Blog

Protecting employees’ personal information: GDPR guide

Decorative visual highlighting the GDPR article title

The General Data Protection Regulation (GDPR) establishes the protection of employee personal data as a direct legal obligation for any employer operating in Europe. Non-compliance exposes organizations to penalties reaching €20 million or 4% of global annual turnover. In France, the CNIL imposed fines ranging from €30,000 to €250,000 between 2020 and 2024. These figures demonstrate that compliance is not optional. Protecting employee personal information under the GDPR requires precise organization, sound legal foundations, and appropriate technical safeguards.

Table of Contents

What employee personal data must be protected under the GDPR?

Employee personal data encompasses any information that identifies an individual, directly or indirectly. This broad definition applies throughout the employee lifecycle, from recruitment through contract termination.

The most common HR data categories include:

  • Identification data: surname, first name, social security number, badge number
  • Contact details: postal address, personal email address, telephone number
  • Contractual and financial data: pay slips, employment contracts, performance reviews
  • Monitoring data: video surveillance recordings, connection logs, company vehicle geolocation
  • Sensitive data: health information (sick leave, medical files), union membership, disability status

Sensitive data receives enhanced protection under the GDPR. Processing such data is prohibited by default, with exceptions limited to strictly defined circumstances such as fulfilling legal obligations under employment law. For instance, sick leave submitted to HR constitutes health data subject to these specific rules.

The distinction between occasional and routine processing matters considerably. Companies with more than 250 employees must maintain a record of processing activities pursuant to Article 30 of the GDPR. This requirement also applies to smaller organizations when they process sensitive data or conduct non-occasional processing. Monthly payroll processing is routine; a one-time internal investigation may be occasional.

An expert reviews GDPR-related documents in her office

Every personal data processing operation must rest on a valid legal basis. In the HR context, three legal bases predominate: contract performance, legal obligation, and legitimate interest of the employer.

Contract performance justifies collecting data necessary for payroll management, work organization, or training. Legal obligation covers social security declarations, paid leave management, or data transmission to authorities like Urssaf. Legitimate interest applies, under specific conditions, to processing such as IT security or internal fraud prevention.

Consent is almost never valid in the HR context. The structural power imbalance between employer and employee renders such consent questionable: employees may legitimately fear consequences if they refuse. The CNIL and the European Data Protection Board (EDPB) regularly emphasize this limitation. Relying on consent for HR processing exposes organizations to non-compliance risk.

Infographic: GDPR legal bases for employee data management

Pro tip: Before launching any new HR data processing, systematically identify the applicable legal basis and document it in your register. Resort to consent only as a last option and solely for clearly optional processing unrelated to the employment relationship.

How to organize GDPR compliance in HR departments?

GDPR compliance in HR rests on four operational pillars: documentation, employee information, internal governance, and rights management.

Document with the processing register

The record of processing activities, required by Article 30 of the GDPR, forms the foundation of any compliance approach. It catalogs each processing operation, its purpose, data categories involved, recipients, retention periods, and security measures. The DPO (data protection officer), HR, and IT departments co-construct this register. Regular updates are mandatory, particularly when launching new HR projects involving personal data.

Inform employees from day one

The absence of a clear information notice provided to employees upon hiring is a frequent cause of CNIL sanctions. Article 13 of the GDPR mandates this obligation. The notice must specify processing purposes, legal bases, retention periods, and employee rights. It is distinct from the employment contract and should be delivered separately, preferably during onboarding.

Manage employee rights

Employees hold extensive rights over their data: access, rectification, erasure, restriction, and portability. Requests to exercise these rights must be handled within one month, extendable to three months for complex requests. This deadline is established by Article 12 of the GDPR. A clear internal process with an identified point of contact is essential for meeting these timelines.

The employee right of access is unconditional and may extend to professional emails containing their personal data, including in litigation contexts. This reality often surprises HR and legal teams. Anticipating these requests through sound data organization prevents awkward situations.

Respect retention periods

Retention periods vary by data type. The following table summarizes key obligations:

Data typeRetention period
--
Pay slips50 years
Recruitment files (unsuccessful candidates)Less than 2 years
Employment contracts5 years after contract termination
Video surveillance data1 month maximum
Training dataDuration of contractual relationship

Poor retention period management directly exposes organizations to sanctions. Retaining former employee files indefinitely is among the most frequently identified errors during CNIL inspections.

Pro tip: Schedule automatic purges in your HRIS for data exceeding legal retention periods. An annual alert suffices to trigger systematic verification.

For further guidance on HR data protection standards in force, a detailed compliance guide is available.

What are common mistakes and how to avoid them?

CNIL inspections reveal recurring deficiencies across organizations of all sizes. Identifying them enables preventive action before sanctions occur.

The most frequent errors include:

  • Excessive retention: former employee files retained well beyond legal periods due to absent purge procedures
  • Insufficient information: employees not receiving complete information notices at hiring or when new processing begins
  • Uncontrolled access: staff accessing sensitive data without justification based on job functions
  • Rights processing delays: access or rectification requests remaining unanswered within legal deadlines
  • Incomplete mapping: certain HR processing operations absent from the register, particularly those managed by external providers

The European Data Protection Board (EDPB) and the CNIL recommend comprehensive mapping of HR processing to ensure effective compliance. Without this mapping, organizations cannot identify risks or demonstrate compliance during audits.

The HR data breaches concretely illustrate consequences of these errors. Each breach documented by the CNIL follows a similar pattern: absent procedures, deficient information, or uncontrolled access.

What technical measures strengthen personal data security?

Technical security of HR data extends beyond IT department responsibility. It engages HR and the DPO in a shared effort.

Priority measures to implement include:

  • Data encryption: personal data must be encrypted both at rest (on servers) and in transit (during inter-system exchanges). An unencrypted payroll file sent by email constitutes a potential breach.
  • Firewalls and updates: servers hosting HR data must be protected by active firewalls and maintained with current security patches. Uncorrected security flaws are a classic attack vector.
  • Principle of least privilege: each staff member accesses only data strictly necessary for their functions. A payroll administrator should not consult disciplinary files, and vice versa.
  • Pseudonymization and anonymization: pseudonymization replaces direct identifiers with codes, rendering data less exploitable in breach scenarios. Anonymization permanently removes all links to individuals. Both techniques are recommended by the GDPR for high-risk processing.

Access compartmentalization and the principle of least privilege are essential measures for preventing sensitive data leaks. Their implementation requires close collaboration among HR, IT, and the DPO.

Data Protection Impact Assessment (DPIA) is mandatory for high-risk processing, such as artificial intelligence tool deployment or video surveillance. The DPO, IT, and HR co-author this analysis, which identifies specific risks and corrective measures before processing deployment.

Pro tip: Pseudonymizing HR data before processing by third-party AI tools considerably reduces leak risk. Safe-doc applies this technique in real time without storing documents, maintaining GDPR compliance even when using tools like ChatGPT or Claude.

Key takeaways

Protection of employee personal data rests on sound legal bases, rigorous documentation, and appropriate technical measures-without which any GDPR compliance approach remains fragile.

PointDetails
--
Legal bases in HRPrioritize contract performance or legal obligation; consent is rarely valid.
Processing registerDocument each HR processing operation in the Article 30 register, continuously updated.
Employee informationProvide complete information notice at hiring, separate from the contract.
Retention periodsApply precise durations by data type and schedule regular purges.
Technical securityEncrypt, compartmentalize access, and pseudonymize sensitive data before external processing.

What I observe after years of HR compliance support

Protection of employee data is often perceived as an administrative burden. This is a misreading. Organizations that take this obligation seriously transform it into a genuine competitive advantage: they recruit more effectively, retain talent better, and withstand audits more successfully.

What I most frequently observe in practice is a disconnect between teams. HR manages data, IT secures systems, the DPO validates procedures. Yet these three functions rarely work together proactively. The processing register is sometimes maintained by a single person without cross-validation. Result: entire processing operations fly under the radar, particularly those outsourced to external providers.

Another blind spot I regularly encounter involves artificial intelligence. HR teams use consumer AI tools to analyze CVs, draft interview summaries, or process performance data. These practices constitute Shadow AI. They expose organizations to data breaches without anyone's awareness. Pseudonymizing documents before sending them to third-party AI tools is the simplest and most effective measure to contain this risk.

GDPR compliance is not a one-time project. It is an ongoing discipline requiring regular reviews, training, and shared organizational culture. Companies that integrate it into daily operations avoid sanctions and earn employee trust.

- Jacques

Safe-doc for GDPR compliance of your HR data

HR teams processing employee files with AI tools face real risks if these documents are not previously secured.

https://safe-doc.ai

Safe-doc addresses this need by pseudonymizing sensitive documents in real time without storing any data. HR and legal professionals can therefore use their customary AI tools while remaining GDPR compliant. The solution integrates without modifying existing workflows. For DPOs and compliance teams, Safe-doc also offers audit and GDPR pseudonymization capabilities adapted to HR department requirements. To understand the technical implementation, the security and architecture page details the zero-storage-by-design approach.

Frequently asked questions

What employee data is protected by the GDPR?

All data enabling employee identification is protected: name, social security number, pay slips, health data, video surveillance recordings, and professional emails containing personal information.

No. Consent is rarely valid in HR due to the employer-employee power imbalance. Contract performance or legal obligation constitute the appropriate legal bases in the vast majority of cases.

How long should former employee files be retained?

Duration varies by data type: pay slips for 50 years, employment contracts for 5 years after contract termination, and unsuccessful candidate files for less than 2 years.

What is the deadline for responding to an employee access request?

Article 12 of the GDPR establishes a one-month deadline, extendable to three months for complex requests. This period runs from request receipt.

Is pseudonymization sufficient for GDPR compliance?

Pseudonymization reduces risks but does not replace other GDPR obligations. It must be accompanied by a valid legal basis, information notice, and rigorous access management to ensure full compliance.