
HR data protection standards define precisely how organizations must manage, retain, and secure employee personal data in 2026. The CNIL 2026 reference framework serves as the authoritative guide for HR departments, DPOs, and data controllers. This guide details legal retention periods, valid legal bases, security requirements, and applicable sanctions. Every HR or legal professional must master these rules to protect employees and avoid fines of up to €250,000.
Table of Contents
- What are HR data retention periods under the CNIL 2026 framework?
- What legal bases govern HR data processing?
- How to strengthen HR data management system security?
- What are the risks and sanctions for non-compliance?
- How to apply the CNIL 2026 framework in your HR practices?
What are HR data retention periods under the CNIL 2026 framework?
Since April 2026, the CNIL distinguishes between two categories of retention periods: mandatory periods established by law, and recommended periods that serve as best-practice benchmarks. This distinction is fundamental. A mandatory period applies without discretion, whereas a recommended period can be adapted based on the organization's context.
Here are the key retention periods:
| Data type | Retention period | Nature |
|---|---|---|
| Employee file after departure | 5 years | Recommended |
| Payslip | 50 years | Mandatory |
| Badge access logs | 3 months | Recommended |
| Video surveillance | 1 month | Mandatory |
| Unsuccessful job applications | 2 years (5 years for evidential purposes) | Mixed |
Unsuccessful job applications warrant particular attention. They must be deleted at the end of the recruitment process, but may be archived for 5 years for evidential purposes to defend against potential discrimination claims, in accordance with Article L. 1134-5 of the French Labour Code. This rule often surprises HR teams who assume everything can be deleted immediately.
Pro tip: Configure automatic alerts in your HRIS for each data category. A retention period has legal value only if technically enforced, not merely documented.
Automated purging and logical or physical separation in intermediate archiving are essential for real compliance. A tracking spreadsheet alone is insufficient.
What legal bases govern HR data processing?
The GDPR requires identifying a specific legal basis for each data processing activity. In HR, three legal bases predominate:
1. Performance of the employment contract: covers payroll management, leave administration, performance evaluations, and training.
2. Legal obligation: applies to social security declarations, mandatory record-keeping, and statutory medical examinations.
3. Legitimate interest: used for premises security, internal fraud prevention, or litigation management.
Employee consent is virtually inoperable in HR matters. The reason is straightforward: the contractual imbalance between employer and employee renders such consent not freely given, and therefore legally invalid under the GDPR. An employee who refuses cannot be sanctioned, which renders consent meaningless.
Exceptions do exist. Using a photograph for an internal directory or ID badge may rely on consent, provided refusal carries no professional consequences. This nuance must be documented in the processing register.

Pro tip: For each HR processing activity, ask yourself: "If the employee refuses, could they be penalized?" If the answer is yes, consent is not the appropriate legal basis. Choose contract performance or legal obligation instead.
Consent is never the preferred basis for HR data processing. Organizations must precisely identify the most appropriate legal basis for each data type.
How to strengthen HR data management system security?
HR system security rests on three technical pillars: encryption, access management, and access traceability. These three elements are inseparable.
Best practices to implement:
- Encryption at rest and in transit: all data stored in the HRIS and exchanged via email must be encrypted using recognized standards (AES-256 for storage, TLS 1.3 for transmission).
- Granular access controls: each employee accesses only data strictly necessary for their function. A payroll administrator should not access disciplinary records.
- Comprehensive access logging: every consultation, modification, or data export must be timestamped and logged.
- Vendor certifications: outsourced HR tools must hold ISO 27001, SOC 2 certifications, or HDS hosting for health data.
Strong emphasis is placed in 2026 on access and action traceability as a means of proof during audits or incidents. Maintaining precise records of access to sensitive HRIS data, with timestamps and justification, is crucial for securing evidence during inspections or disputes.
Access traceability is no longer optional. It is an evidential requirement the CNIL verifies during inspections. An HRIS without access logging directly exposes the organization to formal notice.
What are the risks and sanctions for non-compliance?
The CNIL is intensifying inspections of HR departments in 2026. Sanctions can reach €250,000 for identified breaches. This amount applies to mid-sized companies. For large enterprises, GDPR fines can reach 4% of global annual revenue.
The principal identified risks are:
- Incomplete or outdated processing register: more than 20 to 30 HR processing activities must be mapped and legally justified. An outdated register constitutes a violation identified in any inspection.
- Retention periods not respected: retaining data beyond legal limits constitutes a direct GDPR breach.
- Absence of documented legal basis: each processing activity must state its legal basis. Missing documentation is sanctionable, even if the processing itself is legitimate.
- Unreported security breaches: any data breach must be reported to the CNIL within 72 hours.
The impact extends beyond financial sanctions. An HR data breach destroys employee trust. It generates real social risk: increased turnover, deteriorating workplace climate, negative media coverage. Compliance is a trust lever with employees, not merely a regulatory obligation.
How to apply the CNIL 2026 framework in your HR practices?
Compliance follows a four-step process. Each step conditions the next.
1. Map all HR processing activities: list every activity (recruitment, payroll, training, evaluations, access control, video surveillance) and assign each a legal basis and retention period. Professionals must map HR processing and document legal bases in the register.
2. Configure automated deletion in the HRIS: a documented retention period that is not technically enforced has no legal value. Configure automatic purge rules for each data category.
3. Implement intermediate archiving: certain data cannot be deleted immediately for evidential reasons. Create logical or physical separation between the active database and intermediate archive, with restricted access.
4. Train HR teams: HR managers must know the applicable retention periods for their scope. Annual training on deletion procedures and data subject rights requests is essential.
Pro tip: The CNIL framework is soft law. It facilitates compliance but does not replace [context-specific analysis](https://www.seban-associes.avocat.fr/durees-de-conservation-en-matiere-rh-la-cnil-commission-nationale-de-linformatique-et-des-libertes-publie-un-referentiel-actualise-distinguant-obligations-et-recommandations/) for each organization. A recommended period can be adapted if you document the reasoning.
Demonstrating compliance requires written policies, up-to-date registers, documented training, and technical traceability. These four elements constitute the evidence file the CNIL requests during an inspection.
Key Takeaways
Compliance with HR data protection standards in 2026 requires comprehensive processing mapping, automated retention periods, documented legal bases, and technical access traceability.
| Point | Details |
|---|---|
| CNIL 2026 framework | Distinguishes mandatory and recommended retention periods for each HR data type. |
| Legal bases in HR | Consent is invalid in HR. Prefer contract performance or legal obligation. |
| Technical security | Encryption, access controls, and access logging are evidential requirements verified by the CNIL. |
| Financial sanctions | Breaches can lead to fines of up to €250,000 for mid-sized companies. |
| Compliance implementation | Map processing, automate deletion, archive separately, and train teams annually. |
What HR compliance taught me about real risk management
After years supporting HR teams on GDPR compliance projects, I have observed one recurring mistake: treating data protection as a one-time project rather than an ongoing discipline. Organizations mobilize significant resources during an audit or formal notice, then relax vigilance once pressure subsides.
What the CNIL 2026 framework changes concretely is the requirement for continuous proof. The CNIL no longer asks merely "do you have a policy?" but "can you demonstrate that you apply it technically, today?" This evolution is healthy. It forces organizations to embed compliance in their systems, not only in their documentation.
HR data protection has become a strategic issue extending beyond legal compliance. It impacts internal trust and operational continuity. An employee who knows their data is poorly managed no longer trusts their employer. The link between compliance and workplace climate is underestimated by most leadership teams.
The risk I see emerging in 2026 concerns AI tool usage by HR teams. Employees use generative AI tools to process employee files, draft performance reviews, or analyze job applications. These uncontrolled uses constitute Shadow AI. They expose sensitive personal data to non-compliant processing without the DPO being informed. This is the next focus of CNIL inspections.
- Jacques
Safe-doc: pseudonymize HR data before sending it to AI
HR teams use AI tools daily to analyze CVs, draft interview summaries, or prepare training plans. These uses expose sensitive personal data if no protection is in place.

Safe-doc solves this problem by automatically pseudonymizing HR documents before they are processed by an AI tool. Names, social security numbers, addresses, and other identifying data are replaced with pseudonyms. The AI works on a secured document. Safe-doc does not durably store original documents, ensuring GDPR compliance by design. For HR teams wanting to use AI without exposing their data, the Safe-doc HR solution is designed to integrate into existing workflows. DPOs can also consult the compliance and audit page to assess alignment with the CNIL 2026 framework.
Frequently Asked Questions
What is the CNIL 2026 framework for HR data?
The CNIL 2026 framework is soft-law guidance published in April 2026 that establishes HR data retention periods, distinguishing mandatory and recommended durations. It covers employee files, payslips, badge access logs, and video surveillance.
What is the retention period for a payslip?
The retention period for a payslip is 50 years. This period is mandatory and applies to all employers without possibility of adaptation.
Why is employee consent invalid as an HR legal basis?
Consent is invalid in HR because the contractual imbalance between employer and employee renders it not freely given under the GDPR. The legal bases to prefer are performance of the employment contract and legal obligation.
What sanctions apply for non-compliance with HR standards in 2026?
The CNIL can impose fines of up to €250,000 for mid-sized companies. Large enterprises face sanctions of up to 4% of global annual revenue.
How does Shadow AI threaten HR data compliance?
Shadow AI refers to uncontrolled use of AI tools by employees to process personal data. These uses expose sensitive HR data without a legal basis or security measures, constituting a GDPR violation that can be sanctioned during a CNIL inspection.