Data Privacy in the HR Department: Duty and Practice

Data Privacy in the HR Department: Duty and Practice

By Matthias Mut in Compliance August 20, 2026

Photo of Matthias Mut

CEO & Datenstrategie - Matthias Mut

Datenschutz

HR

Personalakte

DSGVO

Why the HR Department Is the Most Sensitive Place for Data

No other department processes sensitive data as consistently as HR: application documents, salaries, sick notes, references, warnings, in some cases even health data or information on religious affiliation – information that the GDPR rightly places under special protection. Legally, all of this falls within employee data protection, which in Germany is specified above all by Section 26 of the Federal Data Protection Act (BDSG) [1], flanked by Article 88 of the GDPR [2].

What makes this area special: processing begins before the first working day and does not end with the last. Applicant data is subject to short deletion periods, personnel files sometimes to retention obligations lasting decades, and in between lie countless everyday processes – from the birthday calendar to travel expense reports – that have rarely ever been checked for data protection compliance.

In practice, we see a pattern: it is not the large HR systems that pose the main risk, but the many small paths alongside them. That is exactly where data privacy in the HR department succeeds or fails.

The Five Most Common Data Privacy Gaps in Day-to-Day HR

  1. Excel lists alongside the HR system. Salary overviews, vacation planning, or applicant lists often live as spreadsheets on network drives or in e-mail attachments – without access control, without a deletion concept, without traceability. We described why this is structurally problematic in our article Excel as a database; in the HR context, the particular sensitivity of the content comes on top.
  2. Access rights that are too broad. Historically grown permissions mean that assistants, team leads, or IT can see more than they should. The need-to-know principle is quickly stated and rarely implemented consistently.
  3. Missing deletion routines. Rejected applications from four years ago, personnel files of long-departed employees, old applicant pools: without defined and technically implemented deletion periods, exactly the material accumulates that becomes a problem in an audit or an access request.
  4. Sensitive communication via open channels. Sick notes via team chat, salary data as unencrypted e-mail attachments, application documents sent to "all managers" – each of these paths creates uncontrolled copies.
  5. Unclear responsibilities with service providers. Payroll office, applicant management tool, time tracking: wherever processing on behalf takes place, contracts under Art. 28 GDPR are required – and an overview of which provider processes which data where.

None of these points is exotic; taken together, they describe the normal state of many HR departments. The good news: they can be dismantled systematically – and a large part of it through better processes rather than more paperwork.

How secure are your HR processes? Together with you, we examine where personal data flows uncontrolled today and build processes with data protection built in rather than bolted on – from our data protection & regulatory consulting to concrete solutions for HR & human resources. The fastest way is a direct conversation: book a 30-minute intro call.

Confidential consultation on personnel data

Digital Personnel Files and HR Software: What Matters

For many companies, the digital personnel file is the occasion to put HR data protection in order – and introduced correctly, it is a security gain over paper files and file shares. What matters is less the providers' marketing promises than four sober requirements:

| Requirement | How to recognize it | |---|---| | Roles and permissions concept | Access controllable per file section (e.g. health data stricter than master data), access logging | | Deletion and retention concept | Periods configurable per document type, deletion automated and verifiable | | Processing on behalf & hosting | Data processing agreement under Art. 28 GDPR, clear statement on processing location and subcontractors | | Export capability | Complete data export in open formats – data ownership stays with the company |

With cloud solutions, a close look at the processing location and the subcontractor chain pays off; this is not a question of cloud yes/no, but of transparency. And as with any system change: anyone who migrates old data unchecked takes their legacy along – the introduction is the best moment to implement deletion and clean-up concepts properly. We examined how outdated systems themselves become a data protection risk in our article on GDPR and legacy systems.

Automation and AI: Opportunity Instead of Additional Risk

At first glance, automation and data protection seem like opponents – in fact, the opposite is often true. It is manual processes that produce uncontrolled copies, typos, and forgotten deletions. Well-designed automation reduces precisely these risks:

  • Automated deletion enforces periods reliably instead of leaving them to follow-up reminders.
  • Workflows instead of e-mail attachments keep sensitive documents in the system, with permissions and logging – the attachment to the wrong distribution list disappears.
  • Anonymization and pseudonymization make HR data usable for analyses and AI applications without revealing personal references – for us the key to HR benefiting from data analytics without risking trust.
  • Automated compliance checks verify recurringly whether permissions, periods, and processes still match the target state – our article on automated compliance checks shows how this works in principle.

Anyone planning AI applications in HR – from applicant screening to HR chatbots – should additionally keep the requirements of the EU AI Act in view: employment-related AI systems are in many cases classified there as high-risk applications with corresponding obligations [3]. That does not speak against using them, but for clean preparation.

The Practical Roadmap for the HR Department

From our project experience, a pragmatic four-step approach has proven itself:

  1. Inventory: Record all HR data flows – systems, spreadsheets, e-mail paths, service providers. The record of processing activities turns from a mandatory document into a useful tool.
  2. Prioritize risks: First close the paths on which particularly sensitive data flows uncontrolled – in our experience, these are the everyday spreadsheet and e-mail processes.
  3. Processes instead of appeals: Any rule that people must actively remember in everyday work will eventually be forgotten. Rules embedded in the process – permissions, workflows, automatic deadlines – work permanently.
  4. Check regularly: Permissions, deletion runs, and the provider list belong on a fixed review rhythm, ideally monitored automatically.

Conclusion

Data privacy in the HR department is not a project you complete once, but a property of good HR processes. The biggest risks rarely lie in the HR system itself, but in the grown side paths – spreadsheets, e-mail attachments, forgotten legacy data. Anyone who replaces these paths with clean processes, a well-thought-out permissions and deletion concept, and targeted automation wins twice: less risk in audits and access requests – and an HR department that can finally use its data productively and with a clear conscience.

References

  1. (Section 26 BDSG – Data processing for employment purposes)
  2. (Art. 88 GDPR – Processing in the context of employment)
  3. (EU AI Act – Regulation (EU) 2024/1689, Annex III (high-risk systems, incl. employment))

Share

Newsletter

Stay updated with the latest news, insights, and updates. Join our newsletter and never miss a thing.

By subscribing, you agree that we use your email address to send you our newsletter. You can unsubscribe at any time.

Let's talk

Stay in touch with us

Whether you have a specific project or just want to explore options — we look forward to hearing from you.