Every company is a data controller for its own workforce, and HR holds some of the most sensitive data in the building — health records, performance notes, salary, background checks, often far more than anyone consciously decided to collect. The catch that trips up most HR functions is structural: the power imbalance between employer and employee means consent, the basis companies reach for by reflex, almost never works at work. Build the employee-data programme on consent and it collapses the first time someone says no and faces no consequence — which, legally, they must be free to do.
Why Consent Fails at Work
The regulation requires consent to be freely given, and an employee cannot meaningfully refuse their employer without fear of consequence — so for most employment processing, consent is presumed invalid before it’s even collected. That single fact reshapes the whole programme. The bases that actually work are contract (payroll and everything intrinsic to the employment relationship), legal obligation (tax, social security, statutory records), and legitimate interest with a balancing test (for things like proportionate security). Consent is left for the genuinely optional — the team photo on the website, the social club, the wellness perk someone can decline with no cost.
Collect What the Job Needs, Not What’s Convenient
Data minimisation bites hardest in HR, because it’s the function most tempted to over-collect “just in case.” Background checks should be proportionate to the role, not a blanket deep-dive on everyone. Health data belongs only where a specific justification exists — occupational health, a workplace accommodation — and then under an Article 9 condition, not casually noted by a manager. The principle is simple and routinely ignored: hold what the role actually requires, and nothing gathered because it might one day be useful.
| HR activity | Basis that fits | The common mistake |
|---|---|---|
| Payroll and managing the role | Performance of the contract | Asking employees to “consent” to being paid |
| Tax and social-security filings | Legal obligation | Treating mandatory filings as optional or consented |
| Security and IT monitoring | Legitimate interest, with balancing | Monitoring with no test and no notice |
| Optional perks and photos | Genuine, refusable consent | Bundling perks into the contract |
Monitoring Is Allowed — Quietly Isn’t
Employers can monitor — email, CCTV, location, productivity tools — but only where it’s necessary and proportionate to a real, stated aim, and only with transparency about what’s happening. The fast route to a fine is the opposite: covert monitoring, blanket surveillance with no specific justification, or recording far more than the purpose needs. The question a regulator asks isn’t “did you have a reason?” but “was this the least intrusive way to achieve it, and did people know?” Most heavy-handed monitoring fails on one or both.
At an H&M service centre in Germany, team leaders held informal “Welcome Back Talks” with staff returning from sick leave or holiday — and then wrote down what they learned. Over years, notes accumulated on employees’ illnesses and diagnoses, family problems, religious beliefs, and holiday experiences, stored on a network drive readable by up to fifty managers and used to build profiles that fed employment decisions. In 2020 the Hamburg regulator fined H&M €35.3 million, one of the largest employee-data penalties in Europe. There was no hacker and no leak to the outside world — the violation was entirely internal: a company quietly amassing intimate detail about its workforce with no lawful basis and no boundary. The case is the clearest statement that the regulation governs the inside of the building as strictly as the customer-facing edge, and that “we were just keeping notes” is not a basis for processing someone’s private life.
Employees Have Rights, and They Use Them
Staff and ex-staff have the same access and deletion rights as any customer — and they exercise them more often, usually around a dispute, a grievance, or a departure. An access request from a former employee can sweep in appraisals, emails, manager notes, and HR records, and it runs on the same one-month clock, with the same duty to redact third parties caught in the same files. HR functions that treat these requests as a nuisance to stall discover that stalling is itself the violation — and that a disgruntled requester often knows it.
Looks Fine vs. Is Lawful
Pattern-matching from real HR reviews — the gap between looking fine and being lawful tends to follow the same shape:
| Looks compliant | Is actually compliant |
|---|---|
| ✗ “The employee consented in the contract” | ✓ Contract and legal-obligation bases; consent only where real |
| ✗ Collect everything HR might one day want | ✓ Only the data the role actually requires |
| ✗ Monitoring quietly switched on | ✓ Necessary, proportionate, and disclosed monitoring |
| ✗ Health notes kept informally by managers | ✓ Health data under an Article 9 condition, tightly scoped |
| ✗ Manager notes on employees’ private lives | ✓ A clear boundary on what’s recorded, and why |
| ✗ Employee access requests treated as a nuisance | ✓ A process that finds and produces the data on time |
| ✗ Records kept long after someone leaves | ✓ Retention matched to obligation, then deletion |
HR Is Privacy’s Blind Spot
Companies pour privacy effort into customer data — the website, the marketing stack, the product — and quietly leave HR to improvise with spreadsheets and manager discretion. The largest employee-data fine in Europe came from exactly that blind spot: not a breach, not the customer side, but the inside of the building, where intimate detail was collected because no one had drawn a line. Treating the workforce’s data with the same rigour as the customer’s isn’t generosity; it’s where the sector’s biggest internal fines actually land.
Final Thought
HR holds the most sensitive data most companies process and governs it the most casually, on a basis — consent — that legally doesn’t hold between an employer and an employee. The discipline that fixes it is unspectacular: the right basis per activity, collection limited to what the role needs, monitoring that’s proportionate and disclosed, a hard boundary on recording private lives, and a process for the access requests employees increasingly send. None of it is hard. All of it is what the largest internal fines are about.
The test: pick any employee record and answer three things without a meeting — on what basis is each part of it processed, would a regulator call the monitoring proportionate and disclosed, and could an ex-employee’s access request be answered on time. If the honest answer rests on “they agreed when they joined,” the foundation isn’t there.
Frequently Asked Questions
Rarely. GDPR requires consent to be freely given, and an employee can’t meaningfully refuse their employer without fear of consequence, so for most employment processing consent is presumed invalid. Consent is left for the genuinely optional, like a team photo or a wellness perk.
Performance of the contract for payroll and anything intrinsic to employment; legal obligation for tax, social security, and statutory records; and legitimate interest with a balancing test for things like proportionate security monitoring.
Yes, but only where it is necessary and proportionate to a real, stated aim, and only with transparency. Covert or blanket surveillance, or recording more than the purpose needs, is the fast route to a fine. The test is whether it was the least intrusive way and whether people knew.
The same as any customer, and they use them more, usually around a grievance or departure. An access request can sweep in appraisals, emails, and manager notes, runs on the same one-month clock, and carries the same duty to redact third parties.