Cornerstone OnDemand · Works council

HR analytics your works council can sign off

Section 87 BetrVG, the court decision that drew the line, minimum group sizes and what a works agreement asks for – and how to enforce it in the product.

Robert Bucher Robert BucherOctober 11, 2026 · 5 min read

In Germany, and in many other European countries, HR analytics does not start with a dashboard. It starts with a meeting with the works council. Get that meeting right and a good tool goes live in weeks. Get it wrong and the best tool in the world stays on the shelf – or worse, goes live and gets switched off by a court.

This is what the works council will ask, why it asks, and what an HR analytics setup on Cornerstone OnDemand data has to do so the answer can be "yes". We are not lawyers and this is not legal advice; it is what we have learned building for HR teams who have to have this conversation.

Why the works council has a say at all

Section 87(1) no. 6 of the German Works Constitution Act (BetrVG) gives the works council a right of co-determination over "the introduction and use of technical devices designed to monitor the behaviour or performance of the employees".

The word that trips people up is "designed". The Federal Labour Court (BAG) reads it broadly: a data-processing system is designed to monitor when it collects and records individualised or individualisable data about behaviour or performance – whether or not the employer actually intends to evaluate it. In a 2018 decision the court did not even need a full hearing to confirm that this applies to everyday standard software such as Microsoft Excel used to record attendance times, and that there is no "minor use" threshold below which co-determination falls away (BAG, 23 October 2018, 1 ABN 36/18). The same decision recalls that using SAP ERP for personnel administration is subject to co-determination as well.

An analytics platform fed with Cornerstone transcripts, certifications and the reporting line is therefore co-determined. The question is never "do we have to talk to the works council?" but "what do we agree?"

The case that shows where the line is

The clearest warning comes from a BAG decision of 25 April 2017 (1 ABR 46/15). An insurer's group-wide agreement on a "workload statistic" recorded quantitative work data per claims handler, compared each person's results with the average of their group, and showed significant deviations to the team leader. The court held the arbitration board's ruling void: continuously recording and evaluating individual performance data in this way was a serious, disproportionate intrusion into the employees' general right of personality.

The lesson for HR analytics is concrete. Figures about groups are one thing. A system that lines up named individuals against their group's average – even with good intentions – is exactly the pattern the court rejected.

Minimum group sizes, and why a "rest" group is needed

Neither the BetrVG nor the GDPR names a minimum group size for anonymous figures; it is something the works agreement sets. The idea is simple: a figure about a group is only anonymous if the group is big enough that no single person can be read out of it. A completion rate of 100 % in a team of two is a statement about two named people.

Two subtleties matter in practice:

  • Extremes. A rate of 0 % or 100 % over a small group says something about every member, so it should be hidden below the minimum, not only the group's size.
  • Subtraction. If a department total is shown together with every team but one, the hidden team can be worked out by difference. Small groups have to be folded into a "rest" group, or the remainder hidden as well, so no figure can be derived one filter step away.

What a typical works agreement asks for

Every agreement is different, but the same points come up again and again:

  • A purpose list. What the system is for (for example mandatory training, certifications, onboarding), and that it is not used to assess individual performance.
  • No rankings of people. No league tables of employees or of named managers.
  • Who sees names. Aggregates for most roles; named lists only where a duty to act justifies them, for example a manager's own team for overdue safety instructions.
  • Logging. Every access recorded, and the log available on request.
  • Retention. How long history is kept, and that it is deleted afterwards.
  • Where the data lives. Hosting location and sub-processors.

How octo.taxi enforces it, technically

We built octo.taxi with this conversation in mind, and the rules are enforced in the product, not left to good behaviour:

  • Minimum group sizes are on by default, with a floor of five. Rates of 0 % or 100 % over fewer people are never shown, and neither is a figure that could be worked out by subtracting visible groups from a total.
  • Ask octo, the plain-English question box, answers only with aggregates over groups of at least five people, whatever the organization sets.
  • Managers are compared without names. No tile, answer or list ranks named managers or people against each other or an average; a manager sees named values only for their own reporting line.
  • One individual data policy per role decides who may open a single person's record at all: aggregates only, the own reporting line, or individuals. Pay, performance, recruiting and termination data need an explicit grant per role.
  • Every access is logged, and the data is stored in Frankfurt.
  • No monitoring features. There are no rankings of people, no behaviour tracking and no automated decisions about people.

The full list, including sub-processors, is on the Trust Center – the page we suggest you send the works council before the first meeting.

The honest bit

No software makes a works agreement unnecessary, and no vendor should claim it does. What the right software does is make the agreement easy to write and easy to keep: the minimum group size is a setting, not a promise; the logs exist; and the features the works council fears simply are not there.

If the agreement is about mandatory training first – it often is, because safety instructions are where both sides agree – the compliance dashboard article shows what such a view contains.

Your data should move freely, from A to B, in style.


Sources. Works Constitution Act, Section 87 (official English translation) · BAG, 23 October 2018, 1 ABN 36/18 (decision, PDF) · BAG, 25 April 2017, 1 ABR 46/15 · octo.taxi Trust Center.

Robert Bucher

Robert Bucher is the founder of Octily, a creative studio dedicated to Cornerstone OnDemand, and the maker of octo.taxi. Octily has delivered 300+ Cornerstone projects for 104+ clients.

Your Cornerstone data, without the rate-limit wall

Dashboards, org chart, plain-language queries, and a REST API of your own – synced and kept current for you.

Get started →

Related articles