Summary
Your HR software provider is a data processor under GDPR. Article 28 requires you to have a written Data Processing Agreement (DPA) in place before they process any employee data on your behalf. Check where your HR software vendor stores and processes data. Many US-headquartered vendors process data on US servers, which requires a valid transfer mechanism and a Transfer Impact Assessment (TIA). Audit trails: Enable logging of who accessed, modified, or exported data and when. This is essential for demonstrating accountability and investigating incidents.
GDPR Guide for HR Software: Everything You Need to Know
Human Resources departments sit at the heart of personal data processing. From recruitment and onboarding to payroll and performance management, HR software handles some of the most sensitive employee information imaginable. If your organisation uses HR software to manage people data, GDPR compliance isn’t optional — it’s a legal obligation that carries real financial and reputational consequences.
This guide breaks down exactly what GDPR means for HR software users, what your obligations are, and how to build a compliant data management framework from the ground up.
Why GDPR and HR Software Are Inseparable
HR software is, by definition, a personal data processing engine. Every module — applicant tracking, employee records, absence management, benefits administration — touches data that falls squarely within GDPR’s scope.
The regulation defines personal data broadly: any information that can identify a living individual. In an HR context, this includes:
- Full names, addresses, and contact details
- National insurance or social security numbers
- Salary, bank account, and tax information
- Health and disability records
- Performance reviews and disciplinary records
- Biometric data (if used for time-tracking or access control)
- Diversity and equality monitoring data
Because much of this data qualifies as special category data under Article 9 of the GDPR, it attracts the highest level of protection. Mishandling it can result in fines of up to €20 million or 4% of global annual turnover — whichever is higher.
Core GDPR Principles That Apply to HR Data Processing
Before diving into specifics, every HR team needs to understand the six core data protection principles. Your HR software configuration and processes must reflect all of them.
1. Lawfulness, Fairness, and Transparency
You must have a valid legal basis for processing employee data. In HR, this typically means:
- Contract performance — processing necessary to fulfil the employment contract
- Legal obligation — payroll tax reporting, right-to-work checks
- Legitimate interests — fraud prevention, internal audits
- Consent — used sparingly, as it’s difficult to demonstrate truly freely given consent in an employment relationship
2. Purpose Limitation
Data collected for recruitment cannot simply be repurposed for marketing or unrelated analytics. Your HR software should enforce clear data silos and access controls that reflect defined purposes.
3. Data Minimisation
Only collect what you genuinely need. If your HR system allows you to store 50 fields per employee record, that doesn’t mean you should. Audit your data collection forms regularly.
4. Accuracy
Employee data changes constantly. HR software must support update workflows, and employees should have accessible mechanisms to correct their own records.
5. Storage Limitation
You need documented retention schedules. Payroll records, for example, typically need to be kept for six years in the UK. Unsuccessful job applications generally should not be retained beyond six months without explicit consent.
6. Integrity and Confidentiality
Your HR software must be configured with appropriate technical and organisational security measures — encryption, role-based access controls, audit logs, and regular security testing.
Key GDPR Obligations for HR Software Users
Conducting a Data Protection Impact Assessment (DPIA)
If your HR software processes data at scale or handles special category data — which it almost certainly does — you are likely required to conduct a DPIA before or during implementation. A DPIA:
- Identifies the risks associated with your data processing activities
- Documents the measures taken to mitigate those risks
- Demonstrates accountability to your supervisory authority
Many organisations skip this step when implementing new HR platforms. That’s a significant compliance gap.
Maintaining Records of Processing Activities (RoPA)
Under Article 30, most organisations must maintain a Record of Processing Activities. For HR software, your RoPA entry should document:
- The categories of data being processed
- The purposes of processing
- Legal bases relied upon
- Data retention periods
- Details of any third-party processors (including your HR software vendor)
- Data transfers outside the UK/EEA
Managing Data Subject Rights
Employees have enforceable rights under GDPR, and your HR software needs to support them:
- Right of access — employees can request a copy of all data held about them
- Right to rectification — employees can demand corrections to inaccurate data
- Right to erasure — limited in employment contexts due to legal retention obligations, but still relevant for ex-employees
- Right to restrict processing — employees can ask you to pause processing in certain circumstances
- Right to data portability — relevant where processing is based on consent or contract
Your HR software vendor should be able to support data subject access request (DSAR) workflows. If it can’t, that’s a problem worth raising with your vendor immediately.
Reviewing Your Vendor Agreements
Your HR software provider is a data processor under GDPR. Article 28 requires you to have a written Data Processing Agreement (DPA) in place before they process any employee data on your behalf.
This DPA must cover:
- The nature and purpose of processing
- The types of data processed
- The vendor’s obligations regarding security and confidentiality
- Sub-processor arrangements
- Data breach notification timelines
- Assistance with data subject rights requests
- Data deletion or return at contract termination
Many major HR software vendors (Workday, BambooHR, HiBob, Personio, etc.) provide standard DPAs. Review them carefully — don’t just accept them without scrutiny.
Special Considerations for International HR Software Deployments
If your organisation operates across multiple countries or uses a cloud-based HR platform with servers outside the UK or EEA, international data transfer rules apply.
Post-Brexit, the UK has its own data transfer mechanisms. Transfers to most EEA countries are permitted under adequacy regulations. Transfers to countries without adequacy decisions require additional safeguards such as:
- Standard Contractual Clauses (SCCs) — the most common mechanism
- Binding Corporate Rules (BCRs) — for multinational corporate groups
- UK International Data Transfer Agreements (IDTAs)
Check where your HR software vendor stores and processes data. Many US-headquartered vendors process data on US servers, which requires a valid transfer mechanism and a Transfer Impact Assessment (TIA).
Building a GDPR-Compliant HR Software Configuration
Getting your HR software configured correctly from the start saves significant remediation effort later. Focus on these areas:
Access controls: Implement role-based permissions. Line managers should only see data relevant to their direct reports. Payroll teams should not have access to health records.
Audit trails: Enable logging of who accessed, modified, or exported data and when. This is essential for demonstrating accountability and investigating incidents.
Retention automation: Configure automated alerts or workflows to prompt deletion or review of data at the end of defined retention periods.
Privacy notices: Ensure employees receive clear, plain-language privacy notices explaining how their data is used. These should be provided at the point of collection — during onboarding, not buried in an employee handbook.
Breach response: Establish a clear process for identifying and reporting data breaches. GDPR requires notification to your supervisory authority within 72 hours of becoming aware of a qualifying breach.
FAQ: GDPR and HR Software
Do we need employee consent to process their data in HR software?
Generally, no. Consent is rarely the appropriate legal basis in employment contexts because of the inherent power imbalance. Most HR data processing is justified under contract performance, legal obligation, or legitimate interests. Consent should only be used where no other basis applies — for optional benefits or voluntary diversity surveys, for example.
What happens if our HR software vendor suffers a data breach?
You remain the data controller and share responsibility for the breach. Your vendor must notify you without undue delay. You then have 72 hours to assess whether the breach must be reported to your supervisory authority (the ICO in the UK). This is why your DPA must include clear breach notification obligations.
How long should we retain employee data in our HR system?
Retention periods vary by data type. Payroll records: typically 6 years. Personnel files: often 6 years post-employment. Health and safety records: up to 40 years in some cases. Unsuccessful job applications: generally 6 months. Always document your retention schedule and apply it consistently.
Is a DPIA mandatory for all HR software implementations?
A DPIA is mandatory when processing is “likely to result in a high risk” to individuals. Given that HR software processes special category data at scale, a DPIA is strongly recommended — and in most cases required. Even where not strictly mandatory, conducting one demonstrates good faith compliance.
Can employees request deletion of their data while still employed?
The right to erasure is not absolute. Where processing is necessary for legal compliance or contract performance — which covers most active employment data — deletion requests can be refused. However, you should document your reasoning and communicate it clearly to the employee.
Get Compliant Faster With Ready-to-Use GDPR Templates
Building GDPR compliance documentation from scratch is time-consuming, legally complex, and easy to get wrong. Our professionally drafted GDPR compliance template bundle for HR software gives you everything you need to demonstrate compliance immediately:
- ✅ HR Data Processing Agreement template
- ✅ Employee Privacy Notice (GDPR-compliant)
- ✅ DPIA template for HR software implementations
- ✅ Record of Processing Activities (RoPA) for HR data
- ✅ Data Retention Schedule for HR records
- ✅ DSAR response workflow and letter templates
- ✅ Data Breach Response Plan
Stop starting from a blank page. Our templates are written by compliance professionals, regularly updated to reflect regulatory guidance, and ready to customise for your organisation in hours — not weeks.
👉 [Browse our GDPR HR Compliance Template Bundle →]
Trusted by HR teams, People Operations leaders, and compliance professionals across the UK and Europe.
Best for teams organizing privacy documentation and operating guidance.