Skip to content

Security

Security, data protection and codetermination, including the open points.

This page describes the current state of development. What is not in place yet is written in the future tense, and what is missing is listed further down.

We do not claim a certification we do not hold.

Technical and organisational measures

State of implementation

  • Processing and storage in the EUplanned
  • Agreement under Art. 28 GDPRbefore first processing
  • Roles and access rightsbeing built
  • External penetration teststill open
  • ISO/IEC 27001 certificationnot held

Whatever is not listed here, we state just as plainly on request. The status is updated with every change.

Data protection

Processing, storage, rights

The fundamentals are settled before the first production workforce file is ever touched. That is not evidence, it is a commitment.

01

Processing and storage in the EU

QualiShift will run in data centres inside the European Union. If a provider outside the EU becomes necessary for part of the service, it appears in the register of sub-processors, with the legal basis, before it is used.

02

Data processing agreement under Art. 28 GDPR

The company is the controller and QualiShift is the processor. Annexes to the agreement will cover the technical and organisational measures, the sub-processors, the binding instructions and deletion at the end of the contract.

03

Roles and access rights

Access follows from a role, not from a position in the hierarchy. Employees see their own data, departments see their unit, the works council sees the aggregated documents. Administrative rights stay separate.

04

Deletion

Data is deleted as soon as the purpose ends: participation data once record-keeping periods run out, analysis data with the end of the initiative, access when someone leaves. Backups expire on a shorter cycle.

Data minimisation

Which data is genuinely needed

The shortest security measure is the category of data that is never collected in the first place.

The second column is the actual point. A system that merges pay, appraisal and learning behaviour into one record becomes a monitoring device, no matter how it was intended.

6

Genuinely needed

categories of data

  • Unit, site and shift
  • Membership of a role cluster
  • Current skill level, captured at role level
  • Formal certificates where admission requires them
  • Attendance, scheduling and completion status
  • One contact route for the invitation

6

Not collected

categories of data

  • Pay and pay grade
  • Performance appraisal and potential rating
  • Health and absence data
  • Assessments of resignation risk
  • Usage profiles on learning time and click behaviour
  • Free-text assessments written by managers

Data model

Role level and individual level are kept apart

The analysis works on the role level. No name appears anywhere in that chain. The individual level only begins with the invitation to a specific measure.

The split is a question of the data model, not only of permissions. A report at role level stays meaningful even when nobody may see the individuals behind it, and that is exactly the document works council participation requires.

Role level, no personal reference

  1. Initiative and affected units
  2. Role clusters with headcount
  3. Current and future activity profile
  4. Skill gap and learning path
  5. Programme proposal and cohort size

Individual level, only from the invitation on

  1. Invitation to a specific cohort
  2. Enrolment, admission and release from work
  3. Attendance and completion status
Industrial robot arm in a blue lit manufacturing plant

Codetermination

What the German Works Constitution Act requires here

Anyone planning a wave of qualification touches several participation rights at once, and earlier than most project plans assume.

Section 92 BetrVG

Information on workforce planning

Information on workforce planning including vocational training, in good time, comprehensively and on the basis of documents. In good time means before the decision.

Consequence for the workThat document falls out of the analysis: units, role clusters with headcount, the changed activity profile and the training need, dated and traceable.

Section 96 (1) BetrVG

Identifying the training need

At the request of the works council, the employer has to identify the vocational training need and discuss training matters with it.

Consequence for the workIdentifying the need is therefore not voluntary diligence but a duty the works council can trigger. QualiShift makes it repeatable rather than a one-off.

Section 97 (2) BetrVG

Codetermination where the work itself changes

Where measures by the employer change the work of employees and their occupational knowledge no longer suffices, the works council codetermines the introduction of vocational training measures.

Consequence for the workThe core case of a transformation initiative and the most important provision on this page. Qualification is then subject to codetermination, not merely to consultation.

Section 98 BetrVG

Carrying out workplace training

Codetermination in how measures are carried out, plus the right of the works council to propose which employees take part.

Consequence for the workCodetermination does not stop at whether training happens. A cohort list drawn up without the works council is open to challenge even when it is professionally correct.

Section 94 BetrVG

Questionnaires and assessment criteria

Personnel questionnaires and general assessment criteria require the consent of the works council.

Consequence for the workWe say openly what many leave out: a skill profile held per employee very probably falls under this. The route is a works agreement, not a narrow reading.

Section 87 (1) no. 6 BetrVG

Technical monitoring devices

Codetermination on technical devices designed to monitor behaviour or performance. Under settled case law, an objective capability to monitor is enough.

Consequence for the workBecause capability is enough and intent is not required, any software storing learning progress per person is caught in case of doubt. We treat that as given.

What follows from this for the product

Documents come out of the analysis. The document required under section 92 BetrVG comes from the same calculation as the programme proposal, not from a late night before the meeting.

No assessment of individuals. No suitability grade, no ranking, no score. What is compared are the requirements of a target role and the level of a group.

We state the uncomfortable half too. As soon as a skill profile is held per employee, consent under section 94 BetrVG is the likely case.

What a works agreement usefully covers

  • The purpose of processing and an explicit limitation to it
  • A closed list of the categories of data processed
  • Roles, access rights and who grants them
  • Minimum group sizes for reports
  • A ban on behaviour and performance monitoring
  • The procedure for introducing new reports
  • Deletion periods once the initiative ends
  • Term, termination and what happens to the data

This list replaces neither legal advice nor a model text. It describes the points that come up first in conversations with works councils.

EU AI Act

A documentation tool is not a system that decides about people

QualiShift documents and assigns. It does not propose dismissals, rate performance, screen applications or steer promotions.

Whether and how far the AI Regulation applies depends on how the customer shapes the deployment. We therefore assign ourselves no risk class, but clarify the classification case by case and document it.

What we commit to regardless of the classification

  • Disclosure of the classifications and rules in use
  • Traceability of every assignment back to its source
  • A human decision wherever a specific person is concerned
  • Logging of changes to profiles and reports
  • No training of models on one customer's data for others

Open points

What is not in place yet

Four things are missing, and it is cheaper to read them here than to find them in the second security review.

No certification
We hold no ISO/IEC 27001 certification and claim none. If your procurement requires one, that is a requirement we should discuss.
Penetration test still open
A test by an external provider is planned before any production employee data is processed. We share the result with customers on request.
Documentation in progress
The register of processing activities, the description of technical and organisational measures and a skeleton for a works agreement are taking shape with the first partner companies.
No funding advice
We do not assess eligibility under Section 82a SGB III, file applications or judge entitlements. The provision is cited only as evidence that the legislator recognises the problem.

Next step

Questions on security, data protection or participation?

Write to us, including with the questionnaire from your information security team. We answer in writing and say plainly what we cannot yet evidence.

Email: hello@qualishift.de