Data Sovereignty / Source date:

Cross-Border HR Data: The Gap Inside Every Global Company

Employee data moves between entities constantly, yet HR transfers receive far less scrutiny than customer data.

Illustrative distinction between detailed employee-record storage and minimal group reporting, with a generic processor-routing register.

Most organizations that spent 2013 worrying about where their customer data lived never examined the data set that was almost certainly more exposed, more sensitive and more widely distributed: their employee records. HR data moves across borders constantly and largely invisibly. A global payroll provider processes salaries in twelve countries from one platform. A human capital management system holds the whole workforce in a single instance hosted in one region. Recruitment data flows to an applicant tracking system. Benefits administration reaches insurers and brokers. Performance and succession data is consolidated for group reporting. Expense claims, travel bookings, learning platforms, engagement surveys, background screening, occupational health — every one of these is a cross-border transfer of personal data about identifiable individuals who did not meaningfully consent and frequently do not know. And the content is unusually sensitive. Salary, bank details, national identity numbers, passport and visa documents, home addresses, dependants, medical information supporting leave and insurance claims, disciplinary records, performance assessments. A breach of this data harms employees directly and personally in a way that a marketing database does not.

The reflex in many HR functions is to put a clause in the employment contract and consider the matter closed. This is one of the more consistent compliance errors in the area. The objection is straightforward: consent must be freely given, and the employment relationship is not one in which an employee can freely refuse. A candidate who declines to consent to overseas processing of their application will not be hired. An employee who withdraws consent to payroll processing cannot be paid. European regulators have been explicit that consent is generally an inappropriate basis in the employment context precisely because of this imbalance, and the same reasoning has been adopted in frameworks modelled on it. The practical consequence is that HR processing needs a different legal basis — performance of the employment contract, compliance with a legal obligation, or legitimate interests where that concept exists — and cross-border transfer needs a separate mechanism of its own. Adequacy, standard contractual clauses, binding corporate rules or a specified derogation. A signed consent clause is not one of them in most cases, and organizations relying on it have documentation that will not survive scrutiny.

The Architecture Problem

The mechanisms are not the hard part. The hard part is that the technology strategy and the compliance requirement point in opposite directions. Every argument in favour of a single global HR system is sound. One instance, one data model, consistent process, group-level analytics, lower cost, simpler integration, a single source of truth for headcount and cost. Fragmented country systems produce reconciliation work, inconsistent definitions and reporting that takes three weeks. Every argument for local processing is also sound. Several jurisdictions require employee data to remain in-country or restrict what may leave. Works councils in parts of Europe have consultation and in some cases veto rights over systems that monitor or evaluate employees. Sector regulators impose their own rules. And the country entity, not the group, is usually the controller with local obligations. The pattern that works is a deliberate split rather than a winner. Transactional and detailed personal data — payroll calculation, identity documents, medical records, disciplinary files — processed locally or regionally where the requirement demands it. Aggregated, pseudonymised or minimal-field data — headcount, cost, structure, aggregate turnover, banded compensation — consolidated centrally for group reporting. Most organizations transfer far more than group reporting actually needs, because the system was designed to hold everything and nobody asked what the centre required.

What Is Usually Missing

Nobody has mapped the flows. The HR data inventory is the most commonly absent artefact in this area. Organizations know about the HCM system and the payroll provider, and routinely miss the background screening vendor, the relocation agency, the visa processing intermediary, the benefits broker, the engagement survey tool a regional HR manager licensed independently, and the spreadsheet of salary data emailed to a consultant. Transparency to employees is thin. Privacy notices to employees are frequently shorter and vaguer than those given to customers, which is the wrong way round given the sensitivity of the data. Employees are entitled to know what is held, why, where it goes and for how long. Retention is unlimited by default. HR systems accumulate. Records of applicants who were not hired, employees who left a decade ago, dependants no longer covered. Retention periods differ by country and by record type — some records must be kept for statutory periods, others must be deleted — and almost nobody enforces this in the system. Access rights inside HR are too broad. Regional HR staff frequently have visibility across countries they have no responsibility for. Salary data is accessible to people who do not need it. Manager self-service configurations expose more than intended. This is the most common finding in any HR system access review. Subject access requests from employees are unprepared for. They arrive, frequently in the context of a dispute or a termination, and the organization discovers it cannot assemble a complete picture of what it holds about one person across a dozen systems within the statutory window. And works council consultation is discovered late. In several European jurisdictions, deploying a system that evaluates or monitors employees requires consultation, and doing it after the contract is signed is expensive.

Practical Guidance for HR Data Compliance

  • Map every HR data flow including the small vendors. Screening, relocation, visa processing, brokers, survey tools and locally licensed applications are where the unmapped transfers are.
  • Stop relying on employment-contract consent. Establish a proper legal basis for processing and a separate documented mechanism for each cross-border transfer.
  • Split transactional from analytical data deliberately. Process detailed records locally where required; consolidate only aggregated or pseudonymised data centrally.
  • Minimise what leaves the country. Ask what the group actually needs for reporting; it is usually far less than what is currently transferred.
  • Enforce retention in the system, by country and record type. Manual retention policy is not retention policy.
  • Review HR system access by geography and role. Cross-country visibility for regional staff is the standard over-permissioning pattern.
  • Give employees a real privacy notice and a workable rights process. Rehearse a subject access request before you receive a contentious one.
  • Involve works councils and employee representatives before contracting. Consultation obligations do not disappear because the system is already purchased.

The Regional Dimension

In the Gulf, HR data carries requirements and sensitivities that most global HR templates do not anticipate. Immigration and identity documentation is central to the record. Passport copies, visa pages, Emirates ID, labour cards, entry permits, medical fitness certificates and dependants' documentation are held as a matter of operational necessity for essentially the whole expatriate workforce. This is high-sensitivity personal data, held in volume, frequently duplicated across HR systems, shared drives, email and the files of external PRO service providers. Government intermediaries are a material processor risk. PRO and government relations firms handling visa processing, labour contract registration and licensing hold complete identity document sets for the workforce. They are frequently small firms, rarely subject to any security review, and almost never covered by a processor agreement with proper terms. This is one of the clearest unaddressed exposures in regional HR operations. Payroll is jurisdictionally constrained by construction. Wage protection system submission in the UAE and Saudi Arabia, GOSI contributions, end-of-service gratuity calculation and per-entity statutory reporting mean payroll data has hard local processing requirements regardless of where the HCM sits. A global payroll platform has to accommodate local submission mechanics rather than replace them. Transfer rules now apply formally. Under the UAE data protection framework and Saudi PDPL, moving employee data outside the jurisdiction requires an adequacy determination, appropriate safeguards or a specified exception, and both regimes impose controller obligations around notice, security and breach handling. DIFC and ADGM entities operate under their own data protection laws with their own transfer mechanisms — so a group with entities inside and outside the financial free zones has multiple regimes governing one workforce. Employment-linked residency makes accuracy consequential. Errors in employee data do not just produce a payroll correction; they can affect visa status, dependant sponsorship and the right to remain. Data quality in HR systems here has consequences that go well beyond administrative inconvenience. Bilingual records create duplication and matching problems. Names transliterated inconsistently between Arabic and English produce duplicate employee records, mismatches against government portal submissions and failures in automated reconciliation. This is a persistent operational issue and a data protection one, because a duplicate record means an incomplete deletion and an incomplete subject access response. And multi-entity structures fragment controllership. A group with entities across mainland UAE, several free zones, Saudi Arabia, Qatar and Egypt has a separate employing entity in each, each with local obligations. Group HR operating a single system is processing on behalf of multiple controllers, which needs to be documented as such.

What Has Changed

The direction of travel since 2013 has been toward more regulation, not less. Comprehensive data protection frameworks have been adopted across the region and worldwide, transfer mechanisms between major jurisdictions have been invalidated and rebuilt more than once, and employee data has attracted specific regulatory attention because the consent problem makes it a distinct category. Two newer developments are worth flagging. Remote and cross-border working arrangements have created a category of employee whose data is processed in a country where the employer has no establishment, which raises questions about applicable law that most HR functions have not worked through. And AI in HR is now the fastest-moving exposure: automated CV screening, attrition prediction, performance analytics, productivity monitoring and increasingly assistants with access to the entire HR record. These attract specific regulatory treatment. Several frameworks classify employment-related automated decision-making as high risk, with requirements around transparency, human review, bias assessment and the right to contest a decision. An assistant with access to the HR system inherits its permission model, which means years of over-broad access becomes queryable in natural language by anyone entitled to use it. The 2013 question was where the data is. The current question is who and what can read it, what decisions are being made from it, and whether the employee has any visibility into either. HR functions that never completed the first exercise are poorly placed to answer the second.

Common Questions

Because consent must be freely given and the employment relationship involves a power imbalance that makes genuine refusal impractical. Regulators have been explicit that consent is generally inappropriate in employment contexts; contractual necessity, legal obligation or legitimate interests are the usual alternatives, with a separate mechanism required for cross-border transfer.

Should HR data be held in one global system or locally?

Neither exclusively. Detailed transactional data — payroll, identity documents, medical records, disciplinary files — should be processed locally or regionally where regulation requires. Aggregated or pseudonymised data sufficient for group reporting can be consolidated centrally. The split should be deliberate rather than accidental.

What is the most commonly missed HR data flow?

Small vendors: background screening providers, relocation agencies, visa and PRO intermediaries, benefits brokers, and tools licensed locally by regional HR teams. The main HCM and payroll platforms are always mapped; these rarely are.

What is specific to the Gulf?

The volume and sensitivity of immigration documentation held for expatriate workforces, PRO intermediaries acting as unmanaged processors, jurisdictionally fixed payroll submission requirements, multiple applicable regimes across mainland, free-zone and financial-free-zone entities, and bilingual name records causing duplication and incomplete deletion.


HR Data Compliance Review — Outpace maps where your employee data actually goes, fixes the basis it travels on, and closes the vendors nobody reviewed.

Continue reading

Talk to OPS

Start with the operating problem.