Games Contact us
Games Contact us Finance Crypto Finance Fintech & Transfers Insurance Financial Reporting Banking Budgeting & Planning Auditing & KPIs Financial Planning Accounting Bookkeeping Cost Accounting Financial Statements Accounts Payable & Receivable Auditing Fixed Assets & Depreciation Accounting Software IFRS & GAAP Standards Marketing Brand Strategy Content Marketing SEO & AI Search Social Media Email Marketing Digital Ads TikTok Marketing & Shop Growth Hacking Marketing Analytics Pricing Psychology Brand Ambassadors Tools & Comparisons HR Compensation & Benefits Employee Engagement HR Strategy Recruitment & Talent Acquisition Sales B2B Sales AI in Sales CRM Systems Cold Outreach Pricing Strategy Pipeline Management Sales Enablement Sales Leadership Technology AI Tools & LLMs Cloud Infrastructure Cybersecurity Data Analytics Emerging Tech All → Startup Corporate Governance Law Procurement Procurement: Sourcing Procurement: Vendor Management Procurement: Supply Chain Procurement: Contract Negotiation Procurement: Cost Reduction All Departments
Select Page
⚡ TL;DR
GDPR applies to virtually everything HR does with personal data — recruitment, contracts, payroll, performance, absence, monitoring and exits. HR must have a lawful basis for each purpose (consent is rarely the right one for employees), give clear privacy information, protect special-category data such as health, limit monitoring to what is proportionate, control data shared with vendors, keep data only as long as needed and respond to employees’ rights such as subject access requests within the legal deadlines.
Disclaimer: This article is general information, not legal advice. Employment law varies by country, state and sector and changes frequently. Consult a qualified employment lawyer about your specific situation.

GDPR for HR is not just a legal checklist — it shapes how recruitment, people analytics, monitoring and HR technology can be used. Employee data is extensive and often sensitive, and employees are in a position of dependency, which regulators take into account. This guide explains the GDPR principles as they apply to HR, the lawful bases for processing employee data, special-category data, monitoring, recruitment, international transfers and vendors, retention, subject access requests and the impact of AI tools in HR.

Key Takeaways

Does GDPR apply to employee data?
Yes. Employee and candidate data is personal data, and employers are controllers responsible for compliance.

Can HR rely on employee consent?
Rarely. Because of the imbalance of power, consent is often not freely given; contract, legal obligation and legitimate interests are more common bases.

What are the biggest risk areas?
Health data, employee monitoring, subject access requests, retention of old records and data shared with HR technology vendors.

How does GDPR apply to HR?

The EU General Data Protection Regulation and the UK GDPR apply whenever an organisation processes personal data of candidates, employees, former employees, contractors and their dependants in a way that falls within their scope. HR acts as a controller for most of this processing and must comply with GDPR principles: lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability.

GDPR also applies to non-EU employers in some circumstances, for example when they employ people in the EU or monitor the behaviour of people in the EU. Member states can add specific rules for employment data under Article 88, so national law — and sometimes works-council agreements — adds further requirements. Many other jurisdictions, including Turkey’s KVKK, follow similar principles, so a GDPR-aligned HR data programme is a sound baseline for multinational employers.

What lawful bases can HR use?

The most common lawful bases for HR processing are performance of the employment contract (payroll, managing work), legal obligation (tax, social security, right-to-work checks), legitimate interests (security, some monitoring, people analytics) and, in limited cases, consent. Each purpose must have a documented basis.

Purpose Typical lawful basis Notes
Payroll and benefits Contract; legal obligation Tax and social-security reporting are legal obligations
Right-to-work / immigration checks Legal obligation Keep only what the law requires
Performance management Contract; legitimate interests Be transparent about criteria and tools
IT security monitoring Legitimate interests Requires balancing test and proportionality
Diversity monitoring Consent or specific legal provision Special-category data — extra conditions
Optional wellbeing programmes Consent may be appropriate Must be genuinely optional
People analytics Legitimate interests Assess impact; aggregate where possible

Consent is problematic in employment because employees may feel unable to refuse. Regulators therefore expect employers to use other bases where possible and to reserve consent for genuinely optional activities where refusal carries no disadvantage.

GDPR for HR: The Employee Data Lifecycle1RecruitCVs, interviews,background checks— retention limits2EmployContracts, payroll,performance,absence, health3MonitorIT, email, CCTV,location — must beproportionate4SharePayroll vendors,benefits, EOR —DPAs, transfers5ExitRetention schedule,secure deletion,access requests
Where personal data flows through the HR lifecycle — and where GDPR risk concentrates.

How should HR handle health and other special-category data?

Special-category data — including health, ethnic origin, religion, sexual orientation, trade-union membership, biometrics and genetic data — requires both a lawful basis and an additional condition under Article 9, such as obligations in employment law. Access must be restricted, and processing documented and minimised.

In practice, HR commonly processes health data for sickness absence, occupational health, reasonable adjustments and statutory sick pay. Keep detailed medical information with occupational health or a restricted HR file rather than in general personnel records, share only what managers need to know (“fit for work with adjustments” rather than diagnoses), and set clear retention periods. Criminal records data is subject to separate restrictions and national rules. Many organisations also need an “appropriate policy document” under national law when processing special-category data for employment purposes.

⚠️ Risk: Employee monitoring — email, chat, screen activity, keystrokes, location, CCTV, productivity software — is one of the most heavily scrutinised areas of HR data protection. Monitoring must be necessary, proportionate and transparent; covert monitoring is only justifiable in exceptional circumstances. Carry out a data protection impact assessment and consult employee representatives where required before introducing new tools.

What does GDPR mean for recruitment?

Recruitment involves large volumes of personal data from people who never become employees. Employers must give candidates privacy information, collect only what is needed, limit background checks to what is proportionate and lawful, keep unsuccessful candidates’ data only for a defined period and handle automated screening carefully.

Automated decision-making with legal or similarly significant effects — such as fully automated rejection of candidates — is restricted under Article 22, requiring safeguards such as human review and the right to contest. AI-driven screening and interview analysis also fall under the EU AI Act, which classifies many employment-related AI systems as high-risk. Our articles on the EU AI Act and HR and the legal risks of AI interview summaries explain how these rules combine. If you want to keep CVs for future vacancies, tell candidates and set a clear time limit.

How should HR manage vendors and international transfers?

HR relies on many processors — payroll providers, HRIS platforms, benefits administrators, background-check firms, learning platforms and Employers of Record. Each needs a data processing agreement, appropriate security, and a lawful mechanism for any transfer of data outside the EEA or UK, such as an adequacy decision or standard contractual clauses with a transfer risk assessment.

Before selecting HR software, ask where data is hosted, which sub-processors are used, what certifications the vendor holds and how access is controlled. Our software comparisons — for example HRIS platforms and payroll software — are a starting point; follow up with a privacy and security questionnaire. Our payroll process guide covers payroll-specific data controls.

💡 Pro Tip: Keep an HR data map: a simple register of each HR system, the data it holds, the purpose, lawful basis, retention period, who has access and which vendors process it. It is the foundation for answering subject access requests, responding to breaches and demonstrating accountability to regulators.

How long should HR keep employee data?

Keep personal data only as long as necessary for its purpose and any legal obligations. Set a retention schedule covering candidate data, personnel files, payroll and tax records, absence and health records, disciplinary records and investigation files, then delete or anonymise data securely when the period ends.

Retention periods depend on tax, social-security, pension, health and safety and limitation-period rules, which vary by country. A common pattern is short retention for unsuccessful candidates (months), longer for payroll and tax records (several years after the tax year), and specific periods for health and safety records. Expired warnings should not be relied on indefinitely. Automating deletion in HR systems is far more reliable than manual clean-ups.

How should HR respond to subject access requests?

Employees and former employees can request a copy of their personal data. HR must verify the requester’s identity, search all relevant systems and records, provide the data within one month (extendable in limited cases), redact third-party information where appropriate and apply any exemptions carefully. Requests often arise during disputes, so handle them consistently and on time.

Subject access requests can be extensive, covering emails and chat messages that mention the employee. Have a documented procedure, search tools and a trained team. Combine this with good record-keeping practices in workplace investigations and terminations, because notes written during those processes may later be disclosed.

What should an HR data protection programme include?

A practical programme includes an HR data map, employee and candidate privacy notices, documented lawful bases, policies for monitoring, health data, retention and AI tools, data protection impact assessments for high-risk processing, vendor agreements, access controls, breach procedures, training for HR and managers, and periodic audits.

Include data protection in your employee handbook and onboarding, and make sure managers understand basic rules: do not keep private files on team members, share sensitive information only on a need-to-know basis and never put employee personal data into unapproved AI tools. The HR Compliance & Employment Law guide brings these topics together with other legal obligations.

How do AI tools in HR affect data protection?

AI tools used for screening, interview analysis, performance analytics or employee assistants process personal data and may make or support significant decisions. Employers must identify a lawful basis, provide transparency, assess risks through a data protection impact assessment, prevent inappropriate automated decisions and ensure vendors do not reuse employee data improperly.

In the EU, data protection and the AI Act apply side by side. Many employment-related AI systems are classified as high-risk, which brings obligations around human oversight, transparency, logging and data quality for deployers. Practical steps include keeping a register of AI tools used in HR, checking vendor contracts for data-use restrictions, informing employees and candidates when AI is used, and ensuring a human makes and can explain final decisions. Our guides to AI hiring regulation worldwide and AI in learning and development cover related use cases.

What should HR do after a data breach?

Contain the breach, assess the risk to individuals, record it, notify the supervisory authority within 72 hours where the breach is likely to result in a risk to people’s rights and freedoms, and inform affected employees without undue delay where the risk is high. Then investigate the cause and fix it.

HR data breaches often involve misdirected emails containing payslips or personal details, lost devices, overly broad access to HR systems or phishing attacks targeting payroll. A clear internal reporting route — so employees know to report suspected breaches immediately — is essential, as is coordination between HR, IT security and the data protection officer.

After each incident, review whether access rights, email safeguards or training need to change, and record the lessons learned alongside the breach log.

Test the breach procedure at least once a year with a short exercise, so that HR, IT and the data protection officer know their roles before a real incident happens.

Keep evidence of each exercise and the improvements made, because regulators value demonstrated preparedness under the accountability principle.

Frequently Asked Questions

Do employees have to consent to HR processing their data?

Generally no. Most HR processing relies on contract, legal obligation or legitimate interests. Consent is used only for genuinely optional activities.

Can employers read employees’ work emails?

Only in limited, proportionate circumstances, with transparency about monitoring and a legitimate reason such as security or investigating serious misconduct. Blanket or covert monitoring is rarely lawful in the EU and UK.

What should be in an employee privacy notice?

The purposes and lawful bases for processing, categories of data, recipients, international transfers, retention periods, employees’ rights and contact details for the data protection officer, if any.

Does GDPR apply to former employees?

Yes. Data about former employees remains personal data. Retain it only as long as necessary and respond to their rights requests in the same way as for current employees.

Last Updated: October 2026 · Reviewed by the Kurums HR editorial team.

Discover more from Kurums | Business Intelligence

Subscribe to get the latest posts sent to your email.

Discover more from Kurums | Business Intelligence

Subscribe now to keep reading and get access to the full archive.

Continue reading

Discover more from Kurums | Business Intelligence

Subscribe now to keep reading and get access to the full archive.

Continue reading