Use of employee’s swipe-card data for disciplinary purposes
Ireland's Data Protection Commission has taken up a case involving an employer's use of swipe-card access data against an employee for disciplinary purposes. The case centers on whether repurposing that data — collected to manage building access — for disciplinary action is lawful under data protection rules.
Why this matters: Most people assume the card that lets them into the office just opens a door. It also creates a timestamped record of where they were and when. Using that record to discipline someone is a different purpose than the one it was collected for, and that gap matters legally. Employers often collect more than workers realize, and the rules exist to limit how far that data can travel inside a company. This case is a test of whether those limits mean anything in practice.
Who should care: General readers · Privacy officers · Policy
This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.