HR files hold identity documents, bank details, salaries, medical information, disciplinary records and next-of-kin contacts. It is the most sensitive collection of personal data in most organisations, and it is frequently the least controlled — sitting in shared drives, email attachments and an unlocked cabinet.

Data protection obligations vary and change. Confirm the current requirements applicable to your organisation.

Keep what you need, and know why

The safest data is the data you never collected. Before adding a field to a form, ask what decision it informs. Marital status, number of children, religion and photographs are collected routinely and are frequently unnecessary — and each one is something you must then protect, justify and eventually dispose of.

Set retention periods and act on them

Most organisations keep everything forever, which is both a risk and an obligation nobody planned for. Records of employees who left a decade ago sit in cabinets, still sensitive, still the organisation's responsibility.

Set a retention period for each category, reflecting any statutory minimum for payroll and tax records, and then actually dispose of what is past it. A schedule nobody enforces is worse than none, because it documents that you knew and did not act.

Restrict access by role

Not everyone in HR needs everything, and line managers need much less than they typically get. A sensible split:

  • Line managers: their own team's contact details, leave, attendance and performance records
  • HR: full records for the employees they administer
  • Payroll: pay, bank and statutory data
  • Medical information: tightly restricted, never on the general file

Disciplinary and grievance records deserve particular care. They are frequently the most damaging records to leak and the most casually stored.

The everyday leaks

Serious breaches rarely involve hacking. They look like this:

  1. A payroll file emailed to the wrong person
  2. A spreadsheet of salaries on a shared drive everyone can open
  3. Printed records left on a desk or in a meeting room
  4. A departed employee whose system access was never removed
  5. An unencrypted laptop or phone, lost

All five are prevented by habit rather than technology: check the recipient before sending anything sensitive, restrict shared folders by default, clear desks, and make access removal part of the exit checklist.

Make exits a controlled process

The moment someone leaves, several things must happen the same day: system access removed, email forwarded or closed, devices returned, and building access revoked. A written checklist, owned by a named person, is what makes this reliable — and it is the control auditors ask about first.

Employees have rights over their own data

People are generally entitled to know what is held about them and to have inaccuracies corrected. A request to see a personnel file is not an act of hostility, though it is often treated as one.

The practical implication is that files should contain nothing you would be uncomfortable showing the employee. Informal notes, opinions and comments about someone's personal circumstances do not belong there — and if they exist, you will have to explain them.

Know what you would do after a breach

Decide now: who is told, who assesses the impact, who communicates with affected people, and what notification may be required. Working that out during an incident, at speed and under pressure, guarantees a worse outcome than working it out today on a single page.

An annual review that takes an afternoon

  • What are we collecting, and is each field still needed?
  • Who has access, and is that still appropriate?
  • What is past its retention period and should be destroyed?
  • Do leavers still have access to anything?
  • Where does sensitive data leave the system — reports, exports, email?

Five questions, once a year. It prevents most of what goes wrong.