Human Resources
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.Processing of employee and HR data
Overview
20 sources · Sep 8, 2026Legal Framework
HR data processing falls under the GDPR, with employers required to identify a valid legal basis under Article 6 for each processing operation, comply with data minimisation and purpose limitation under Article 5(1)(b) and (c), and honour access requests under Article 15. The EDPB has mapped the scope of employee data processing across the employment lifecycle — from recruitment through performance monitoring to disciplinary procedures — while noting that teleworking operations may fall outside existing certification frameworks.
The Croatian DPA's enforcement illustrates how minimisation principles apply in practice:
Key Developments
Dutch courts have addressed the limits of restoration sanctions where employee data was processed without a legal basis. In a case before the Rechtbank, an employer sent a mass email to current and former employees without a valid processing ground. The court declined to impose a restoration sanction because the one-time violation could not be undone and recurrence was unlikely:
"De e-mail van 8 juni 2021 is eenmalig verzonden zonder geldige verwerkingsgrondslag en dat kan niet worden teruggedraaid."
— Rechtbank
The Raad van State addressed a personnel-file access dispute where a former employee's records were lost during a system migration. The municipality had moved active employees' files to a new digital system but never migrated those of former staff, who were retained in a legacy system subject to eventual deletion:
"De dossiers van voormalig medewerkers, zoals dat van [appellante], zijn nooit overgebracht naar het nieuwe systeem."
— Raad van State
The EDPB's opinion on Greek certification criteria confirms the breadth of HR processing operations:
"processing operations regarding employee data in relation to certain topics (recruitment procedures, monitoring of employment status, payroll, trainings, disciplinary procedures"
— EDPB Opinion 34/2025
Status of the Debate
This topic is contested in court. Courts diverge on the boundaries of employer processing — particularly regarding the proportionality of employee data collection, retention periods for former employees' records, and the scope of access obligations over legacy HR systems. The Rechtbank's decision that a one-time violation without risk of recurrence does not warrant restoration sanctions sits in tension with stricter enforcement approaches that treat any unauthorized processing as requiring corrective action. No formal court split is on record yet. The open questions that would resolve the ambiguity concern: whether system migrations causing data loss breach Article 15 access obligations, and how far minimisation constrains routine collection of employee identity documents. A CJEU preliminary reference on retention of ex-employee data would settle the matter.
Practical Guidance
- Legal basis mapping: Document a specific Article 6 GDPR basis for each HR processing operation. Do not rely on a blanket legitimate-interest assessment for unrelated activities such as disciplinary monitoring or identity-document collection.
- Minimisation audits: The Croatian DPA's finding against collecting copies of ID cards and criminal-records certificates signals that employers cannot request such documents by default. Limit collection to what is strictly necessary for each purpose.
- System migration planning: When migrating HR systems, ensure that former employees' data is either transferred to the new platform or retained in the legacy system with documented retention periods. The Raad van State case shows that undocumented deletions during migration can defeat access obligations.
- Retention policies for ex-employees: Establish clear retention schedules. The Dutch court accepted a one-year post-employment retention period as reasonable, but exceeding that without documented justification invites enforcement risk.
- DPO compliance integration: The Croatian enforcement decision penalized the controller for disregarding its DPO's opinion on excessive data collection. Ensure that DPO recommendations on HR processing are documented and acted upon.
why this is here
to publish the names and incomes of employees to a third party is an interference with the right to respect for private life
The document involves processing of employee salary data in the public employment context, bearing on HR data protection, though it is not primarily about general HR practices.
assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026
Nothing of this type on this topic.
This is the top of each pile — all 98 Guidance · all 49 Case Law · all 179 Enforcement · all 29 Literature · all 149 News