PrivacySignal
News

Use of employee’s swipe-card data for disciplinary purposes

Data Protection Commission · · EU / Ireland · Privacy Law

Ireland's Data Protection Commission has taken up a case involving an employer's use of swipe-card access data against an employee for disciplinary purposes. The case centers on whether repurposing that data — collected to manage building access — for disciplinary action is lawful under data protection rules.

Why this matters: Most people assume the card that lets them into the office just opens a door. It also creates a timestamped record of where they were and when. Using that record to discipline someone is a different purpose than the one it was collected for, and that gap matters legally. Employers often collect more than workers realize, and the rules exist to limit how far that data can travel inside a company. This case is a test of whether those limits mean anything in practice.

Who should care: General readers · Privacy officers · Policy

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Analysis

All analysis →

Weekly Editorial Analysis from Experts and Editors

The Attacker Did Not Need to Sleep

Spain received its first reported personal-data breach carried out by an AI agent. The techniques were familiar. The speed and autonomy were not.

· 4 min read Read →

Related stories