GuideLevel: IntermediateData ProtectionUK GDPRDigital HR FilesUK Employment LawICO Compliance

UK GDPR in HR – Digital Personnel Files, Retention Policies, and Subject Access Requests

What belongs in the file, who is permitted to view it, and when it must be erased

8 min read · Updated on

In Human Resources, more personal data is generated than in virtually any other area of an organisation — and a significant portion of it constitutes special category or highly sensitive data. Under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 (DPA 2018), compliant data handling is guided by three core questions: For what purpose? Who has access? For how long?

The Lawful Basis for Processing

"Necessity" is the decisive benchmark under guidance from the Information Commissioner's Office (ICO). It requires a strict proportionality test: Is there a less intrusive, equally effective means available? Is the data processing proportionate to the legitimate operational objective?

In practice, the following lawful bases apply to employment data:

  • Performance of a contract under Art. 6(1)(b) UK GDPR — managing core employment terms, day-to-day duties, and agreed remuneration,
  • Legal obligation under Art. 6(1)(c) UK GDPR — compliance with statutory duties, including the Working Time Regulations 1998, National Minimum Wage Act 1998, Statutory Sick Pay (SSP), PAYE tax reporting, and HMRC submissions,
  • Legitimate interests under Art. 6(1)(f) UK GDPR — managing business operations, IT security, and workforce productivity, provided these interests are balanced against employee rights through a Legitimate Interests Assessment (LIA),
  • Employment and social protection law under Art. 9(2)(b) UK GDPR in conjunction with Schedule 1, Part 1 of the Data Protection Act 2018 — providing the mandatory legal condition for processing special category data (such as health information or fit notes),
  • Consent — highly vulnerable to challenge in an employment context due to the clear hierarchy and dependency, and subject to unconditional revocation at any time.

What Belongs in the Personnel File

Belongs in the FileDoes Not Belong in the File
Employment contract, Section 1 statement, and variationsDiagnostic data and detailed medical histories
Application forms and CV of the successful candidateUnsubstantiated personal allegations or rumours
References, professional certifications, and right-to-work checksPolitical opinions or religious beliefs (unless a genuine occupational requirement applies)
Performance appraisals, formal reviews, and training recordsDetails of sexual orientation
Remuneration records, PAYE details, and pension enrolmentPrivate domestic circumstances with no work-related bearing
Disciplinary and grievance records (where formal process concluded)Subjective, informal notes made outside formal HR processes
Absence logs, holiday tracking, and statutory fit notesTrade union membership records (unless required for payroll deduction with explicit agreement)

A standard Statement of Fitness for Work (fit note) or self-certification form confirms only the employee's fitness to work, any temporary workplace adjustments recommended by a GP, and the expected duration of illness. Detailed clinical diagnoses and underlying medical reports must be kept strictly confidential and separated from general personnel files.

Access Control Concept (Role-Based Access)

Under the ICO Employment Practices Code, organisations must implement strict technical and organisational measures to ensure confidentiality and integrity. A compliant role-based access control (RBAC) model distinguishes at least four authorization tiers:

RoleAccess Level
EmployeesFull self-service access to their own records, time logs, and leave entitlements
Line Managers / SupervisorsLimited strictly to their direct team and the operational data necessary for supervision (e.g. timesheets, holiday approvals) — not the complete personnel file
HR DepartmentFunctional access based on defined administrative responsibilities, segregated by specialty where appropriate
System AdministratorsTechnical maintenance access only, with comprehensive audit logging enabled for any file access or configuration changes

The division of access between line managers and HR is critical in day-to-day operations: A line manager requires access to absence calendars and overtime balances to organise shift cover, but should never have access to historical salary negotiations from prior roles, sensitive health reports, or spent disciplinary warnings from a previous department.

Data Retention and Deletion Periods

Under the UK GDPR storage limitation principle (Art. 5(1)(e)), personal data must not be kept for longer than necessary for the purposes for which it is processed. Once statutory retention obligations and limitation periods expire, data must be securely erased or anonymised.

Data CategoryBenchmark Retention PeriodStatutory / Legal Benchmark
Application records of unsuccessful candidates6 months following conclusion of recruitmentLimitation period for bringing discrimination claims under the Equality Act 2010 (typically 3 months plus ACAS Early Conciliation window)
Working time records and timesheetsAt least 2 years (standard best practice: 6 years)Regulation 9 of the Working Time Regulations 1998; 6-year limitation period for breach of contract claims
National Minimum Wage (NMW) & payroll records6 years following the end of the pay reference periodNational Minimum Wage Act 1998 and HMRC compliance regulations
PAYE, tax, and Statutory Sick Pay (SSP) recordsAt least 3 years following the end of the relevant tax yearHMRC statutory record-keeping requirements; Social Security Contributions and Benefits Act 1992
General personnel files, contracts, and references6 years following the termination of employmentLimitation Act 1980 (standard limitation period for breach of contract claims)
Workplace injury and accident recordsAt least 3 years from the date of the incident (longer for minors)Reporting of Injuries, Diseases and Dangerous Occurrences Regulations 2013 (RIDDOR)
System access and security audit logs6–12 months on a rolling scheduleICO IT security and auditing standards

Where statutory retention obligations apply, the right to erasure under Art. 17 UK GDPR is precluded pursuant to Art. 17(3)(b). In such circumstances, the employer must apply restriction of processing, ensuring the data is archived and shielded from routine operational access.

Right of Access (Subject Access Requests – SARs)

Under Article 15 of the UK GDPR, employees and former workers are entitled to request access to their personal data, including the purposes of processing, the categories of data held, third-party recipients, anticipated retention schedules, and the commercial or administrative source of the data.

Subject Access Requests must be fulfilled without undue delay and at the latest within one calendar month of receipt. This statutory deadline may be extended by up to two additional months where requests are complex or numerous, provided the employer notifies the employee within the initial month explaining the reasons for the delay.

Additional Statutory Compliance Obligations

Record of Processing Activities (ROPA) under Art. 30 UK GDPR — mandatory documentation detailing all HR data processing activities: processing purposes, data subject categories, recipient categories, retention timeframes, and technical and organisational security measures (TOMs).

Data Protection Impact Assessment (DPIA) under Art. 35 UK GDPR — mandatory before deploying technologies likely to result in a high risk to individuals' rights and freedoms, such as biometric clock-in terminals, automated performance profiling, or continuous keystroke/screen tracking.

Data Processing Agreements (DPA) under Art. 28 UK GDPR — mandatory binding contracts with all external software vendors, cloud SaaS providers, and payroll bureaus processing workforce data on the employer's behalf.

Personal Data Breach Notification under Art. 33 UK GDPR — mandatory notification to the Information Commissioner's Office (ICO) within 72 hours of becoming aware of a breach, unless the incident is unlikely to result in a risk to individuals' rights and freedoms.

Trade Union Consultation and Employee Involvement

Deploying technical systems capable of monitoring employee attendance, working time, or performance requires careful handling under UK employment law and industrial relations frameworks:

  • Information and Consultation of Employees (ICE) Regulations 2004: In organisations where ICE arrangements or European Works Councils are established, employers must inform and consult employee representatives regarding structural changes or the introduction of substantial monitoring systems.
  • Trade Union Recognition Agreements: Where a trade union is recognised for collective bargaining, terms regarding electronic monitoring, surveillance, and working time recording are frequently governed by collective agreements or require consultation with workplace union representatives.
  • ICO Guidance on Monitoring at Work: The ICO explicitly requires employers to conduct a DPIA and consult workers before introducing workplace monitoring tools, ensuring monitoring is proportionate, transparent, and non-intrusive.

Statutes and Statutory Instruments

Regulatory Guidance and Precedent

Status of analysis: August 2026. This article provides general legal information and does not constitute formal legal advice.

Frequently asked questions

Primarily under Article 6(1)(b) of the UK GDPR (performance of an employment contract) and Article 6(1)(c) (statutory legal obligations), supplemented by Schedule 1, Part 1, paragraph 1 of the Data Protection Act 2018, which supplies the employment condition required for special category data.
While technically possible, consent is rarely appropriate in employment relationships due to the clear imbalance of power. Because consent must be freely given and can be withdrawn at any time without detriment, employers should instead rely on contractual necessity, statutory obligations, or legitimate interests.
Under Article 15 UK GDPR, employees have the right to obtain confirmation of whether their data is being processed, access to that personal data, the purposes of processing, categories of recipients, retention periods, and information regarding the data's source — usually supplied as a free copy within one calendar month.
Only individuals who strictly require access to perform their specific management or administrative functions (the principle of data minimisation and role-based access). Line managers generally only require operational data such as working time records and leave balances, not unrestricted access to the entire personnel file.
Author
PlainStaff Editorial Team
HR Editorial Team
Updated on