Data protection when working from home

Cindy Stefanet
by Cindy Stefanet · 27.09.2026

Best practices for companies

Working from home has now become a permanent part of modern work models in many companies. However, with the shift of data processing to private environments, increased data protection risks are associated. Without clear guidelines and appropriate technical and organizational measures, an adequate level of protection cannot be regularly ensured.

Companies are therefore required to consistently implement the requirements of the GDPR even in a work-from-home environment by creating appropriate frameworks and establishing clear behavioral guidelines for employees.

Step 1: The workplace

Even in the home office, it must be ensured that personal data is protected from unauthorized access. Employees must therefore set up their workplace in such a way that the confidentiality and availability of the data are generally guaranteed in the same way as in the office.

Best practices:

  • The workplace should be set up in such a way that unauthorized persons cannot gain access to the screen or the paper documents lying around.
  • At the end of the workday, the employee should ensure that the desk is tidy and that no personal or confidential documents remain open (Clean Desk Policy).
  • Physical documents and work equipment should be kept in lockable cabinets or in a separate work room that is not accessible to third parties.
  • If the workplace is visible from the outside, for example through a window to the street, you can provide your employees with a privacy screen for their laptops.
  • Work equipment should always be locked when leaving the workplace so that data cannot be viewed by third parties or unintentionally modified or deleted, for example by children or pets.
  • Employees should choose an appropriate environment for conversations (e.g., by phone or video conference) in which unauthorized persons cannot overhear them.

Step 2: The hardware used

Using company devices in a home office is regularly the safest solution. They can be managed centrally, provided with current security updates, and adapted to internal security requirements.

Private devices typically do not offer this level of security. They often lack necessary protection measures such as hard drive encryption, centralized antivirus solutions, or secure network configurations, thereby increasing the risk of data loss or unauthorized access. Additionally, there is a risk that personal and professional data are mixed together, which causes additional data protection and security issues.

Best practices:

  • Provide your employees with business laptops as well as smartphones or softphones.
  • Limit the use of private devices to absolutely exceptional cases.
  • If a private device is used exceptionally, access to corporate resources should be provided via a secure remote connection to a terminal server. The data is not processed or stored on the private device, but remains within the corporate network and is displayed and processed only via the connection.
  • Turn off the private use of devices provided by the company.

Step 3: Handling of paper documents

Paper-based processes cannot yet be completely avoided. In the home office, this creates additional risks, especially when transporting and storing documents.

Best practices:

  • Paper documents should be kept in suitable, preferably sealed folders during transport between the home office and the office.
  • Documents should not be left unattended during transportation. In particular, they should not be left in the vehicle, for example during short stops such as when shopping.
  • Confidential documents should not be disposed of in household waste. Destruction should be carried out in the office or at home using a suitable shredder that ensures an appropriate level of protection for confidential documents.
  • If possible, work in the home office should be done using copies instead of original documents to minimize the risk of damage or loss of important documents.

Step 4: Using video conferencing systems

Video conferencing solutions are an integral part of collaboration in the home office and should be selected and used in a manner compliant with data protection regulations.

Best practices:

  • Enter into a contract for order processing with the provider in accordance with Art. 28 GDPR. If the service provider processes personal data outside the EU, appropriate transfer mechanisms should be in place, such as standard contractual clauses.
  • Ensure that communication is protected by appropriate encryption; end-to-end encryption should be used for sensitive content.
  • Protect conferences with passwords or individual invitation links.
  • Make sure that records are generally kept unless there is a clear legal basis (e.g. consent from all participants).
  • Disactivate functions such as tracking, telemetry, or biometric analysis, as far as possible.
  • Establish clear rules for screen sharing as well as for the use and deletion of chat content.
  • Involve the data protection officer and, if necessary, the works council in the selection and implementation.

Step 5: IT security

Working from home brings special requirements for IT security. Unlike in the office, employees often access corporate systems through private networks and devices, which creates additional risks.

To ensure an appropriate level of protection, technical safeguards and clear organizational requirements should be coordinated. The goal is to control access to data, prevent unauthorized access, and ensure the safe handling of information even outside the corporate environment.

Best practices:

  • To access corporate systems, use exclusively encrypted VPN connections and restrict access to the servers, file storage, and applications that are actually required for home office.
  • For VPN connections, use two-factor authentication.
  • State that data is stored exclusively on network drives within the company that are accessible via the VPN connection and not locally on the end devices.
  • State that your home Wi-Fi should be secured with a strong password and that public networks should only be used in conjunction with a VPN connection.
  • Make sure that end devices are updated regularly and have up-to-date virus protection.
  • Install hard drive encryption for laptops and secure them with a PIN or password. Business smartphones should also be fully encrypted and secured with a PIN lock.
  • Establish clear measures for the loss of devices, such as the possibility of remote deletion.
  • Set rules or restrictions on the use of USB ports. For example, ports can be disabled or the use of private USB sticks prohibited.
  • Make sure that IT support for employees working from home is always available.

Step 6: Using cloud services

Cloud services are almost indispensable in today’s work environment and enable flexible collaboration from home. At the same time, personal data is transferred to external providers and processed outside the company’s own IT infrastructure.

This creates additional data protection requirements, particularly regarding control over data processing, the security of systems, and possible data transfers to third countries. To ensure an adequate level of protection, it is therefore necessary to clearly regulate the use of cloud services and specifically manage the associated risks.

Best practices:

  • Make sure that only approved cloud services are used (whitelist).
  • Enter into a contract for order processing with the provider in accordance with Art. 28 GDPR. If the service provider processes personal data outside the EU, appropriate transfer mechanisms should be in place, such as standard contractual clauses.
  • The transmission and storage of data by the provider should be secured by appropriate encryption procedures in accordance with current state-of-the-art technology.
  • Make sure that data is completely deleted upon termination of the contract and have this confirmed in writing by the provider.
  • Use strong passwords for all access points and implement two-factor authentication for all users for cloud applications with a large amount of sensitive data; for administrative accounts, this should be mandatory in all cases.
  • Continuously sensitize your employees to current phishing risks, especially through practical examples such as fake emails, manipulated login pages, or attacks on cloud access.

Step 7: Using Messenger services

Messenger services are also increasingly used in a professional context, for example for quick team-based communication. However, personal data is regularly processed by external providers. Therefore, their use should be clearly regulated and limited to data protection-compliant solutions.

Best practices:

  • For corporate communications, only use messaging services that ensure secure communication through end-to-end encryption and transport encryption.
  • Ensure that communication data, in particular metadata, is not used by the provider for advertising or profiling purposes.
  • Control access to contact data technically, for example by using mobile device management solutions.

Step 8: The organizational arrangements

Finally, in addition to technical measures, clear organizational rules should be established. These serve to create uniform processes for handling data, establish responsibilities, and ensure that the specified protection measures are actually observed in everyday work..

Best practices:

  • Keep an overview of the employees working from home and the devices they use.
  • Inform and train your employees regularly about the applicable home office regulations.
  • Obtain a written commitment to comply with the requirements.
  • Disallow the forwarding of business emails to private accounts.
  • Limit the use of confidential documents to secure office environments.

Conclusion:

A variety of suitable technical and organizational measures are available for data protection-compliant work from home. The key is a consistent and practical implementation in everyday work. Only when clear guidelines exist and are adhered to by employees can data protection risks be effectively minimized and an adequate level of protection be permanently ensured.

We are happy to assist you in creating or reviewing your home office policies, as well as in implementing appropriate technical and organizational measures.

Check the mandatory fields –
Step-by-step in the webinar

FAQ

What data protection requirements apply in the home office?


How should the workplace in the home office be designed?


Are private devices allowed to be used for work in the home office?

What should be considered when using video conferencing in the home office?


Which IT security measures are particularly important in a home office?


What organizational rules should companies establish for home office work?