To be clear from the outset: this article is not legal advice. It sets out the data-protection questions HR should settle before a 360° feedback process and points to the official texts. What is right for your organisation depends on purpose, audience, employee representation and risk – and belongs with your data protection officer and, where needed, a lawyer. Points specific to Germany are flagged as such.
Why 360° feedback is a data-protection project
360° feedback collects assessments of a person and is therefore almost entirely personal data. The leader's data is obvious: name, role, self-assessment, aggregated ratings, free text about them. Less obvious: every answer is also personal data of the person who gave it. Raters are data subjects under the GDPR, not merely data sources. Art. 5 GDPR provides the checklist: lawfulness and transparency, purpose limitation, data minimisation – and accountability, being able to demonstrate compliance.
- DefinitionPersonal data in 360° feedback
- Any information relating to an identified or identifiable person. For the leader: master data, self-assessment, group averages, free text about them. For the raters: assignment (supervisors, peers, direct reports), individual answers, completion status. Aggregation shields answers from the leader – it does not make them anonymous in the GDPR sense inside the vendor's database.
Legal basis: contract, legitimate interest, § 26 BDSG – and why consent is fragile
Under Art. 6(1) GDPR, processing is lawful only if one of the listed bases applies. For a 360° in employment, three are usually discussed: contract (point (b)), legitimate interest with a documented balancing test (point (f)) and, in Germany, § 26 BDSG, enacted under the opening clause in Art. 88 GDPR. Consent (point (a)) is the most fragile option in an employment relationship.
| Basis | Discussed for | Where it can fail |
|---|---|---|
| Consent (Art. 6(1)(a) GDPR; § 26(2) BDSG) | Voluntary programmes at the leader's request | Voluntariness in a relationship of dependence; withdrawal; usually written or electronic form |
| Contract (Art. 6(1)(b) GDPR) | Development as part of the employment relationship | Necessity must follow from the contract |
| Legitimate interest (Art. 6(1)(f) GDPR) | Leadership development as a business interest | Documented balancing test; interest named in the notice (Art. 13(1)(d)) |
| § 26(1) BDSG (Germany) | Necessity for the employment relationship | Since CJEU C-34/21 no longer reliable as the sole basis |
| Works agreement (Germany) | Purpose, anonymity, access, retention agreed collectively | Needs a works council and time; does not replace informing each individual |
Why consent is fragile was set out by the Article 29 Working Party in Opinion 2/2017 on data processing at work (WP 249): given the imbalance of power, employees can give free consent only in exceptional circumstances, where refusing carries no adverse consequence. Contract and legitimate interest hold only where processing is genuinely necessary, proportionate and the least intrusive option.
The opinion predates the GDPR's application and was not among the documents the European Data Protection Board formally endorsed in 2018; supervisory authorities still rely on it. In Germany, § 26(2) BDSG adds that voluntariness is assessed with the employee's dependence in mind and may exist in particular where the employee gains a legal or economic advantage.
Germany: § 26 BDSG after the CJEU's C-34/21 ruling
On 30 March 2023 the CJEU held in C-34/21 that a national provision which merely restates the necessity condition of Art. 6(1)(b) or (e) GDPR is not a "more specific rule" under Art. 88(1) and must be disregarded unless it independently qualifies as a legal basis under Art. 6(3). The case concerned a Hessian provision whose wording mirrors § 26(1) BDSG; the prevailing reading in German commentary is that § 26(1) sentence 1 BDSG is equally affected. A 360° resting on § 26 BDSG alone stands on thin ice: anchor it in Art. 6(1)(b) or (f) GDPR as well and, where a works council exists, in a works agreement.
Co-determination under § 87(1) no. 6 and § 94 BetrVG is covered in 360° feedback and the works council.
Purpose limitation: development or appraisal?
The most important decision is the purpose. Art. 5(1)(b) GDPR requires specified, explicit and legitimate purposes and prohibits incompatible further processing. A 360° for development, with results seen only by the leader and their consultant, is a different undertaking from an appraisal system whose scores feed pay, promotion or exit decisions – it changes the balancing test, co-determination, risk and the raters' willingness to answer honestly. Fix the purpose in writing before you invite anyone.
Art. 22 GDPR adds a limit: nobody may be subject to a decision based solely on automated processing, including profiling, that produces legal or similarly significant effects. A 360° result must not be the sole basis of an automated promotion or selection decision unless an Art. 22(2) exception applies and the Art. 22(3) safeguards – human intervention, the right to contest – are in place. Who sees results at all: Can HR see individual 360° results?
Transparency and data-subject rights: Art. 13 and the right of access
Where data is collected from the data subject, they must be informed at that point (Art. 13 GDPR) – including purposes and legal basis (para. 1(c)) and, where you rely on legitimate interest, that interest (1(d)). That applies to the leader at the self-assessment and to every rater at the invitation. The vendor's privacy policy does not replace this notice: your organisation is the controller, the vendor a processor.
The hardest question is the right of access. The leader may access the personal data processed about them – ratings included. The same answers are personal data of the raters, who were promised anonymity. Both positions are legitimate; the tension can only be weighed case by case. Settle in advance: in what form access is given (for instance group values and unattributed free text, as in the report), who handles the request, how free text that could identify a person is treated, and how raters are told about that rule. How technical anonymity is produced: Is 360° feedback anonymous?
Data protection impact assessment: when it becomes likely
Art. 35(1) GDPR requires a data protection impact assessment (DPIA) before processing that – in particular using new technologies, and given its nature, scope, context and purposes – is likely to result in a high risk to the rights and freedoms of natural persons. Art. 35(3)(a) expressly names a systematic and extensive evaluation of personal aspects based on automated processing, including profiling, on which decisions with legal or similarly significant effects are based. Whether a purely developmental 360° falls under that is settled by the supervisory authorities' lists under Art. 35(4) – in Germany coordinated by the Datenschutzkonferenz (DSK), the conference of the federal and state supervisory authorities.
- A DPIA becomes more likely when results feed appraisal, pay or selection decisions;
- when many leaders are assessed repeatedly and profiles are linked across cycles;
- when free text is analysed automatically or combined with other HR data;
- when questions about workload and recovery are asked – for instance on Well-being – whose proximity to health data you should assess with your data-protection adviser.
Ask the vendor for support – Art. 28(3)(f) GDPR obliges a processor to assist the controller with its obligations under Art. 32 to 36, the DPIA included – and a description of the processing: data categories, storage locations, sub-processors, anonymity mechanics, deletion concept. Document a "not required" outcome with reasons too.
Processors, hosting and retention
A 360° vendor processes data on your behalf; Art. 28 GDPR requires a data processing agreement (DPA) setting out the processor's obligations. Ask specifically: where do database, authentication, files and application run? Which sub-processors exist, does any process data outside the EU – on what basis? Are free-text comments processed by third parties or AI services? A vendor who cannot answer in a list is not ready for a DPIA.
Retention is the question most often postponed. Define per data category how long it is needed for the purpose – invitation and status data, individual answers, reports, free text, logs. A report the leader wants to compare across cycles needs a different period from the raw answers behind it. Record the periods in the DPA and in the notice, including what happens when the leader leaves or the contract ends.
Pre-launch checklist
- Set the purpose down in writing – development, not appraisal – and rule out a later change of purpose.
- Document the legal basis, including the balancing test; in Germany, do not let § 26 BDSG carry it alone.
- Involve the works council (Germany): check § 87(1) no. 6 and § 94 BetrVG, negotiate a works agreement – see 360° feedback and the works council.
- Write the Art. 13 notice separately for leaders and raters, including the anonymity rules.
- Decide how access requests are handled before the first one arrives.
- Check whether a DPIA is required and document the outcome – a "no" as well.
- Sign the DPA; review sub-processors, storage locations and third-country transfers.
- Record retention, deletion and access rules: periods per data category, and who sees what.
Frequently asked questions
Is 360° feedback GDPR-compliant?
It can be – compliance is a property of your programme, not of the tool. It depends on a documented legal basis, purpose limitation, notices to data subjects, how you handle data-subject rights, and a proper data processing agreement. A vendor can create the preconditions; it cannot take over your responsibility as controller.
What is the legal basis for 360° feedback of employees?
The bases usually discussed are necessity for the employment contract (Art. 6(1)(b) GDPR) and the employer's legitimate interest with a documented balancing test (Art. 6(1)(f)); in Germany § 26 BDSG and a works agreement are added, with the caveat from CJEU C-34/21. Consent is fragile at work because free choice is hard to demonstrate (WP 249). Which combination holds for you is a question for your data-protection adviser.
Do we need a DPIA for 360° feedback?
Not automatically. Art. 35 GDPR requires one where processing is likely to result in a high risk, in particular a systematic evaluation of personal aspects with decision consequences; the supervisory authorities' lists under Art. 35(4) settle individual cases. Check and document the outcome either way, and ask the vendor for support – Art. 28(3)(f) obliges them to provide it.
Can a leader request access to their 360° feedback under GDPR?
The right of access covers the personal data processed about the leader, and ratings about them are part of that – but the same answers are the raters' personal data. Settle the rule before launch: access in the form the data takes in the report (group values, unattributed free text), a defined process for free text with identification risk, and raters informed of that rule. Background in Is 360° feedback anonymous?.
How long can 360° feedback data be kept?
What matters is how long the data is needed for the stated purpose. Define a period per data category – raw answers, reports, free text, logs – and record it in the data processing agreement and in the notice to data subjects.
What GDPR questions should we ask a 360° feedback vendor?
Where the database, authentication, files and application run; which sub-processors exist and whether any of them process data outside the EU, on what basis; whether free text is processed by third parties or AI; what the DPA covers; and what DPIA support material they provide. LEADBeyond 360° is hosted in Frankfurt am Main and names its processors in the privacy policy.
Does this apply outside Germany?
The GDPR articles discussed here apply across the EU/EEA. § 26 BDSG, works agreements and the BetrVG co-determination rights are specific to Germany; other member states may have their own employment-data rules under the opening clause in Art. 88 GDPR, so check the national position with local advice.
Sources
- Regulation (EU) 2016/679 (General Data Protection Regulation), Art. 5, 6, 13, 22, 28, 35, EUR-Lex (2016) — Official consolidated text.
- CJEU, Judgment of 30 March 2023, C-34/21 (Hauptpersonalrat der Lehrerinnen und Lehrer beim Hessischen Kultusministerium), ECLI:EU:C:2023:270, EUR-Lex (2023) — The judgment concerned § 23 HDSIG (Hesse); its extension to § 26(1) sentence 1 BDSG is the prevailing reading in German commentary, not part of the CJEU judgment itself.
- Article 29 Data Protection Working Party, Opinion 2/2017 on data processing at work (WP 249), adopted 8 June 2017, European Commission (Article 29 Working Party newsroom) (2017) — WP29 guidance issued before the GDPR applied; not among the documents the European Data Protection Board formally endorsed on 25 May 2018 (Endorsement 1/2018).
- European Data Protection Board, Endorsement 1/2018 (25 May 2018), European Data Protection Board (2018) — List of the 16 WP29 documents endorsed on the GDPR's application date; WP 249 is not among them.
- § 26 BDSG – Datenverarbeitung für Zwecke des Beschäftigungsverhältnisses (German Federal Data Protection Act, employee data), Federal Ministry of Justice / juris (gesetze-im-internet.de) (2018) — Official German text; no official English translation is cited here.
- § 87 BetrVG – Mitbestimmungsrechte (German Works Constitution Act; para. 1 no. 6: technical devices intended to monitor behaviour or performance), Federal Ministry of Justice / juris (gesetze-im-internet.de) (2026) — Statute text only; the case-law reading of "intended to" is outside the scope of this article.
- § 94 BetrVG – Personalfragebogen, Beurteilungsgrundsätze (German Works Constitution Act; personnel questionnaires and appraisal principles), Federal Ministry of Justice / juris (gesetze-im-internet.de) (2026) — Statute text only; whether a specific 360° questionnaire falls under it must be assessed case by case.
Related reading
Trust & governance
Does a German works council have to approve 360° feedback? What to settle before you roll out
Why §§ 87 and 94 of the German Works Constitution Act come up for 360° feedback, what a works agreement usually covers and how to involve the works council early. Not legal advice.
Read more →Trust & governance
Is 360° feedback anonymous? Anonymous in the answers, confidential in participation
Anonymous in the answers, confidential in participation: what the anonymity threshold does, why written comments are the weak point, and what you can honestly promise raters.
Read more →Trust & governance
Who sees what – and who does not: confidentiality at LEADBeyond 360°
Anonymity threshold, free-text rules, what HR sees, when supervisors appear separately, consultant review, Frankfurt hosting: how LEADBeyond 360° enforces confidentiality.
Read more →