Data Protection Duties for HR Records

Editorial Status & Legal Guidance

This guide is maintained as a current resource for July 2026 and covers only the laws of England and Wales. Information is for general guidance, not legal advice. Consult a qualified solicitor for advice specific to your situation.

Key Takeaways for Data Protection Duties for HR Records

Data protection duties for HR records in the UK explained, including UK GDPR requirements, lawful processing of employee data, retention rules, employee rights, security obligations, data breaches, and employer compliance duties in England and Wales.

Employer Compliance: Employers must comply with strict statutory duties regarding health, safety, and employee rights. Failure to comply leads to heavy litigation.

Human Resources (HR) records contain some of the most sensitive personal data held by organisations, including employment history, payroll details, performance reviews, disciplinary records, and health information. In the United Kingdom, the handling of HR records is strictly regulated under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

Employers act as data controllers when processing HR data, meaning they have legal responsibility for ensuring that all employee data is collected, stored, used, and deleted in compliance with data protection law. Failure to meet these obligations can result in regulatory enforcement by the Information Commissioner's Office (ICO), Employment Tribunal claims, and significant financial penalties.

This article explains the legal duties applying to HR records, including lawful processing requirements, retention rules, employee rights, security obligations, and common compliance risks in England and Wales.

Legal Framework Governing HR Records

UK GDPR and Data Protection Act 2018

The UK GDPR establishes the core principles governing personal data processing. HR records fall within its scope because they relate to identifiable employees or job applicants.

Employers must ensure that HR data is:

  • Processed lawfully, fairly, and transparently
  • Collected for specified, explicit purposes
  • Limited to what is necessary (data minimisation)
  • Accurate and kept up to date
  • Stored only for as long as necessary
  • Secured against unauthorised access or loss

The Data Protection Act 2018 supplements the UK GDPR and includes provisions for sensitive personal data such as health records and criminal conviction information.

What Counts as HR Personal Data?

HR records typically include:

  • Employment contracts and application forms
  • Payroll and tax information
  • Attendance and sickness records
  • Performance evaluations
  • Disciplinary and grievance documentation
  • Training and qualification records
  • Equality monitoring data
  • Medical and occupational health reports
Related:  Wrongful Dismissal: Legal Definition (UK Employment Law Explained)

Much of this data is classified as special category data, requiring higher levels of protection under data protection law.

Lawful Basis for Processing HR Data

Employers must identify a lawful basis under UK GDPR for processing HR records. Common lawful bases include:

1. Legal obligation

Processing required to comply with employment law, tax law, or health and safety obligations.

2. Contractual necessity

Processing required to fulfil an employment contract, such as paying salary or managing benefits.

3. Legitimate interests

Used for purposes such as workforce management, provided these interests do not override employee rights.

4. Consent (limited use)

Consent is rarely relied upon in employment relationships due to imbalance of power, but may be used in specific contexts such as optional benefits schemes.

Data Protection Principles Applied to HR Records

Lawfulness, fairness, and transparency

Employers must inform employees about:

  • What data is collected
  • Why it is collected
  • How it will be used
  • Who it may be shared with

This is typically set out in a privacy notice.

Purpose limitation

HR data must only be used for legitimate employment-related purposes. For example, disciplinary records cannot be reused for unrelated decision-making without justification.

Data minimisation

Employers must only collect HR data that is necessary. Excessive or irrelevant information should not be stored.

Accuracy

HR records must be kept accurate and updated. Employees have the right to request correction of incorrect data.

Storage limitation

HR records must not be retained indefinitely. Employers should establish retention schedules, such as:

  • Recruitment records: typically 6–12 months if unsuccessful
  • Disciplinary records: often 6–24 months depending on policy
  • Payroll records: usually up to 6 years for tax purposes

Integrity and confidentiality

Employers must implement appropriate security measures, including:

  • Access controls
  • Encryption of sensitive data
  • Secure HR systems
  • Staff confidentiality obligations

Employee Rights in Relation to HR Records

Employees have several enforceable rights under UK GDPR:

Right of access (Subject Access Requests)

Employees can request copies of their HR records, including emails, disciplinary files, and performance data.

Related:  Fixed-Term Contract Protections

Employers must respond within one month.

Right to rectification

Employees can require correction of inaccurate HR data.

Right to erasure (limited)

In certain circumstances, employees may request deletion of HR data, although this is restricted where legal retention obligations apply.

Right to restriction and objection

Employees may limit or object to certain processing activities, particularly where legitimate interests are used as the lawful basis.

Data Security Obligations for HR Records

Employers must implement “appropriate technical and organisational measures” to protect HR data.

Common requirements include:

  • Role-based access to HR systems
  • Secure cloud storage systems
  • Password protection and multi-factor authentication
  • Staff training on confidentiality
  • Secure disposal of physical records
  • Cybersecurity protections against hacking or data breaches

Failure to secure HR records may lead to regulatory fines and compensation claims.

Data Sharing and Third Parties

HR data may be shared with third parties such as:

  • Payroll providers
  • Pension administrators
  • Occupational health services
  • Legal advisors
  • Regulatory bodies

However, employers must ensure:

  • Data sharing agreements are in place
  • Only necessary data is shared
  • Third parties comply with UK GDPR standards

Data Retention and HR Record Management

Employers must establish clear retention policies for HR records.

Retention periods should be based on:

  • Legal requirements (tax and employment law)
  • Potential litigation risks
  • Business necessity

Once data is no longer required, it must be securely deleted or anonymised.

Data Breaches Involving HR Records

A personal data breach occurs where HR records are:

  • Lost
  • Stolen
  • Accessed without authorisation
  • Accidentally disclosed

Employers must:

  • Report serious breaches to the ICO within 72 hours
  • Inform affected employees where there is a high risk
  • Take steps to mitigate harm

Breaches may lead to enforcement action and compensation claims.

Employment Tribunal and Legal Liability

Employees may bring claims related to HR data breaches, including:

The ICO may also impose administrative fines for non-compliance.

Related:  Employee Reference Legal Duties in UK Employment Law

Time Limits for Data Protection Claims

Typical limitation periods include:

  • Data protection claims: usually 6 years in civil courts
  • Employment-related claims involving data: typically 3 months less 1 day in tribunals
  • ICO complaints: no strict statutory time limit, but prompt reporting is expected

Practical Compliance Measures for Employers

Employers should ensure compliance by:

  • Maintaining an up-to-date HR privacy notice
  • Implementing clear data retention schedules
  • Conducting regular data protection impact assessments (DPIAs)
  • Training HR staff on GDPR obligations
  • Auditing HR systems and access controls
  • Documenting lawful bases for processing

Common Questions from our Readers

Can employers keep HR records indefinitely?

No. HR records must only be kept for as long as necessary for legal or business purposes.

Can employees access all HR records?

Yes, subject to limited exceptions such as third-party confidentiality or legal privilege.

Are disciplinary records personal data?

Yes, and they are subject to full UK GDPR protections.

What happens if HR data is misused?

Employers may face ICO enforcement, compensation claims, and reputational damage.

Key Takeaways

Data protection duties for HR records in the UK require employers to comply with UK GDPR and the Data Protection Act 2018 when collecting, storing, and processing employee information. HR data must be handled lawfully, securely, and transparently, with clear retention policies and strict access controls.

Employees have significant rights, including access to their records and correction of inaccuracies, while employers face legal risks for breaches, including regulatory fines and tribunal claims. Effective HR data governance is essential for legal compliance and workplace trust.

James William Steven Parker
James William Steven Parker
James is the founder of UKLegalGuides.com and a former agent at the Ministry of Justice (UK). With a background in processing legal claims, he launched this platform to make the laws of England and Wales accessible to everyone.
Scroll to Top