In Human Resources, more personal data is generated than in virtually any other area of an organisation — and a significant portion of it constitutes special category or highly sensitive data. Under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 (DPA 2018), compliant data handling is guided by three core questions: For what purpose? Who has access? For how long?
The Lawful Basis for Processing
"Necessity" is the decisive benchmark under guidance from the Information Commissioner's Office (ICO). It requires a strict proportionality test: Is there a less intrusive, equally effective means available? Is the data processing proportionate to the legitimate operational objective?
In practice, the following lawful bases apply to employment data:
- Performance of a contract under Art. 6(1)(b) UK GDPR — managing core employment terms, day-to-day duties, and agreed remuneration,
- Legal obligation under Art. 6(1)(c) UK GDPR — compliance with statutory duties, including the Working Time Regulations 1998, National Minimum Wage Act 1998, Statutory Sick Pay (SSP), PAYE tax reporting, and HMRC submissions,
- Legitimate interests under Art. 6(1)(f) UK GDPR — managing business operations, IT security, and workforce productivity, provided these interests are balanced against employee rights through a Legitimate Interests Assessment (LIA),
- Employment and social protection law under Art. 9(2)(b) UK GDPR in conjunction with Schedule 1, Part 1 of the Data Protection Act 2018 — providing the mandatory legal condition for processing special category data (such as health information or fit notes),
- Consent — highly vulnerable to challenge in an employment context due to the clear hierarchy and dependency, and subject to unconditional revocation at any time.
What Belongs in the Personnel File
| Belongs in the File | Does Not Belong in the File |
|---|---|
| Employment contract, Section 1 statement, and variations | Diagnostic data and detailed medical histories |
| Application forms and CV of the successful candidate | Unsubstantiated personal allegations or rumours |
| References, professional certifications, and right-to-work checks | Political opinions or religious beliefs (unless a genuine occupational requirement applies) |
| Performance appraisals, formal reviews, and training records | Details of sexual orientation |
| Remuneration records, PAYE details, and pension enrolment | Private domestic circumstances with no work-related bearing |
| Disciplinary and grievance records (where formal process concluded) | Subjective, informal notes made outside formal HR processes |
| Absence logs, holiday tracking, and statutory fit notes | Trade union membership records (unless required for payroll deduction with explicit agreement) |
A standard Statement of Fitness for Work (fit note) or self-certification form confirms only the employee's fitness to work, any temporary workplace adjustments recommended by a GP, and the expected duration of illness. Detailed clinical diagnoses and underlying medical reports must be kept strictly confidential and separated from general personnel files.
Access Control Concept (Role-Based Access)
Under the ICO Employment Practices Code, organisations must implement strict technical and organisational measures to ensure confidentiality and integrity. A compliant role-based access control (RBAC) model distinguishes at least four authorization tiers:
| Role | Access Level |
|---|---|
| Employees | Full self-service access to their own records, time logs, and leave entitlements |
| Line Managers / Supervisors | Limited strictly to their direct team and the operational data necessary for supervision (e.g. timesheets, holiday approvals) — not the complete personnel file |
| HR Department | Functional access based on defined administrative responsibilities, segregated by specialty where appropriate |
| System Administrators | Technical maintenance access only, with comprehensive audit logging enabled for any file access or configuration changes |
The division of access between line managers and HR is critical in day-to-day operations: A line manager requires access to absence calendars and overtime balances to organise shift cover, but should never have access to historical salary negotiations from prior roles, sensitive health reports, or spent disciplinary warnings from a previous department.
Data Retention and Deletion Periods
Under the UK GDPR storage limitation principle (Art. 5(1)(e)), personal data must not be kept for longer than necessary for the purposes for which it is processed. Once statutory retention obligations and limitation periods expire, data must be securely erased or anonymised.
| Data Category | Benchmark Retention Period | Statutory / Legal Benchmark |
|---|---|---|
| Application records of unsuccessful candidates | 6 months following conclusion of recruitment | Limitation period for bringing discrimination claims under the Equality Act 2010 (typically 3 months plus ACAS Early Conciliation window) |
| Working time records and timesheets | At least 2 years (standard best practice: 6 years) | Regulation 9 of the Working Time Regulations 1998; 6-year limitation period for breach of contract claims |
| National Minimum Wage (NMW) & payroll records | 6 years following the end of the pay reference period | National Minimum Wage Act 1998 and HMRC compliance regulations |
| PAYE, tax, and Statutory Sick Pay (SSP) records | At least 3 years following the end of the relevant tax year | HMRC statutory record-keeping requirements; Social Security Contributions and Benefits Act 1992 |
| General personnel files, contracts, and references | 6 years following the termination of employment | Limitation Act 1980 (standard limitation period for breach of contract claims) |
| Workplace injury and accident records | At least 3 years from the date of the incident (longer for minors) | Reporting of Injuries, Diseases and Dangerous Occurrences Regulations 2013 (RIDDOR) |
| System access and security audit logs | 6–12 months on a rolling schedule | ICO IT security and auditing standards |
Where statutory retention obligations apply, the right to erasure under Art. 17 UK GDPR is precluded pursuant to Art. 17(3)(b). In such circumstances, the employer must apply restriction of processing, ensuring the data is archived and shielded from routine operational access.
Right of Access (Subject Access Requests – SARs)
Under Article 15 of the UK GDPR, employees and former workers are entitled to request access to their personal data, including the purposes of processing, the categories of data held, third-party recipients, anticipated retention schedules, and the commercial or administrative source of the data.
Subject Access Requests must be fulfilled without undue delay and at the latest within one calendar month of receipt. This statutory deadline may be extended by up to two additional months where requests are complex or numerous, provided the employer notifies the employee within the initial month explaining the reasons for the delay.
Additional Statutory Compliance Obligations
Record of Processing Activities (ROPA) under Art. 30 UK GDPR — mandatory documentation detailing all HR data processing activities: processing purposes, data subject categories, recipient categories, retention timeframes, and technical and organisational security measures (TOMs).
Data Protection Impact Assessment (DPIA) under Art. 35 UK GDPR — mandatory before deploying technologies likely to result in a high risk to individuals' rights and freedoms, such as biometric clock-in terminals, automated performance profiling, or continuous keystroke/screen tracking.
Data Processing Agreements (DPA) under Art. 28 UK GDPR — mandatory binding contracts with all external software vendors, cloud SaaS providers, and payroll bureaus processing workforce data on the employer's behalf.
Personal Data Breach Notification under Art. 33 UK GDPR — mandatory notification to the Information Commissioner's Office (ICO) within 72 hours of becoming aware of a breach, unless the incident is unlikely to result in a risk to individuals' rights and freedoms.
Trade Union Consultation and Employee Involvement
Deploying technical systems capable of monitoring employee attendance, working time, or performance requires careful handling under UK employment law and industrial relations frameworks:
- Information and Consultation of Employees (ICE) Regulations 2004: In organisations where ICE arrangements or European Works Councils are established, employers must inform and consult employee representatives regarding structural changes or the introduction of substantial monitoring systems.
- Trade Union Recognition Agreements: Where a trade union is recognised for collective bargaining, terms regarding electronic monitoring, surveillance, and working time recording are frequently governed by collective agreements or require consultation with workplace union representatives.
- ICO Guidance on Monitoring at Work: The ICO explicitly requires employers to conduct a DPIA and consult workers before introducing workplace monitoring tools, ensuring monitoring is proportionate, transparent, and non-intrusive.
Sources and Legal References
Statutes and Statutory Instruments
- UK GDPR & Data Protection Act 2018 — Core principles, lawful processing bases, special category conditions, and data subject rights
- Employment Rights Act 1996 (ERA 1996) — Section 1 statements of employment particulars, statutory notice, and wage protections
- Working Time Regulations 1998 (SI 1998/1833) — Maximum weekly working hours, rest breaks, daily/weekly rest, and Regulation 9 record-keeping requirements
- National Minimum Wage Act 1998 & Regulations 2015 — Employer obligations regarding minimum wage compliance and 6-year record retention
- Social Security Contributions and Benefits Act 1992 / HMRC Guidance — Statutory Sick Pay (SSP) administration and payroll tax records
- Information and Consultation of Employees Regulations 2004 (SI 2004/3426) — Employee representation and consultation frameworks
Regulatory Guidance and Precedent
- Information Commissioner's Office (ICO) – Employment Practices and Data Protection — Code of practice covering employee records, SARs, and workplace monitoring
- European Court of Justice (ECJ), Judgment in CCOO v Deutsche Bank SAE (C-55/18) — Requirement for employers to establish an objective, reliable, and accessible system for measuring daily working time
Status of analysis: August 2026. This article provides general legal information and does not constitute formal legal advice.
Frequently asked questions
- Author
- PlainStaff Editorial Team
- HR Editorial Team
- Updated on