When most companies map their GDPR obligations, they start with customer data. The CRM, the marketing lists, the website analytics. Employee data barely comes up, even though it's often the most sensitive personal data you hold. Salaries, sick leave, performance reviews, background checks, bank details, and sometimes union membership all sit in your HR systems, and every one of them is regulated.

The reason for the gap is simple. HR data feels internal, so it skips the privacy review that customer data gets. But your staff have the same rights as your customers, and supervisory authorities take employee complaints seriously. This post covers what GDPR asks of you as an employer and how OptiTech captures HR processing with the right legal basis and retention.

Why employee data gets overlooked

Privacy programs tend to grow outward from the data that touches revenue. Sales and marketing get the attention because that's where customers, contracts, and security reviews live. HR runs quietly in the background on tools that were chosen for payroll and recruiting, not for data protection.

That's how you end up with resumes sitting in an inbox for years, spreadsheets of salary data on a shared drive, and a recruiting tool nobody added to the vendor list. None of it is malicious. It's just unowned. And unowned personal data is exactly what turns a routine audit into a finding.

The instinct many employers have is to ask staff to sign a consent form for data processing. It feels tidy. It's also the wrong basis in most cases. Consent has to be freely given, and the power imbalance between an employer and an employee means it rarely is. An employee who feels they can't say no hasn't really consented, and a regulator will see it that way too.

For most employment processing, a stronger basis applies:

  • Contract. You process the data you need to run the employment relationship, like paying salaries, managing benefits, and administering leave.
  • Legal obligation. Tax reporting, workplace safety records, and statutory retention periods all rest on the law, not on consent.
  • Legitimate interest. Things like network security, fraud prevention, and reasonable performance management can rely on legitimate interest, as long as you've weighed it against the employee's rights.

Consent still has a narrow place, for genuinely optional extras like a voluntary photo on the intranet. But if you catch yourself using consent as the basis for something the employee can't realistically refuse, that's a signal to pick a different one.

Transparency your staff can actually read

Employees have the right to know what you do with their data, and a privacy notice buried in an onboarding pack doesn't cut it. The notice has to explain what you collect, why, on what legal basis, how long you keep it, and who you share it with, including payroll providers and any transfers.

Write it for the people who have to read it. A short, plain-language notice that staff actually understand does more for compliance than a dense legal document nobody opens. And keep it current, because a notice that describes tools you stopped using two years ago is its own kind of problem.

Special-category data raises the bar

Some HR data falls into a protected category: health information, trade union membership, and data about ethnicity or religion where you happen to hold it. Sick leave records alone put most employers into this territory.

Special-category data needs an extra condition on top of your normal legal basis, usually the employment-law provisions that let you process it for obligations like sick pay and workplace accommodations. The practical rules are stricter too. Limit who can see it, keep it separate from general HR records where you can, and never collect it just because it might be useful someday.

Sick leave is special-category data

Health data is easy to underestimate because it arrives as an ordinary absence record. Treat sick leave, medical certificates, and accommodation requests as special-category data from the start, with tighter access and a clear legal basis, and you avoid the most common employer misstep.

How long to keep HR records

Retention is where good intentions quietly fail. The default in most companies is to keep everything forever, which GDPR doesn't allow. You keep personal data only as long as you have a reason, and for HR that reason is usually a mix of the employment relationship and specific legal retention periods.

Payroll and tax records have statutory minimums you have to meet. Recruiting data for candidates you didn't hire should go after a short, defined window unless you have a reason and a basis to keep it. The point isn't a single number. It's having a defined retention period for each type of record and actually acting on it, so data that's served its purpose gets deleted instead of lingering.

Monitoring at work, done lawfully

Employers monitor more than they used to: email systems, access logs, sometimes cameras or device management. Monitoring employees is processing personal data, and it's some of the most sensitive processing you'll do, because it touches the relationship of trust with your staff.

You can monitor for legitimate reasons like security, but you have to be proportionate and open about it. Tell people what you monitor and why, limit it to what the purpose needs, and don't repurpose the data later for something you never disclosed. Covert monitoring is a legal minefield and rarely worth it. If you're weighing a monitoring measure, a documented assessment of its impact on staff is your friend.

What's different in the Nordics

The GDPR baseline is the same across the EU, but employment is where national rules add texture. The Nordic countries have strong traditions of collective agreements and co-determination, so unions and works councils often have a say in monitoring and in new HR systems. Data protection authorities in Sweden, Denmark, Finland, and Norway have each published guidance on workplace privacy, and they don't always land in the same place on questions like camera surveillance or monitoring.

If you operate in more than one Nordic country, don't assume one setup fits all of them. Keeping your HR processing recorded per activity, with the local specifics noted, saves you from discovering a gap during a works council meeting.

Capture HR processing in OptiTech

All of this becomes manageable when your HR processing lives in the same record of processing activities as everything else, instead of in the heads of two people on the people team.

In the OptiTech Console, each HR activity is a processing entry with the details attached: the purpose, the legal basis you actually rely on (contract or legal obligation far more often than consent), the categories of data including any special-category data, the retention period, and the recipients like your payroll provider. Because the register is structured, you can show at a glance that sick leave is handled as special-category data, that candidate records have a defined retention window, and that a monitoring measure has an assessment behind it.

That's also what makes your program provable. When an auditor or a customer's security review asks how you handle employee data, or when a staff member exercises their rights, the answer is already recorded rather than reconstructed. And the same records feed your trust center, so the work you do for your own people also supports the story you tell buyers.

Ready to bring HR data into your compliance program? Book a demo and see how OptiTech captures every processing activity with the right legal basis and retention.