Compliance Handbook
All risks around remote work simply explained
WorkFlex does not just assess the risks, it also implements a compliant solution for each trip. This saves the employer on average 3 hours of manual work per trip.
The compliant solution consists of (a combination of) the 8 measures:
Knowing that WorkFlex will put the compliant solution in place, allows the global compliance engine to qualify more requests as low risk with two main results:
WorkFlex immediately and automatically establishes an audit trail of the entire process. There is no need to keep any additional administration, as all information and documentation remain available on the platform for both the employer and the employee. The details of the employee`s request as well as the manager and HR approval (including time stamp), are examples of the audit trail.
Based on the data provided, all risks are immediately assessed, and the result is stated in a so-called "Risk Assessment" (for workations) and "Compliance Summary" (for business trips).
This will include all measures to be taken, either by WorkFlex or the employee or employer.
WorkFlex immediately and automatically requests social security statements. After it has been issued - it will be directly uploaded to the platform along with all other necessary trip documents. As of now, WorkFlex can request A1s and CoCs in these countries (see here for details).
Further - for documentation of the applicable social security rules, the unique WorkFlex Social Security Statement – Provisional A1 or Provisional CoC - is always immediately produced and uploaded. The content is similar to an A1 or CoC (see example here), so the employee and employer can prove the legal background has been checked and subsumed. Moreover, for short requests (60 days or below) and for cases where asocial security treaty applies, the WorkFlex Social Security Statement ensures that the no-risk concept applies.
If agreed upon with the employer, WorkFlex ensures that every employee is covered by adequate travel insurance from Hallesche ALH Group, an established German insurance company. Immediately after the request has been approved, WorkFlex automatically generates a confirmation of this travel insurance – the WorkFlexTravel Insurance Certificate (WTIC) document and makes it available on the platform.
Each company can upload its individually drafted company policy determining day thresholds, destination thresholds, work locations such as Co-Working spaces, VPN regulation, etc. Based on the rules determined in the company policy, WorkFlex is double-checking via employee confirmation to protect the employer. Many risk assumptions are based on the talent’s answers, which can create a risk if the employee does not respond truthfully. So, making them accept the employee confirmation, is one step more than just having a policy on the intranet. Examples are the employee accepting the policy and the data protection instructions. Also, via WorkFlex, the employee confirms that all information provided is correct and complete.
Immediately after the request has been approved, WorkFlex automatically generates an employee instructions document and makes it available on the platform. The employee instructions can be made employer-specific, and generally include the most important do`s and don`ts from the policy, as well as the WorkFlex emergency contact details.
WorkFlex will determine whether the planned trip needs to be registered in the destination country. Upon the assessment, when registration is necessary, the employee will be asked for further details to enable WorkFlex to directly register the employee in the respective portal. Required to proceed with the country registration, details of the trip are asked, often the contact details of the client/customer/business contact in the destination as well as workplace and hourly or yearly wages of the traveller.
As part of the Data Protection sub-assessment, WorkFlex assesses whether a so-called Data Transfer Impact Assessment (TIA) is required. If so, WorkFlex will do such an assessment on behalf of the employer and upload a report with the result to the platform – ensuring GDPR compliance for the employer. The TIA is generated with the risk assessment file, not after submission. Furthermore, we ensure compliance with GDPR requirements, e.g. through employer guidelines and employee instructions.
Download now our extensive whitepaper with best practices to mitigate the risks of unsecured Wi-Fi networks, Phishing attacks, and international data transfers
Download now our extensive whitepaper with best practices to mitigate the risks of unsecured Wi-Fi networks, Phishing attacks, and international data transfers
Download now our extensive whitepaper with best practices to mitigate the risks of unsecured Wi-Fi networks, Phishing attacks, and international data transfers
Download now our extensive whitepaper with best practices to mitigate the risks of unsecured Wi-Fi networks, Phishing attacks, and international data transfers