Summary
Many organizations skip this document, but it’s essential for demonstrating accountability (GDPR Article 5(2)). A lawful basis register maps every HR data processing activity to its legal justification. Not necessarily. A DPO is mandatory if your organization processes special category data at large scale, conducts systematic monitoring of employees, or is a public authority. However, even if not mandatory, appointing a DPO or privacy lead is strongly recommended when using HR software.
GDPR Policy Examples for HR Software: A Complete Guide for 2024
Managing employee data is one of the most compliance-sensitive tasks any organization faces. HR software platforms collect, store, and process vast amounts of personal information — from payroll details and performance reviews to health records and disciplinary notes. If your organization operates in or serves the EU/EEA, GDPR compliance isn’t optional. This guide walks you through practical GDPR policy examples specifically tailored for HR software, so you can protect your employees and your business.
Why HR Software Requires Specific GDPR Policies
Generic privacy policies won’t cut it when you’re handling employee data. HR systems are unique because:
- They process special category data (health information, union membership, biometric data)
- They involve an inherent power imbalance between employer and employee
- Data is often shared with third-party processors (payroll providers, benefits platforms, background check services)
- Retention requirements vary by jurisdiction and data type
GDPR Article 88 specifically allows EU member states to set additional rules for processing employee data, making HR compliance even more layered than standard consumer data protection.
Core GDPR Policies Every HR Software User Needs
1. Employee Data Privacy Notice (Fair Processing Notice)
This is the foundational document. Under GDPR Articles 13 and 14, you must inform employees about how their data is processed at the time of collection.
What to include:
- Identity and contact details of the data controller (your organization)
- Contact details of your Data Protection Officer (DPO), if applicable
- The lawful basis for each type of processing (contract, legal obligation, legitimate interest, or consent)
- Categories of personal data collected
- Retention periods for each data category
- Third parties the data is shared with
- Employee rights and how to exercise them
- Right to lodge a complaint with a supervisory authority
Example policy language:
“[Company Name] collects and processes personal data about employees for the purposes of managing the employment relationship. This includes contact information, payroll data, performance records, and, where applicable, health information required to fulfill our legal obligations under employment law. Your data is stored in [HR Software Name] and retained for [X years] following the end of employment, in accordance with [applicable law].”
2. Lawful Basis Register for HR Data Processing
Many organizations skip this document, but it’s essential for demonstrating accountability (GDPR Article 5(2)). A lawful basis register maps every HR data processing activity to its legal justification.
Example entries:
| Processing Activity | Data Category | Lawful Basis | Retention Period |
|---|---|---|---|
| Payroll processing | Financial, tax data | Legal obligation | 7 years |
| Performance management | Professional records | Legitimate interest | Duration of employment + 2 years |
| Sick leave tracking | Health data | Legal obligation / explicit consent | Duration of employment + 3 years |
| Background checks | Criminal records | Legal obligation / consent | 12 months post-hire |
| Employee monitoring | Behavioral data | Legitimate interest (with balancing test) | 30–90 days |
3. Data Retention and Deletion Policy
HR software accumulates data quickly. Without a clear retention policy, you risk holding data longer than necessary — a direct GDPR violation under the storage limitation principle.
Recommended retention periods by data type:
- Recruitment records (unsuccessful candidates): 6–12 months
- Employment contracts: Duration of employment + 7 years
- Payroll and tax records: 7 years (varies by country)
- Performance reviews: Duration of employment + 2 years
- Disciplinary records: Duration of employment + 1–5 years depending on severity
- Health and safety records: Up to 40 years (for occupational exposure records)
- CCTV/access logs: 30–90 days
Your policy should also specify the deletion process — who is responsible, how deletion is verified, and how you handle data stored in backups.
4. Data Processing Agreement (DPA) with Your HR Software Vendor
When you use HR software, the vendor processes employee data on your behalf, making them a data processor under GDPR Article 28. You are legally required to have a signed DPA in place.
Your DPA should cover:
- The subject matter, duration, and nature of processing
- The types of personal data and categories of data subjects
- The processor’s obligations regarding security measures
- Sub-processor restrictions and notification requirements
- Assistance with data subject rights requests
- Deletion or return of data upon contract termination
- Audit rights
Most reputable HR software vendors (Workday, BambooHR, HiBob, Personio) provide standard DPAs. Always review these carefully — the default terms may not fully protect your organization.
5. Employee Rights Request Procedure
GDPR grants employees specific rights. Your HR team needs a documented procedure for handling these requests within the 30-day response window.
Rights employees can exercise:
- Right of access — receive a copy of their personal data
- Right to rectification — correct inaccurate data
- Right to erasure — request deletion (limited in employment context)
- Right to restriction — limit processing during a dispute
- Right to data portability — receive data in a machine-readable format
- Right to object — object to processing based on legitimate interest
Example procedure steps:
- Receive request via designated email or HR portal
- Verify the identity of the requestor
- Log the request with date received
- Assess which rights apply (erasure may be restricted if legal obligations require retention)
- Compile response using HR system’s data export function
- Respond within 30 calendar days
- Document the outcome
6. Special Category Data Policy
Health data, disability information, and similar records require explicit consent or another Schedule 1 condition under UK GDPR (or Article 9 conditions under EU GDPR).
This policy should address:
- Which categories of sensitive data your HR system processes
- The specific legal basis for each
- Access controls (who can view sensitive data within the system)
- Encryption and security requirements
- How consent is obtained and recorded when required
Common GDPR Mistakes in HR Software Deployments
Even well-intentioned HR teams frequently make these errors:
- Using consent as the default lawful basis — In employment relationships, consent is rarely freely given due to the power imbalance. Default to contract or legal obligation instead.
- Failing to update privacy notices when switching HR software vendors
- Granting excessive user permissions within the HR system — not all managers need access to all employee data
- Ignoring data stored in integrations — your HR software likely syncs with Slack, Google Workspace, or other tools
- No process for offboarding data when an employee leaves
FAQ: GDPR and HR Software
Q1: Do we need a DPO if we use HR software to process employee data?
Not necessarily. A DPO is mandatory if your organization processes special category data at large scale, conducts systematic monitoring of employees, or is a public authority. However, even if not mandatory, appointing a DPO or privacy lead is strongly recommended when using HR software.
Q2: Can employees request deletion of their data while still employed?
Generally, no — not for data required to fulfill the employment contract or legal obligations (like payroll records). The right to erasure has specific exceptions, and HR data often falls within them. You should document this limitation clearly in your employee privacy notice.
Q3: What happens if our HR software vendor suffers a data breach?
As the data controller, you remain responsible. You must notify your supervisory authority within 72 hours if the breach is likely to result in a risk to individuals’ rights and freedoms. Your DPA should require the vendor to notify you promptly so you can meet this deadline.
Q4: Are job applicants covered by GDPR, not just employees?
Yes. Applicant tracking systems (ATS) and recruitment modules in HR software must comply with GDPR. Candidates must receive a privacy notice at application, and their data should be deleted within a reasonable period if they’re unsuccessful (typically 6–12 months).
Q5: Do we need separate policies for each country if we’re a multinational?
You need a core GDPR-compliant policy, but local addendums are often necessary. Germany, France, and the Netherlands, for example, have specific national rules about employee monitoring, works council involvement, and data transfers. Always consult local counsel for multi-jurisdiction deployments.
Building Your GDPR HR Compliance Framework
Effective GDPR compliance for HR software isn’t a one-time task — it’s an ongoing program that includes:
- Annual reviews of your data processing register
- Regular DPA reviews when vendors update their terms
- Training for HR staff on data subject rights handling
- Periodic access control audits within your HR system
- Documentation of all compliance decisions
The policies outlined above form the backbone of a defensible compliance program. The key is having them documented, approved, and consistently applied.
Save Time with Ready-to-Use GDPR HR Policy Templates
Writing these policies from scratch is time-consuming and easy to get wrong. Our GDPR HR Software Compliance Template Pack includes professionally drafted, legally reviewed documents you can customize and deploy immediately:
✅ Employee Data Privacy Notice (GDPR-compliant) ✅ Lawful Basis Register template ✅ Data Retention and Deletion Schedule ✅ Data Processing Agreement checklist and review guide ✅ Employee Rights Request Procedure (with response letter templates) ✅ Special Category Data Policy
Stop spending hours on compliance drafting. Our templates are built by compliance specialists, regularly updated to reflect regulatory guidance, and trusted by HR teams across the EU and UK.
👉 [Browse the GDPR HR Compliance Template Pack →] and get your documentation in order today.
Best for teams organizing privacy documentation and operating guidance.