HR holds more personal data than any other function in most organizations.
Payroll data. Tax identification numbers. Bank account details. Health and medical leave records. Biometric attendance data. Background check results. Performance assessments. Disciplinary records. Psychological assessment scores. Salary history. Family dependent information. Emergency contact details. In some organizations, even location data from GPS-based attendance systems.
Employee data belongs legally to the employee who generated it. HR is its custodian, not its owner, and custody carries obligations that ownership would not. That distinction is at the heart of a compliance challenge that most HR functions are not yet prepared for.
Employee data does not sit in one place. It is created in recruiting, becomes the input to onboarding, then to payroll, then to performance and finally to exit, over one record that keeps travelling. Privacy obligations do not attach to systems. They attach at the handoffs, which is precisely where nobody owns them.
Data protection frameworks are now in place in 179 of 240 jurisdictions worldwide, covering over 6.6 billion people, roughly 80% of the world’s population, according to the IAPP’s Global Privacy Law and DPA Directory. AI adoption is what keeps enlarging the surface area: in the Cisco 2026 Data and Privacy Benchmark Study, which surveyed more than 5,200 practitioners across 12 markets, 90% of organizations reported their privacy programs expanded because of AI, and 93% plan to spend more. And the cost of getting it wrong stopped falling. IBM’s 2026 Cost of a Data Breach Report put the global average at a record $4.99 million, up 12% in a year, with one in four malicious breaches now AI-enabled and averaging closer to $6 million. None of those figures include the employee trust damage no insurer will cover.
What modern data protection laws mean for HR-held employee data
The global privacy landscape has fragmented into dozens of overlapping frameworks, but they share a consistent set of obligations that apply directly to HR operations regardless of jurisdiction.
- Lawful basis for processing. Every piece of employee data HR collects must have a documented lawful basis for processing. Payroll data is typically justified by contractual necessity. Performance management data may rely on legitimate interests. Health data is special category data and needs a second condition on top of the lawful basis. In employment, that condition is usually an obligation under employment or social security law, not consent. The critical gap in most HR functions is not that they lack lawful bases but that they have never documented them. When a regulator asks why HR processes a specific data category, “because we always have” is not a lawful basis.
- Data minimization. Modern privacy frameworks require that organizations collect only the data they actually need for a defined purpose. HR systems that capture extensive employee information because the system allows it, rather than because the business needs it, are accumulating liability with every additional field. A performance management system that collects personality assessment results used once at onboarding and then stored indefinitely is holding data beyond its purpose window.
- Retention limits. Employee data cannot be held indefinitely. Payroll records typically have statutory minimum retention periods. Performance data, disciplinary records, and health information have defined windows after which deletion is legally required. Most HR systems hold data in perpetuity by default because deletion requires deliberate action that nobody has been assigned to take.
- Data subject rights. Employees have the right to access their own data, correct inaccuracies, and, in some jurisdictions, request deletion of data that is no longer necessary. HR functions that cannot respond to a data subject access request within the statutory timeframe, one month under GDPR, extendable by two further months where the request is complex, are already in breach before any breach event occurs.
- Cross-border data transfers. For organizations managing employees across multiple countries, transferring employee data across jurisdictions requires specific legal mechanisms. Payroll data flowing from a Southeast Asia subsidiary to an Indian head office for consolidated reporting runs into three different regimes at once: standard contractual clauses or an adequacy decision under GDPR, the significant data fiduciary and transfer provisions of India’s DPDP Act 2023 and its Rules, and the consent and cross-border rules under Singapore’s PDPA or the UAE PDPL depending on the entity.
Consent, biometric data, and background-check implications
Three categories of HR-held data create disproportionate legal exposure. Each requires a different approach.
Employee consent and its limits
Many HR functions rely on employee consent as the default lawful basis for data processing because it feels intuitive. Employees signed something at onboarding. That should cover it.
It does not, for two structural reasons.
First, consent in an employment relationship is legally problematic because it is not freely given. When an employee must provide data to keep their job, the voluntary element that consent requires under most frameworks is absent. The Article 29 Working Party, in its Opinion 2/2017 on data processing at work, later endorsed by the European Data Protection Board, found that employer-employee power dynamics undermine the validity of employment-based consent for routine HR processing.
Second, consent must be specific, informed, and withdrawable. A blanket consent clause in an employment contract covering all data HR might ever collect does not meet this standard. An employee who later withdraws consent creates an obligation to stop processing that the HR function cannot easily meet if consent was the only legal basis for the processing in the first place.
The practical implication: consent should be used for optional HR processing, such as participation in a wellness program or inclusion in a talent mobility database. For core HR operations, organizations should document legitimate interests or contractual necessity as the lawful basis and build their privacy notices around those bases instead.
Biometric data: the highest-risk category
Biometric data, including fingerprints, facial recognition images, iris scans, and voice prints, is special category data under GDPR when it is processed to uniquely identify a person, which is exactly what an attendance terminal does, sensitive personal information under the Philippines’ Data Privacy Act, and specifically regulated under biometric-specific laws such as Illinois BIPA in the United States. India’s DPDP Act takes a different route: it creates no sensitive-data category at all, so biometric data carries the same obligations as every other personal data category. That is a lighter classification and a heavier practical burden, because nothing in the statute tells you to treat a fingerprint differently from a phone number.
Illinois BIPA remains the strictest US biometric statute and is the one that carries a private right of action, which is why it generates the litigation it does. In India, the framework reaches biometric attendance through general obligations rather than a special category: standalone consent notices stating the specific purpose, the security safeguards in the DPDP Rules, and erasure once the purpose is served. The Rules were notified in November 2025 on a phased timeline, so most Indian employers are inside the transition window rather than past it.
The legal obligations for biometric data are materially stricter than for ordinary personal data. Collection typically requires explicit, separate consent. Retention is often capped at defined periods. Security requirements are elevated. And the consequences of a breach are significantly higher, because biometric data cannot be changed the way a password or account number can. An employee whose fingerprint data is compromised faces a lifetime of elevated identity risk.
For organizations using biometric attendance systems across multiple countries, the patchwork of biometric-specific regulations creates a compliance matrix that most HR functions have not mapped. Before deploying any biometric HR technology, employers must seek consent from employees before collecting and processing biometric information, disclose how the data will be processed, stored, and removed, and implement role-based access and data minimization policies as safeguards.
Background check data: purpose limitation and retention
Background check data presents a specific purpose limitation challenge. The data collected to make a hiring decision, including criminal record checks, credit history, and professional reference assessments, serves a defined and time-limited purpose. Once the hiring decision is made, that purpose is fulfilled.
Retaining background check data in an employee HR file indefinitely, which is standard practice in many organizations, violates the purpose limitation and data minimization principles enforced under GDPR Article 5, India’s DPDP Act 2023, and Singapore’s PDPA. For employees who have been with an organization for five or ten years, the original background check data is almost certainly being held beyond any reasonable retention window.
The additional complexity is that background check data often flows through a third-party provider, which creates a separate data processing relationship that requires its own legal documentation.
This is the handoff problem in its clearest form. The data was collected by recruiting for one decision, then travelled into an employee file that exists for a different purpose under a different lawful basis, and no one signed off on the journey.
Also read: Best practices for biometric attendance systems
Vendor and HR-tech accountability: data processors vs data controllers
This is the legal distinction that most CHROs and HR Ops leaders do not understand until they are in the middle of a vendor-related breach response.
- The controller: The organization that determines the purposes and means of data processing. In employment, the employer is the data controller for employee personal data. The CHRO’s function owns this obligation.
- The processor: A third party that processes personal data on behalf of the controller, under the controller’s instructions. HRMS vendors, payroll processors, recruitment platforms, background check providers, and learning management systems are all data processors when they handle employee data on the organization’s behalf.
Why this distinction matters operationally:
When an HRMS vendor experiences a security incident and employee data is exposed, the legal liability under GDPR, India’s DPDP Act 2023 (which uses the term “data fiduciary”), and Singapore’s PDPA sits with the data controller, which is the employer, not just with the vendor. The organization must notify the relevant regulatory authority within the statutory timeframe, becomes “72 hours under GDPR Article 33. The organization must notify affected employees. The organization faces regulatory scrutiny and potential fines.
The vendor may face their own consequences. But the organization cannot outsource its data protection obligations simply by using a third-party platform.
The practical implication is that every HR technology vendor relationship must be governed by a Data Processing Agreement that specifies what data the vendor processes, the legal basis for that processing, the security measures the vendor maintains, the sub-processors the vendor uses, the vendor’s breach notification obligations to the controller, and the data deletion process when the contract ends.
Most HR technology contracts include some version of a data processing addendum. What they rarely include is a complete sub-processor list, a tested breach notification timeline, or a contractual obligation to notify the controller within 24 hours of a breach event. The gap shows up in the benchmark data: 81% of organizations say their vendors give them sufficient transparency, but only 55% have contractual terms defining data ownership and liability. CHROs should request all three before signing any HR tech contract.
Read more: Top features of an employee management system
Building an HR data governance framework
A governance framework for HR data is not a single policy or a one-time audit. It is a system of interlocking decisions, processes, and accountabilities that runs continuously. Here is a five-layer structure that CHROs can use to build or assess their current state.
Ownership splits four ways, and the splits are where it fails. The CHRO owns the fact that the framework exists and gets reviewed. HR Ops owns the inventory, the retention schedule, and the DSAR process as standing operational work. Legal or the DPO owns the lawful basis determinations and the vendor DPAs. IT security owns the access controls and the audit trail in the HRMS. Line managers own almost nothing here and should be told so explicitly, because the most common access-creep failure is a manager given a permission set nobody ever revoked.
Five layers, in build order: inventory what you hold, tell employees what you hold it for, decide when it gets deleted, control who can see it, and govern the vendors and AI systems that touch it. Most HR functions have partial versions of layers 4 and 5 and nothing at all of layer 1, which is why the other four cannot be verified.
Layer 1: Catalogue what you hold
HR cannot govern what it has not catalogued. The foundation of any HR data governance framework is a complete inventory of every category of employee data the function holds, which systems it is held in, who has access to it, what the lawful basis for processing it is, how long it is retained, where it flows, including to vendors and across borders, and who is responsible for its accuracy.
Owner: HR Ops, reviewed by legal.
Exit test: you are done when a named person can produce the inventory in a day without asking IT for a schema dump.
Failure mode: the inventory is built once for an audit, then never updated, so the first new system added makes it wrong.
Layer 2: Tell employees what you collect, at the point you collect it
Every point at which HR collects employee data should have a corresponding privacy notice that is specific to that collection point, written in plain language, and accessible to the employee at the time of collection. Employee handbooks with a general “we collect your data” paragraph do not meet this standard.
Owner: HR Ops drafts, legal approves, the HRMS admin places the notice at the collection screen.
Exit test: you are done when every collection point in the HRMS shows its own notice, and you can name the ones that do not.
Failure mode: notices live in the handbook rather than at the form, so the employee sees them once, on day one, in a stack of twelve documents.
Layer 3: Set the deletion clock and let it run
For each data category in the inventory, define the minimum and maximum retention period, the trigger event that starts the retention clock, such as employment start, employment end, or last performance review, and the deletion or anonymization process when the retention period expires.
Owner: HR Ops defines, legal signs, the system executes.
Exit test: you are done when deletion runs on a schedule and somebody reviews its log, not when the policy is written.
Failure mode: retention rules exist on paper while the system retains everything, so the policy becomes evidence against you rather than for you.
Layer 4: Restrict access to actual need, and log it
Employee personal data should be accessible only to the people who need it for a defined HR purpose. A payroll administrator does not need access to disciplinary records. A line manager does not need access to health data held by the occupational health function. A recruiter does not need access to the performance data of existing employees.
Owner: IT security configures, HR Ops certifies the roles quarterly.
Exit test: you are done when an access review runs on a cycle and somebody is accountable for revoking what it finds.
Failure mode: access is granted on promotion and never removed on transfer, so a five-year HRBP accumulates the permissions of every role they have held.
Layer 5: Govern the vendors and the AI
For every HR technology vendor, maintain a current Data Processing Agreement, a sub-processor list, and a record of the security certifications the vendor holds. Review these annually or when a vendor relationship changes materially.
Owner: procurement plus legal for DPAs, CHRO for the AI decision review.
Exit test: you are done when a named person can produce every vendor DPA and sub-processor list on request, and every AI-assisted decision has a documented human reviewer.
Failure mode: the committee exists and the governance does not. 75% of organizations have set up AI governance committees, and only 12% describe them as mature.
Watch it at an archetype 1,400-person services firm with entities in India, Singapore, and the UAE. A DSAR arrives from an employee in Singapore who is midway through a grievance. HR Ops pulls the HRMS record in an hour. Then the gaps open: the recruiting platform still holds the original background check from 2019, the biometric terminal vendor holds eleven months of raw scans nobody knew were retained, and a former manager’s exported spreadsheet of performance notes sits in a shared drive with no owner. The statutory clock is one month. Three of those four sources were not in any inventory, because there was no inventory. The organization was not careless. It simply never catalogued what it held, and layer 1 is the layer that makes the other four provable.
Explore: Core HR functions and employee management best practices
The consequences HR teams rarely see coming
Non-compliance with HR data privacy obligations has three consequence categories that most HR leaders underestimate.
- Regulatory consequences are the visible ones: GDPR fines have reached hundreds of millions of euros for large organizations. Asian privacy regulators are increasingly active. But the regulatory consequence that most affects mid-market organizations is not a maximum fine. It is the operational cost of a regulatory investigation: the internal time consumed, the external legal fees, the remediation requirements, and the reputational exposure of appearing on a public enforcement register.
- Employee trust erosion is the invisible one: When employees discover that their personal data was mishandled, whether through a breach, an unauthorized disclosure, or a data subject access request that reveals unexpected data holdings, the damage to trust is not captured in any regulatory fine. It shows up in engagement scores, attrition rates, and employer brand metrics. In industries where talent is scarce, a reputation for poor employee data stewardship is a recruitment liability.
- M&A due diligence risk is the one nobody plans for: For organizations considering acquisition or investment, an acquiring party’s due diligence process now routinely includes HR data privacy assessments. An HR function with no documented data inventory, no retention schedules, and no vendor DPAs faces a material valuation risk that most CHROs only discover at the worst possible moment.
What this looks like from the employee’s side
A data subject access request rarely comes from a privacy hobbyist. It usually arrives because something else is already going wrong, a grievance, a dispute over a performance rating, an exit that feels unfair, and the DSAR is the mechanism available to find out what the company actually holds and why.
Consent, from that side of the table, often means a biometric enrollment form handed over on day one, in the same stack as the offer letter and the laptop. It does not feel like a choice, because it is not meaningfully one. Trust is measured by whether the answer to a request arrives on time and matches what was actually collected, not by how well the underlying policy is drafted.
What good HR data privacy governance looks like
Five observable markers of a mature HR data privacy function:
- The CHRO can answer “what employee data do we hold and why?” without a three-week data collection exercise.
- Every HR technology vendor has a current, signed Data Processing Agreement that includes a sub-processor list and a 24-hour breach notification obligation.
- Biometric data collection has explicit, separate consent documented per employee, with a defined retention period and a deletion process.
- Every AI-driven HR decision process has a documented human review step and an explanation mechanism that an employee could understand if they requested it.
- Data subject access requests from employees are handled within the statutory timeframe as a standard operational process, not a crisis response.
Closing the gap
Most HR functions are behind on this. The gap is not from lack of intent. It is from a compliance environment that moved faster than the HR function’s governance infrastructure was designed to handle.
The organizations that close this gap earliest end up with something better than an absence of fines. They end up with employees who believe the company handles their data properly, which is increasingly how people choose employers.
FAQs
Can employers use employee consent as the lawful basis for all HR data processing?
No. Consent is legally problematic in employment relationships because of the power imbalance between employer and employee. Regulators in the EU and India have found that employment-based consent is not freely given. Core HR processing should rely on contractual necessity or legitimate interests, with consent reserved for optional programs only.
What is a data processing agreement, and why does every HR tech vendor need one?
A DPA is a contract that defines how a vendor processes employee data on the organization’s behalf. It covers security measures, sub-processors, breach notification timelines, and data deletion at contract end. Without one, the organization cannot demonstrate that its vendor relationships meet modern privacy law requirements.
Does India’s DPDP Act change what HR must do with employee data?
Yes. The DPDP Act 2023 requires a documented lawful basis for processing, defines cross-border transfer conditions, and imposes heightened obligations, including audits and a data protection officer, on organizations designated as Significant Data Fiduciaries.