The General Data Protection Regulation (GDPR) defines the protection of employees' personal data as a direct legal obligation for any employer established in Europe. Breaches expose companies to sanctions reaching 20 million euros or 4% of global turnover. In France, the CNIL has issued fines ranging from 30,000 to 250,000 euros between 2020 and 2024. These figures show that compliance is not optional. Protecting employees' personal information according to the GDPR requires precise organization, solid legal bases and appropriate technical measures.
What personal data of employees must be protected according to the GDPR?
Employee personal data covers any information that can identify a person, directly or indirectly. This definition is broad and concerns the entire life cycle of the employee in the company, from recruitment to the end of the contract.
The most common human resources data falls into several categories:
- Identification data: last name, first name, social security number, badge number
- Contact details: postal address, personal email address, telephone number
- Contractual and financial data: pay slips, employment contract, performance evaluations
- Monitoring data: video surveillance recordings, connection logs, geolocation of service vehicles
- Sensitive data: state of health (sick leave, medical records), union membership, disability situation
Sensitive data benefits from enhanced protection under the GDPR. Their processing is prohibited in principle, except in strictly regulated exceptions such as the execution of legal obligations in labor law. Sick leave transmitted to the HR department, for example, constitutes health data subject to these specific rules.
The distinction between occasional and usual treatments is also decisive. Companies with more than 250 employees must keep a record of processing activities pursuant to Article 30 of the GDPR. This obligation also applies to smaller structures as long as they process sensitive data or data on a non-occasional basis. Monthly payroll processing is usual; a one-off internal investigation may be occasional.

What legal bases apply to the processing of employee data?
Each processing of personal data must be based on a valid legal basis. In the HR context, three legal bases dominate: execution of the employment contract, compliance with a legal obligation, and the legitimate interest of the employer.
The execution of the employment contract justifies the collection of data necessary for payroll management, work organization or training. The legal obligation covers social declarations, the management of paid leave or the transmission of data to Urssaf. Legitimate interest applies, under conditions, to processing such as IT security or the prevention of internal fraud.
Consent is almost never valid in an HR context. The structural imbalance between employer and employee makes this consent suspect: an employee can legitimately fear consequences if he refuses. The CNIL and the European Data Protection Board (EDPB) regularly remind us of this limit. Basing processing on consent in HR therefore exposes the company to a risk of non-compliance.

Pro tip: Before launching any new HR data processing, systematically identify the applicable legal basis and document it in your register. Use consent only as a last resort and only for clearly optional processing, unrelated to the employment relationship.
How to organize GDPR compliance in HR departments?
GDPR compliance in HR is based on four operational pillars: documentation, employee information, internal governance and rights management.
Document with the treatment register
The register of processing activities, provided for in Article 30 of the GDPR, is the basis of any compliance approach. It lists each processing operation, its purpose, the categories of data concerned, the recipients, the retention periods and the security measures. The DPO (data protection officer), HR and IT department co-construct this register. Its regular updating is mandatory, particularly during any new HR project involving personal data.
Inform employees upon hiring
The absence of a clear information notice given to employees upon hiring is a frequent cause of sanctions by the CNIL. Article 13 of the GDPR imposes this obligation. The notice must specify the purposes of the processing, the legal bases, the retention periods and the rights of employees. It is separate from the employment contract and must be submitted separately, preferably during integration.
Manage employee rights
Employees have extensive rights over their data: access, rectification, erasure, limitation and portability. Requests to exercise rights must be processed within a maximum of one month, extendable to three months for complex requests. This deadline is set by Article 12 of the GDPR. A clear internal process, with an identified point of contact, is essential to meet these deadlines.
The employees' right of access is unconditional and can relate to professional emails containing their personal data, including in the event of litigation. This reality often surprises HR and legal teams. Anticipating these requests through good data organization avoids delicate situations.
Respect storage periods
Retention periods vary depending on the nature of the data. The following table summarizes the main obligations:
| Data type | Shelf life |
|---|---|
| Pay slips | 50 years |
| Recruitment files (unsuccessful candidates) | Less than 2 years |
| Employment contracts | 5 years after the end of the contract |
| Video surveillance data | 1 month maximum |
| Training data | Duration of the contractual relationship |
Poor management of retention periods is directly exposed to sanctions. Keeping former employees' files indefinitely is one of the most frequently encountered errors during CNIL checks.
Pro tip: Schedule automatic purges in your HRIS for data whose legal duration has exceeded. An annual alert is enough to trigger a systematic verification.
To go further on the HR data protection standards in force, a detailed compliance guide is available.
What are the common mistakes and how to avoid them?
CNIL controls reveal recurring shortcomings in organizations, regardless of their size. Identifying them allows you to act before a sanction occurs.
The most common errors are:
- Excessive retention: the files of former employees are kept well beyond the legal periods, due to lack of a purge procedure.
- Insufficient information: employees do not receive complete information notices upon hiring or when implementing new treatments.
- Uncontrolled access: employees access sensitive data without this being justified by their functions.
- Delays in processing rights: requests for access or rectification remain unanswered within the legal deadlines.
- Incomplete mapping: certain HR processing operations do not appear in the register, particularly those managed by external service providers.
The European Data Protection Board (EDPB) and the CNIL recommend exhaustive mapping of HR processing to ensure effective compliance. Without this mapping, the company cannot identify its risks or demonstrate its compliance during an audit.
The HR data breaches concretely illustrate the consequences of these errors. Each breach documented by the CNIL follows a similar pattern: absence of procedure, lack of information or uncontrolled access.
What technical measures should be strengthened to secure personal data?
The technical security of HR data is not the sole responsibility of the IT department. It engages the HR department and the DPO in a common approach.
The priority measures to be implemented are as follows:
- Data encryption: personal data must be encrypted both at rest (on servers) and in transit (during exchanges between systems). An unencrypted emailed payroll file is a potential breach.
- Firewalls and updates: servers hosting HR data must be protected by active firewalls and kept up to date. Unpatched security vulnerabilities are a common entry point for attacks.
- Principle of least privilege: each employee only accesses the data strictly necessary for their functions. A payroll manager does not have to consult disciplinary files, and vice versa.
- Pseudonymization and anonymization: pseudonymization replaces direct identifiers with codes, making the data less usable in the event of a leak. Anonymization permanently removes any link with the person. These two techniques are recommended by the GDPR for high-risk processing.
Access compartmentalization and the principle of least privilege are essential measures to prevent leaks of sensitive data. Their implementation requires close collaboration between the HR department, the IT department and the DPO.
Data Protection Impact Assessment (DPIA) is mandatory for high-risk processing, such as the use of artificial intelligence tools or video surveillance. It is co-written by the DPO, the IT department and the HR department. This analysis identifies specific risks and corrective actions before deploying a treatment.
Pro tip: Pseudonymizing HR data before it is processed by third-party AI tools significantly reduces the risk of leaks. Safe-doc applies this technique in real time, without storing documents, which maintains GDPR compliance even when using tools like ChatGPT or Claude.
Key points
The protection of employees' personal data is based on solid legal foundations, rigorous documentation and appropriate technical measures, without which any GDPR compliance approach remains fragile.
| Point | Details |
|---|---|
| Legal bases in HR | Prioritize the execution of the contract or legal obligation; consent is rarely valid. |
| Treatment register | Document each HR processing in the article 30 register, updated continuously. |
| Information for employees | Provide a complete information notice upon hiring, separate from the contract. |
| Shelf life | Apply specific durations depending on the type of data and schedule regular purges. |
| Technical security | Encrypt, partition access and pseudonymize sensitive data before any external processing. |
What I observe after years of HR compliance support
The protection of employee data is often perceived as an administrative constraint. This is a reading error. Organizations that treat this obligation seriously make it a real competitive advantage: they recruit better, retain more and are more resistant to audits.
What I see most often on the ground is a disconnect between the teams. The HR department manages the data, the IT department secures the systems, the DPO validates the procedures. But these three functions rarely work together proactively. The processing register is sometimes kept by a single person, without cross-validation. Result: entire treatments go under the radar, particularly those entrusted to external service providers.
The other blind spot I regularly encounter concerns artificial intelligence. HR teams use consumer AI tools to analyze CVs, write interview reports or process performance data. These uses constitute Shadow AI. They expose the company to data breaches without anyone being aware of it. Pseudonymizing documents before sending them to a third-party AI tool is the simplest and most effective measure to contain this risk.
GDPR compliance is not a one-off project. It is an ongoing discipline that requires regular reviews, training and a shared culture. Companies that integrate it into their daily operations avoid sanctions and gain the trust of their employees.
- Jacques
Safe-doc for GDPR compliance of your HR data
HR teams who process employee files with AI tools expose themselves to real risks if these documents are not secured beforehand.

Safe-doc meets this need by pseudonymizing sensitive documents in real time, without storing any data. HR and legal professionals can therefore use their usual AI tools while remaining GDPR compliant. The solution integrates without changing existing workflows. For DPOs and compliance teams, Safe-doc also offers auditing and GDPR pseudonymization functionalities adapted to the requirements of HR departments. To understand how it works technically, page security and architecture details the zero storage by design approach.
Frequently asked questions
What employee data is protected by the GDPR?
All data allowing an employee to be identified is protected: name, social security number, pay slips, health data, video surveillance recordings and professional emails containing personal information.
Is employee consent sufficient as a legal basis?
No. Consent is rarely valid in HR due to the imbalance between employer and employee. The execution of the employment contract or the legal obligation constitute the appropriate legal bases in the vast majority of cases.
How long should former employees’ files be kept?
The duration varies depending on the type of data: pay slips are kept for 50 years, employment contracts for 5 years after the end of the contract, and files of unsuccessful candidates for less than 2 years.
How long does it take to respond to an employee's access request?
Article 12 of the GDPR sets a deadline of one month, extendable to three months for complex requests. This period runs from receipt of the request.
Is pseudonymization sufficient to comply with the GDPR?
Pseudonymization reduces risks but does not replace other GDPR obligations. It must be accompanied by a valid legal basis, an information notice and rigorous access management to ensure full compliance.