GDPR and Remote Work — Data Security Outside the Office
Remote and hybrid work have become a permanent fixture in Polish companies — and with them come new challenges for personal data protection. When data leaves the office for home laptops, private Wi-Fi networks and printouts kept on the kitchen table, the risk of loss, disclosure or unauthorised access grows. The employer remains the data controller and is responsible for the security of the data regardless of where the work is performed.
The Polish legislator recognised this directly. Since 7 April 2023, the Labour Code has contained provisions on remote work, including Article 67²⁶ — which obliges the employer to define data protection procedures for remote work. It is a rare instance of labour law referring directly to GDPR matters. In practice, remote work is also a separate processing operation, worth analysing through a privacy-by-design lens before employees start working away from the office.
This article discusses the employer’s obligations under the Labour Code and the GDPR, shows what the remote-work regulations and the data protection procedure should contain, which technical and organisational measures to implement, and how to approach private devices (BYOD), employee oversight, remote-work tools and breach response. It is a practical extension of the topics covered in our guide to GDPR in the employment relationship.
Remote Work in the Labour Code
The amendment to the Labour Code (the Act of 1 December 2022) replaced the earlier “teleworking” and regulated remote work in a separate chapter (Articles 67¹⁸–67³⁴) from 7 April 2023. Three forms are distinguished:
Full remote work — the employee works 100% outside the employer’s premises, at an agreed location or locations.
Partial (hybrid) remote work — the employee combines work at the premises with work elsewhere.
Occasional remote work — at the employee’s request, a maximum of 24 days a year, in a simplified mode (Article 67³³), without the need to create regulations and an agreement.
Importantly for data protection, the obligation to prepare a data protection procedure also covers occasional remote work — the provisions do not disapply Article 67²⁶ of the Labour Code here. In other words, even if an employee works remotely only a few days a year, the procedure must exist.
Remote-Work Regulations and Agreement vs Data Protection
The rules for performing remote work (other than occasional work) are set out in an agreement concluded with a trade union organisation or — where there is none — in remote-work regulations. Where remote work is ordered or individually agreed with an employee, part of these rules is transferred accordingly to the order or the individual agreement.
From a data protection perspective, two elements are key and, under Article 67²⁰ of the Labour Code, should appear in these documents:
Rules for checking compliance with information security and data protection requirements, including data protection procedures. It is on the basis of these rules that the employer can later verify whether the employee complies with data security rules.
Rules for installing, inventorying, maintaining, updating software and servicing the work tools provided, including technical devices. This is the foundation of equipment security — without up-to-date, serviced software, data protection is hard to ensure.
The remote-work regulations and the data protection procedure are two distinct but related documents: the first governs work organisation and the framework for oversight, the second the detailed rules for handling data. They should be mutually consistent.
The Obligation to Have a Data Protection Procedure (Article 67²⁶)
Article 67²⁶ of the Labour Code imposes two obligations on the employer. First, for the purposes of remote work, the employer defines data protection procedures and carries out — as needed — instruction and training in this respect. Second, the employee confirms in paper or electronic form that they have read those procedures and is obliged to comply with them.
The Act does not specify what exactly the procedure should contain — it leaves this to the controller. This means the starting point should be a risk analysis appropriate to the organisation, with the procedure tailored to that risk. Different rules will suit a law firm processing special-category data than a trading company. The employee’s declaration of having read the procedure is worth including in the employment documentation — it is an element of accountability.
The Employer as Controller — Article 32 GDPR and Risk Analysis
Regardless of labour law, the GDPR applies in full to remote work, in particular Article 32 — which requires implementing appropriate technical and organisational measures to ensure the security of data processed in any form, especially electronic and paper. The challenge is that these measures must extend to an environment over which the employer has limited control: the employee’s home, their network, and sometimes their private equipment.
The starting point is a risk analysis. In one of its decisions, the President of UODO stressed that applying technical measures without a prior risk analysis for the specific processing operation offers no guarantee that they will be effective and adequate — and that an organisation focusing only on IT-infrastructure threats overlooks the risks tied to the particular undertaking. For remote work, the analysis should cover technical threats (network, devices, software) as well as organisational and physical ones (the workplace, paper documents, household members’ access).
Technical and Organisational Measures in Remote Work
Implementing Article 32 GDPR in remote work relies on a layered set of measures. In practice, it is worth ensuring:
Secure authentication. Strong, unique passwords and — where possible — multi-factor authentication (MFA), especially for email, VPN and systems containing personal data.
Encrypted connection. Using a VPN to connect to company resources and securing the home Wi-Fi network (changing default passwords, WPA2/WPA3 encryption).
Data encryption. Encrypting whole device disks (for example with a tool like BitLocker) and sensitive attachments, with secure storage of the recovery key.
Device management. Central management of company equipment (MDM/EMM), remote locking and wiping in case of loss, control of installed software.
Patching and malware protection. Regular updates of the system and applications, antivirus/EDR software, a firewall.
Access control and minimisation. Granting permissions on a need-to-know basis, limiting the scope of data accessible remotely, using network drives and servers designated by the employer rather than saving data locally.
Backups. Regular, tested backups, preferably on the employer’s side rather than on the employee’s private media.
Physical security. Screen lock and password-protected screensavers, a clean-desk policy, lockable drawers for documents, secure destruction of printouts.
The choice of measures should be proportionate to the risk — the more sensitive the data, the stronger the safeguards.
Common Threats in Remote Work
Understanding typical threats helps build a sensible procedure. The most common include:
An unsecured network. Using open, public Wi-Fi (cafés, airports) without a VPN exposes data to interception.
Eavesdropping and screen-peeking in public places. Working with data on a train or in a café lets bystanders read the content or overhear work conversations.
Loss of equipment. A lost or stolen, unencrypted laptop or storage medium is a classic source of a breach.
Malware and phishing. Less-secured home devices are easier targets for ransomware and phishing campaigns.
Household members’ access. Sharing a device with family or leaving the computer unlocked gives access to unauthorised persons.
Private email and unauthorised apps. Sending data to a private inbox or using unapproved tools moves data beyond the employer’s control.
Paper documentation. Printouts left unattended, thrown in an ordinary bin, or transported without protection.
What the Data Protection Procedure Should Contain
Although the provisions do not dictate the content of the procedure, in practice — drawing on UODO guidance and commentary — it should address several areas. It should regulate the security of the remote workplace (including limits on working in public places), securing the network and email (VPN, company servers and drives), rules for using company and private devices, encryption of media and attachments, the screen lock and clean-desk rule, the handling of paper documentation (transport, scanning, storage, destruction), methods of securely passing on information (password-protecting documents, verifying identity), prohibitions (private email on company equipment, unauthorised software, saving data outside designated resources), and a clear path for handling data breaches, including the obligation to report to UODO within 72 hours (Article 33 GDPR).
A Skeleton Data Protection Procedure for Remote Work
You can use the skeleton below as a starting point for drafting your own procedure — tailoring it to the results of the risk analysis in your organisation.
DATA PROTECTION PROCEDURE FOR REMOTE WORK
- Purpose and scope of the procedure (who and which forms of remote work it covers).
- Definitions and roles (controller, remote worker, authorised persons).
- Permitted places for remote work and limits on public places.
- Device requirements (company equipment, admissibility of BYOD, minimum safeguards).
- Securing the network and connections (VPN, Wi-Fi, email, servers and drives).
- Authentication and access control rules (passwords, MFA, screen lock).
- Encryption of data and media and storage of keys.
- Handling of paper documentation (transport, storage, destruction).
- Rules for passing on and sharing information (password-protection, recipient verification).
- Prohibitions and limitations (private email, unauthorised software).
- Handling a data breach (reporting path, deadlines).
- Rules for checking compliance with the procedure and the employee’s responsibility.
- Employee declaration of having read the procedure.
The Employee’s Private Equipment (BYOD)
The remote-work provisions allow the use of the employee’s own tools, such as a laptop or monitor — subject to agreement with the employer, in which case the employee is entitled to an allowance. From a GDPR perspective, however, private equipment should be treated with limited trust: the employer has less control over it, the device is sometimes shared with household members, and work data mixes with private data.
If the organisation permits the BYOD model, the procedure should set minimum security requirements: up-to-date software and operating system, disk encryption, screen lock, antivirus software, separation of work data from private data (for example through containerisation or working solely in the employer’s remote environment), and rules for responding to device loss. Where sensitive data is processed or the risk is high, company equipment managed centrally by the employer is the safer option — this usually outweighs the savings from BYOD.
Oversight of Remote Work vs Monitoring — An Important Distinction
This is one of the most frequently confused areas. Two things must be distinguished.
Oversight of compliance with security rules (Article 67²⁸). The employer has the right to check the performance of remote work, including compliance with information security requirements and data protection procedures. The check is carried out on terms agreed with the employee, at the place of remote work and during working hours. It must not infringe the privacy of the employee and household members or hinder the use of domestic premises in accordance with their purpose — which in practice rules out unannounced “raids”. If shortcomings are found, the employer may require the employee to remedy them within a set time or withdraw consent to remote work.
Employee monitoring. Monitoring the workstation, websites visited or activity in applications is a separate matter. The data protection procedure is not the appropriate instrument for introducing monitoring — it must have a basis in the work regulations (a collective agreement or notice), in line with the rules on other forms of employee monitoring (Article 22³ of the Labour Code), and employees must be informed 14 days in advance. Monitoring must be proportionate to its purpose and must not lead to excessive surveillance or extend to the employee’s private life.
Remote-Work Tools and Processors
Remote work relies on messengers, the cloud and video conferencing. The providers of these tools process data on the employer’s behalf and are therefore processors — a data processing agreement compliant with Article 28 GDPR is required, covering among other things sub-processing and data location. Many popular services transfer data outside the EEA (for example, to the US), which requires verifying the transfer mechanism (e.g. the Data Privacy Framework or standard contractual clauses). It is also worth configuring the tools with privacy in mind: limiting the scope of data collected, disabling unnecessary meeting recording, and reviewing default settings.
Data Breaches in Remote Work
Working outside the office raises the risk of breaches. A breach is not only a data leak — it is also the accidental destruction, loss or alteration of data (Article 4(12) GDPR). Typical scenarios include a lost or stolen laptop, a ransomware attack on a poorly secured device, sending a file to private email, leaving printouts unattended, or accidentally exposing data to a household member.
The procedure should clearly indicate how an employee promptly reports an incident, and how the organisation assesses whether a breach has occurred that must be reported to UODO within 72 hours and possibly communicated to the data subjects (where the breach involves a high risk to their rights and freedoms). It is crucial that employees are not afraid to report incidents — a culture of prompt reporting shortens response time. Regular training and reminders significantly reduce the risk, since most remote-work breaches result from human error.
Common Mistakes
No data protection procedure for remote work, despite the obligation in Article 67²⁶ — including for occasional work.
An “off-the-shelf” procedure not tailored to the organisation’s actual risk, with no risk analysis.
No employee declaration of having read the procedure.
Omitting information security rules from the remote-work regulations (Article 67²⁰).
Confusing oversight with monitoring and introducing monitoring without a basis in the work regulations.
Permitting BYOD without rules and without minimum security requirements.
No data processing agreements with the providers of remote-work tools, and overlooking transfers outside the EEA.
No training and no clear path for reporting breaches.
Checklist — GDPR in Remote Work
- Carry out a risk analysis for the remote-work process.
- Regulate information security rules in the regulations/agreement (Article 67²⁰).
- Develop a data protection procedure for remote work (Article 67²⁶).
- Obtain employees’ declarations that they have read the procedure.
- Provide instruction or training (as needed).
- Ensure technical measures: VPN, MFA, encryption, screen lock, antivirus, backups.
- Set rules for using company and private equipment (BYOD).
- Regulate the handling of paper documentation outside the office.
- Establish oversight rules in line with Article 67²⁸ — agreed with the employee.
- If you use monitoring, base it on the work regulations (Article 22³) and inform employees 14 days in advance.
- Conclude data processing agreements with tool providers and check transfers outside the EEA.
- Implement a breach-reporting path and a 72-hour response procedure.
- Include the remote-work process in the record of processing activities.
- Regularly train employees on data security outside the office.
Need Help with GDPR in Remote Work?
Remote work is an area where the requirements of the Labour Code and the GDPR intertwine at every step — from the regulations and the data protection procedure, through oversight and monitoring, to agreements with tool providers and breach response. At the Law Office of Dr Joanna Maniszewska-Ejsmont, we help prepare a data protection procedure for remote work, adapt employment documentation, and implement security measures in line with Article 32 GDPR.

Contact us — we will help you organise remote work safely in your company.
