Data Protection for HR Teams: Managing Employee Records Compliantly

Learn how UK HR teams can manage employee records lawfully and securely throughout the employment lifecycle. Understand GDPR rules for recruitment data, health records, DBS checks, retention and employee access requests. Build stronger HR data protection practices through practical controls, clear policies and compliance training.
D
Dr Amelia Hartwell
Aug 09, 2026
12 min read
Data protection for HR teams managing employee records securely and maintaining UK GDPR compliance.

Data protection for HR teams UK compliance is particularly important because HR departments process personal information at almost every stage of the employee lifecycle. From a candidate's first job application through onboarding, payroll, sickness absence, performance management and eventually departure, HR records can contain extensive information about an individual.

Some of that information is especially sensitive. Health and disability records, trade union membership, equality-monitoring information and criminal-record checks are subject to additional data protection rules, while disciplinary and grievance files can create significant confidentiality risks.

HR teams therefore need more than secure filing systems. They must understand lawful processing, access controls, retention, individual rights and when an issue should be escalated to a Data Protection Officer or compliance lead.

For a broader explanation of the legal framework behind these responsibilities, see our UK GDPR overview.

Why HR Holds Some of the Most Sensitive Data in an Organisation

HR often has a wider view of an employee than almost any other department.

An HR file may contain someone's home address, salary, bank details, emergency contacts, employment history, sickness records, disciplinary information and identification documents. It may also contain details about disability, trade union membership, family circumstances or allegations made during an internal investigation.

This concentration of information means HR data protection UK controls need to address both external security threats and inappropriate internal access.

Not every manager, administrator or senior employee should automatically have access to an entire personnel file. Access should normally be based on a person's role and genuine business need.

Particular care is required with investigations. Grievance, disciplinary, whistleblowing and misconduct records may contain allegations, witness statements and information about several people. Access should therefore be limited, and HR teams should avoid circulating investigation material more widely than necessary.

The same principle applies when working remotely. HR records should not be transferred to personal email accounts, stored on uncontrolled devices or left accessible through shared folders simply because remote access is convenient.

Good employee records GDPR practice combines technical security with confidentiality procedures, clear ownership and staff awareness.

Personal Data HR Teams Process Throughout the Employee Lifecycle

A useful way to manage employee information is to map it across the entire employment lifecycle.

During recruitment, HR may collect:

  • names and contact details;
  • CVs and employment histories;
  • qualifications;
  • interview notes;
  • assessment results;
  • references; and
  • equality-monitoring information.

During onboarding, additional information may include:

  • addresses and dates of birth;
  • National Insurance numbers;
  • bank and payroll details;
  • emergency contacts;
  • right-to-work evidence;
  • pension information; and
  • background-check information.

During employment, HR records may expand to include:

  • salary and benefits;
  • attendance and absence information;
  • appraisals;
  • training records;
  • occupational health information;
  • flexible-working requests;
  • maternity or family-leave records;
  • performance management;
  • grievances and disciplinary matters; and
  • workplace adjustments.

Finally, the exit stage may involve resignation or termination documents, final-pay information, exit interviews, references and records needed after employment has ended.

Mapping these activities helps HR determine why information is being processed, the appropriate lawful basis, who can access it and how long it should remain identifiable.

Consent should not automatically be used as the lawful basis simply because HR deals directly with employees. The ICO warns that employers are in a position of power over workers, meaning consent may not be freely given in many employment situations.

Depending on the purpose, more appropriate bases may include performance of a contract, compliance with a legal obligation or legitimate interests.

Recruitment and Candidate Data

UK GDPR applies before someone becomes an employee.

Job applicants have data protection rights over information contained in applications, interview notes, assessments and other recruitment records. Employers should therefore collect information that is relevant and necessary for deciding whether a candidate is suitable for the role.

Candidates should also receive appropriate privacy information explaining how their information will be used.

Recruitment teams should be particularly careful about unnecessary vetting. For example, the ICO says employers should not routinely conduct credit-reference checks on candidates without being able to justify why the information is necessary for the particular role.

The same data-minimisation principle applies to identity documents, social-media research and other background information.

What about unsuccessful applicants?

Unsuccessful candidates do not lose their UK GDPR rights when their application is rejected.

However, this does not mean HR must immediately delete every recruitment record. Organisations may have legitimate reasons to retain some information temporarily, including responding to queries or potential legal claims.

The UK GDPR does not prescribe one universal retention period for unsuccessful applications. ICO storage-limitation guidance says recruitment information should not be retained beyond the period in which it is genuinely required unless there is another clear business reason.

If HR wants to keep someone's details for future vacancies, that is a separate purpose that should be explained clearly. Candidate information should not quietly remain in an applicant tracking system indefinitely.

The retention period should therefore be documented and applied consistently to applications, interview notes, assessment results and related correspondence.

Special Category Data in HR Records

Some of the most sensitive employee personal data UK GDPR rules concern special category information.

Special category data includes information revealing or concerning matters such as:

  • racial or ethnic origin;
  • religious or philosophical beliefs;
  • political opinions;
  • trade union membership;
  • genetic information;
  • biometric data used for unique identification;
  • health or disability;
  • sex life; and
  • sexual orientation.

HR departments frequently process health information through sickness records, occupational health reports, reasonable-adjustment requests and fitness-to-work assessments.

The ICO confirms that health information is special category data. Employers must therefore identify both an appropriate Article 6 lawful basis and an applicable Article 9 condition before processing it. In some circumstances, the Data Protection Act 2018 also requires a Schedule 1 condition and an appropriate policy document.

For example, processing may be necessary to meet obligations relating to employment law, statutory sick pay, workplace safety or disability rights.

HR teams should also practise data minimisation. If a manager only needs to know that an employee is unavailable for work, they may not need detailed medical information about the condition responsible for the absence.

The ICO specifically distinguishes simple absence records from detailed sickness records and recommends limiting access to medical information.

Trade union membership also requires additional care. Payroll teams processing union subscriptions, for example, may be processing special category data even though the activity appears administratively routine.

Teams dealing regularly with these records can strengthen their understanding through Data Protection & GDPR Compliance training, particularly where HR administrators are responsible for identifying lawful processing and escalating higher-risk cases.

References, Background Checks and Right to Work

References, DBS information and right-to-work documents all involve personal data, but they should not be treated as though they are legally identical.

Employment references should be accurate, relevant and handled securely. Organisations do not necessarily have to provide every piece of information requested by another employer; the ICO notes that a neutral reference confirming matters such as role and employment dates may be appropriate.

Confidential references also receive specific protection under the Data Protection Act 2018. Where a reference is genuinely provided in confidence for employment or another specified purpose, an exemption from the right of access can apply.

DBS checks

A common HR misconception is that a DBS check result is special category data.

It is not. Information relating to criminal convictions, offences and related security measures is instead criminal offence data, which has its own rules under Article 10 UK GDPR and the Data Protection Act 2018.

Importantly, even a DBS result showing no convictions can still be criminal offence data because it conveys information about the person's criminal-record status.

Organisations generally need an Article 6 lawful basis and appropriate legal authority under domestic law, commonly involving a relevant Schedule 1 condition under the DPA 2018.

HR should therefore avoid retaining full DBS information merely because it was collected during recruitment. ICO recruitment guidance says intrusive vetting information should normally be securely destroyed once it is no longer required, although an organisation may retain an appropriate record of the outcome and decision where justified.

Right-to-work checks

Right-to-work records have more specific retention requirements.

Current Home Office guidance requires employers to retain evidence of prescribed right-to-work checks securely for the duration of employment and for a further two years after employment ends. The records should then be securely destroyed when no longer required.

HR retention schedules should therefore distinguish records with statutory retention requirements from records whose periods are determined by necessity and organisational risk.

Employee Access Requests to HR Records

Current and former employees can make subject access requests, usually called SARs, for personal information held about them.

A request does not need to use legal terminology or mention the UK GDPR. An employee saying, “Please send me my HR file” or asking for emails concerning their performance may constitute a valid SAR.

Current ICO guidance, updated in July 2026 to reflect Data (Use and Access) Act 2025 changes, says organisations must normally respond without undue delay and within one month. An extension of up to two further months may be available where necessary because a request is complex or multiple requests have been received. Organisations must carry out a reasonable and proportionate search.

This is why HR teams often act as first responders for data subject rights.

Potentially relevant records can include:

  • personnel files;
  • appraisal notes;
  • performance records;
  • disciplinary correspondence;
  • grievance records;
  • emails between managers and HR;
  • absence information; and
  • information held in relevant HR systems.

However, a SAR does not automatically mean handing over the entire unredacted HR file.

Records may contain personal information about colleagues, witnesses or managers. The employer must consider the requester's access rights alongside the rights of other individuals, including whether information should be redacted. Certain statutory exemptions may also apply.

This is particularly important with workplace investigations. HR should not assume that marking a document “confidential” automatically excludes it from a SAR, nor should it disclose witness or third-party information without considering the applicable rules.

Our data subject rights guide explains these rights in more detail. For broader organisational preparation, GDPR Essentials for UK Businesses can help managers recognise and correctly escalate requests when they arrive.

Retention of HR Records After Employment Ends

UK GDPR does not create one standard retention period for every HR document.

Instead, the storage-limitation principle requires organisations to keep identifiable personal information only for as long as it is needed for the purpose for which it is held. Retention should also take account of statutory requirements, potential legal claims and legitimate operational needs.

This means HR needs a documented retention schedule, rather than a rule such as “keep every employee file for seven years”.

Different categories may require different periods.

For example:

  • right-to-work evidence has a specific Home Office retention requirement;
  • payroll and tax information may be subject to separate statutory record-keeping duties;
  • investigation files should be reviewed according to their purpose and potential legal relevance;
  • unsuccessful-candidate information should not remain indefinitely without justification;
  • health information should be retained only for as long as the specific employment purpose requires it; and
  • unnecessary copies of identity or vetting documents should be securely deleted.

Retention should also be technically enforced where possible. A written deletion policy has limited value if HR systems, email archives and shared drives continue storing duplicate files indefinitely.

When someone leaves, HR should therefore consider where their information exists across payroll, benefits, recruitment platforms, shared drives, occupational health services and third-party systems.

Deletion should be secure, but information should not be destroyed simply because a former employee submits a complaint or SAR. Normal retention must be managed consistently, and relevant records may need to be preserved where there is a genuine legal or regulatory reason.

Training HR Teams on Data Protection

GDPR for HR professionals is not simply a matter for the organisation's DPO.

HR administrators are often the first people to receive sensitive health information, requests for employee files, complaints about incorrect data or questions about how records are being used.

Training should therefore prepare HR staff to recognise when everyday administration creates a data protection issue.

Useful scenarios include:

  • An employee asks HR for “everything you hold about me”.
  • A manager requests detailed medical information about a team member.
  • An unsuccessful candidate asks why their CV is still retained.
  • A witness asks that a grievance statement remain confidential.
  • A former employee asks for a copy of a reference.
  • A manager wants a DBS certificate emailed to several colleagues.
  • A staff member accidentally sends a payroll spreadsheet to the wrong recipient.

HR teams should know what they can handle themselves and when to involve the DPO, information-security team, legal advisers or senior management.

Effective HR compliance training UK should cover data minimisation, special category information, criminal offence data, confidentiality, retention, SAR recognition and secure sharing.

It should also extend beyond HR itself. Line managers regularly handle absence records, appraisals and disciplinary matters, so GDPR training for employees and managers can help prevent HR information from being copied into insecure emails, personal notes or unauthorised systems.

For organisation-wide awareness, data protection training for employees provides a practical foundation for staff who handle personal data without working in a dedicated compliance role.

FAQs

What personal data can HR legally hold on employees?

HR can hold personal information that it has a valid purpose and lawful basis to process, provided it complies with principles including necessity, transparency, data minimisation, security and storage limitation. Special category and criminal offence information require additional legal conditions and safeguards.

How long should HR keep records after someone leaves?

There is no single UK GDPR retention period covering every HR record. Employers should use a documented retention schedule based on the purpose, legal requirements and genuine organisational need; for example, prescribed right-to-work evidence is normally retained for employment plus two further years.

Can an employee request their HR file under GDPR?

Yes. Current and former employees can make a SAR for personal information an employer holds about them, including relevant HR information. The organisation must normally respond within one month, subject to applicable extensions, exemptions and third-party considerations.

Is a DBS check result special category data?

No. A DBS result is generally criminal offence data, which is governed by Article 10 UK GDPR and relevant provisions of the Data Protection Act 2018 rather than the special category rules in Article 9. This can apply even where the check confirms that the person has no convictions.

Do unsuccessful job applicants have data protection rights?

Yes. Candidates retain data protection rights even if they are not offered employment. Employers should explain recruitment processing transparently and should not retain unsuccessful-candidate information indefinitely without a justified purpose.

Manage employee data with confidence. Give your HR team the compliance knowledge they need to handle recruitment records, sensitive employee information and data protection requests correctly — explore our Data Protection & GDPR Compliance training

Article by:

Professional portrait of a sector compliance writer specialising in healthcare, education, finance and legal services

Dr Amelia Hartwell

Dr Amelia Hartwell is a sector compliance writer specialising in data protection across healthcare, education, finance and legal services. She translates sector-specific requirements into clear, practical guidance for professionals and organisations.

Start Building Your Data Protection Skills Today

Explore flexible online courses designed to help you learn, apply, and strengthen data protection knowledge at your own pace.

Browse Courses