Managing GDPR HR records correctly is one of the most consequential compliance obligations facing UK HR teams in 2026. Employee data is, almost by definition, personal data and in many cases it includes special category data that attracts the highest level of GDPR protection. Get it wrong and the risks are not abstract: ICO enforcement action, substantial fines, reputational damage, and the loss of employee trust.

Yet for many HR departments, GDPR compliance remains reactive rather than systematic. Documents are retained indefinitely because no one has defined a deletion policy. Access to sensitive personnel files is broader than it should be. Requests from employees for their own data create chaos because records are scattered across paper files, email inboxes, and shared drives.

This guide is a complete, practical reference for UK HR teams who want to get and stay compliant in 2026. It covers the UK GDPR framework as it applies to HR, the lawful basis for processing employee data, retention requirements, employee rights, breach obligations, and the role that digital document management plays in making compliance systematic rather than accidental.

What UK GDPR Means for HR: Understanding GDPR Employee Records

Since the UK’s departure from the EU, the applicable framework for data protection in Great Britain is UK GDPR the retained version of the EU General Data Protection Regulation, as incorporated into UK law by the European Union (Withdrawal) Act 2018 and supplemented by the Data Protection Act 2018 (DPA 2018). For most practical HR purposes, UK GDPR and its EU counterpart are substantively identical, but HR teams must use the UK framework when assessing compliance.

GDPR employee records encompass everything an organisation holds about current and former employees, as well as job applicants and contractors. This includes but is not limited to:

  • Personal details: name, address, date of birth, national insurance number, bank details
  • Employment records: contracts, offer letters, job descriptions, salary history
  • Performance and conduct: appraisal records, disciplinary files, grievance documentation
  • Attendance and leave: timesheets, holiday records, sick leave, maternity and paternity leave
  • Recruitment records: applications, interview notes, references, right-to-work documents
  • Health and occupational data: fit notes, occupational health reports, disability adjustments
  • Training and qualifications: certificates, CPD records, mandatory training completions
  • DBS check results and criminal records information (where applicable)

All of this data is subject to the six data protection principles set out in Article 5 of UK GDPR: lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; and integrity and confidentiality. Every HR data protection decision should be tested against these six principles.

GDPR Employee Data UK: The Six Principles Applied to HR

Lawful basis for HR records

Before processing any employee personal data, you must identify a lawful basis under Article 6 of UK GDPR. For HR processing, the most commonly applicable bases are:

  • Contract: Processing necessary for the performance of an employment contract payroll, HR administration, managing leave and absence. This is the primary basis for most routine HR processing.
  • Legal obligation: Processing required to comply with a legal obligation right-to-work checks, payroll tax records, compliance with health and safety legislation.
  • Legitimate interests: Processing necessary for the legitimate interests of the employer, provided those interests are not overridden by the rights of the employee. Commonly used for security monitoring, fraud prevention, and business continuity. Requires a Legitimate Interests Assessment.
  • Consent: Generally not recommended as a lawful basis for employee data because of the imbalance of power in the employment relationship consent given by an employee to their employer is rarely freely given. Use it only where genuinely appropriate and where withdrawal of consent will have no employment consequence.

The ICO HR guidance makes clear that UK GDPR does not prevent employers from keeping records they need to run their business but it does require that processing is proportionate, documented, and lawfully based.

GDPR special category data in HR

Certain categories of employee data attract a higher level of protection under Article 9 of UK GDPR. Processing special category data requires both a lawful basis under Article 6 and a separate condition under Article 9. In the HR context, special category data includes:

  • Health and medical data: sick notes, occupational health reports, disability information, fit-for-work assessments
  • Racial or ethnic origin: monitoring for equality purposes
  • Trade union membership: relevant to collective bargaining or industrial relations
  • Biometric data: fingerprint time-and-attendance systems, for example
  • Criminal records: DBS check results and information about criminal convictions

Criminal records data is subject to additional restrictions under Schedule 1 of the DPA 2018 and the Rehabilitation of Offenders Act 1974. DBS certificates should not be retained beyond six months after the recruitment decision, and the result should be recorded separately from the main personnel file.

Access to special category data must be restricted to those with a clear business need. In a digital document management system, this means assigning granular access permissions at the document type level so that, for example, a line manager can see an employee’s absence record but not their occupational health report.

Data minimisation in HR

The data minimisation principle requires that you collect only the personal data that is adequate, relevant, and limited to what is necessary for the purpose. In HR terms, this means resisting the temptation to collect information ‘just in case’. Collecting date of birth when it is not required for any employment purpose, asking for marital status on application forms, or retaining emergency contact details indefinitely after employment ends are all potential minimisation failures. Review your HR data collection practices regularly and remove fields or records that cannot be justified against a specific, documented purpose.

HR Data Protection UK: The DPA 2018 and Employment Specifics

The Data Protection Act 2018 provides the domestic framework that sits alongside UK GDPR and contains important employment-specific provisions. Schedule 2, Part 1 of the DPA 2018 includes an exemption that allows employers to withhold certain personal data from Subject Access Requests where disclosing it could prejudice the prevention or detection of crime, legal proceedings, or management forecasting and planning but these exemptions must be applied carefully and documented.

The DPA 2018 also requires that organisations processing criminal records data outside the DBS regime have an appropriate policy document in place. For most employers, the only lawful basis for processing criminal records is Schedule 1, Part 2, paragraph 6 of the DPA 2018 processing for the purposes of preventing or detecting unlawful acts, and only to the extent necessary.

HR data protection UK obligations do not end at the point of collection. They extend through the entire employee lifecycle and into the post-employment period which is precisely why a systematic approach to records management, built on the right technology, is so important.

UK GDPR HR: Building Your Compliance Framework

A robust UK GDPR HR compliance framework has several interconnected components. Each one is necessary; none is sufficient on its own.

Data inventory and records of processing activities (ROPA)

Article 30 of UK GDPR requires most organisations to maintain a Record of Processing Activities (ROPA) a documented inventory of all data processing operations, including HR processing. Your HR ROPA entry should capture: the categories of personal data processed, the purposes of processing, the lawful basis for each purpose, the categories of data subjects, retention periods, and any third parties with whom data is shared (payroll bureau, occupational health provider, HR software vendor, etc.).

The ROPA is not a public document, but the ICO can request it during an investigation. It is also the starting point for any DPIA and for responding to Subject Access Requests.

DPIA for HR records

A Data Protection Impact Assessment (DPIA) is required under Article 35 of UK GDPR where processing is likely to result in a high risk to individuals. In an HR context, DPIAs are typically required when:

  • Implementing a new HR technology system that will process employee data at scale
  • Introducing monitoring or surveillance of employees (including productivity monitoring software)
  • Processing special category data particularly health data in a new way
  • Migrating HR records to a new document management system or cloud platform
  • Implementing biometric time-and-attendance systems

A DPIA does not need to conclude that a project is problem-free it needs to demonstrate that risks have been identified and mitigated. Conducting a DPIA and documenting it properly is itself evidence of accountability under UK GDPR.

Access permissions for HR records

The integrity and confidentiality principle of UK GDPR (Article 5(1)(f)) requires that personal data is processed in a manner that ensures appropriate security including protection against unauthorised access. In HR, this means implementing role-based access controls so that:

  • HR administrators can access all employee records within their remit
  • Line managers can access the records of their direct reports but not special category data or other sensitive file types
  • Payroll teams can access payroll-relevant data but not disciplinary records
  • Senior leadership has visibility of anonymised workforce data but not individual records unless there is a specific business need

In a paper-based HR environment, enforcing access permissions is practically impossible. Anyone with physical access to a filing room can access any file. A digital document management system with granular access controls removes this risk entirely and creates the audit trail to prove it.

GDPR audit trail for HR

An audit trail is a log of who accessed, modified, or deleted a record, and when. Under the accountability principle of UK GDPR (Article 5(2)), you must be able to demonstrate compliance not merely assert it. A comprehensive GDPR audit trail for HR records enables you to:

  • Show that access to sensitive records was restricted to authorised individuals
  • Demonstrate that records have been retained for the correct period and deleted on schedule
  • Provide evidence of your response to a Subject Access Request, including what was disclosed and when
  • Support an internal investigation into a suspected data breach

DocuWare implemented and supported by BPMS for HR teams provides a complete audit trail for every document in the system, capturing access, modification, and deletion events with timestamp and user identity. This is the kind of accountability evidence that satisfies an ICO investigation.

GDPR HR Records Retention: How Long to Keep What

The storage limitation principle of UK GDPR requires that personal data is kept no longer than necessary for the purpose for which it was collected. For HR records, ‘necessary’ is defined partly by statute (employment law, tax law, health and safety legislation) and partly by the organisation’s own legitimate needs (defending employment tribunal claims, for example).

There is no single definitive GDPR retention schedule for HR records requirements vary by record type, sector, and circumstance. The table below reflects widely adopted guidance for UK employers in 2026, but organisations should always seek legal advice for their specific situation.

 

Record type Minimum retention Statutory basis
Payroll records 6 years HMRC / Taxes Management Act 1970
Right-to-work checks 2 years after leaving Immigration, Asylum & Nationality Act 2006
Personnel files (general) 6 years after leaving Limitation Act 1980 (claims window)
Recruitment records (unsuccessful) 6–12 months Equality Act 2010
Maternity / parental leave 3 years after relevant pay period HMRC guidance
Disciplinary & grievance 6 years (or longer if litigation risk) Limitation Act 1980
Occupational health / medical Up to 40 years (hazardous exposure) Control of Substances Regulations 2002
Training records Duration of employment + 6 years Various sector-specific regulations
DBS certificates 6 months after recruitment decision DBS Code of Practice

 

Note: These are minimum periods. Organisations may retain records longer where there is a specific legitimate purpose an active or reasonably foreseeable employment tribunal claim, for example. The key is that the reason for extended retention is documented.

Automated retention management is one of the most significant practical benefits of a digital HR document management system. Rather than relying on HR administrators to remember to delete files, the system applies your defined retention schedule automatically flagging records for review and deletion when their retention period expires, and creating an audit trail of the deletion action.

For a detailed walkthrough of retention periods across all HR record types, see our companion guide: HR Document Retention: Complete UK Guide for 2026.

Data Subject Rights in HR: What Employees Can Ask For

UK GDPR grants employees a range of rights in relation to their personal data. These are enforceable rights, not guidelines and HR teams need reliable processes to respond within the statutory timeframes (generally one calendar month from receipt of the request).

Right of access (Subject Access Requests)

An employee can request a copy of all personal data held about them. This is a Subject Access Request (SAR) and must be responded to free of charge within one calendar month (extendable to three months for complex requests, with notification). In a paper-based HR environment, completing a SAR can take days of administrative effort across multiple filing locations. In a well-configured HR document management system, the same task can be completed in hours with confidence that the response is complete and documented.

Right to rectification, erasure, and restriction

Employees can request correction of inaccurate personal data (right to rectification), deletion of data that is no longer necessary or lawfully held (right to erasure), or restriction of processing in certain circumstances. In HR, the right to erasure is frequently misunderstood it does not override an employer’s legal obligation to retain records for statutory periods. An employee cannot require deletion of payroll records that must be retained for HMRC purposes. However, you should have clear processes for responding to all rights requests, documenting the request, the decision, and the outcome.

Right to object

Where processing is based on legitimate interests, employees have the right to object. HR teams should be prepared to demonstrate, in response to an objection, that the legitimate interests pursued override the individual’s rights and interests. If they cannot do so, they must stop processing. Documenting the Legitimate Interests Assessment at the outset makes this far easier to demonstrate.

GDPR HR Compliance: Your Practical Checklist

Use this checklist as a working tool for your HR team. It is not exhaustive, but it covers the areas most likely to attract ICO scrutiny.

  1. Privacy notice. Employees and applicants receive a clear, plain-English privacy notice at the point of data collection, setting out what data is collected, why, on what lawful basis, and for how long it will be retained.
  2. ROPA entry. A current and accurate Record of Processing Activities entry exists for all HR data processing operations.
  3. Lawful basis documented. Each category of HR processing has a documented lawful basis, reviewed and signed off by a data protection lead.
  4. Special category data identified and controlled. All special category data is identified, held separately where possible, and accessible only to those with a documented business need.
  5. Retention schedule in place. A documented retention schedule exists for all HR record types, aligned to statutory requirements. Deletion is automated or managed through a systematic review process.
  6. Access controls implemented. Role-based access permissions are in place and reviewed regularly. Access is restricted to those with a genuine need.
  7. Audit trail active. All access to and modification of HR records is logged with user identity and timestamp.
  8. SAR process defined. A documented process exists for receiving, logging, and responding to Subject Access Requests within the one-month statutory window.
  9. Data breach response plan. A documented plan exists for identifying, containing, assessing, and reporting personal data breaches involving HR records.
  10. Third-party data sharing agreements. Data processing agreements are in place with all third parties who process employee data (payroll bureau, occupational health, HR software vendors).
  11. Staff training. All HR staff receive regular data protection training, including how to recognise and report a personal data breach. Training completion is documented.
  12. DPO or data protection lead designated. A named individual has accountability for data protection compliance within HR.

GDPR Breach and HR Records: What to Do When Things Go Wrong

GDPR breach in HR records: notification obligations

A personal data breach is any security incident that results in the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. In an HR context, this includes a lost personnel file, a payroll spreadsheet emailed to the wrong recipient, or unauthorised access to an employee’s occupational health record.

Under Article 33 of UK GDPR, you must report a breach to the ICO within 72 hours of becoming aware of it if the breach is likely to result in a risk to individuals’ rights and freedoms. If the breach is unlikely to result in such a risk, you do not need to notify the ICO, but you must document it internally. Where the breach is likely to result in a high risk to individuals, you must also notify the affected individuals directly (Article 34).

The 72-hour clock starts from when the organisation not just the individual who discovered it becomes aware. This makes internal reporting processes critical. HR teams must know exactly how to escalate a suspected breach immediately.

GDPR fines in HR: the financial consequences of non-compliance

The ICO has powers to issue fines of up to £17.5 million or 4% of global annual turnover (whichever is higher) for serious breaches of UK GDPR. For lower-level infringements, fines of up to £8.7 million or 2% of global annual turnover apply. In practice, fines are calibrated to the nature and severity of the infringement, the number of individuals affected, and the degree of responsibility including whether the organisation took reasonable steps to comply.

Beyond ICO fines, organisations also face the risk of compensation claims from affected employees under Section 82 of the DPA 2018 (the right to claim for material or non-material damage from a data protection breach), employment tribunal claims, and the reputational damage that invariably follows a publicised HR data breach.

Prevention is substantially cheaper than enforcement. Investing in proper HR document management infrastructure with the access controls, audit trails, and retention automation that compliance requires is a cost that needs to be weighed against the very real financial and reputational cost of getting it wrong.

How an HR Document Management System Enables GDPR Compliance

Achieving and maintaining GDPR HR compliance with paper-based or loosely organised digital records is, in practice, extremely difficult. The accountability principle being able to demonstrate compliance, not just assert it requires the kind of systematic control that only a proper document management system can provide.

A well-implemented HR document management system addresses the following compliance requirements directly:

  • Granular access controls. Role-based permissions mean only authorised staff can access specific record types, enforcing the confidentiality principle automatically.
  • Automated retention and deletion. Retention schedules are configured once and enforced automatically eliminating the risk of records being held indefinitely through administrative inaction.
  • Complete audit trail. Every access, modification, and deletion event is logged providing the accountability evidence that UK GDPR requires.
  • SAR support. Responding to Subject Access Requests in hours rather than days, with confidence that the response is complete.
  • Secure digital storage. Encryption at rest and in transit, with cloud or on-premises deployment options. Eliminates the physical loss and theft risks associated with paper records.
  • Workflow automation for compliance processes. Automate the routing and sign-off of data protection-related documents DPIA approvals, SAR responses, breach notification workflows.

BPMS implements and supports DocuWare for HR across a wide range of UK organisations configuring the platform specifically to each client’s HR structure, retention requirements, and access control needs. Our approach begins with a thorough understanding of your current records landscape and compliance obligations, and results in a system that makes compliance the default rather than the exception.

For HR teams that are not yet ready for a full enterprise platform, BPMS Online provides an accessible, cost-effective route to digital HR records management with the security and control that GDPR compliance demands.

Where to Start: Getting Your GDPR HR Compliance in Order

If you are reading this guide because your current HR records management falls short of where it needs to be, here is a practical sequence for getting started:

  • Conduct a document and process audit. Understand what HR records you currently hold, where they are, who can access them, and what retention periods apply. BPMS can carry out this audit on your behalf.
  • Identify your highest-risk areas. Where is special category data held? Who has access to it? Are there records that should have been deleted years ago? Address these first.
  • Document your lawful bases and update your privacy notice. Ensure every category of HR processing has a documented lawful basis and that employees are informed through an up-to-date privacy notice.
  • Digitise your paper HR records. Have your physical HR files professionally scanned, indexed, and imported into your document management system. BPMS provides specialist document scanning for HR with OCR and metadata indexing.
  • Implement an HR document management system. Configure access controls, retention schedules, and audit trails. This is where compliance becomes systematic rather than manual.
  • Train your HR team. Ensure everyone involved in handling employee data understands their obligations and knows how to respond to a SAR or a breach.
  • Review annually. GDPR compliance is not a project with a completion date. Review your ROPA, retention schedules, access controls, and privacy notice at least once a year and whenever there is a significant change to your HR processes or technology.

Talk to BPMS About GDPR-Compliant HR Records Management

BPMS has been helping UK organisations manage their records securely and in compliance with data protection obligations since 1988. Our team understands the specific challenges that HR data presents the sensitivity, the volume, the complexity of retention requirements, and the consequences of getting it wrong.

Whether you need to digitise a large volume of paper HR files, implement a fully compliant HR document management system, or simply understand where your current approach falls short, we can help. We offer a free initial consultation with no obligation and our approach begins with listening to your specific situation before recommending any solution.

Contact BPMS today on 0333 772 1631, email info@bp-ms.co.uk, or complete the contact form on our website. We work with HR teams across the UK from SMEs to large multi-site organisations in every sector where GDPR HR compliance matters most.