed by the employer. In practice, the employer may access such electronic correspondence only in limited situations stipulated in the Act on Protection of Privacy in Working Life (759/2004), or by obtaining case-specific consent from the employee, which is typically not possible in internal investigations, particularly concerning the employee suspected of wrongdoing.

However, monitoring data flow strictly between the employee and the employer's information systems (eg, the employee saving data to USB sticks, using printers) is allowed under Finnish legislation, provided that employee emails, chats, etc, are not accessed and monitored. If documentation is unrelated to electronic communications, it also may be reviewed by the employer. Laptops, paper archives and other similar company documentation considered "physical evidence" may be investigated while gathering evidence on the condition that any private documentation, communications, pictures or other content of an employee are not accessed.

Last updated on 15/09/2022

Flag / Icon

Spain

  • at Uría Menéndez
  • at Uría Menéndez

The General Data Protection Regulation and the Spanish Data Protection Law apply when gathering any type of evidence, including physical evidence. This means that companies may only process personal data when they have lawful grounds to do so and within the limits set forth for special categories of personal data (health, union affiliation, criminal records, etc.).

The Spanish Statute of Workers specifically states that employees and their possessions may be registered when it is necessary to protect the companies’ property (or the property of other co-workers). This registration must:

  • be conducted in the workplace and during working hours;
  • respect the employee’s privacy and dignity; and
  • be performed in front of an employee representative or, if not possible, in the presence of another employee of the company.
Last updated on 15/09/2022

21. How do you handle a parallel criminal and/or regulatory investigation?

21. How do you handle a parallel criminal and/or regulatory investigation?

Flag / Icon
Finland

Finland

  • at Roschier
  • at Roschier

Regardless of a possible criminal investigation, the employer must run its internal workplace investigation without unnecessary delay. A workplace investigation and a criminal investigation are two separate processes and can be ongoing simultaneously, so the criminal process does not require the workplace investigation to be stayed. Thus, parallel investigations are to be considered as two separate matters. The police may only obtain evidence or material from the company or employer if strict requirements for equipment searches are met after a request for investigation has been submitted to the police.

Last updated on 15/09/2022

Flag / Icon

Spain

  • at Uría Menéndez
  • at Uría Menéndez

Criminal or regulatory investigations may (and usually do) run in parallel to workplace investigations.

There is no need to stay the internal investigation and, in practice, this normally is not possible or advisable considering the substantially longer timeframe of criminal or regulatory investigations (which can extend for several months or years).

The police or a regulator may request a company to share any relevant information that it might have on the facts being reviewed by them. However, the company’s obligation to provide that information would have to be reviewed on a case-by-case basis, depending on the information being requested (eg, whether it is sensitive to the business, such as trade secrets or internal correspondence) and the grounds to do so (if the police or regulator have a search warrant issued by a court or not).

Last updated on 15/09/2022