This guide is maintained as a current resource for July 2026 and covers only the laws of England and Wales. Information is for general guidance, not legal advice. Consult a qualified solicitor for advice specific to your situation.
GDPR compliance for HR data explained in UK law, covering employee records, lawful bases, retention rules, employee rights, subject access requests, ICO guidance, and employer obligations for lawful HR data processing.

Why HR data is highly regulated
Human resources (HR) data is one of the most sensitive categories of personal data processed by organisations. It includes recruitment records, payroll information, performance reviews, disciplinary records, sickness absence data, and equality monitoring information.
In the UK, processing this data must comply with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, enforced and overseen by the Information Commissioner's Office.
HR departments must balance operational needs with strict legal duties relating to transparency, fairness, retention limits, and employee rights. Non-compliance can lead to regulatory enforcement, tribunal claims, and financial penalties.
What counts as HR data under UK GDPR
HR data is personal data relating to workers, applicants, contractors, and former employees. It commonly includes:
- Recruitment applications and CVs
- Right to work documentation
- Payroll and tax records
- Pension information
- Performance and appraisal records
- Disciplinary and grievance files
- Sickness and health records
- CCTV and monitoring data in the workplace
Some HR data, such as health information, is classified as special category data under UK GDPR and requires additional safeguards.
Legal framework governing HR data processing
UK GDPR and Data Protection Act 2018
The core legislation is UK GDPR, supplemented by the Data Protection Act 2018. These laws require organisations to ensure that personal data is:
- Processed lawfully, fairly, and transparently
- Collected for specified, explicit purposes
- Limited to what is necessary (data minimisation)
- Accurate and kept up to date
- Stored only for as long as necessary (storage limitation)
- Kept secure using appropriate technical measures
The storage limitation principle is particularly important in HR contexts, requiring organisations not to retain employee data indefinitely without justification.
Employment law and limitation periods
HR retention decisions are also influenced by employment law and limitation rules, particularly under the Limitation Act 1980. Employers often retain records for several years after employment ends to defend potential tribunal claims.
Lawful bases for processing HR data
Employers must identify a lawful basis under UK GDPR Article 6. Common lawful bases include:
- Legal obligation (e.g., tax and payroll compliance)
- Contract performance (employment contract administration)
- Legitimate interests (performance management, security, internal operations)
For special category data, such as medical or diversity data, additional conditions under Article 9 are required, such as employment law obligations or occupational health requirements.
Consent is rarely appropriate in HR contexts due to the imbalance of power between employer and employee.
Core GDPR compliance obligations for HR departments
1. Transparency and employee information notices
Employers must provide clear privacy information explaining:
- What data is collected
- Why it is processed
- Who it is shared with
- Retention periods
- Employee rights
This is typically delivered through a staff privacy notice and recruitment privacy statement.
2. Data minimisation in HR processes
HR teams must ensure they only collect data that is necessary for legitimate employment purposes.
Examples:
- Collecting health data only where required for workplace adjustments
- Avoiding excessive monitoring of employee communications
- Limiting recruitment data to job-relevant information
Excessive or irrelevant data collection is a breach of UK GDPR principles.
3. Storage limitation and HR record retention
HR data cannot be kept indefinitely. Under UK GDPR, data must be retained only as long as necessary for the purpose collected.
The Information Commissioner's Office expects organisations to maintain:
- A written retention schedule
- Defined retention periods for each HR record type
- Regular reviews and deletion or anonymisation procedures
Common retention approaches include:
- Recruitment data: short-term retention after hiring decision
- Payroll records: longer retention due to tax obligations
- Disciplinary records: limited retention based on relevance and risk
- Employee files: retained post-employment for potential legal claims
Retention must always be justified and documented.
4. Security and confidentiality of HR data
Employers must implement appropriate technical and organisational measures, including:
- Access controls based on job role
- Encryption of sensitive HR databases
- Secure storage of physical files
- Audit logs for HR systems
- Staff training on confidentiality
Security obligations are part of the “integrity and confidentiality” principle under UK GDPR.
5. Special category HR data (health and equality data)
Health-related HR data requires stronger protection. This includes:
- Occupational health reports
- Sickness absence details
- Disability-related information
- Medical assessments
Processing must be strictly necessary and supported by a valid legal condition under UK GDPR Article 9.
Employee rights in relation to HR data
Employees and former employees have several enforceable rights:
Subject access requests (SARs)
Individuals can request copies of their HR data, including:
- Emails and internal HR notes
- Disciplinary records
- Payroll information
- Performance evaluations
Employers must respond within one month, subject to limited extensions.
Right to rectification
Employees can require correction of inaccurate HR records.
Right to erasure
Data must be deleted when it is no longer necessary, unless retention is required for legal or regulatory reasons.
Right to restriction and objection
Employees may limit or challenge certain types of processing, particularly where legitimate interest is used.
Subject Access Requests and HR compliance risks
HR departments face significant compliance risk when handling SARs. Common issues include:
- Failure to locate all relevant HR data
- Redaction errors involving third-party data
- Over-retention of unnecessary records
- Delays beyond statutory deadlines
Poor SAR handling can lead to complaints to the Information Commissioner's Office and may be used as evidence in employment tribunal proceedings.
HR data retention challenges and best practice
Organisations must reconcile multiple legal regimes:
- UK GDPR storage limitation rules
- Tax and payroll record requirements
- Employment tribunal limitation periods
- Sector-specific compliance obligations
Best practice includes:
- A documented HR data retention policy
- Automated deletion systems where possible
- Regular audits of HR databases
- Clear categorisation of HR record types
- Defined retention triggers (e.g., end of employment date)
Failure to manage retention properly increases legal exposure and storage risk.
Common compliance failures in HR data processing
Frequent breaches include:
- Keeping applicant data indefinitely
- Excessive monitoring of employees without justification
- Inadequate privacy notices
- Sharing HR data without proper controls
- Missing lawful basis documentation
- Retention policies not being implemented in practice
These issues often result in ICO scrutiny or employee claims.
Practical steps for HR GDPR compliance
Organisations should ensure:
- A complete HR data inventory
- Lawful basis identified for each processing activity
- Clear employee privacy notices
- Structured retention schedules
- Secure HR systems with access controls
- Staff training on data protection duties
- Regular compliance reviews and audits
Key Takeaways
GDPR compliance for HR data requires strict control over how employee information is collected, used, stored, and deleted. Employers must comply with UK GDPR principles, maintain clear retention schedules, ensure transparency, and respect employee rights such as subject access and data correction. The most common compliance risks arise from excessive data retention, lack of transparency, and inadequate handling of HR records.