How to Comply With GDPR for HR Records

Editorial Status & Legal Guidance

This guide is maintained as a current resource for September 2026 and covers only the laws of England and Wales. Information is for general guidance, not legal advice. Consult a qualified solicitor for advice specific to your situation.

Key Takeaways for How to Comply With GDPR for HR Records

Clear, practical guide to complying with GDPR for HR records in England and Wales. Explains lawful bases, data protection principles, retention policies, employee rights, data sharing, breach reporting and accountability for HR teams.

Employer Compliance: Employers must comply with strict statutory duties regarding health, safety, and employee rights. Failure to comply leads to heavy litigation.

Employers in England and Wales must handle HR records in line with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. HR data includes personal and sensitive information about employees, job applicants and sometimes former staff. Compliance is not just a legal obligation but a key part of maintaining trust and reducing risk of complaints, enforcement action or claims for compensation under data protection law. This guide explains the legal duties, practical steps and common issues that organisations should address when processing HR records.

Why GDPR Matters for HR Records

HR departments process a wide range of personal data every day, from basic contact details and payroll information to sensitive data about health, diversity characteristics and disciplinary issues. Under UK GDPR, employers are data controllers responsible for collecting, storing, using and disposing of this information lawfully and transparently.

GDPR applies whether HR records are held on paper, in spreadsheets or in human resources information systems. Employers can face significant penalties - up to £17.5 million or 4 % of global turnover - for serious breaches, as well as individual claims for compensation.

The key legal sources for GDPR compliance include:

  • UK General Data Protection Regulation (UK GDPR) - the principal data protection regime setting out rights and duties;
  • Data Protection Act 2018 (DPA 2018) - supplements UK GDPR, including provisions on special category data;
  • Guidance from the Information Commissioner's Office (ICO) setting out how employers should apply GDPR to employment records.

Under UK GDPR, HR records must be processed lawfully, fairly and in a transparent manner, in line with defined principles such as purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality, and accountability.

Lawful Basis for Processing HR Records

Every processing activity must have a lawful basis under Article 6 of UK GDPR. For HR records, common lawful bases include:

  • Performance of a contract - necessary for administering contractual rights and duties, such as payroll, leave and benefits;
  • Legal obligation - required to comply with laws such as tax reporting or right‑to‑work checks;
  • Legitimate interests - where processing is necessary for legitimate business needs and does not override the individual's rights.
Related:  Limitation Period: Data Breach Compensation Claims

For information such as health data – a “special category” under Article 9 – an additional condition must be met, such as processing being necessary for employment obligations or health and safety requirements.

What HR Data Must Employers Handle Carefully

HR records often include:

  • Personal contact details, date of birth and emergency contacts;
  • Payroll and tax information;
  • Absence and sickness records, including fit notes;
  • Disciplinary and grievance files;
  • Performance appraisals and training records;
  • Diversity and equal opportunities data.

Certain categories such as health, trade union membership, racial or ethnic origin, religion, sexual orientation or biometric data are treated as special category data and attract extra protections.

Core GDPR Principles for HR Records

1. Lawfulness, Fairness and Transparency

Employers must process HR data in a way that employees would reasonably expect and not in ways that unfairly disadvantage them. HR policies and privacy notices should explain:

  • What data is collected;
  • Why it is processed;
  • Who will have access to it;
  • Any automated decision‑making or profiling;
  • Where data is shared outside the organisation.

Transparency is vital to avoid misinformation claims and complaints to the ICO. Employees have rights to be informed, and this must be reflected clearly in onboarding material and staff handbooks.

2. Data Minimisation and Purpose Limitation

Organisations should only collect data that is necessary for a specific and legitimate purpose. Collecting additional information “just in case” is not compliant with GDPR. Employers should periodically review whether the data held is still relevant and necessary.

3. Accuracy and Rectification

Employers must keep HR records up to date and accurate. If an employee identifies incorrect information, organisations must have processes to correct or erase it, consistent with the employee's right to rectification.

Related:  Duty to Maintain Workplace Insurance Requirements 

4. Storage Limitation and Retention

HR data must not be kept longer than necessary. UK GDPR does not prescribe specific timescales, but employers must justify retention periods based on legal obligations or business needs. For example, payroll records must generally be kept for at least six years for tax and employment claim purposes, whereas other records may be deleted sooner or anonymised after they are no longer needed.

Employers should document retention policies and ensure secure disposal of both paper and digital files when they are no longer required.

5. Integrity and Confidentiality (Security)

Appropriate security measures must protect HR data from unauthorised access, loss, or damage. These measures may include:

  • Role‑based access controls;
  • Encryption of digital records;
  • Locked storage for physical files;
  • Audit logs showing who accessed records and when.

Security safeguards should be proportionate to the sensitivity of the data. Health information, as special category data, typically requires more stringent protections.

Individual Rights and HR Records

Employees and job applicants have specific rights under UK GDPR, including:

  • Right of access (Subject Access Request) - individuals can request copies of their personal data, and employers must respond within one month;
  • Right to rectification - if data is inaccurate or incomplete;
  • Right to erasure - known as the “right to be forgotten” in certain circumstances;
  • Right to object - where processing is based on legitimate interests.

Employers must have processes to recognise and respond to these requests promptly and document the rationale for any refusal.

Data Sharing and Third Parties

Sharing HR data with third parties - for example, payroll processors, benefits providers, or external counsel - must be justified under GDPR. Employers should:

  • Conduct due diligence on third parties' data protections;
  • Have written contracts with processors;
  • Limit shared data to the minimum necessary for the stated purpose.

Where sensitive data is shared, explicit documentation of lawful basis and security measures is essential.

Responding to Data Breaches

A personal data breach - such as unauthorised access or loss of HR records - must be assessed for risk. If the breach is likely to result in a risk to rights and freedoms, employers must report it to the ICO within 72 hours and, where there is high risk, notify affected individuals.

Related:  How Employers Must Calculate Holiday Entitlement

Maintaining a breach response plan is a key part of accountability and reduces the impact of potential enforcement action.

Documentation and Accountability

UK GDPR requires employers to demonstrate compliance. Practical steps include:

  • Keeping records of processing activities (ROPA);
  • Maintaining up‑to‑date privacy notices and policies;
  • Documenting retention schedules and data minimisation decisions;
  • Conducting Data Protection Impact Assessments (DPIAs) for high‑risk processing.

Smaller organisations may tailor documentation to their scale, but accountability remains a core obligation.

Common Challenges and Practical Tips

Health and Special Category Data

Health information, such as fit notes and occupational health reports, has elevated protections. Employers should handle this data transparently, with restricted access and a clear lawful basis beyond general employment administration.

Retention decisions must balance GDPR principles with statutory requirements. For example, accident records may need to be retained for extended periods for health and safety purposes.

Responding to SARs

Subject Access Requests can be broad. HR teams should plan to search all relevant systems and respond within statutory deadlines, redacting third‑party personal information where necessary.

Conclusion

Complying with GDPR for HR records is essential for lawful, fair and transparent processing of employee data. Employers in England and Wales must establish lawful bases for processing, document purposes and retention, secure personal data appropriately, respect individual rights, and demonstrate accountability. Robust policies, data security measures, and clear procedures for handling access requests and breaches help minimise legal risk and support organisational integrity.

James William Steven Parker
James William Steven Parker
James is the founder of UKLegalGuides.com and a former agent at the Ministry of Justice (UK). With a background in processing legal claims, he launched this platform to make the laws of England and Wales accessible to everyone.
Scroll to Top