How to choose the right ISO 27001 HR software
What ISO 27001 certification actually covers in HR software, the controls worth verifying, and the questions to put to a vendor holding staff data.
7 min read
Mathan Allington
Updated on September 30, 2026
GDPR-compliant HR software is a system that lets you prove, rather than assert, that employee and candidate data is collected for a stated purpose, held only as long as it is needed, visible only to people with a reason to see it, exportable or erasable on request, and processed under a written agreement with the vendor. No product makes an organisation compliant on its own. The software supplies the controls and the audit trail. You still supply the lawful basis, the retention rules and the records.
Last reviewed September 2026.
That distinction matters when you are shortlisting vendors, because almost every HR product on the market describes itself as GDPR compliant. The phrase on its own tells you very little. What you are actually buying is a set of capabilities that make your own obligations achievable, plus a contract that sets out what the vendor does with the data you put in. The checks below are the ones worth running before you sign.
The General Data Protection Regulation sets out data protection principles in Article 5, and the practical test of a product is whether it helps you meet each of them without a spreadsheet on the side. Read against those principles, a system that holds people data should give you:
Centralisation is doing a lot of the work in that list. Scattered spreadsheets and paper forms fail on almost every principle at once, and they fail quietly. The first time most teams discover how scattered their people data has become is when someone exercises their rights and the search takes a fortnight.

Vendor websites answer the question 'are you GDPR compliant' with a yes. A procurement conversation should ask for the evidence instead. Pair each requirement with the artefact that proves it.
| Requirement | What to look for in the product | What to ask the vendor for |
|---|---|---|
| Erasure and access requests | One search that finds every record for a person, then deletes or anonymises across modules with a receipt | A live walkthrough on a test record, not a slide |
| Retention | Retention periods set per record type, applied automatically, different for employees and unsuccessful applicants | The default retention settings and how they are changed |
| Access control | Role-based permissions fine enough to hide medical certificates and home addresses from line managers | The permission matrix and a sample audit log |
| Processing terms | A data processing agreement offered as standard, naming sub-processors | The DPA and the current sub-processor list |
| Data location and transfers | Choice of hosting region, and documented safeguards where data leaves it | Hosting locations and the transfer mechanism used |
| Security assurance | Encryption, multi-factor authentication, penetration testing, certification | The latest certification or audit report and test summary |
| Breach handling | Monitoring and alerting that would surface an incident quickly | The notification timeframe and process written into the contract |
| Exit | Full export in a usable format, plus deletion at the end of the contract | The offboarding and deletion commitment in writing |
If you are running a structured selection, the HR tech requirements builder will turn that list into a weighted requirements document you can send to several vendors at once, which makes the answers comparable.
Buying good software shifts less of the burden than people expect. In most HR arrangements the employer is the controller and the vendor is the processor, which means the decisions about why and how data is processed remain yours. A few obligations that no product discharges for you:
None of this argues for staying on spreadsheets. It does mean the software works as the control layer for a policy you have already written, and never as a substitute for writing one. This is general guidance rather than legal advice, and an organisation formalising its approach should take advice from a privacy or employment law professional.

The gaps are rarely in the system itself. They sit around it.
Sometimes, and more often than people assume. Article 3 gives the regulation extraterritorial reach, so an organisation outside the European Union can fall within scope where it processes the data of people in the EU, including employees and candidates based there. A business with one EU-based remote worker or an open role advertised into Europe should check its position rather than assume distance protects it.
Domestic obligations sit alongside it either way. Australian organisations have the Privacy Act 1988 and the Australian Privacy Principles, along with the Notifiable Data Breaches scheme. New Zealand has the Privacy Act 2020, which carries its own breach notification duty. The practical upshot for a buyer is that the controls worth asking about are largely the same, so a product that stands up to GDPR scrutiny is usually a reasonable answer locally too. Where the two regimes genuinely differ, that is a question for a professional adviser rather than a blog post.
Most breaches are mundane. An email sent to the wrong recipient, a laptop open on a cafe table, a spreadsheet attached by mistake, a share link that never expired. Technology reduces the odds; habits decide them. Four things worth doing alongside any implementation:
Handled this way, the obligations become a property of the system and the routine rather than a task somebody remembers on a Friday afternoon. Centralising candidate and employee records in HR software built for the whole employee lifecycle is what makes that possible, because the controls only work on data the system can actually see.
Compono keeps hiring, engagement and development records in one system with role-based access and retention controls, so privacy obligations are easier to meet and easier to evidence.
Talk to usHR software that gives you the controls needed to meet the General Data Protection Regulation: purpose-specific collection, configurable retention, role-based access, audit logging, and the ability to find, export or erase every record held about one person. The product supplies the controls and the evidence trail; the lawful basis, retention policy and processing records remain the employer's responsibility.
No. Compliance is a property of the organisation, not the product. Software makes the obligations achievable and provides the audit trail, but you still decide the lawful basis for each type of processing, set retention periods, keep records of processing activities and respond to requests within the statutory timeframes.
A well-built system finds every record associated with an individual in one search, then deletes or anonymises them across modules and logs that the request was completed. Ask for a live demonstration on a test record during evaluation, because this is the capability most often described on a website and least often easy to use.
Only as long as there is a stated purpose for holding it, which usually means a defined period after the role closes rather than indefinitely. Set the period deliberately, record the reasoning, and configure the system to enforce it. Indefinite retention of applicant records is one of the most common gaps in HR data practice.
It can. Article 3 gives the regulation extraterritorial reach, so processing the data of people located in the European Union can bring an organisation within scope regardless of where it is based. Australian organisations also have the Privacy Act 1988 and the Australian Privacy Principles, and New Zealand has the Privacy Act 2020. Take professional advice on your specific position.
Usually, though it depends on both parties. Established providers run encryption, monitoring, regular security testing and certified data centres that most mid-sized organisations cannot match internally. The trade-off is that you are relying on someone else's controls, which is why the processing agreement, the sub-processor list, the audit evidence and the exit terms matter as much as the feature list.

Compono Hire helps you predict job-fit and team-fit using behavioural science, so you can shortlist with confidence.
Request a demoBuilt for mid-market hiring teams.

Voice-first coaching that adapts to your personality. Get actionable steps you can take this week.
Start freeBuilt by Compono. Not therapy — practical behaviour change.
What ISO 27001 certification actually covers in HR software, the controls worth verifying, and the questions to put to a vendor holding staff data.
How to use compensation analytics to test pay equity, benchmark against the market, and spot flight risk in the people you cannot afford to lose.
The security features to check before buying HR software: encryption, MFA, granular access controls, data residency and audit trails, explained...