Office, Karriere und IT Blog

Office, Karriere und IT Blog

   
Anzeige

Who is responsible for data protection in the Homeoffice

Working in the home office is a model that was used in exceptional cases in Germany in the past and was not common practice. But in times when the Corona Virus has completely changed our lives, this work model is wherever possible a good alternative to short-time work, or even having to face the situation of losing your job.

Call center employees who would normally be sitting in an open-plan office with their colleagues, for example, now simply get an account from their employer to be able to access the company server from home, and work can start from their home computer. But in contrast to the internal company network, which is well protected from the outside, this security structure at home is generally not as extensive.

So the question arises who is actually responsible for data protection in the home office. After all, sensitive customer data is always used here, which is exchanged with the internal company network from home.

Who is responsible for data protection in the home office

Topic Overview

Anzeige

Who is responsible for data protection in the Homeoffice

Working in the home office is a model that was used in exceptional cases in Germany in the past and was not common practice. But in times when the Corona Virus has completely changed our lives, this work model is wherever possible a good alternative to short-time work, or even having to face the situation of losing your job.

Call center employees who would normally be sitting in an open-plan office with their colleagues, for example, now simply get an account from their employer to be able to access the company server from home, and work can start from their home computer. But in contrast to the internal company network, which is well protected from the outside, this security structure at home is generally not as extensive.

So the question arises who is actually responsible for data protection in the home office. After all, sensitive customer data is always used here, which is exchanged with the internal company network from home.

Who is responsible for data protection in the home office

Topic Overview

Anzeige

GDPR rules also apply in the home office

That everyone has adequate current virus protection and a firewall on their home PC should be a matter of course. This is all the more true, of course, if an employee works for his company in the home office and transfers sensitive data. However, when it comes to the question of responsibility for data protection, it doesn’t matter which data is transferred.

The decision on this is already regulated in the applicable GDPR (Article 4 No. 7 GDPR). Accordingly, the person who decides on the purpose and means of data processing is responsible. And that is usually the employer with the authority to issue instructions to you as an employee. This principle also applies to freelancers who generally work for a company in the context of a service contract, provided that it is not a separate service in which data processing is not an important core component of the work.

In this case, the freelancer would be the responsible body for compliance with the GDPR. However, this basically never applies to salaried employees, which is why the responsibility remains with the company.

But even if the responsibility of data protection lies with the employer, you should make sure to secure your own PC and the network as well as possible so as not to get into the area of negligence. In the home office, too, the employee has to comply with his due diligence obligations as well as at the regular workplace.

Data carriers and documents related to the professional activity should never be kept unattended. Adequate encryption of data carriers also makes sense.

Larger companies in particular have often already established clear rules for employees in their home office, and they also equip them with the necessary security tools. This can be, for example, a company notebook that has been set up so that only certain activities that are intended for the home office can be carried out. This would also eliminate the vulnerability of an employee’s home PC.

The use of a VPN (Virtual Private Network), via which data can be transmitted in encrypted form, can also be very useful.

GDPR rules also apply in the home office

That everyone has adequate current virus protection and a firewall on their home PC should be a matter of course. This is all the more true, of course, if an employee works for his company in the home office and transfers sensitive data. However, when it comes to the question of responsibility for data protection, it doesn’t matter which data is transferred.

The decision on this is already regulated in the applicable GDPR (Article 4 No. 7 GDPR). Accordingly, the person who decides on the purpose and means of data processing is responsible. And that is usually the employer with the authority to issue instructions to you as an employee. This principle also applies to freelancers who generally work for a company in the context of a service contract, provided that it is not a separate service in which data processing is not an important core component of the work.

In this case, the freelancer would be the responsible body for compliance with the GDPR. However, this basically never applies to salaried employees, which is why the responsibility remains with the company.

But even if the responsibility of data protection lies with the employer, you should make sure to secure your own PC and the network as well as possible so as not to get into the area of negligence. In the home office, too, the employee has to comply with his due diligence obligations as well as at the regular workplace.

Data carriers and documents related to the professional activity should never be kept unattended. Adequate encryption of data carriers also makes sense.

Larger companies in particular have often already established clear rules for employees in their home office, and they also equip them with the necessary security tools. This can be, for example, a company notebook that has been set up so that only certain activities that are intended for the home office can be carried out. This would also eliminate the vulnerability of an employee’s home PC.

The use of a VPN (Virtual Private Network), via which data can be transmitted in encrypted form, can also be very useful.

Who pays for data loss in the home office?

If data is lost, or even worse gets into the wrong hands, this can cause great damage, which is why the question of liability quickly arises. In principle, liability is derived from the provisions of the GDPR, according to which the body responsible for data processing must be consulted. And as already mentioned, this is the employer.

So if a fine is imposed by a supervisory authority, this goes directly to the company, but not to the employee who cannot be held liable towards the responsible body (employer).

Here too, caution is required for negligence or intent. Because even if, from your point of view as an employee, it was not a deliberate act, this can be interpreted for you in the event of gross negligence.

In such a case, you would be fully liable for damage. However, the extent of liability on the part of the employee in the home office is also balanced between slight, medium and gross negligence.

Ads

Working in the home office can be a win-win situation for companies and employees even after the Corona crisis, provided that there are clear rules about the work processes and the general conditions. If your employer has not yet made any arrangements with you in this regard, you should write down these important points in the home office before starting.

Blogverzeichnis Bloggerei.de

Who pays for data loss in the home office?

If data is lost, or even worse gets into the wrong hands, this can cause great damage, which is why the question of liability quickly arises. In principle, liability is derived from the provisions of the GDPR, according to which the body responsible for data processing must be consulted. And as already mentioned, this is the employer.

So if a fine is imposed by a supervisory authority, this goes directly to the company, but not to the employee who cannot be held liable towards the responsible body (employer).

Ads

Here too, caution is required for negligence or intent. Because even if, from your point of view as an employee, it was not a deliberate act, this can be interpreted for you in the event of gross negligence.

In such a case, you would be fully liable for damage. However, the extent of liability on the part of the employee in the home office is also balanced between slight, medium and gross negligence.

Working in the home office can be a win-win situation for companies and employees even after the Corona crisis, provided that there are clear rules about the work processes and the general conditions. If your employer has not yet made any arrangements with you in this regard, you should write down these important points in the home office before starting.

Blogverzeichnis Bloggerei.de

Search for:

About the Author:

Michael W. SuhrDipl. Betriebswirt | Webdesign- und Beratung | Office Training
After 20 years in logistics, I turned my hobby, which has accompanied me since the mid-1980s, into a profession, and have been working as a freelancer in web design, web consulting and Microsoft Office since the beginning of 2015. On the side, I write articles for more digital competence in my blog as far as time allows.

Search by category:

Search for:

About the Author:

Michael W. SuhrDipl. Betriebswirt | Webdesign- und Beratung | Office Training
After 20 years in logistics, I turned my hobby, which has accompanied me since the mid-1980s, into a profession, and have been working as a freelancer in web design, web consulting and Microsoft Office since the beginning of 2015. On the side, I write articles for more digital competence in my blog as far as time allows.

Search by category:

Popular Posts:

911, 2025

Microsoft Loop in Teams: The revolution of your notes?

November 9th, 2025|Categories: Microsoft Office, Microsoft Excel, Microsoft Outlook, Microsoft PowerPoint, Microsoft Teams, Microsoft Word, Office 365, Software|Tags: , , |

What exactly are these Loop components in Microsoft Teams? We'll show you how these "living mini-documents" can accelerate your teamwork. From dynamic agendas to shared, real-time checklists – discover practical use cases for your everyday work.

911, 2025

Career booster 2026: These Microsoft Office skills will take you further!

November 9th, 2025|Categories: Microsoft Office, Microsoft Excel, Microsoft Outlook, Microsoft PowerPoint, Microsoft Teams, Microsoft Word, Office 365, Software|Tags: , |

A new year, new career opportunities! But which Office skills will really be in demand in 2026? "Skilled use" is no longer enough. We'll show you today's must-haves – like advanced Excel, using AI in the office, and relevant certifications for your resume.

311, 2025

Why Zero Trust doesn’t work without identity protection!

November 3rd, 2025|Categories: Shorts & Tutorials, Artificial intelligence, AutoGPT, ChatGPT, Data Protection, Homeoffice, LLaMa, TruthGPT|Tags: , |

Zero Trust means: Trust no one, verify everyone. Identity protection is at the heart of this modern security model. Learn how IAM, MFA, Conditional Access, and the principle of least privilege effectively protect your business when the old network perimeter is gone.

211, 2025

How AI fuels cyberattacks – and how it protects us from them

November 2nd, 2025|Categories: Shorts & Tutorials, Artificial intelligence, AutoGPT, ChatGPT, Data Protection, Homeoffice, LLaMa, TruthGPT|Tags: , |

Cybercriminals are using AI for deepfakes and automated attacks. Defenses are also relying on AI: through behavioral analysis (UEBA) and automated responses (SOAR). Learn how this arms race works and how modern security strategies can protect your business.

211, 2025

Information overload: Protection & tips against digital stress

November 2nd, 2025|Categories: Shorts & Tutorials, Homeoffice|Tags: |

Constantly online, overwhelmed by news, emails & social media? Digital information overload leads to stress and concentration problems. Learn the best strategies and practical tips to effectively protect yourself, manage the chaos, and regain your focus.

111, 2025

Put an end to password chaos: Why a password manager is important

November 1st, 2025|Categories: Shorts & Tutorials, Data Protection, Google, Homeoffice, Software|Tags: , , , |

Passwords are constantly being stolen through data leaks. A password manager is your digital vault. It creates and stores strong, unique passwords for every service. This effectively protects you against identity theft through "credential stuffing".

Offers 2024: Word & Excel Templates

Popular Posts:

911, 2025

Microsoft Loop in Teams: The revolution of your notes?

November 9th, 2025|Categories: Microsoft Office, Microsoft Excel, Microsoft Outlook, Microsoft PowerPoint, Microsoft Teams, Microsoft Word, Office 365, Software|Tags: , , |

What exactly are these Loop components in Microsoft Teams? We'll show you how these "living mini-documents" can accelerate your teamwork. From dynamic agendas to shared, real-time checklists – discover practical use cases for your everyday work.

911, 2025

Career booster 2026: These Microsoft Office skills will take you further!

November 9th, 2025|Categories: Microsoft Office, Microsoft Excel, Microsoft Outlook, Microsoft PowerPoint, Microsoft Teams, Microsoft Word, Office 365, Software|Tags: , |

A new year, new career opportunities! But which Office skills will really be in demand in 2026? "Skilled use" is no longer enough. We'll show you today's must-haves – like advanced Excel, using AI in the office, and relevant certifications for your resume.

311, 2025

Why Zero Trust doesn’t work without identity protection!

November 3rd, 2025|Categories: Shorts & Tutorials, Artificial intelligence, AutoGPT, ChatGPT, Data Protection, Homeoffice, LLaMa, TruthGPT|Tags: , |

Zero Trust means: Trust no one, verify everyone. Identity protection is at the heart of this modern security model. Learn how IAM, MFA, Conditional Access, and the principle of least privilege effectively protect your business when the old network perimeter is gone.

211, 2025

How AI fuels cyberattacks – and how it protects us from them

November 2nd, 2025|Categories: Shorts & Tutorials, Artificial intelligence, AutoGPT, ChatGPT, Data Protection, Homeoffice, LLaMa, TruthGPT|Tags: , |

Cybercriminals are using AI for deepfakes and automated attacks. Defenses are also relying on AI: through behavioral analysis (UEBA) and automated responses (SOAR). Learn how this arms race works and how modern security strategies can protect your business.

211, 2025

Information overload: Protection & tips against digital stress

November 2nd, 2025|Categories: Shorts & Tutorials, Homeoffice|Tags: |

Constantly online, overwhelmed by news, emails & social media? Digital information overload leads to stress and concentration problems. Learn the best strategies and practical tips to effectively protect yourself, manage the chaos, and regain your focus.

111, 2025

Put an end to password chaos: Why a password manager is important

November 1st, 2025|Categories: Shorts & Tutorials, Data Protection, Google, Homeoffice, Software|Tags: , , , |

Passwords are constantly being stolen through data leaks. A password manager is your digital vault. It creates and stores strong, unique passwords for every service. This effectively protects you against identity theft through "credential stuffing".

Offers 2024: Word & Excel Templates

Ads

Popular Posts:

Search by category:

Autumn Specials:

Anzeige
Go to Top