Aristotelis Zervos
Aristotelis Zervos, Editorial Director at 2B Advice, combines legal and journalistic expertise in Data protection, IT-Compliance and AI regulation.
The Pay Transparency Directive (EU) 2023/970 imposes new obligations on companies in Germany, which must be implemented by June 7, 2026, at the latest. These include employees’ rights to information regarding pay and benchmark figures, transparency reports, and, where applicable, joint pay assessments. At the same time, pay data constitutes personal information. This article highlights the areas where the directive poses challenges under data protection law and explains how companies can already begin developing strategies for providing information, reporting, and access GDPR-compliant.
Background and implementation of the EU Pay Transparency Directive
The EU Pay Transparency Directive (Directive (EU) 2023/970) entered into force on June 6, 2023. The directive aims to more effectively enforce the principle of „equal pay for equal or equivalent work“ and to reduce the gender pay gap. Germany is required to transpose the directive into national law by June 7, 2026, at the latest. Accordingly, an amendment to the German Pay Transparency Act (EntgTranspG) is expected by that date. A commission of experts already submitted implementation proposals in November 2025, and the legislative process is scheduled to begin in early 2026.
Note: The specific scope of obligations may still change before implementation. Among other things, the German legislature must decide exactly how the directive’s requirements will be implemented at the national level. For example, whether a minimum size for comparison groups (similar to the current 6-person threshold in the EntgTranspG) will be retained and how Article 12(3) of the Directive will be implemented. However, companies should begin addressing the upcoming new regulations now, as extensive adjustments to compensation systems and internal processes will be necessary.
The controversial aspect of these requirements in terms of data protection law is that they Transparency about salaries. A topic that has often been treated confidentially up to now. Employers have to collect, evaluate and forward considerable amounts of personal pay data to Third (Employees, Works Council, authorities): This must be done in compliance with data protection regulations.
The Tension Between Pay Transparency and Data Protection
The Directive expressly emphasizes in Art. 12 (1) that any collection, Processing and disclosure of information in accordance with Art. 7, 9 and 10 in compliance with the GDPR must take place. Basic principles of data protection law therefore also apply without restriction to the implementation of pay transparency measures.
Charge data are personal data. This is not limited to cases where an employee’s name is mentioned directly. Even seemingly anonymized information can indirectly identify an individual. For example, if the individual can be identified based on a small comparison group or other contextual information. Since the directive—unlike the current Remuneration Transparency Act (EntgTranspG)—does not prescribe a minimum size for comparison groups, the average comparative pay may reveal an individual’s salary, particularly in the case of very small comparison groups. Example: If a male employee asks about the average salary of women in his narrow comparison group and there is only one woman in that group, the information provided would disclose her salary. The German legislature was already aware of this risk under the previous law: Section 12(3), second sentence, of the EntgTranspG stipulates that no comparative pay shall be disclosed if the comparable job is performed by fewer than six employees of the opposite sex. This safeguard clause prevented the identification of individual salaries. However, it also means that in small companies, the right to information often comes to naught.
Although the EU Directive now dispenses with rigid thresholds, it does provide an instrument to mitigate this tension in Art. 12 para. 3 of the Remuneration Transparency Directive. According to this provision, member states can stipulate that in cases where there is a risk of indirect disclosure of individual salaries, sensitive pay information is not provided directly to the employee making the request, but only to an intermediary body. This can be the Works Councilwhich Regulatory Authority or the equality body. These bodies should then advise the employee on their rights without disclosing the specific pay levels. This would affected person would be informed of possible claims (e.g. due to discrimination), but at the same time the salary of the comparator would remain protected.
Restricted Use of Salary Data
The Directive also contains a clear provision in Art. 12 (2) that Earmarking: Personal data, ...collected as part of transparency measures may be used exclusively to enforce the principle of equality. Further processing of this data for other purposes incompatible with pay transparency (e.g., general salary benchmarking analyses that go beyond the required scope) is prohibited.
Companies should therefore ensure that they do not use compensation data collected for the purpose of providing information or preparing reports for any other purpose.
Important requirements of the Pay Transparency Directive with reference to data protection
The Pay Transparency Directive includes several Transparency- and reporting requirements that the Processing of employees' remuneration data. The following requirements in particular are in conflict with data protection:
- Individual Right to Information (Art. 7 of the Payment Services Transparency Directive): Employees have the right to receive information about their individual compensation as well as the average compensation levels of colleagues performing the same or equivalent work. This information must be broken down by gender. The request for information must be granted in writing within two months. Unlike the previous legal situation, the restriction to companies with more than 200 employees no longer applies. Going forward, this right applies regardless of company size. In addition, all employees must be informed annually about this Right to information to inform.
- Pay Transparency Report (Art. 9 of the Pay Transparency Directive): Employers with at least 100 employees are required to prepare a regular report on the gender pay gap within their company. These reports must include, among other things, the overall gender pay gap as well as differences within individual groups of employees performing the same or equivalent work, broken down by pay components in each case. The reports must be made available to employees and employee representatives. Upon request, the Regulatory Authority or the Equal Opportunity Office. Companies with 250 or more employees must report annually (for the first time by June 7, 2027, covering the year 2026). Companies with 100 to 249 employees, on the other hand, are only required to report every three years.
- Joint Fee Assessment (Art. 10 of the Fee Transparency Directive): If the transparency report identifies a disparity in average pay between women and men in a comparison group that exceeds 5 %, and if the employer cannot objectively justify this gender pay gap, the employer must conduct a detailed pay assessment in collaboration with the employee representatives. As part of this joint analysis, the causes of the pay gap must be investigated and corrective measures developed. The results of the pay assessment must then be disclosed to the workforce and the Regulatory Authority make it available. In addition, the employer must eliminate any unjustified disparities within six months of the report’s publication.
Recommendations for Implementation in Compliance with Data Protection Regulations
In light of the upcoming requirements, companies should take early action to ensure that the GDPR-Compliance at the Processing of charge data. The following principles and precautions in particular have proven to be essential:
- Earmarking ensure: Pay data may be used exclusively to implement pay transparency requirements. It must not be used for any other purposes (such as general workforce planning statistics or salary comparisons outside the context of equal pay) (Art. 12(2) of the Pay Transparency Directive). Companies should therefore clearly communicate internally what the collected salary data may and may not be used for.
- Data minimization and memory limitation: The aim is to use as few personal data as far as possible. Only the data required to fulfill the transparency obligations (Art. 5 para. 1 lit. c GDPR) may be processed. In addition, a Fire Suppression Plan Recommended: Newly collected data records (e.g., payroll records for the report) should be stored only as long as necessary. Once the purpose has been fulfilled, the data should be deleted or anonymized promptly.
- Need-to-know principle implement (access restriction, Art. 5 lit. f GDPR): Highly sensitive compensation data may only be accessible to a strictly limited group of individuals. Therefore, develop an access policy that specifies which individuals in which roles are granted access to which compensation data. Access should be granted only to the extent strictly necessary for the performance of their duties. Access to raw data, for example, could be restricted to selected HR or Compliance-employees. Document the assignment of permissions and deliberately keep the group of authorized individuals as small as possible. In addition, all authorized individuals should be explicitly informed of the Confidentiality of the data (keyword: official secrecy). If data is transferred to the Works Council or other employee representatives, it must be ensured that only the absolutely necessary information is passed on and that the recipients are made aware of their statutory duty of confidentiality. According to Section 79 BetrVG, works councils are obliged to maintain confidentiality as soon as the employer discloses the information. Confidentiality expressly emphasized in the information provided.
TOMs and documentation
- Technical and Organizational Measures: Develop a data management strategy that specifies how and where compensation data is securely stored. Compensation data should be stored exclusively in designated, secure locations and accessed only from there. The uncontrolled circulation of payroll lists—for example, via email to broad distribution lists or as Excel files stored in insecure locations—must be strictly avoided. Such scenarios pose a high risk of data leaks and misuse: If extensive payroll data falls into the wrong hands, there is a risk not only of GDPR-Fines, but also significant damage to your reputation and a loss of trust. Whenever possible, use technical solutions that have already implemented “privacy by default.” Specialized payroll transparency software, for example, can offer role-based access rights, automatic logging of every access event, and preconfigured security measures. This ensures that sensitive data cannot be copied or stolen without being detected. In any case, companies should implement appropriate Technical and organizational measures (TOMs) in accordance with Art. 32 GDPR to ensure a level of protection appropriate to the risk. Although salary data does not count as particularly sensitive data within the meaning of Art. 9 GDPR, However, they are highly personal and confidential for most employees, so a higher level of protection is justified.
- Documentation and accountability: Companies should document all measures and concepts taken in writing (Art. 5 para. 2 GDPR). In the event of an audit, it can be demonstrated to the supervisory authorities that the principles of the GDPR were adhered to. A clean Documentation also creates internal clarity and can gain the trust of employees.
Reading tip: Health data in the event of continued illness as a data protection challenge
Pay Transparency and Data Protection: 2B Advice Helps You Implement These Measures
Companies should set the organizational course now so that they are not unprepared for the deadline of 7 June 2026. This includes developing role and authorization concepts at an early stage and drawing up internal guidelines for handling pay data. If necessary, company agreements with the Works Council It is advisable to draw up a binding regulation for the implementation of transparency measures in the company. Finally, all those involved - from the HR department to the data protection officer and management - should be prepared for the new requirements through training.
Careful and confidential handling of salary information is essential to ensure that the noble goal of the directive—equal pay for all genders—is achieved without violating the Privacy can be achieved among employees.
2B Advice helps you, among others with:
- Readiness check / gap analysis (EntgTranspRL requirements vs. actual processes, data situation)
- Data protection concept for pay transparency (Legal basis, Earmarking, Data minimization, Fire Suppression Plan)
- Access and authorization concept (need-to-know, roles, logging, governance)
- Process design For Information Requests and Reporting
- TOM review and risk assessment practical action plans
- Training courses for HR, Legal, Data Protection & Compliance (incl. communication guidelines)
If you want to implement Early, Legally Sound, and Pragmatic If you'd like to set one up, please contact us! We'd be happy to assist you with the planning and implementation.
Aristotelis Zervos is Editorial Director at 2B Advice, a lawyer and journalist with profound expertise in data protection, GDPR, IT-Compliance and AI governance. He regularly publishes in-depth articles on AI regulation, GDPR-Compliance and risk management. You can learn more about him on his Author profile page.





