Data Protection for Employees: The 10 Most Important Rules for Everyday Work

Data protection for employees means above all: handling the personal data of customers, colleagues, and applicants carefully, from a locked screen to conscious use of email distribution lists to internally reporting data breaches. Violations rarely arise from intent but from carelessness: in five minutes, you will know when to lock your screen, why BCC is mandatory, and what to do in the event of a data breach.
From the Provimedia editorial team · Status: July 2026 · This article is general information, not legal advice.
This is exactly the kind of carelessness that a GDPR training for employees addresses: the following ten rules form the basis for acting safely in everyday work, even without being a lawyer.
The 10 most important data protection rules for employees
Rule 1: Lock your screen as soon as you leave your desk
Even if you leave your desk for just a few minutes, lock your screen (Windows key + L or Cmd+Ctrl+Q). An unattended, unlocked computer is one of the most common ways for unauthorized people to access customer or personnel data. This reflects the principle of integrity and confidentiality under Article 5(1)(f) GDPR: data must be protected against unauthorized access.
Rule 2: Clean desk, no documents left lying around
Printouts containing names, addresses, or contract data do not belong openly on the desk, but in locked cabinets or straight into the shredder. Anyone leaving the room or receiving visitors puts documents away: a simple but effective organizational measure within the meaning of Article 5(1)(f) GDPR.
Rule 3: Always send group emails via BCC
When you send a message to several external recipients, enter their addresses in the BCC field, not in To or CC. Otherwise, all recipients see each other's email addresses: this already counts as a data breach that must be reported internally and checked against the notification requirement under Article 33 GDPR, something that occurs regularly in practice.
Rule 4: Do not click suspicious links or attachments
Check the sender address, salutation, and link destination before clicking on attachments or links, especially with supposedly urgent payment or password requests. According to the Federal Office for Information Security (Bundesamt für Sicherheit in der Informationstechnik, BSI), phishing is among the most common attack vectors on company data; when in doubt, ask the IT department rather than click.
Rule 5: Do not enter personal data into unapproved AI tools
Customer, applicant, or colleague data may only be entered into AI or cloud tools for which the company has concluded a data processing agreement under Article 28 GDPR. A private ChatGPT account or an unapproved tool is off limits for this. You can read the details in the article AI and data protection: ChatGPT rules.
Rule 6: Forward requests from data subjects immediately
If a customer or applicant contacts you asking for access to, erasure of, or correction of their data, forward the request immediately to the data protection officer or the responsible department. A response is generally required within one month, a deadline that often becomes tight internally if requests are noticed only late.
Rule 7: Report data breaches internally right away
If a laptop has been lost, an email has gone to the wrong recipient, or a record has been accidentally deleted, report it internally right away, even if the mistake is uncomfortable. Under Article 33 GDPR, the company must notify the supervisory authority of personal data breaches without undue delay and, wherever possible, within 72 hours, unless a risk to data subjects is unlikely; this only works if employees report it immediately.
Rule 8: Do not use private USB sticks or unauthorized tools
Private USB sticks, unapproved cloud storage, or apps installed without authorization (so-called shadow IT) escape the control of the IT department and open up attack surfaces for data loss and malware. Use only the systems provided and approved by the company.
Rule 9: Only provide information to clearly authorized persons
Do not disclose personal data by phone or email without having verified beyond doubt the identity and authorization of the person requesting it. Alleged colleagues, supposed authorities, or urgent-sounding supervisors are a classic gateway for social engineering; when in doubt, call back rather than answer immediately.
Rule 10: When in doubt, ask the data protection officer
Not every situation is clear-cut: whether new software may be used, a form may be changed, or a request may be answered. Contact the data protection officer or the responsible contact person instead of deciding on your own. This protects you and the company alike.
The following overview shows at a glance exactly which risk each rule prevents. You can pass this checklist on to your team unchanged:
| Rule | Risk it prevents |
|---|---|
| Lock your screen | Unauthorized access to data during absence |
| Clean desk | Visible or removable documents |
| BCC for group emails | Disclosure of recipient addresses (data breach) |
| Phishing caution | Account takeover, malware, data leakage |
| No personal data in free AI tools | Processing without a legal basis or data processing agreement |
| Forwarding data subject requests | Missed deadline for the right of access |
| Reporting data breaches immediately | Missed 72-hour notification deadline |
| No private USB sticks / shadow IT | Uncontrolled data leakage, malware |
| Information only to authorized persons | Social engineering, data disclosure to unauthorized persons |
| Asking the data protection officer | Wrong decisions made out of uncertainty |
Frequently asked questions (FAQ)
Which data protection rules apply to employees?
In principle: employees may only process personal data within the scope of their duties and on the employer's instructions (Article 29 and Article 32(4) GDPR). This includes careful handling of access, documents, and email distribution lists, as well as immediately reporting anything unusual; the ten rules above summarize the most important points for everyday work.
Are employees personally liable for data protection violations?
Fines under Article 83 GDPR are directed at the controller or processor, meaning usually the company, not directly at individual employees. However, anyone who intentionally or through gross negligence violates internal guidelines must expect employment law consequences up to and including termination; in exceptional cases, personal liability is also possible.
Do the rules also apply when working from home?
Yes, the same obligations apply when working from home as in the office: the location of work does not change the responsibility for personal data. Family members also count as third parties under data protection law: locking your screen, keeping documents locked away, and holding confidential phone calls out of earshot are therefore also part of everyday life at home.
What should I do if I notice a data protection violation by a colleague?
Speak to the colleague directly wherever possible, for example if you notice an unlocked screen or an incorrectly sent group email. If the incident cannot be clarified or is more serious, report it to the supervisor or the data protection officer, not to get anyone in trouble, but to limit the damage.
These ten rules take only a few minutes to read but are easily forgotten in everyday work. The GDPR fundamentals training conveys exactly these everyday rules systematically and with practical examples; every participant receives a dated certificate of participation afterward as proof for their personnel file or for clients.
Sources
Share this article
Stay up to date
Get the latest articles, insights and industry updates straight to your inbox.
Decide for yourself what Google shows you
Google lets you choose which sources appear more prominently in your search results: in Top Stories and in AI answers. Two clicks, and you see the sites you trust.
Add provimedia.de to my preferred sourcesRelated articles
More articles you might find interesting.
Phishing and Social Engineering: How Your Employees Can Spot an Attack
Phishing, spear phishing, CEO fraud, and smishing target people, not systems. The warning signs a phishing employee training should teach, and why a successful attack quickly turns into a reportable data breach.
GDPR Fines: Real Cases from Germany and What Companies Can Learn from Them
Four real GDPR fine cases from Germany show how authorities calculate the amount, and that courts can also significantly reduce them afterward.
Information Security Training vs. GDPR Training: What Companies Actually Need
Information security protects systems and information, data protection protects people and their data. The difference, the overlap under Art. 32 GDPR, and what the new NIS2 training duty means for management boards.
Bereit für den dokumentierten Schulungsnachweis?
Die DSGVO-Grundlagenschulung für Ihr Team – online, in rund 90 Minuten, mit datiertem Teilnahmezertifikat je Person.