GDPR and cybersecurity: what HR needs to know to protect employee data
HR teams are the primary custodians of sensitive personal data. GDPR, retention periods, employee rights: your practical guide.
Why HR is a priority target for attackers
The HR function handles the most sensitive data in the company every day: salaries, bank details, social security numbers, health data and family information. For a criminal, that is a goldmine for payment fraud, identity theft or blackmail.
In 2024, attacks targeting HR departments rose by 67 %. The main entry point is phishing by email, impersonating an executive or a payroll provider.
What the GDPR requires of HR departments
1. The HR record of processing activities
You must document all your processing of personal data: payroll, recruitment, training, appraisal, disciplinary matters. For each one: the purpose, the data collected, the retention period and the recipients.
2. Statutory retention periods
| Type of data | Retention period |
|---|---|
| Payslips | 5 years (employment tribunal limitation) |
| Employment contracts | 5 years after the end of the contract |
| Unsuccessful applications | 2 years maximum |
| Occupational health data | 50 years |
| Disciplinary records | Duration of the contract plus 5 years |
| Payroll accounting files | 10 years |
3. The employee rights you must respect
- Right of access: an employee may request all the data you hold about them. Response deadline: one month.
- Right to rectification: correct inaccurate data without delay.
- Right to erasure: limited in HR, since a great deal of data is subject to a statutory retention obligation.
- Right to portability: provide the data in a structured, machine-readable format.
An HR data breach must be notified to the regulator within 72 hours. Without a procedure in place, you are past the deadline before you have even understood what happened.
The five cyber reflexes to adopt in HR immediately
- Never change bank details by email: always verify by phone on a known number before changing any payment details.
- Encrypt payroll files: no payslip or banking file should travel unprotected by email.
- Limit access to sensitive data: only those who need the data should be able to reach it.
- Train HR teams on phishing: one simulation per quarter reduces the click rate by 80 %.
- Secure onboarding and offboarding: create and remove access on the day, not two weeks later.
HR GDPR checklist
- Record of processing activities kept up to date
- Retention periods respected
- 72-hour breach notification procedure
- Confidentiality clauses in contracts
- GDPR training for the HR team
- Formal procedure for changing bank details
Train your HR team
The CyberMasterClass Talent covers GDPR in HR, employee data protection and the right cyber reflexes for HR teams.
Get the next publications.
One analysis per publication on cyber governance, resilience and compliance.
Take action in 90 minutes
Our CyberMasterClasses train executives, sales teams and HR on cyber issues, without technical jargon.
See the masterclasses