Documenting psychosocial risk without collecting health data
Written by Nicolai Bjerknes Slinning, Founder, Sydera.io Technologies AS · Working Group Expert, ISO/TC 283/WG 6 and WG 10 · member of SN/K 551. Last reviewed .
Employers are expected to show that psychosocial working conditions are managed systematically. At the same time, data protection law places tight limits on what an employer may record about an individual's health. The two duties look like a contradiction. The way out is a distinction between two levels — and putting the documentation on the level that is not about people.
The duty that does not go away
Occupational health and safety law requires systematic management of the working environment, and internal control rules set out what must exist in writing: objectives, responsibilities, hazard identification with risk assessment, plans and measures, a non-conformity process, and a review of the system itself. Psychosocial conditions are not carved out. Sustainability reporting adds similar expectations where it applies. The documentation duty is real, and sensitivity does not remove it.
The line that cannot be moved
Health data is a special category of personal data under GDPR Article 9. The starting point is a prohibition, with exceptions that must be identified before processing begins. In an employment relationship consent is rarely considered freely given, because the imbalance between the parties makes refusal costly. Data minimisation applies on top: what is collected must be necessary for a stated purpose. A manager who notes “X sleeps badly — shorter shifts” is processing health data, however well intentioned the note is.
The distinction that resolves it: system level and individual level
At system level the organisation describes conditions in the work: workload, pace, role clarity, shift patterns, breaks, participation, access to rest and flexibility. The arrangements are available to everyone, and nobody has to disclose anything about their health to use them. No special category data is processed here. At individual level the organisation handles what genuinely requires a case-by-case judgement — and there the lawful basis must be identified, in practice in employment-law necessity rather than consent, with clear limits on what may be written down and who can see it.
Put the documentation at system level
What has to be shown is what the organisation has decided, how it is triggered, who owns it, and what changed at the last review. All of that can be written without a single detail about a named person. Where the individual level must be recorded, it belongs in a separate track with different access and a different retention period — not in the governance document shared with auditors, employee representatives or customers.
Signs that a document sits at the wrong level
Four patterns recur. The document assumes the employee takes the initiative and explains why before anything happens. The assessment is a survey about how people feel, without a stated purpose for the answers. Measurement uses sickness absence figures as a proxy for psychosocial conditions. And the follow-up form has an open free-text field where a manager writes something that later becomes hard to defend.
Guidance alongside legal requirements
ISO 45003 offers guidance on psychosocial risk, and ISO 45010:2026 offers guidance on menstruation and menopause at work. Neither is a requirements document, and neither replaces an assessment of your lawful basis under data protection law. Treated as guidance alongside relevant legal requirements they are useful. Treated as the answer key they become a source of documentation the organisation is not allowed to hold.
How to do it in practice
Start with one routine. Read it with two questions. Does anything happen on its own, or only once a person explains themselves? And does the text require someone to record something about a person's health for the routine to work? Where the answer to the second is yes, the measure can almost always move one level up — from individual follow-up to an arrangement that applies to everyone. That is the same exercise we run in a free review.
One governance document reviewed free of charge. We read the document, never employees. The document must not contain personal data.
Sources
Frequently asked questions
- Is psychosocial documentation personal data?
- Not necessarily. Descriptions of conditions in the work — workload, roles, breaks, participation — are not personal data. They become personal data once the text can be linked to an individual, directly or indirectly.
- Can we rely on consent when an employee tells us about their health?
- Be careful. In an employment relationship consent is rarely considered freely given. Someone telling you something does not in itself give the employer a right to record or share it. Consider whether another basis applies, and whether it needs writing down at all.
- Does pseudonymisation make the data safe to collect?
- Pseudonymised information is still personal data where a route back to the individual exists. In small organisations and small groups that route is often shorter than assumed.
- How do we document measures without naming people?
- Describe the arrangement, not the case: what is available, to whom, how it is triggered, who owns it, and when it was last reviewed. Individual cases belong in a separate track with restricted access.
- What does the free review look at?
- We read one governance document and point to up to three areas for improvement with reference to relevant legal requirements, plus one suggested rewrite. We read the document, never employees, and the document must not contain personal data.