Why integrate: rationale and benefits
Law 31/1995 requires that prevention be integrated into the company’s overall management system, across all its activities and at all hierarchical levels, and Royal Decree 39/1997 specifies that this integration must extend to technical processes, work organization, and the conditions under which work is performed. When the prevention system operates with data isolated from corporate systems, integration is formal but not real: new employees do not appear in the prevention system until weeks later, job changes do not trigger information reviews and training, new equipment is not evaluated, and absenteeism and accident indicators are not linked to the organizational structure.
Integration with human resources provides the personnel master data (identification, location, position, contract, shift, start and end dates, changes), which is the basis for assigning risks, generating training and information needs, planning medical examinations, controlling the delivery of personal protective equipment, and managing fitness and adaptations. Integration with the ERP system provides the asset master data, including facilities, chemicals, suppliers and contractors, work and maintenance orders, purchases, and costs. This allows for linking equipment with its evaluations and inspections, coordinating contractors, connecting work permits with orders, and assessing the cost of accidents and corrective measures.
Typical benefits include the elimination of double data entry and associated errors, reduced administrative times, ensuring that no person or team is left out of the preventive system, traceability of each piece of data from its origin, the availability of integrated indicators for management, and the ability to demonstrate compliance to audits and inspections with consistent evidence across systems.
Data flows and integration architecture
- People and positions. Synchronization of new hires, terminations, changes in position, center, shift and contract from human resources to the preventive system, with automatic generation of tasks (information, training, medical examinations, equipment).
- Organizational structure. Centers, departments, lines and hierarchy of command, basis for assigning preventive responsibilities and consolidating indicators.
- Assets and equipment. Machinery, facilities, vehicles and ERP tools linked to assessments, inspections, maintenance and energy isolation.
- Chemical products. Product catalog and safety data sheets linked to purchasing and inventory.
- Contractors and suppliers. Data on participating companies and their staff for the coordination of business activities.
- Absenteeism and incidents. Exchange of data on temporary disability and absences (without diagnoses) for the analysis of absenteeism and return to work .
- Training. Synchronization with the training platform or with the human resources module to register training actions and expiration dates.
- Costs. Allocation of costs for measures, equipment, training and accidents for the economic analysis of prevention.
- Architecture. Integration through programming interfaces (APIs), programmed files, integration buses or standard connectors, with data master rules, synchronization frequency, error handling and audit logging.
Data protection and security requirements
- Minimization. Exchange only the data necessary for each purpose; health data (diagnoses, examination results) is not transferred to the ERP or human resources, who only receive the necessary aptitude and limitations.
- Legal basis and purpose. Processing is based on compliance with legal prevention obligations, with defined purposes and a record of processing activities.
- Confidentiality. Separation of access: healthcare personnel access health data; human resources and management access administrative and fitness-for-work information.
- Security. Encryption in transit and at rest, authentication, role-based access control, audit logging and incident management, aligned with ISO/IEC 27001 and the National Security Scheme where applicable.
- Impact assessment. Data protection impact assessment when the processing involves large-scale or profiling health data.
- Data processors. Contracts with software and integration providers in accordance with the General Data Protection Regulation.
- Consultation and transparency. Information for staff and consultation with employee representatives regarding the systems and their purposes.
Organizational application: how to approach integration
- Define the objectives and priority data flows (people and positions, assets, contracts, training, absenteeism, costs) and the system that acts as the master for each piece of data.
- Perform the data protection analysis: purposes, minimization, separation of health data, access roles, contracts with processors and, if applicable, impact assessment; inform the staff and consult the workers’ representatives.
- Design the integration architecture (API, files, integration bus) with synchronization frequency, transformation rules, error handling, and audit logging.
- Clean and standardize master data (center codes, position, equipment) before integration to avoid duplication and inconsistencies.
- Implement in phases, starting with the master data for people and positions, with controlled environment testing, validation by those responsible for prevention, human resources and systems, and a contingency plan.
- Automate the resulting processes: generation of information tasks, training, equipment and health monitoring in new hires and changes; linking equipment with evaluations and inspections; coordination of contracts.
- Establish integration quality indicators (errors, delays, orphaned records) and review them periodically with system changes.
Preventive management software with integration capabilities allows you to synchronize master data with the ERP and human resources, automatically generate preventive obligations associated with each person and team, maintain traceability of each data point, and offer integrated dashboards, with separation of health data and audit records.
Limits and common mistakes
- Integrating without defining the master system for each piece of data generates conflicts and duplications.
- Transferring health data to human resources or the ERP, violating confidentiality and data protection regulations.
- Not cleaning master data before integration and passing errors to the preventative system.
- Manually integrate with periodic exports that are abandoned or become out of sync.
- Failure to provide for error management or audit logging prevents the detection of missing records.
- Addressing integration without the participation of prevention, human resources, systems and data protection, and without informing the workers’ representatives.
Data protection and information security obligations depend on each processing activity and must be analyzed on a case-by-case basis; this document is for informational purposes only.
Practical example
Situation: An industrial group with 2,200 people in eight centers manages prevention on a specific platform and human resources and maintenance in a corporate ERP, with duplicate data and delays in incorporating new hires into the prevention system.
- Analysis. Prevention, human resources, systems and the data protection officer define the flows: the ERP is the master of people, positions, centers and assets; the preventive platform is the master of assessments, preventive training, protective equipment, skills and actions; health data remains in the health module with restricted access.
- Design and implementation. An API integration is implemented with daily synchronization of people and positions and weekly synchronization of assets, transformation rules, error management and audit log; the position codes are cleaned and the staff and the health and safety committee are informed.
- Automation. Each new hire or job change generates information, training, equipment delivery, and medical examination tasks on the preventive platform; ERP maintenance orders are linked to work permits and inspections.
- Results. The time between hiring and incorporation into the prevention system goes from weeks to one day, double data entry disappears, absenteeism and accident indicators are consolidated by center and position, and audits have consistent evidence between systems.
Regulatory and reference framework
- Law 31/1995, of November 8. Law on Prevention of Occupational Risks; integration of prevention in the management system (article 16) and documentation (article 23).
- Royal Decree 39/1997, of January 17. Regulation of Prevention Services; integration of prevention in processes and in the organization.
- Regulation (EU) 2016/679 . General Data Protection Regulation; principles, special categories of data, processors and impact assessment.
- Organic Law 3/2018, of December 5. Protection of Personal Data and guarantee of digital rights.
- ISO 45001:2018 . Occupational health and safety management systems; documented information and information control.
- ISO/IEC 27001:2022 . Information security management systems.
- Spanish Strategy for Safety and Health at Work 2023-2027 . Digitalization of prevention as a line of action.
The National Security Scheme applies to public sector systems and their providers, and the Spanish Data Protection Agency publishes criteria on the processing of health data in the workplace.
