🇪🇺 GDPR👥 For HR🏭 Phase 4 · Industry-Specific

GDPR for HR and Employee Data — What Companies Must Know

Employees can’t freely consent to their employer. That single fact rewrites how HR is allowed to handle their data.

GK
Gauri Khatate
🔐 Cybersecurity Expert & Technical Writer·📖 5 min read
📅 June 2026·🏢 SecComply
GDPR for HR and employee data — the most sensitive data a company processes

HR holds the most sensitive data most companies process — and governs it the most casually, on a basis that legally doesn’t hold between employer and employee.

Every company is a data controller for its own workforce, and HR holds some of the most sensitive data in the building — health records, performance notes, salary, background checks, often far more than anyone consciously decided to collect. The catch that trips up most HR functions is structural: the power imbalance between employer and employee means consent, the basis companies reach for by reflex, almost never works at work. Build the employee-data programme on consent and it collapses the first time someone says no and faces no consequence — which, legally, they must be free to do.

Consent fails
The employer–employee power imbalance undermines ‘freely given’
Contract + duty
The bases that actually carry most HR processing
Monitoring limits
Surveillance needs necessity, proportionality, and transparency
€35.3M
The fine on a retailer for secretly profiling employees’ private lives

Collect What the Job Needs, Not What’s Convenient

Data minimisation bites hardest in HR, because it’s the function most tempted to over-collect “just in case.” Background checks should be proportionate to the role, not a blanket deep-dive on everyone. Health data belongs only where a specific justification exists — occupational health, a workplace accommodation — and then under an Article 9 condition, not casually noted by a manager. The principle is simple and routinely ignored: hold what the role actually requires, and nothing gathered because it might one day be useful.

HR activityBasis that fitsThe common mistake
Payroll and managing the rolePerformance of the contractAsking employees to “consent” to being paid
Tax and social-security filingsLegal obligationTreating mandatory filings as optional or consented
Security and IT monitoringLegitimate interest, with balancingMonitoring with no test and no notice
Optional perks and photosGenuine, refusable consentBundling perks into the contract

Monitoring Is Allowed — Quietly Isn’t

Employers can monitor — email, CCTV, location, productivity tools — but only where it’s necessary and proportionate to a real, stated aim, and only with transparency about what’s happening. The fast route to a fine is the opposite: covert monitoring, blanket surveillance with no specific justification, or recording far more than the purpose needs. The question a regulator asks isn’t “did you have a reason?” but “was this the least intrusive way to achieve it, and did people know?” Most heavy-handed monitoring fails on one or both.

THE FILE NO ONE WAS SUPPOSED TO KEEP — H&M (HAMBURG, 2020)

At an H&M service centre in Germany, team leaders held informal “Welcome Back Talks” with staff returning from sick leave or holiday — and then wrote down what they learned. Over years, notes accumulated on employees’ illnesses and diagnoses, family problems, religious beliefs, and holiday experiences, stored on a network drive readable by up to fifty managers and used to build profiles that fed employment decisions. In 2020 the Hamburg regulator fined H&M €35.3 million, one of the largest employee-data penalties in Europe. There was no hacker and no leak to the outside world — the violation was entirely internal: a company quietly amassing intimate detail about its workforce with no lawful basis and no boundary. The case is the clearest statement that the regulation governs the inside of the building as strictly as the customer-facing edge, and that “we were just keeping notes” is not a basis for processing someone’s private life.

Employees Have Rights, and They Use Them

Staff and ex-staff have the same access and deletion rights as any customer — and they exercise them more often, usually around a dispute, a grievance, or a departure. An access request from a former employee can sweep in appraisals, emails, manager notes, and HR records, and it runs on the same one-month clock, with the same duty to redact third parties caught in the same files. HR functions that treat these requests as a nuisance to stall discover that stalling is itself the violation — and that a disgruntled requester often knows it.

Looks Fine vs. Is Lawful

Pattern-matching from real HR reviews — the gap between looking fine and being lawful tends to follow the same shape:

Looks compliantIs actually compliant
✗ “The employee consented in the contract”✓ Contract and legal-obligation bases; consent only where real
✗ Collect everything HR might one day want✓ Only the data the role actually requires
✗ Monitoring quietly switched on✓ Necessary, proportionate, and disclosed monitoring
✗ Health notes kept informally by managers✓ Health data under an Article 9 condition, tightly scoped
✗ Manager notes on employees’ private lives✓ A clear boundary on what’s recorded, and why
✗ Employee access requests treated as a nuisance✓ A process that finds and produces the data on time
✗ Records kept long after someone leaves✓ Retention matched to obligation, then deletion

HR Is Privacy’s Blind Spot

Companies pour privacy effort into customer data — the website, the marketing stack, the product — and quietly leave HR to improvise with spreadsheets and manager discretion. The largest employee-data fine in Europe came from exactly that blind spot: not a breach, not the customer side, but the inside of the building, where intimate detail was collected because no one had drawn a line. Treating the workforce’s data with the same rigour as the customer’s isn’t generosity; it’s where the sector’s biggest internal fines actually land.

Final Thought

HR holds the most sensitive data most companies process and governs it the most casually, on a basis — consent — that legally doesn’t hold between an employer and an employee. The discipline that fixes it is unspectacular: the right basis per activity, collection limited to what the role needs, monitoring that’s proportionate and disclosed, a hard boundary on recording private lives, and a process for the access requests employees increasingly send. None of it is hard. All of it is what the largest internal fines are about.

The test: pick any employee record and answer three things without a meeting — on what basis is each part of it processed, would a regulator call the monitoring proportionate and disclosed, and could an ex-employee’s access request be answered on time. If the honest answer rests on “they agreed when they joined,” the foundation isn’t there.

Could You Defend How You Handle Your Own People’s Data?

SecComply reviews HR and employee data where it quietly goes wrong — replacing reflexive consent with bases that hold, trimming collection to what the role needs, putting necessity and transparency around monitoring, drawing the line on what managers record, and building a process for employee access requests.

Frequently Asked Questions

Can employees consent to data processing by their employer?

Rarely. GDPR requires consent to be freely given, and an employee can’t meaningfully refuse their employer without fear of consequence, so for most employment processing consent is presumed invalid. Consent is left for the genuinely optional, like a team photo or a wellness perk.

What lawful basis should HR use instead?

Performance of the contract for payroll and anything intrinsic to employment; legal obligation for tax, social security, and statutory records; and legitimate interest with a balancing test for things like proportionate security monitoring.

Can we monitor employees?

Yes, but only where it is necessary and proportionate to a real, stated aim, and only with transparency. Covert or blanket surveillance, or recording more than the purpose needs, is the fast route to a fine. The test is whether it was the least intrusive way and whether people knew.

Do employees have access and deletion rights?

The same as any customer, and they use them more, usually around a grievance or departure. An access request can sweep in appraisals, emails, and manager notes, runs on the same one-month clock, and carries the same duty to redact third parties.