GDPR and cybersecurity: what HR needs to know to protect employee data

février 15, 2026
Sécurité des données et sauvegardes, protection RGPD

HR teams are the primary custodians of sensitive personal data. GDPR, retention periods, employee rights: your practical guide.

Why HR is a priority target for attackers

The HR function handles the most sensitive data in the company every day: salaries, bank details, social security numbers, health data and family information. For a criminal, that is a goldmine for payment fraud, identity theft or blackmail.

In 2024, attacks targeting HR departments rose by 67 %. The main entry point is phishing by email, impersonating an executive or a payroll provider.

What the GDPR requires of HR departments

1. The HR record of processing activities

You must document all your processing of personal data: payroll, recruitment, training, appraisal, disciplinary matters. For each one: the purpose, the data collected, the retention period and the recipients.

2. Statutory retention periods

Type of data Retention period
Payslips 5 years (employment tribunal limitation)
Employment contracts 5 years after the end of the contract
Unsuccessful applications 2 years maximum
Occupational health data 50 years
Disciplinary records Duration of the contract plus 5 years
Payroll accounting files 10 years

3. The employee rights you must respect

  • Right of access: an employee may request all the data you hold about them. Response deadline: one month.
  • Right to rectification: correct inaccurate data without delay.
  • Right to erasure: limited in HR, since a great deal of data is subject to a statutory retention obligation.
  • Right to portability: provide the data in a structured, machine-readable format.

An HR data breach must be notified to the regulator within 72 hours. Without a procedure in place, you are past the deadline before you have even understood what happened.

The five cyber reflexes to adopt in HR immediately

  1. Never change bank details by email: always verify by phone on a known number before changing any payment details.
  2. Encrypt payroll files: no payslip or banking file should travel unprotected by email.
  3. Limit access to sensitive data: only those who need the data should be able to reach it.
  4. Train HR teams on phishing: one simulation per quarter reduces the click rate by 80 %.
  5. Secure onboarding and offboarding: create and remove access on the day, not two weeks later.

HR GDPR checklist

  • Record of processing activities kept up to date
  • Retention periods respected
  • 72-hour breach notification procedure
  • Confidentiality clauses in contracts
  • GDPR training for the HR team
  • Formal procedure for changing bank details

Train your HR team

The CyberMasterClass Talent covers GDPR in HR, employee data protection and the right cyber reflexes for HR teams.

Publications

Get the next publications.

One analysis per publication on cyber governance, resilience and compliance.

Take action in 90 minutes

Our CyberMasterClasses train executives, sales teams and HR on cyber issues, without technical jargon.

See the masterclasses