The Czech Ministry of Health, led by Adam Vojtěch (ANO), reportedly carried out a secret, multi-week audit this spring to check what employees were doing on their work computers. According to officials, the monitoring took place even outside working hours, and the external firm hired for the job may have gained access to sensitive personal data.
Ministry staff have drawn up a petition against the monitoring and plan to file complaints with the Office for Personal Data Protection and the State Labour Inspection Office. Several dozen ministry employees have already signed the document.
According to staff, the ministry tracked all activity on so-called active computer screens. The resulting analysis reportedly included employees’ invoices, bank statements and medical certificates. The petition’s authors note that this method could also have swept up data belonging to third parties the officials were dealing with in the course of their work.
Moreover, staff were not informed in advance about the audit, even though employers are legally required to give at least a general notice of such monitoring. The petitioners argue that the scope of the surveillance was excessive and failed to meet legal requirements.
The ministry’s press office insists there was no “spying” involved and that this was simply a standard procedure that employees misunderstood. At the same time, the ministry has refused to disclose which company carried out the analysis, how much it cost, or to publish the results of the audit.
Minister Vojtěch sent staff a letter attempting to reassure them, saying the goal of the analysis was to obtain an objective picture of the state of the ministry’s IT and technological environment following the change of leadership, and to check whether work systems were being used safely and effectively. However, in the same letter he admitted that some of the cases identified could be discussed further with specific employees — a statement that contradicts his own claim that the data collection was purely statistical in nature.
Employee accounts confirm that data on individual staff members was indeed passed on to their superiors, including lists of visited websites — without any clear distinction between work-related and personal internet use. The petition’s authors describe the classification method used as “inconsistent and questionable.”
The ministry maintains that it acted within the law and its internal regulations, and considers any accusations of wrongdoing unfounded. Employees, however, believe the Labour Code and GDPR rules may have been breached, and are now awaiting an assessment from the relevant oversight bodies.
Source: seznamzpravy.cz