Employers process personal data every day: recruitment files, payroll information, absence records, evaluations, access logs, training records and much more.
GDPR compliance is therefore not just about having an employee privacy notice. Employers need documentation that reflects how staff and candidate data is actually processed.
1. Record of processing activities
Your record of processing activities is one of the central GDPR documents.
For HR, it can cover processes such as:
- Recruitment
- Personnel administration
- Payroll
- Time registration
- Absence management
- Performance management
- Training
- Benefits
- IT and access management
- Workplace security
- Termination and offboarding
For each activity, document relevant information such as purposes, categories of data, data subjects, recipients, transfers, retention and security measures as required. The structure of a record of processing activities is the same for HR as for anything else.
Small organisations regularly assume they are exempt. They are usually not. Article 30(5) lifts the record-keeping obligation for employers with fewer than 250 employees only where all three of the following hold: the processing is occasional, it is unlikely to result in a risk to individuals, and it involves no special category or criminal conviction data.
HR fails the first condition on its own. Recruitment, payroll and personnel administration run continuously, not occasionally. Add sick leave records or anything else touching health, and the third condition fails too. In practice, if you employ people you need an HR record of processing, whatever your headcount.
2. Candidate privacy notice
Applicants need information about what happens to their personal data during recruitment.
The notice should cover the recruitment process, including relevant data sources, purposes, legal bases, recipients, retention periods, transfers and candidate rights.
3. Employee privacy notice
Employees need appropriate information about staff data processing.
This usually goes much further than recruitment and can include payroll, benefits, absence, performance, IT use, security and other employment processes. A full employee privacy policy sets out each of those.
4. Retention policy or schedule
Define how long different categories of HR information are kept.
Do not use one retention period for every document.
Payroll records, unsuccessful applications, performance records and access logs may have very different legal and operational retention requirements. A data retention policy is where those differences get written down.
5. Data processing agreements
Employers often use external service providers to process staff data.
Examples include:
- Payroll providers
- HR software
- Recruitment platforms
- Cloud services
- Benefits providers
- Training platforms
Where a provider acts as your processor, the GDPR requires an appropriate data processing agreement containing the mandatory elements.
First determine the role of each provider; not every third party is necessarily your processor.
6. Data breach procedure and register
HR data can be involved in data breaches.
Examples include:
- A payslip sent to the wrong person
- A lost laptop containing employee files
- An HR account compromised by phishing
- A spreadsheet with staff data shared with the wrong recipients
Have a procedure for identifying, assessing and escalating incidents. Document personal data breaches as required, including relevant facts, effects and remedial action.
7. Data subject rights procedure
Candidates, employees and former employees can exercise GDPR rights.
Your organisation should know who handles requests, how identity is verified where necessary, where information is searched and how deadlines are monitored.
8. Legitimate interest assessments
Where you rely on legitimate interests for processing that requires a balancing assessment, documenting that assessment is good accountability practice.
This is particularly useful where processing could affect employees’ or candidates’ privacy expectations.
9. Data Protection Impact Assessments
A DPIA is required where processing is likely to result in a high risk to individuals’ rights and freedoms.
In an employment context, this may become relevant for certain monitoring, biometric systems, large-scale sensitive-data processing or higher-risk AI and profiling uses.
Assess the requirement before implementing the processing.
10. Security and access documentation
HR information is often sensitive even where it is not legally classified as special category data.
Document appropriate measures for:
- Access control
- Authentication
- Confidentiality
- Backups
- Device security
- Offboarding
- Incident response
Policies should match what actually happens in your systems.
11. International transfer documentation
If HR or recruitment providers process personal data outside the EEA, assess the transfer mechanism and maintain the required documentation.
Cloud software can create international transfers even when your organisation operates only in Europe.
12. AI governance documentation
If you use AI in recruitment or employment, additional documentation may be needed under both GDPR and the EU AI Act.
Start by documenting the use case, data involved, provider, purpose, legal basis, risks and human oversight.
Higher-risk systems may require significantly more.
Do you need all of these documents?
Not every employer needs every document in exactly the same form.
The correct approach is to start with your real processing activities and determine which documentation follows from them.
A five-person business using a payroll provider and basic recruitment process will not have the same compliance file as an international employer using biometrics, monitoring and AI recruitment.
But both need to know what personal data they process and why.
Build the documents from the processing
GDPR documentation should be the output of understanding your organisation, not a pile of disconnected templates.
GDPRWise helps organisations map their HR and other processing activities and use that information to build and maintain the documentation their GDPR compliance requires.
GDPRWise maps your HR and recruitment processing activities and builds the privacy documentation that follows from them.