This guide is maintained as a current resource for July 2026 and covers only the laws of England and Wales. Information is for general guidance, not legal advice. Consult a qualified solicitor for advice specific to your situation.
Data protection duties for HR records in the UK explained, including UK GDPR requirements, lawful processing of employee data, retention rules, employee rights, security obligations, data breaches, and employer compliance duties in England and Wales.

Human Resources (HR) records contain some of the most sensitive personal data held by organisations, including employment history, payroll details, performance reviews, disciplinary records, and health information. In the United Kingdom, the handling of HR records is strictly regulated under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
Employers act as data controllers when processing HR data, meaning they have legal responsibility for ensuring that all employee data is collected, stored, used, and deleted in compliance with data protection law. Failure to meet these obligations can result in regulatory enforcement by the Information Commissioner's Office (ICO), Employment Tribunal claims, and significant financial penalties.
This article explains the legal duties applying to HR records, including lawful processing requirements, retention rules, employee rights, security obligations, and common compliance risks in England and Wales.
Legal Framework Governing HR Records
UK GDPR and Data Protection Act 2018
The UK GDPR establishes the core principles governing personal data processing. HR records fall within its scope because they relate to identifiable employees or job applicants.
Employers must ensure that HR data is:
- Processed lawfully, fairly, and transparently
- Collected for specified, explicit purposes
- Limited to what is necessary (data minimisation)
- Accurate and kept up to date
- Stored only for as long as necessary
- Secured against unauthorised access or loss
The Data Protection Act 2018 supplements the UK GDPR and includes provisions for sensitive personal data such as health records and criminal conviction information.
What Counts as HR Personal Data?
HR records typically include:
- Employment contracts and application forms
- Payroll and tax information
- Attendance and sickness records
- Performance evaluations
- Disciplinary and grievance documentation
- Training and qualification records
- Equality monitoring data
- Medical and occupational health reports
Much of this data is classified as special category data, requiring higher levels of protection under data protection law.
Lawful Basis for Processing HR Data
Employers must identify a lawful basis under UK GDPR for processing HR records. Common lawful bases include:
1. Legal obligation
Processing required to comply with employment law, tax law, or health and safety obligations.
2. Contractual necessity
Processing required to fulfil an employment contract, such as paying salary or managing benefits.
3. Legitimate interests
Used for purposes such as workforce management, provided these interests do not override employee rights.
4. Consent (limited use)
Consent is rarely relied upon in employment relationships due to imbalance of power, but may be used in specific contexts such as optional benefits schemes.
Data Protection Principles Applied to HR Records
Lawfulness, fairness, and transparency
Employers must inform employees about:
- What data is collected
- Why it is collected
- How it will be used
- Who it may be shared with
This is typically set out in a privacy notice.
Purpose limitation
HR data must only be used for legitimate employment-related purposes. For example, disciplinary records cannot be reused for unrelated decision-making without justification.
Data minimisation
Employers must only collect HR data that is necessary. Excessive or irrelevant information should not be stored.
Accuracy
HR records must be kept accurate and updated. Employees have the right to request correction of incorrect data.
Storage limitation
HR records must not be retained indefinitely. Employers should establish retention schedules, such as:
- Recruitment records: typically 6–12 months if unsuccessful
- Disciplinary records: often 6–24 months depending on policy
- Payroll records: usually up to 6 years for tax purposes
Integrity and confidentiality
Employers must implement appropriate security measures, including:
- Access controls
- Encryption of sensitive data
- Secure HR systems
- Staff confidentiality obligations
Employee Rights in Relation to HR Records
Employees have several enforceable rights under UK GDPR:
Right of access (Subject Access Requests)
Employees can request copies of their HR records, including emails, disciplinary files, and performance data.
Employers must respond within one month.
Right to rectification
Employees can require correction of inaccurate HR data.
Right to erasure (limited)
In certain circumstances, employees may request deletion of HR data, although this is restricted where legal retention obligations apply.
Right to restriction and objection
Employees may limit or object to certain processing activities, particularly where legitimate interests are used as the lawful basis.
Data Security Obligations for HR Records
Employers must implement “appropriate technical and organisational measures” to protect HR data.
Common requirements include:
- Role-based access to HR systems
- Secure cloud storage systems
- Password protection and multi-factor authentication
- Staff training on confidentiality
- Secure disposal of physical records
- Cybersecurity protections against hacking or data breaches
Failure to secure HR records may lead to regulatory fines and compensation claims.
Data Sharing and Third Parties
HR data may be shared with third parties such as:
- Payroll providers
- Pension administrators
- Occupational health services
- Legal advisors
- Regulatory bodies
However, employers must ensure:
- Data sharing agreements are in place
- Only necessary data is shared
- Third parties comply with UK GDPR standards
Data Retention and HR Record Management
Employers must establish clear retention policies for HR records.
Retention periods should be based on:
- Legal requirements (tax and employment law)
- Potential litigation risks
- Business necessity
Once data is no longer required, it must be securely deleted or anonymised.
Data Breaches Involving HR Records
A personal data breach occurs where HR records are:
- Lost
- Stolen
- Accessed without authorisation
- Accidentally disclosed
Employers must:
- Report serious breaches to the ICO within 72 hours
- Inform affected employees where there is a high risk
- Take steps to mitigate harm
Breaches may lead to enforcement action and compensation claims.
Employment Tribunal and Legal Liability
Employees may bring claims related to HR data breaches, including:
- Data protection compensation claims
- Claims for distress caused by unlawful processing
- Breach of confidentiality
- Constructive dismissal in severe cases
The ICO may also impose administrative fines for non-compliance.
Time Limits for Data Protection Claims
Typical limitation periods include:
- Data protection claims: usually 6 years in civil courts
- Employment-related claims involving data: typically 3 months less 1 day in tribunals
- ICO complaints: no strict statutory time limit, but prompt reporting is expected
Practical Compliance Measures for Employers
Employers should ensure compliance by:
- Maintaining an up-to-date HR privacy notice
- Implementing clear data retention schedules
- Conducting regular data protection impact assessments (DPIAs)
- Training HR staff on GDPR obligations
- Auditing HR systems and access controls
- Documenting lawful bases for processing
Common Questions from our Readers
Can employers keep HR records indefinitely?
No. HR records must only be kept for as long as necessary for legal or business purposes.
Can employees access all HR records?
Yes, subject to limited exceptions such as third-party confidentiality or legal privilege.
Are disciplinary records personal data?
Yes, and they are subject to full UK GDPR protections.
What happens if HR data is misused?
Employers may face ICO enforcement, compensation claims, and reputational damage.
Key Takeaways
Data protection duties for HR records in the UK require employers to comply with UK GDPR and the Data Protection Act 2018 when collecting, storing, and processing employee information. HR data must be handled lawfully, securely, and transparently, with clear retention policies and strict access controls.
Employees have significant rights, including access to their records and correction of inaccuracies, while employers face legal risks for breaches, including regulatory fines and tribunal claims. Effective HR data governance is essential for legal compliance and workplace trust.