HR holds the most personal data in a company: CVs, salaries, sick leave, performance reviews. It is also where most of the mistakes happen, because they look like normal, everyday things.
If you look at where the most personal data sits in a company, the answer is almost always the same: HR. An employee file has a name, an address, an ID number, a bank account, a salary, a contract, reviews, sometimes sick leave and family details. All in one place, about a person the company also pays.
That is exactly why HR is also where GDPR gets broken most often, with no bad intent. A CV left on a desk, a salary sheet sent to the wrong person, a camera put up "just to be safe". Things that seem minor until they become a problem.
This is the most common confusion, so it is worth stating clearly: in HR, employee consent is usually not valid.
The reason is simple. Consent has to be free, given without pressure. But between a company and an employee the power is not equal, and a "yes" given out of fear of upsetting the boss is not a free "yes". That is why the law says that for employees you rely, in most cases, on something else:
Consent is only valid in a few situations where the employee genuinely has a choice and loses nothing by refusing, for example a photo on the company website.
Recruitment brings a wave of data about people who do not (yet) work for you. Here too there are a few common-sense rules that GDPR puts in black and white.
Cameras, email monitoring, GPS on cars, software that watches what an employee does on the computer. All are possible, but none of them "just to be safe". GDPR requires monitoring to pass three simple tests.
We wrote separately about a heavier form of monitoring, in the article on facial recognition at work. And about the role of people in security, in the human factor.
At INFOSHARE we help HR departments put all of this in place: correct legal bases, retention rules, notices and monitoring policies that actually hold. See our GDPR services, the outsourced DPO role, and for record-keeping, the askGDPR platform.
Usually not, and this is where many companies get it wrong. The relationship between employer and employee is not equal, so consent given out of fear of losing your job is not considered freely given, and therefore not valid. For most HR data the correct basis is the employment contract, a legal obligation (payroll, taxes, health and safety) or the legitimate interest of the company, not consent.
Only as long as it makes sense for that recruitment. Once the role is filled, the CVs of candidates who were not chosen should be deleted, unless you have a clear reason to keep them, for example for another role. If you want to keep a CV for the future, you need the candidate's consent, which here is genuinely valid, because the person does not work for you yet.
Only within clear limits. Monitoring must have a real purpose (for example security), be as little intrusive as possible, and employees must be told in advance, in writing, what is monitored and why. Secret monitoring or reading personal messages is not allowed. Before starting heavier monitoring, you usually need a risk assessment.
Yes, but in moderation. You can place cameras in areas where there is a real reason (entrance, cash desk, warehouse), with signs announcing the surveillance. You may not place cameras where people expect privacy, such as changing rooms or break areas, and you cannot use the footage to track in detail how each employee spends their time.
We put in place the legal bases, retention rules, notices and monitoring policies, tailored to how your company works.