Summary
Understanding this context is essential before diving into the steps. Configure your HR software with role-based access controls (RBAC) and conduct quarterly access reviews. Log who accessed what and when — audit trails are essential for demonstrating compliance. Health information, disability data, trade union membership, and biometric data (like fingerprint clock-in systems) are all special category data under GDPR Article 9. Processing this data requires both a lawful basis under Article 6 AND a separate condition under Article 9.
GDPR Step by Step for HR Software: A Complete Compliance Guide
Managing employee data is at the heart of every HR function — but it also puts HR software squarely in the crosshairs of GDPR. From recruitment records to payroll details, performance reviews to absence logs, HR platforms process some of the most sensitive personal data imaginable. Getting GDPR right isn’t optional, and the consequences of getting it wrong can be severe: fines of up to €20 million or 4% of global annual turnover, whichever is higher.
This guide walks you through GDPR compliance for HR software step by step, giving you a clear, actionable roadmap whether you’re a vendor building an HR platform or an HR team selecting and configuring one.
Why GDPR Compliance Is Especially Critical for HR Software
HR software is unique in the GDPR landscape for several reasons:
- It processes data for every single employee, often from day one of recruitment
- It handles special category data (health records, disability information, trade union membership)
- It typically integrates with multiple third-party systems (payroll, benefits, background checks)
- Data is retained for years, sometimes decades, creating long-term compliance obligations
- Employees are rarely in a position of true “free choice” when consenting — making legal basis selection critical
Understanding this context is essential before diving into the steps.
Step 1: Map All Personal Data Flows
Before you can protect data, you need to know exactly what data you hold, where it comes from, where it goes, and how long you keep it.
Conduct a Data Mapping Exercise
Create a data inventory that captures:
- What data is collected — names, addresses, national insurance numbers, bank details, health information, performance ratings
- Where it comes from — job applicants, employees, managers, occupational health providers
- Where it is stored — your HR software database, cloud storage, integrated apps
- Who has access — HR admins, line managers, payroll teams, third-party processors
- Where it is transferred — payroll bureaus, pension providers, background screening companies
- How long it is retained — and under what policy
This data map becomes the foundation of your Records of Processing Activities (RoPA), which is a legal requirement under GDPR Article 30 for most organisations.
Step 2: Establish a Lawful Basis for Each Processing Activity
This is where many HR teams make critical mistakes. Consent is rarely the right legal basis for employment data — employees cannot freely withhold consent when their job may depend on it.
The Most Common Lawful Bases for HR Processing
| Processing Activity | Recommended Legal Basis |
|---|---|
| Payroll processing | Contract performance |
| Tax reporting | Legal obligation |
| Health and safety records | Legal obligation / Vital interests |
| Employee monitoring | Legitimate interests |
| Occupational health data | Employment law obligations |
| Marketing to job applicants | Consent |
| Diversity and inclusion monitoring | Explicit consent or legal obligation |
Document your chosen legal basis for every processing activity in your RoPA and your privacy notices. If you later need to justify your approach to a regulator, this documentation is your first line of defence.
Step 3: Update Your Privacy Notices
Transparency is a core GDPR principle. Every person whose data you process must be informed about:
- Who is processing their data (the data controller)
- Why their data is being processed and the legal basis
- How long their data will be retained
- Whether data will be transferred internationally
- Their rights as a data subject
- How to make a complaint to the supervisory authority
For HR Software, You Need Multiple Privacy Notices
- Candidate/applicant privacy notice — issued at the point of application
- Employee privacy notice — issued on or before the first day of employment
- Third-party privacy notice — for emergency contacts, references, and guarantors
Make sure these notices are written in plain language, easily accessible, and version-controlled so you can demonstrate what was in place at any given time.
Step 4: Review and Tighten Access Controls
One of the most common GDPR violations in HR software is excessive access — giving too many people access to too much data.
Apply the Principle of Data Minimisation
- Line managers should see only the data they need to manage their team
- Payroll teams need financial data, not performance reviews
- Recruiters need application data, not existing employee records
- IT administrators should have technical access without seeing personal data content where possible
Configure your HR software with role-based access controls (RBAC) and conduct quarterly access reviews. Log who accessed what and when — audit trails are essential for demonstrating compliance.
Step 5: Manage Third-Party Processors Properly
Your HR software almost certainly shares data with third parties: payroll providers, pension administrators, background check services, cloud infrastructure providers. Under GDPR, you are responsible for ensuring these processors meet the same standards you do.
What You Must Do
- Sign Data Processing Agreements (DPAs) with every processor before sharing data
- Vet processors for their security standards, sub-processor arrangements, and breach notification procedures
- Maintain a processor register as part of your RoPA
- Review processor agreements when they update their terms or sub-processors
If your HR software vendor is processing data on your behalf, they are a processor — and you need a DPA with them. Reputable vendors will have a standard DPA ready. If they don’t, treat that as a red flag.
Step 6: Handle Special Category Data with Extra Care
Health information, disability data, trade union membership, and biometric data (like fingerprint clock-in systems) are all special category data under GDPR Article 9. Processing this data requires both a lawful basis under Article 6 AND a separate condition under Article 9.
Practical Steps
- Store special category data in separate, more restricted fields within your HR system
- Apply additional access restrictions so only those with a genuine need can view it
- Document your Article 9 condition explicitly (usually employment law obligations or explicit consent)
- Never use special category data for purposes beyond the original collection intent
Step 7: Build a Process for Data Subject Rights
Employees have the right to access their data, correct inaccuracies, request deletion in some circumstances, and object to certain processing. HR software must support these rights operationally.
Create a Data Subject Rights Procedure That Covers
- Subject Access Requests (SARs) — you have 30 days to respond
- Right to rectification — correcting inaccurate records
- Right to erasure — applicable when employment ends and retention periods expire
- Right to data portability — providing data in a machine-readable format
- Right to object — particularly relevant for automated decision-making
Configure your HR software to easily export individual records, and train your HR team on how to handle requests. Keep a log of every request received and how it was handled.
Step 8: Implement Retention Schedules and Deletion Processes
Keeping data longer than necessary is a GDPR violation. HR data has different retention requirements depending on its type and jurisdiction.
Common HR Data Retention Periods (UK/EU)
- Recruitment records (unsuccessful candidates): 6–12 months
- Employee personnel files: 6–7 years after employment ends
- Payroll and tax records: 6–7 years
- Accident/health records: Up to 40 years in some cases
- Pension records: Indefinitely in some jurisdictions
Automate deletion or anonymisation where possible, and conduct annual data audits to identify records that have exceeded their retention period.
Step 9: Prepare for Data Breaches
GDPR requires you to report certain breaches to your supervisory authority within 72 hours. HR software breaches are particularly serious given the sensitivity of the data involved.
- Maintain an incident response plan specific to HR data breaches
- Know your notification thresholds — not every breach requires reporting
- Train staff to recognise and report potential breaches immediately
- Document all breaches, even those that don’t require notification
Frequently Asked Questions
Do we need a Data Protection Officer (DPO) for our HR software?
A DPO is mandatory if your organisation carries out large-scale, systematic monitoring of employees or processes special category data at scale. Many medium-to-large employers will meet this threshold. Even if not mandatory, appointing a DPO or a designated privacy lead is strongly recommended.
Can we use consent as the legal basis for processing employee data?
Rarely. Because of the power imbalance between employer and employee, consent is generally not considered “freely given” in the employment context. Contract performance, legal obligation, and legitimate interests are typically more appropriate bases.
What happens if our HR software vendor suffers a breach?
As the data controller, you remain responsible even when a processor is breached. This is why robust DPAs and vendor due diligence are so important. Your vendor must notify you “without undue delay” under your DPA, and you must then assess whether to notify the supervisory authority within 72 hours.
How do we handle employee data after someone leaves the company?
Former employee data must be retained only as long as necessary — typically for the duration of any potential legal claims plus your jurisdiction’s limitation periods. After that, data should be deleted or anonymised. Ensure your HR software supports automated retention and deletion workflows.
Is it GDPR compliant to use HR software hosted outside the EU/UK?
It can be, but you must ensure appropriate safeguards are in place for international transfers — such as Standard Contractual Clauses (SCCs), adequacy decisions, or Binding Corporate Rules. Check where your HR software vendor hosts data and what transfer mechanisms they rely on.
Take the Complexity Out of HR GDPR Compliance
Working through GDPR compliance for HR software is a substantial undertaking — but you don’t have to start from a blank page. Our ready-to-use GDPR compliance template bundle for HR software includes everything you need to get compliant faster:
- ✅ Data mapping and RoPA templates
- ✅ Employee and candidate privacy notice templates
- ✅ Data Processing Agreement template
- ✅ Subject Access Request procedure and response templates
- ✅ HR data retention schedule
- ✅ Data breach response plan
- ✅ Processor due diligence checklist
Written by compliance experts, legally reviewed, and immediately usable — just add your organisation’s details and you’re ready to go.
👉 [Browse our HR GDPR compliance template bundle and get compliant today →]
Save weeks of work and reduce your compliance risk starting this week.
Best for teams organizing privacy documentation and operating guidance.