CNIL Updates Data Protection Guidance for Employers in the Context of Lifting COVID-19 Containment Measures


On May 7, 2020, the French Data Protection Authority (the “CNIL”) updated its previous guidance for employers relating to the processing of employee and visitor personal data in the context of the COVID-19 outbreak, in particular, in the context of lifting containment measures (the “Updated Guidance”). Some employers may consider implementing systematic body temperature checks at the entrance to their premises. Similarly, employers may wish to assess employees’ exposure to the virus or their health statuses when they return to work. The Updated Guidance analyzes some of these practices and outlines the principles applicable to data processing activities.

Background

The Updated Guidance reminds employers and employees of their respective safety obligations:

In the event employees report (suspected) infections, employers may only process the following information: (1) the date and the identity of the employee in question; (2) the fact that the employee reported the infection or suspected infection; and (3) the organizational measures implemented by the employer.

Body Temperature Checks

The Updated Guidance stresses that, unless explicitly contemplated by a law, employers are currently not allowed to take the following measurements:

However, employers would be allowed to check temperatures at the entrance to their premises, using a manual thermometer (such as a non-contact infrared thermometer), if no temperature data is recorded and there is no internal or external reporting of that information. The Updated Guidance explains that if these conditions are met, employers are not processing any personal data and therefore the checks would not be subject to the EU General Data Protection Regulation (“GDPR”).

Serology Tests and Health Status Questionnaires

In addition, employers are not allowed to conduct serology tests to detect COVID-19 or require their employees to complete health status questionnaires. The Updated Guidance reminds businesses that only competent health personnel (such as occupational doctors) may collect, implement and have access to medical forms or questionnaires that contain data on employees’ health statuses or information relating to their family situations, living conditions or possible travels. Similarly, the results of serology tests are subject to medical professional secrecy. Employers may only know that employees are fit or unfit to work.

Business Continuity Plans

Employers may need to establish a business continuity plan that aims to maintain the critical activities of their organization in times of crisis. The plan must specify all necessary measures to protect the safety of employees, and identify the critical activities that need to be maintained, as well as the people necessary to ensure business continuity. The organization may then create a data file in order to set up and maintain the plan. Only necessary personal data must be processed to that end.

Read the CNIL’s Updated Guidance (in French).


Copyright © 2025, Hunton Andrews Kurth LLP. All Rights Reserved.
National Law Review, Volume X, Number 132