The Employee Data You Collect and the Obligations That Come With It

Employee data is the most consistently underestimated category of personal data in enterprise privacy programs. Organizations that have invested significantly in customer data governance routinely have less mature governance for the personal data they hold about their employees.

RCDr. Richard Chingombe · Founder, Verisq·4 min read·Practitioner perspective, not legal advice

The reasons are partly historical — employee data was traditionally a human resources domain with its own confidentiality norms rather than a privacy compliance domain — and partly practical — employees are less likely than customers to exercise data subject rights or initiate regulatory complaints. Neither reason is a valid basis for lower governance standards. The legal obligations for employee data under GDPR and comparable legislation are the same as for customer data.

What Employee Data Actually Includes

The employee data estate in most organizations is larger and more complex than the HR team's view of it suggests. The HR system holds the obvious categories: personnel records, compensation data, performance evaluations, leave records. But employee personal data exists across a much wider range of organizational systems.

The IT infrastructure that supports remote and hybrid work generates significant personal data: access logs that record when employees connect to organizational systems and from where, productivity monitoring tools that track application usage and active working hours in some deployments, email systems that hold years of business communications containing personal information, collaboration tools that hold message history and content. The physical infrastructure generates personal data: building access systems that record when employees enter and leave the workplace, CCTV systems in organizational facilities, vehicle management systems for fleet and parking.

The legal and compliance functions generate employee personal data: investigation records for HR matters, disciplinary proceedings documentation, whistleblower reports that name employees. The commercial functions generate employee personal data: business travel records, expense claims, project time records. Each system has its own data handling practices, retention schedules, and access controls that may not be governed under the same standards as the HR system's data.

The employee data estate is not the HR system. It is every system that generates, stores, or processes information about individual employees in the course of their employment relationship. Most privacy programs have mapped the first. Fewer have mapped the rest.

The Legal Obligations That Apply

Legal Basis for Processing

Employee data processing under GDPR requires a valid legal basis for each processing activity. The employment contract provides a legal basis for processing necessary for its performance. Legal obligation provides a basis for processing required by employment law, tax law, and health and safety requirements. Legitimate interests can support some employee data processing. Consent is rarely the appropriate basis for employee data processing, because the power imbalance in the employment relationship means employee consent may not be freely given.

The legal basis analysis for employee data processing is required for each processing activity — not a blanket justification for all employee data processing. Productivity monitoring, which may not be necessary for the employment contract's performance and may not be required by law, requires separate legal basis assessment. Biometric data processing — fingerprint scanners for building access — is special category data requiring explicit consent or another specific legal basis under Article 9.

Data Subject Rights

Employees have the same data subject rights as customers: the right to access their personal data, the right to rectification, the right to erasure in some circumstances, the right to object to processing, and in some cases the right to data portability. Employee data subject access requests are often more complex than customer DSARs because employee data is distributed across more systems, some of which — investigation records, performance management documentation — may be subject to competing confidentiality obligations that require careful assessment before disclosure.

Special Category Data in Employment

Health data collected during employment — occupational health records, absence records with medical detail, disability accommodations — is special category data requiring enhanced protection and a specific legal basis for processing under Article 9. The health and safety obligations that require organizations to collect some employee health data do not automatically provide the legal basis for all health-related data processing in the employment context.

See how your own vendors measure up.Security and privacy posture for any vendor, from the outside, free.
Check a vendor's scorecard

The Monitoring Question

Employee monitoring is one of the most active regulatory areas in employment privacy. The monitoring of employee device usage, application activity, email content, communication metadata, and physical location during working hours is subject to specific legal requirements across EU member states, the UK, and an increasing number of US jurisdictions.

GDPR does not prohibit employee monitoring. It requires that monitoring is carried out under a valid legal basis, with proportionate scope, with transparency to employees, and with appropriate safeguards. The DPA guidance across EU jurisdictions has been specific: broad keystroke logging, content monitoring of personal communications, and continuous screen capture are generally not proportionate. Targeted monitoring for defined security or operational purposes, with employee notification, is more likely to be proportionate.

Organizations that deployed monitoring capabilities during the remote work period without conducting a thorough proportionality assessment, without assessing the legal basis adequacy, and without providing adequate employee transparency may have monitoring infrastructure that does not meet the legal standard. The audit risk for this category of processing has increased as data protection authorities have turned attention to employee monitoring practices.

Apply the same governance standard to employee data that you apply to customer data. The legal obligations are the same. The governance investment should match.

Map the employee data estate beyond the HR system. Assess the legal basis for each processing activity. Address monitoring proportionality. The regulatory attention to employee data is increasing.

Enterprise practitioner perspective. Not legal advice. Part of the Deep Trust Governance Series by Verisq. Get the free weekly Breach Digest.