New Ways of Working

Explore and keep track of key legal and compliance considerations for multinational employers as new ways of working become increasingly embedded as the pandemic begins to recede. Learn more about the response taken in specific countries or build your own report to compare approaches taken around the world.

Choose countries

 

Choose questions

Choose the questions you would like answering, or choose all for the full picture.

02. Outline the key data protection risks associated with remote working in your jurisdiction.

02. Outline the key data protection risks associated with remote working in your jurisdiction.

Flag / Icon

France

  • at Proskauer Rose
  • at Proskauer Rose
  • at Proskauer Rose

Employers must ensure the protection of their company’s data but also of employees’ data.

According to article L. 1222-10 of the French labour code, the employer must inform the teleworking employee of the company's rules regarding data protection and any restrictions on the use of computer equipment or tools. Once informed, the employee must respect these rules.

The collective national agreement of 26 November 2020, provides more details in article 3.1.4. It is the employer's responsibility to take necessary measures to protect the personal data of a teleworking employee and the data of anyone else the employee processes during their activity, in compliance with the GDPR of 27 April 2016 and the rulings of the National Commission for Technology and Civil Liberties (the CNIL).

The CNIL said in its 12 November 2020 Q&A on teleworking that employers are responsible for the security of their company's personal data, including when they are stored on terminals over which they do not have physical or legal control (eg, employee's personal computer) but whose use they have authorised to access the company's IT resources.

The National Agreement of 26 November 2020 recommends three practices:

  • the establishment of minimum instructions to be respected in teleworking, and the communication of this document to all employees;
  • providing employees with a list of communication and collaborative work tools appropriate for teleworking, which guarantee the confidentiality of discussions and shared data; and
  • the possibility of setting up protocols that guarantee confidentiality and authentication of the recipient server for all communications.
Last updated on 21/09/2021

Flag / Icon

Greece

  • at Kyriakides Georgopoulos Law Firm
  • at Kyriakides Georgopoulos Law Firm
  • at Kyriakides Georgopoulos Law Firm

Although necessitated by the circumstances, the transition of employees from corporate networks to largely unmonitored and vulnerable private networks outside the reach of perimeter-based security tools finds most employers unprepared and, thus, exposed to greater cyber threats and personal data breaches compared to on-site work. Employers are urged to take into consideration the increased risks a remote working environment poses to their data, systems, and networks and to invest heavily in IT security, while employees are encouraged to carefully follow all IT security guidelines, stay alert to security incidents, and be vigilant with phishing attacks. Within this framework, the Hellenic Data Protection Authority (HDPA) issued “Guidelines for implementing safety measures in the context of teleworking” on 15 April 2020, including appropriate safety measures concerning network access, the use of email or messaging applications, the use of terminal or storage media and how teleconferencing takes place to mitigate data protection risks associated with remote working.

On the other hand, many of these measures may result in more extensive collection and processing (recording, use, disclosure, etc) of employees’ personal data, including monitoring procedures. The key issue for most employers amid these circumstances is to find the right balance between protecting their IT systems and data, on the one hand, and safeguarding the data protection and privacy rights of their employees while working from home on the other.

Last updated on 14/07/2022

10. Are there some workplaces or specific industries or sectors in which the government has required that employers make access to the workplace conditional on individuals having received a Covid-19 vaccination?

10. Are there some workplaces or specific industries or sectors in which the government has required that employers make access to the workplace conditional on individuals having received a Covid-19 vaccination?

Flag / Icon

France

  • at Proskauer Rose
  • at Proskauer Rose
  • at Proskauer Rose

Please see above (questions 8 and 9) regarding the workplaces and specific industries concerned by making the access to the workplace conditional on individuals having received a Covid-19 vaccination.

Last updated on 21/09/2021

Flag / Icon

Greece

  • at Kyriakides Georgopoulos Law Firm
  • at Kyriakides Georgopoulos Law Firm
  • at Kyriakides Georgopoulos Law Firm

Vaccination is mandatory for specific categories of employees (see question 8) as well as all employees working at public and private hospitals. Employees of the health and care sector cannot duly provide their services if they are not vaccinated and their employer is released from their obligation to pay salaries.

Last updated on 14/07/2022