Skip to content

Data Protection for Employees: The 10 Most Important Rules for Everyday Work

Provimedia Redaktion 6 min read 10 July 2026 2 views
Datenschutz & DSGVO
Data Protection for Employees: The 10 Most Important Rules for Everyday Work
Illustrative image · AI-generated

Data protection for employees means above all: handling the personal data of customers, colleagues, and applicants carefully, from a locked screen to conscious use of email distribution lists to internally reporting data breaches. Violations rarely arise from intent but from carelessness: in five minutes, you will know when to lock your screen, why BCC is mandatory, and what to do in the event of a data breach.

From the Provimedia editorial team · Status: July 2026 · This article is general information, not legal advice.

This is exactly the kind of carelessness that a GDPR training for employees addresses: the following ten rules form the basis for acting safely in everyday work, even without being a lawyer.

The 10 most important data protection rules for employees

Rule 1: Lock your screen as soon as you leave your desk

Even if you leave your desk for just a few minutes, lock your screen (Windows key + L or Cmd+Ctrl+Q). An unattended, unlocked computer is one of the most common ways for unauthorized people to access customer or personnel data. This reflects the principle of integrity and confidentiality under Article 5(1)(f) GDPR: data must be protected against unauthorized access.

Rule 2: Clean desk, no documents left lying around

Printouts containing names, addresses, or contract data do not belong openly on the desk, but in locked cabinets or straight into the shredder. Anyone leaving the room or receiving visitors puts documents away: a simple but effective organizational measure within the meaning of Article 5(1)(f) GDPR.

Rule 3: Always send group emails via BCC

When you send a message to several external recipients, enter their addresses in the BCC field, not in To or CC. Otherwise, all recipients see each other's email addresses: this already counts as a data breach that must be reported internally and checked against the notification requirement under Article 33 GDPR, something that occurs regularly in practice.

Check the sender address, salutation, and link destination before clicking on attachments or links, especially with supposedly urgent payment or password requests. According to the Federal Office for Information Security (Bundesamt für Sicherheit in der Informationstechnik, BSI), phishing is among the most common attack vectors on company data; when in doubt, ask the IT department rather than click.

Rule 5: Do not enter personal data into unapproved AI tools

Customer, applicant, or colleague data may only be entered into AI or cloud tools for which the company has concluded a data processing agreement under Article 28 GDPR. A private ChatGPT account or an unapproved tool is off limits for this. You can read the details in the article AI and data protection: ChatGPT rules.

Rule 6: Forward requests from data subjects immediately

If a customer or applicant contacts you asking for access to, erasure of, or correction of their data, forward the request immediately to the data protection officer or the responsible department. A response is generally required within one month, a deadline that often becomes tight internally if requests are noticed only late.

Rule 7: Report data breaches internally right away

If a laptop has been lost, an email has gone to the wrong recipient, or a record has been accidentally deleted, report it internally right away, even if the mistake is uncomfortable. Under Article 33 GDPR, the company must notify the supervisory authority of personal data breaches without undue delay and, wherever possible, within 72 hours, unless a risk to data subjects is unlikely; this only works if employees report it immediately.

Rule 8: Do not use private USB sticks or unauthorized tools

Private USB sticks, unapproved cloud storage, or apps installed without authorization (so-called shadow IT) escape the control of the IT department and open up attack surfaces for data loss and malware. Use only the systems provided and approved by the company.

Rule 9: Only provide information to clearly authorized persons

Do not disclose personal data by phone or email without having verified beyond doubt the identity and authorization of the person requesting it. Alleged colleagues, supposed authorities, or urgent-sounding supervisors are a classic gateway for social engineering; when in doubt, call back rather than answer immediately.

Rule 10: When in doubt, ask the data protection officer

Not every situation is clear-cut: whether new software may be used, a form may be changed, or a request may be answered. Contact the data protection officer or the responsible contact person instead of deciding on your own. This protects you and the company alike.

The following overview shows at a glance exactly which risk each rule prevents. You can pass this checklist on to your team unchanged:

RuleRisk it prevents
Lock your screenUnauthorized access to data during absence
Clean deskVisible or removable documents
BCC for group emailsDisclosure of recipient addresses (data breach)
Phishing cautionAccount takeover, malware, data leakage
No personal data in free AI toolsProcessing without a legal basis or data processing agreement
Forwarding data subject requestsMissed deadline for the right of access
Reporting data breaches immediatelyMissed 72-hour notification deadline
No private USB sticks / shadow ITUncontrolled data leakage, malware
Information only to authorized personsSocial engineering, data disclosure to unauthorized persons
Asking the data protection officerWrong decisions made out of uncertainty

Frequently asked questions (FAQ)

Which data protection rules apply to employees?

In principle: employees may only process personal data within the scope of their duties and on the employer's instructions (Article 29 and Article 32(4) GDPR). This includes careful handling of access, documents, and email distribution lists, as well as immediately reporting anything unusual; the ten rules above summarize the most important points for everyday work.

Are employees personally liable for data protection violations?

Fines under Article 83 GDPR are directed at the controller or processor, meaning usually the company, not directly at individual employees. However, anyone who intentionally or through gross negligence violates internal guidelines must expect employment law consequences up to and including termination; in exceptional cases, personal liability is also possible.

Do the rules also apply when working from home?

Yes, the same obligations apply when working from home as in the office: the location of work does not change the responsibility for personal data. Family members also count as third parties under data protection law: locking your screen, keeping documents locked away, and holding confidential phone calls out of earshot are therefore also part of everyday life at home.

What should I do if I notice a data protection violation by a colleague?

Speak to the colleague directly wherever possible, for example if you notice an unlocked screen or an incorrectly sent group email. If the incident cannot be clarified or is more serious, report it to the supervisor or the data protection officer, not to get anyone in trouble, but to limit the damage.

These ten rules take only a few minutes to read but are easily forgotten in everyday work. The GDPR fundamentals training conveys exactly these everyday rules systematically and with practical examples; every participant receives a dated certificate of participation afterward as proof for their personnel file or for clients.

Sources

Share this article

Stay up to date

Get the latest articles, insights and industry updates straight to your inbox.

Unsubscribe at any time. See our privacy policy.

Decide for yourself what Google shows you

Google lets you choose which sources appear more prominently in your search results: in Top Stories and in AI answers. Two clicks, and you see the sites you trust.

Add provimedia.de to my preferred sources

Bereit für den dokumentierten Schulungsnachweis?

Die DSGVO-Grundlagenschulung für Ihr Team – online, in rund 90 Minuten, mit datiertem Teilnahmezertifikat je Person.