Insights

    First published on sydera.io

    The paradox: you must document psychosocial working conditions — without collecting health data

    The duty to document psychosocial working conditions meets GDPR Article 9. How it resolves: separate the system level from the individual level, and put the documentation on the level that is not about people.

    By ·

    There is a duty and a limit that look mutually exclusive.

    The duty: an organisation must manage the working environment systematically, and parts of that must exist in writing. Objectives, responsibilities, hazard identification with risk assessment, plans and measures, a non-conformity process, and a review of the system itself. Psychosocial conditions are not carved out. Where sustainability reporting applies, similar expectations come on top.

    The limit: health data is a special category of personal data under GDPR Article 9. The starting point is a prohibition, with exceptions that must be identified before processing begins. And in an employment relationship, consent is rarely considered freely given — the imbalance between the parties makes refusal costly.

    Put the two together and you get the question I am asked most often: how are we supposed to document that psychosocial working conditions are managed, when we are not allowed to collect the very thing we think we have to document?

    The mistake sits in the first reflex

    The most common first move is to assess. We need to know how people are doing. So a survey goes out, or managers are asked to record needs, or a form is created with a free-text field.

    Three things have now happened at once. The organisation has started processing information that may be special category data. The measures that follow become individual follow-up rather than change in the work. And the documentation created is exactly the kind the organisation would rather not hold.

    This is not bad faith. It is that physical hazards taught us a method that does not transfer: air quality is measured, protective equipment is inspected, incidents are logged. Psychosocial conditions have no equivalent gauge, so we try to measure people instead of work.

    The distinction that resolves it

    There are two levels, and their data protection consequences are completely different.

    System level is conditions in the work. Workload and pace. Role clarity and conflicting demands. Influence and participation. Shift patterns, breaks, access to rest and flexibility. Information and managerial support. The arrangements are available to everyone, and nobody has to disclose anything about themselves to use them. No special category data is processed here.

    Individual level is what genuinely requires a case-by-case judgement. It exists, and it should. But there the lawful basis must be identified — in practice in employment-law necessity rather than consent — with clear limits on what is written down, who sees it, and how long it is kept.

    The point is where the documentation goes. Put it at system level. What has to be shown is what the organisation has decided, how it is triggered, who owns it, and what changed at the last review. All of that can be written without a single detail about a named person.

    The individual level gets recorded too, but in a separate track with different access and a different retention period — not in the governance document shared with auditors, employee representatives or customers.

    Four signs a document sits at the wrong level

    1. The arrangement is triggered only once the employee takes the initiative and explains why.
    2. The assessment asks how people are feeling, with no stated purpose for the answers.
    3. Sickness absence figures are used as a proxy for psychosocial conditions.
    4. The follow-up form has an open free-text field with no limit on what a manager may write.

    The fourth is the one that usually creates the problem later. A note written in good faith becomes a document someone has to defend.

    Pseudonymisation is not a way out

    A common fix is to anonymise. It helps less than people expect. Pseudonymised information is still personal data as long as a route back to the individual exists — and in a team of four, "one employee had working hours adjusted" is often identifying on its own.

    That is why floors belong in the routine rather than in a technical annex: what gets reported per unit, and what does not.

    Where guidance helps, and where it does not

    ISO 45003 offers guidance on psychosocial risk. ISO 45010:2026 offers guidance on menstruation and menopause at work. Neither is a requirements document, and neither replaces an assessment of your lawful basis under data protection law.

    Treated as guidance alongside relevant legal requirements, they are useful. Treated as the answer key, they become a source of documentation the organisation is not allowed to hold. That is a real risk when the subject is health and the method is documentation.

    ISO 45001 is under revision now. What the finished text will contain is not decided, and I do not reproduce draft content. But whatever the outcome, this work is worth doing: responsibility written to named roles, non-conformities that get closed, review with a date and a note of what changed, and psychosocial measures moved from individual follow-up to arrangements that apply to everyone.

    The twenty-minute exercise

    Take one routine. Not the whole handbook.

    Read it with two questions. Does anything happen on its own, or only once a person explains themselves? And does the text require someone to record something about a person's health for the routine to work?

    Where the answer to the second is yes, the measure can almost always move one level up. That gives you two things at once: an arrangement more people actually use, and documentation that describes something without describing someone.

    That is the whole point. Documentation should show that the work is happening — not who it happened to.


    Sydera.io Technologies AS is a wholly owned subsidiary of STÖ GROUP AS and a member of SN/K 551, Standard Norway's mirror committee for occupational health and safety management systems. Nicolai Bjerknes Slinning is Working Group Expert, ISO/TC 283/WG 6 and WG 10, nominated by Standards Norway. Participation is in a personal capacity and does not represent ISO or ISO/TC 283. We read governance documents, never employees. You can have [one routine reviewed free of charge](https://sydera.io/en/hse-scan).

    Questions and answers

    Are descriptions of psychosocial conditions personal data?
    Not in themselves. Descriptions of conditions in the work — workload, roles, breaks, participation — are not personal data. They become personal data once the text can be linked to an individual, directly or indirectly.
    Can we rely on consent when an employee tells us about their health?
    Be careful. In an employment relationship consent is rarely considered freely given. Someone telling you something does not in itself give the employer a right to record or share it.
    What should we do first?
    Read one routine and check whether anything happens on its own, or only once a person explains themselves. Where the text requires someone to record something about their health, the measure can almost always move to system level.