Skip to the main content.

7 min read

GDPR HR software: protecting your people and data

GDPR HR software: protecting your people and data

GDPR-compliant HR software is a system that lets you prove, rather than assert, that employee and candidate data is collected for a stated purpose, held only as long as it is needed, visible only to people with a reason to see it, exportable or erasable on request, and processed under a written agreement with the vendor. No product makes an organisation compliant on its own. The software supplies the controls and the audit trail. You still supply the lawful basis, the retention rules and the records.

Last reviewed September 2026.

That distinction matters when you are shortlisting vendors, because almost every HR product on the market describes itself as GDPR compliant. The phrase on its own tells you very little. What you are actually buying is a set of capabilities that make your own obligations achievable, plus a contract that sets out what the vendor does with the data you put in. The checks below are the ones worth running before you sign.

What makes HR software GDPR compliant

The General Data Protection Regulation sets out data protection principles in Article 5, and the practical test of a product is whether it helps you meet each of them without a spreadsheet on the side. Read against those principles, a system that holds people data should give you:

  • Lawfulness, fairness and transparency. Somewhere to record the lawful basis for each type of processing, and privacy notices that candidates and employees actually see at the point their data is collected.
  • Purpose limitation. Field-level control over what gets collected for what. If you are hiring, a candidate's school hobbies are not needed unless they bear on the job, and collecting them only adds to your risk.
  • Data minimisation. Configurable forms, so you are not forced to capture a full personal profile at application stage because the vendor's template says so.
  • Accuracy. Self-service profiles, so employees can correct their own address, emergency contact and bank details instead of emailing a change to HR and hoping.
  • Storage limitation. Retention rules you can set per record type, with automated flagging or deletion when the period expires, and a log that shows it happened.
  • Integrity and confidentiality. Encryption in transit and at rest, role-based permissions, enforced multi-factor authentication, and an audit log of who opened which record.
  • Accountability. Exportable reports that show what data you hold, where it sits and who has access, because the obligation is to be able to demonstrate compliance rather than to claim it.

Centralisation is doing a lot of the work in that list. Scattered spreadsheets and paper forms fail on almost every principle at once, and they fail quietly. The first time most teams discover how scattered their people data has become is when someone exercises their rights and the search takes a fortnight.

What to check before you buy

Checklist for assessing whether HR software meets GDPR requirements before purchase

Vendor websites answer the question 'are you GDPR compliant' with a yes. A procurement conversation should ask for the evidence instead. Pair each requirement with the artefact that proves it.

RequirementWhat to look for in the productWhat to ask the vendor for
Erasure and access requestsOne search that finds every record for a person, then deletes or anonymises across modules with a receiptA live walkthrough on a test record, not a slide
RetentionRetention periods set per record type, applied automatically, different for employees and unsuccessful applicantsThe default retention settings and how they are changed
Access controlRole-based permissions fine enough to hide medical certificates and home addresses from line managersThe permission matrix and a sample audit log
Processing termsA data processing agreement offered as standard, naming sub-processorsThe DPA and the current sub-processor list
Data location and transfersChoice of hosting region, and documented safeguards where data leaves itHosting locations and the transfer mechanism used
Security assuranceEncryption, multi-factor authentication, penetration testing, certificationThe latest certification or audit report and test summary
Breach handlingMonitoring and alerting that would surface an incident quicklyThe notification timeframe and process written into the contract
ExitFull export in a usable format, plus deletion at the end of the contractThe offboarding and deletion commitment in writing

If you are running a structured selection, the HR tech requirements builder will turn that list into a weighted requirements document you can send to several vendors at once, which makes the answers comparable.

GDPR and HR systems: what stays your responsibility

Buying good software shifts less of the burden than people expect. In most HR arrangements the employer is the controller and the vendor is the processor, which means the decisions about why and how data is processed remain yours. A few obligations that no product discharges for you:

  • A written processing agreement. Article 28 requires a contract governing the processor's handling of the data. Check it exists and that it covers sub-processors.
  • A defensible lawful basis. Consent is a weak basis in an employment relationship, because of the power imbalance between employer and employee. Most HR processing rests on contract, legal obligation or legitimate interests instead, and the reasoning needs recording.
  • Records of processing. Article 30 expects a record of the processing activities you carry out. A system report is useful input, not the record itself.
  • A risk assessment where the processing is high risk. Article 35 sets out when a data protection impact assessment is required. Monitoring tools and large-scale profiling are the usual triggers in an HR context.
  • Breach response. Article 33 sets a 72-hour window for notifying the supervisory authority in qualifying cases. The clock starts when you become aware, so the internal escalation path matters as much as the vendor's alerting.
  • Special category data. Health records, union membership and similar data carry extra conditions under Article 9. Plenty of HR processes collect them without anyone having decided they should.

None of this argues for staying on spreadsheets. It does mean the software works as the control layer for a policy you have already written, and never as a substitute for writing one. This is general guidance rather than legal advice, and an organisation formalising its approach should take advice from a privacy or employment law professional.

Where HR teams usually get caught out

Common gaps in HR data protection, from shadow spreadsheets to over-broad system access

The gaps are rarely in the system itself. They sit around it.

  • Shadow copies. The interview scorecard saved to a laptop, the headcount spreadsheet emailed to a manager, the candidate CVs sitting in a shared recruitment inbox. Each one is personal data the central system cannot reach, and each one has to be found when somebody asks to be erased.
  • Unsuccessful applicants. Candidate records often sit indefinitely because nobody set a retention period for people who were not hired. It is also the easiest gap on this list to close.
  • Access that grew with the org chart. Permissions get granted during an urgent project and never revoked. A manager who needs performance notes does not need medical certificates.
  • Migration. Moving between systems is when data sprawls fastest and when old exports get left behind on someone's drive. The data protection side of an ATS migration deserves its own plan rather than a line in the project schedule.
  • Analytics. Aggregated reporting is useful and generally lower risk, but pulling people analytics down to small teams can re-identify individuals. Set a minimum group size before you publish anything internally.

Does GDPR apply to Australian and New Zealand HR teams?

Sometimes, and more often than people assume. Article 3 gives the regulation extraterritorial reach, so an organisation outside the European Union can fall within scope where it processes the data of people in the EU, including employees and candidates based there. A business with one EU-based remote worker or an open role advertised into Europe should check its position rather than assume distance protects it.

Domestic obligations sit alongside it either way. Australian organisations have the Privacy Act 1988 and the Australian Privacy Principles, along with the Notifiable Data Breaches scheme. New Zealand has the Privacy Act 2020, which carries its own breach notification duty. The practical upshot for a buyer is that the controls worth asking about are largely the same, so a product that stands up to GDPR scrutiny is usually a reasonable answer locally too. Where the two regimes genuinely differ, that is a question for a professional adviser rather than a blog post.

Building a culture of privacy around the software

Most breaches are mundane. An email sent to the wrong recipient, a laptop open on a cafe table, a spreadsheet attached by mistake, a share link that never expired. Technology reduces the odds; habits decide them. Four things worth doing alongside any implementation:

  • Tell employees and candidates plainly what you collect, why, how long you keep it and who can see it. Transparency is an obligation, and it also buys you a lot of goodwill.
  • Train the people who touch the data, and repeat it when roles change rather than once at induction.
  • Review permissions on a schedule, the same way you review access to payroll or finance systems.
  • Keep the retention settings under review as the business changes, and record when you last checked them.

Handled this way, the obligations become a property of the system and the routine rather than a task somebody remembers on a Friday afternoon. Centralising candidate and employee records in HR software built for the whole employee lifecycle is what makes that possible, because the controls only work on data the system can actually see.

COMPONO PLATFORM

One place for your people data

Compono keeps hiring, engagement and development records in one system with role-based access and retention controls, so privacy obligations are easier to meet and easier to evidence.

Talk to us

Frequently asked questions

What is GDPR compliant HR software?

HR software that gives you the controls needed to meet the General Data Protection Regulation: purpose-specific collection, configurable retention, role-based access, audit logging, and the ability to find, export or erase every record held about one person. The product supplies the controls and the evidence trail; the lawful basis, retention policy and processing records remain the employer's responsibility.

Does using GDPR compliant HR software make my organisation compliant?

No. Compliance is a property of the organisation, not the product. Software makes the obligations achievable and provides the audit trail, but you still decide the lawful basis for each type of processing, set retention periods, keep records of processing activities and respond to requests within the statutory timeframes.

How does HR software handle the right to be forgotten?

A well-built system finds every record associated with an individual in one search, then deletes or anonymises them across modules and logs that the request was completed. Ask for a live demonstration on a test record during evaluation, because this is the capability most often described on a website and least often easy to use.

How long can we keep unsuccessful candidate data?

Only as long as there is a stated purpose for holding it, which usually means a defined period after the role closes rather than indefinitely. Set the period deliberately, record the reasoning, and configure the system to enforce it. Indefinite retention of applicant records is one of the most common gaps in HR data practice.

Does GDPR apply to Australian or New Zealand businesses?

It can. Article 3 gives the regulation extraterritorial reach, so processing the data of people located in the European Union can bring an organisation within scope regardless of where it is based. Australian organisations also have the Privacy Act 1988 and the Australian Privacy Principles, and New Zealand has the Privacy Act 2020. Take professional advice on your specific position.

Is employee data safer in cloud HR software than on our own servers?

Usually, though it depends on both parties. Established providers run encryption, monitoring, regular security testing and certified data centres that most mid-sized organisations cannot match internally. The trade-off is that you are relying on someone else's controls, which is why the processing agreement, the sub-processor list, the audit evidence and the exit terms matter as much as the feature list.

Related

How to choose the right ISO 27001 HR software

How to choose the right ISO 27001 HR software

What ISO 27001 certification actually covers in HR software, the controls worth verifying, and the questions to put to a vendor holding staff data.

Read More
How to use compensation analytics to build high-performing teams

How to use compensation analytics to build high-performing teams

How to use compensation analytics to test pay equity, benchmark against the market, and spot flight risk in the people you cannot afford to lose.

Read More
Data security HR software: protecting your workforce intelligence

Data security HR software: protecting your workforce intelligence

The security features to check before buying HR software: encryption, MFA, granular access controls, data residency and audit trails, explained...

Read More