Data portability between employers.

 

Data Portability Between Employers

Data portability between employers refers to the ability of an employee to obtain, transfer, or reuse personal and employment-related data from one employer or HR system to another employer, subject to applicable privacy, employment, confidentiality, and data-protection laws.

Employee data may include identification details, contact information, employment history, qualifications, salary information, performance records, training records, attendance information, benefits information, and other HR-related information. However, not every piece of information held by an employer is automatically portable.

1. Meaning and Scope

Data portability generally involves three stages:

  1. Access – The employee obtains a copy of personal data held by the previous employer.
  2. Transfer – The data is provided in a structured or commonly usable format or transferred to another organisation where legally permitted.
  3. Reuse – The employee or new employer uses the transferred information for legitimate employment purposes.

For example, an employee changing jobs may want to transfer employment history, professional certifications, training records, or payroll-related information to the new employer.

2. Data That May Be Portable

Potentially portable information can include:

  • Employee identification information.
  • Contact details.
  • Employment dates and job titles.
  • Qualifications and certifications.
  • Training records.
  • Payroll and benefits information where legally appropriate.
  • Leave and attendance records.
  • Employee-generated information.
  • Certain performance or career-development information.

However, portability may be restricted where the information contains:

  • Confidential business information.
  • Trade secrets.
  • Personal information relating to other employees.
  • Privileged legal communications.
  • Confidential references.
  • Proprietary assessments or internal management material.
  • Information whose disclosure would violate another person's rights.

3. Data Portability Under the GDPR

The EU General Data Protection Regulation (GDPR) expressly recognises a right to data portability under Article 20.

The right generally allows an individual to receive personal data concerning them, which they have provided to a controller, in a structured, commonly used and machine-readable format, and in certain circumstances to transmit that data to another controller.

In an employment context, however, the right is not unlimited. The legal basis for processing, the nature of the data, the circumstances in which it was generated, and the rights of other persons can affect whether portability applies.

4. Employer-to-Employer Transfer

A particularly important distinction is between:

Employee-controlled portability:
The employee receives data and chooses to provide it to a new employer.

Direct employer-to-employer transfer:
The previous employer sends employee information directly to the new employer.

The second situation requires particular care because the former employer needs an appropriate legal basis for disclosing the information. An employee's request alone does not necessarily permit disclosure of every category of employer-held information.

5. Data Portability and Employee Consent

Consent may sometimes be relevant, but it should not automatically be treated as the solution to every portability issue.

Employment relationships often involve an imbalance of power between employer and employee. Consequently, organisations should examine whether another lawful basis is available and whether the proposed transfer is necessary and proportionate.

6. Data Minimisation

Only information genuinely required by the new employer should normally be transferred.

For example, if a new employer needs proof of a professional qualification, it may not need the employee's entire personnel file.

This reflects the broader principle of data minimisation: organisations should avoid transferring excessive personal information merely because it is technically available.

7. Accuracy of Transferred Data

Data portability can create problems where an employee's records contain inaccurate or outdated information.

The employee should have appropriate mechanisms to:

  • identify inaccurate information;
  • request correction;
  • understand the source of the information; and
  • prevent outdated information from being unnecessarily transferred.

This is particularly important for performance evaluations, disciplinary records, and employment references.

8. Confidentiality and Trade Secrets

An employee cannot normally use data portability as a mechanism to obtain an employer's confidential commercial information.

For example, an employee may have a right to access personal information concerning them, but that does not automatically give them the right to obtain:

  • customer databases;
  • business strategies;
  • confidential algorithms;
  • internal pricing information;
  • proprietary software;
  • trade secrets.

The distinction between personal data and employer-owned confidential information is therefore crucial.

9. Data Portability and Employee References

References present a special problem. A reference prepared by a former employer may contain information about the employee, but it may also contain confidential assessments or information relating to third parties.

Courts have therefore frequently considered the balance between an individual's access rights and the confidentiality interests of the organisation or third parties.

10. Cross-Border Employment

International employers may maintain HR information in different countries. When an employee moves between employers located in different jurisdictions, additional rules may apply concerning:

  • international data transfers;
  • adequacy mechanisms;
  • contractual safeguards;
  • employee privacy;
  • localisation requirements;
  • cybersecurity.

Therefore, an employee's ability to move data from one employer to another may vary significantly between jurisdictions.

Important Case Laws

1. Google Spain SL v Agencia Española de Protección de Datos (AEPD) (2014)

The Court of Justice of the European Union recognised important principles concerning individuals' control over personal information and the responsibilities of organisations processing personal data.

Relevance: The case strengthened the broader concept that individuals have legally protected interests in controlling information relating to them, supporting the development of stronger data-subject rights.

2. Wirtschaftsakademie Schleswig-Holstein GmbH (2018)

The CJEU considered responsibility for processing personal data and emphasised that organisations can have data-protection responsibilities even where they do not exercise exclusive control over the technical processing environment.

Relevance: In employment systems involving HR platforms and third-party providers, responsibility for employee data cannot simply be avoided by outsourcing processing.

3. Nowak v Data Protection Commissioner (2017)

In Patrick Breyer? More specifically, Nowak v Data Protection Commissioner concerned whether examination answers and examiner comments could constitute personal data.

The CJEU adopted a broad understanding of personal data where information is linked to an identifiable individual.

Relevance: Employment records may contain personal data even when they involve professional assessments, evaluations, or comments rather than basic identifying information.

4. Lloyd v Google LLC (2021)

The UK Supreme Court considered claims concerning Google's processing of personal data and emphasised the need to establish the relevant legal harm and individual circumstances.

Relevance: The case demonstrates that the existence of personal-data processing does not automatically mean that every individual can obtain compensation; the particular legal requirements must be established.

5. R (on the application of Bridges) v Chief Constable of South Wales Police (2020)

The UK Court of Appeal considered the use of facial-recognition technology and the processing of personal information.

Relevance: The decision illustrates the importance of lawful processing, proportionality and safeguards when organisations process sensitive personal information. These principles are relevant when transferring employee data between organisations.

6. Barbulescu v Romania (2017)

The European Court of Human Rights considered workplace monitoring of an employee's communications and examined the balance between an employer's interests and an employee's right to privacy.

Relevance: Employee data does not lose its privacy protections merely because it is generated or collected in the workplace. Employers transferring such information must consider employees' privacy rights.

7. Antović and Mirković v Montenegro (2017)

The ECtHR considered workplace surveillance and the employee's right to private life.

Relevance: The case reinforces the principle that workplace-generated information can fall within an employee's protected private sphere, making unrestricted transfer of workplace data problematic.

8. Satakunnan Markkinapörssi Oy and Satamedia Oy v Finland (2017)

The Grand Chamber of the ECtHR examined the publication and processing of large quantities of personal tax information.

Relevance: The case demonstrates the importance of balancing data processing against competing rights and legitimate interests. Similar balancing considerations can arise when employee information is transferred to a new employer.

Key Legal Principles

Data portability between employers should therefore be governed by the following principles:

PrincipleApplication
LawfulnessThe transfer must have a valid legal basis.
Purpose limitationData should be transferred for a specified legitimate purpose.
Data minimisationOnly necessary employee information should be transferred.
AccuracyIncorrect or outdated information should be corrected.
TransparencyEmployees should understand how their information is being transferred.
SecurityAppropriate technical and organisational safeguards should protect the data.
ConfidentialityEmployer trade secrets and third-party information must be protected.
AccountabilityEmployers should be able to demonstrate compliance.

Indian Legal Context

In India, employee data portability must be considered alongside the Digital Personal Data Protection Act, 2023, contractual obligations, confidentiality requirements, employment law, and constitutional privacy principles.

The Supreme Court's decision in Justice K.S. Puttaswamy (Retd.) v Union of India (2017) is particularly significant because it recognised privacy as a constitutionally protected right under Article 21.

For employers, this means that transferring employee information should not be treated merely as an administrative exercise. The purpose, necessity, proportionality, security and legitimate basis for the transfer should be considered.

Conclusion

Data portability between employers can make job transitions easier by allowing employees to retain control over useful employment information. However, portability does not mean that an employee is entitled to receive or transfer an entire personnel file.

A legally compliant system should distinguish between portable personal data, confidential employer information, third-party information and proprietary business records. Employers should use data minimisation, appropriate legal bases, security controls, transparency and access/correction mechanisms when employee information moves from one organisation to another.

LEAVE A COMMENT