Blog

Right of access to HR data: what the GDPR really says

Cover illustration highlighting the theme of data protection

The right of access allows any person, employee, former employee or candidate, to know if their employer is processing data concerning them and to obtain a copy. This is what Article 15 of the GDPR provides, under the control of the CNIL in France.

This right is not limited to a simple consultation. The employer must confirm the existence of the processing, transmit the data itself, and provide details on the purposes, categories of data, recipients and retention period.

Any person whose data is processed by their employer can request: confirmation of the processing, a copy of the data, and information on their use.

Three points to remember before going any further:

  • Employees, former employees and candidates for employment can all exercise this right.
  • The process is in principle free, but fees may apply for certain additional copies if justified.
  • The employer has a limited time to respond, which may be extended in the event of complex files.

Key points

The right of access to HR data obliges the employer to confirm, communicate and explain an employee's personal data within a reasonable time, free of charge in principle, and by filtering third parties.

PointDetails
--
Clear legal basisArticle 15 of the GDPR applies to employees, former employees and candidates, with precise response content.
Deadline to respectOne month in principle, extendable by two months for complex or voluminous requests.
Free by defaultOnly additional copies requested after an initial response may be charged.
Mandatory filteringThird party data and business secrets must be removed before any transmission.
Automate filteringSafe-doc pseudonymizes HR documents in real time to accelerate compliant responses without storing them.

Table of contents

What is the right of access to HR data according to article 15 of the GDPR?

Article 15 of the GDPR gives any data subject the right to obtain confirmation that processing of data concerning them exists and, if this is the case, to access this data as well as a series of additional information. This includes the purposes of the processing, the categories of data concerned, the recipients (or categories of recipients) to whom they have been or will be communicated, and the envisaged retention period.

This text does not come out of nowhere. It is part of a broader European logic, where the Charter of Fundamental Rights of the European Union recognizes the protection of personal data as a right in its own right. The EDPB guidelines clarifies how to concretely apply this requirement, in particular on the notion of “intelligible” copy and on the articulation with the rights of others.

Why does this right really exist? Three reasons stand out:

  • Transparency: an employee must be able to know what his employer knows about him, without going through indirect channels.
  • Verification of legality: accessing your data allows you to check that the processing is based on a valid legal basis.
  • Accuracy control: incorrect data in an HR file (a poorly filed evaluation, an obsolete address) can have concrete consequences, and access is often the first step before a request for rectification.

This right therefore does not only concern the curious or employees in conflict with their employer. It is part of a set of tools, alongside the right of rectification and the right of opposition, which give everyone real control over their own data.

What must the employer provide in response to an access request?

A compliant response is more than a vague email confirming that “yes, we have a case.” Article 15 of the GDPR imposes precise content, and CNIL regularly reminds us of what this means in practice for employers.

The employer must transmit:

  • Explicit confirmation that processing of personal data exists.
  • A copy of relevant personal data concerning the person (pay slips, evaluations, administrative exchanges, disciplinary notes depending on the case).
  • The purposes of the processing (payroll management, career monitoring, security, etc.).
  • The categories of data concerned and their recipients, internal or external.
  • The expected shelf life, or the criteria used to determine it.
  • The possible existence of automated decision-making, with an explanation of its logic when applicable.

Concretely, this communication can take several forms: a summary table of the data processed, a secure export in PDF format, or a direct copy of the documents concerned when this remains relevant. The format matters less than the substance, provided that the person can actually understand what is being done with their information.

Securing this transmission deserves particular attention. Sending a complete HR file by unencrypted email, or posting it on a shared space accessible to the entire team, exposes the company to a risk of leak which has nothing to do with the initial request. The CNIL HR reference system recalls that access to HR data must remain limited and traced, including when responding to an access request.

A hand plugging in a hardware security key

Who can exercise this right and how to verify their identity?

The right of access is not reserved for current employees. It extends to former employees, whose data may still be kept for specific legal periods, and to job candidates whose CV and interview discussions have been recorded in an applicant tracking system.

A person can also mandate a third party to act on their behalf: a lawyer, a relative with a written power of attorney, or a staff representative in certain collective contexts. In all cases, the employer must ensure that the request comes from the person concerned or their duly authorized representative.

On identity verification, the CNIL recommends a proportionate approach: the doubt must be reasonable, and the proof requested adapted to this doubt. An employee who sends their request from their usual professional email address generally does not need to prove their identity with an additional document.

Pro tip: Avoid systematically requesting a copy of your ID card for each request. This practice, apparently prudent, often constitutes a disproportionate collection of data and can be seen as a disguised obstacle to the exercise of the right.

How can you actually exercise the right of access to HR data?

Exercising this right does not require a lawyer or complex procedure. Here is the procedure to follow:

1. Identify the recipient of the request: the HR department, the company's data protection officer (DPO) if one exists, or directly the employer for a small structure.

2. Specify the scope of the request: what data, over what period, in what context (disciplinary file, annual evaluation, pay exchanges). A targeted request generally gets a quicker and more complete response than a generic request.

3. Choose a trackable channel: an email with acknowledgment of receipt, registered mail, or the internal contact form if it exists. The Public Service website also offers reusable letter templates.

4. Structure your request: identity, function or status (employee, ex-employee, candidate), precise description of the data requested, and explicit mention of article 15 of the GDPR.

5. Keep proof of sending: this record will be useful in the event of no response or incomplete response.

If the employer does not respond within the legal deadline, or if the response appears clearly incomplete, a written reminder remains the first logical step. In the absence of a reaction after this relaunch, two avenues are open: a complaint to the CNIL, which can carry out an investigation, or recourse to the judicial court for the most blocked situations.

Response times and cost: what the law really provides

The principle is simple on paper: the employer has one month to respond from receipt of the request, in accordance with article 12.3 of the GDPR. This period can be extended by two additional months when the request is complex or concerns a large volume of data, provided that you inform the person within the first month and justify this postponement.

On cost, the rule is just as clear: exercising the right of access is free in principle. The employer can only charge fees for additional copies requested after a first communication already provided, and these fees must remain reasonable in view of the actual administrative costs, as specified by the CNIL.

An extension is justified, for example, when an employee requests their entire file covering fifteen years of seniority, distributed between several HR systems and paper archives. Conversely, a request relating to the last three pay slips generally does not justify any additional time.

Where does the right of access end with regard to third parties and professional emails?

The right of access relates to personal data, not to the automatic delivery of entire documents. This distinction changes a lot of things in practice. A business email that mentions an employee may contain information about other colleagues, customers, or matters covered by trade secrets. The employer is not required to transmit this document in its entirety: he must extract the data concerning the applicant.

This filtering obligation is not an option left to the discretion of the employer, it is a legal requirement. The CNIL explicitly points out this in the case of professional emails: the employee can request access to emails that concern them, but the employer must first remove or hide any element relating to third parties not concerned by the request.

Several situations deserve particular vigilance:

  • Third party data: names, contact details or evaluations concerning colleagues must be redacted before any transmission.
  • Business secrets: a commercial strategy mentioned in an e-mail does not become communicable simply because an employee is mentioned in a copy.
  • Private correspondence: exchanges of a strictly personal nature, even sent from a professional email, benefit from reinforced protection.
  • Voluminous requests: when an employee requests all of his exchanges over ten years, the employer can request details to target the request, without refusing it outright.

In the field, the main difficulty comes from professional emails. The distinction between metadata (sender, date, subject) and content of the message is not always easy to make, and recent case law shows a tension between the employee's right to access their exchanges and the risk of using this right for purely evidentiary purposes in labor disputes. Recent legal analyzes also underline that this right, although almost fundamental, is not absolute: an employer can contest a request that is manifestly excessive or diverted from its initial objective, provided that it provides proof.

Pro tip: When faced with a large request for years of emails, don't try to extract everything manually. Prioritize automated extraction followed by targeted human control: it's faster, more reliable, and reduces the risk of forgetting third-party data.

How should HR respond in practice to an access request?

A compliant response is a process, not a case-by-case improvisation. Here is the structure that works best in most businesses:

  • Receipt and timestamp: record the exact date of receipt, starting point of the legal deadline of one month.
  • Identification of the scope: list the systems concerned (HRIS, payroll, messaging, disciplinary files) likely to contain data on the person.
  • Targeted extraction: output only relevant data, without copying entire folders for ease.
  • Third party redaction: systematically hide mentions about other people.
  • Validation by the DPO: when the company has it, a review before sending limits the risk of error or oversight.
  • Secure transmission: favor an encrypted channel or a protected exchange space rather than a traditional e-mail.

Journaling deserves a special place. Knowing who consulted which data, who extracted it and to whom it was transmitted constitutes valuable proof of diligence in the event of an audit by the CNIL. The CNIL emphasizes this point: access traceability is one of the pillars of compliant HR management, in the same way as technical security.

A minimal checklist is often enough to secure this process: acknowledgment of receipt sent within 48 hours, proportionate identity verification, defined search scope, third-party filtering carried out before validation, and written record kept of each step. Automatic pseudonymization tools significantly reduce this burden, particularly on large files containing numerous mentions of third parties, as detailed in our guide on the protection of employees' personal data.

What recent decisions and CNIL doctrine change

The right of access continues to evolve under the effect of court decisions and clarifications of European doctrine. Two trends clearly emerge in recent years.

On the one hand, the courts and the CNIL tend to confirm the broad scope of the right of access, particularly to professional emails containing the employee's personal data. On the other hand, case law is beginning to better regulate requests which appear less motivated by a real need for information than by a litigation strategy, particularly during dismissals or conflict terminations.

Recent legal analyzes remind us that the burden of proof of a possible abuse of rights rests on the employer: he cannot simply invoke the excessive nature of a request without concrete supporting elements. This requirement pushes companies to precisely document their refusals or limitations, rather than justifying them vaguely.

On an operational level, these developments have a direct consequence: HR must be able to justify each limitation applied to a response, with objective criteria (protection of identified third parties, demonstrated business secrecy) rather than general reasons.

What internal procedure should be put in place to process an access request?

A written procedure, even a short one, avoids many errors the day a request actually arrives. Here are the steps it should cover:

1. Acknowledge receipt within 48 to 72 hours, specifying the start date of the legal deadline of one month.

2. Verify the identity of the applicant in a proportionate manner, without systematically requiring an identity document.

3. Map the relevant data across all relevant HR systems before starting the extraction.

4. Check third parties and business secrets before any transmission, by methodically filtering the mentions concerned.

5. Send a notification of extension if the additional two month period proves necessary, briefly explaining the reason.

6. Give reasons for any partial refusal in writing, citing the concrete elements justifying the limitation (identified third parties, data covered by legal secrecy).

7. Archive the entire process: date of receipt, exchanges, extraction carried out, validation, date of sending.

Three short models are sufficient to cover the majority of cases: a standard acknowledgment of receipt, an extension notification mentioning the reason for complexity, and a reasoned refusal notification precisely listing the data excluded and why. Keeping these templates ready to use saves valuable time, especially for businesses that receive multiple requests per year.

Why pseudonymization facilitates the processing of access requests

Pseudonymization and anonymization are not synonymous, and this difference matters to HR. Pseudonymization replaces direct identifiers with coded references while retaining the possibility of returning to the original data via a secure correspondence table. Anonymization permanently removes any possible link with the person. To respond to an access request, reversible pseudonymization is of interest: it protects third parties mentioned in a document while maintaining the integrity of the data concerning the requester.

The recommended technical flow follows a simple logic: extraction of the documents concerned, automatic pseudonymization of third party mentions, final human validation by the DPO or legal department, then secure delivery to the requester. In practice, it is more efficient to automate this detection of third parties rather than manually redacting each file one by one, a method that is slow and exposed to human error on large files.

The concrete benefits are measured on three axes. Firstly, time: automated extraction processes in a few minutes what would take hours for manual proofreading. Then auditability: each pseudonymization action can be logged, which constitutes proof of diligence in the event of an audit. Finally, the reduction of residual risk, provided that you precisely document which data has been masked and why, rather than relying on a quick visual review.

Diagram highlighting the advantages of pseudonymization when processing HR data

What this right really changes in the employer-employee relationship

Transparency on HR data is not just another regulatory constraint. It directly affects the trust between an employer and its teams, and this trust is built or cracked at the precise moment when an access request arrives on the HR department's desk.

Two hands exchange a secure token through a protective glass.

Companies that anticipate this moment, with a clear procedure and appropriate tools, avoid three frequent pitfalls: delay which exposes them to a CNIL complaint, poorly justified refusal which poisons an already tense relationship, and the leak of third party data through haste. Conversely, those who discover Article 15 of the GDPR at the very moment when a former employee in conflict files their request often find themselves urgently dealing with what should have been a well-established routine.

This observation, observed in numerous HR files, argues for a simple principle: treating compliance with the right of access as a permanent HR skill, not as a subject that we discover in each dispute.

Reduce risk during an HR response with automated filtering

Properly responding to an access request often involves digging through entire files, from work emails to annual reviews, to extract only what concerns the requester without disclosing their colleagues' data. Safe-doc automates this filtering step: the platform detects and pseudonymizes more than 90 types of sensitive data in a document in real time, without ever storing it.

Safe-doc

Concretely, this means fewer hours spent manually redacting emails or reports, and an exportable audit trail to prove diligence in the event of a CNIL audit. The service remains compatible with tools already used internally, without changing the working habits of HR teams. For HR managers who wish to understand how this pseudonymization works in practice with your personnel files, the Safe-Doc HR page details how it works, and the team can organize a demonstration on your own use cases.

Sources

To learn more about your rights or obligations, a few official references are better than ten general guides:

In the event of an unsatisfactory response or total absence of reaction, CNIL can be entered of a complaint, free of charge and online.

This article constitutes general information and is not a substitute for advice from a qualified attorney. Consult a qualified legal professional regarding your individual case before acting on this content.

Recommendation