Most privacy programmes started with customer data. It was the obvious place to look: the marketing database, the CRM, the website, the consent banners. Employee data was quietly assumed to be simpler, because the organisation had a contract with these people, they were on the payroll, and nobody was selling their details to anyone. That assumption was wrong in almost every way that matters. Employee records are the most sensitive personal data most organisations hold. They are spread across more third parties than customer data. They are subject to retention obligations that conflict directly with deletion rights. And the legal basis most employers reached for first — consent — is the one basis that does not work in an employment relationship. HR outsourcing turned this from a policy problem into an operational one, because the data was not sitting in a single system under the organisation's control. It was sitting with a payroll bureau, a benefits administrator, a recruitment agency, a background screening firm, an occupational health provider, a learning platform, a relocation company and a pension administrator — most of which had been engaged by HR without involving legal, procurement or IT security.
Why consent is the wrong basis, and what replaces it
The logic is straightforward once stated. Consent must be freely given, and it must be as easy to withdraw as to give. Neither condition survives the power imbalance between an employer and an employee. A regulator assessing an employee consent form starts from the presumption that it was not freely given, and if consent is invalid then the processing that relied on it had no lawful basis at all. The bases that actually work are less convenient and considerably more durable. Contractual necessity covers what is genuinely required to employ and pay someone. Legal obligation covers tax, social insurance, labour reporting and statutory record keeping. Legitimate interests cover a range of ordinary operational processing, subject to a documented balancing assessment that weighs the employer's interest against the employee's expectations. And for health and other special category data — which appears across occupational health, sick leave, insurance and accommodation records — there is a separate, narrower set of conditions that must be met in addition to the ordinary basis. The practical consequence is that the employee privacy notice becomes the primary compliance artefact rather than a consent form. It has to describe what is processed, why, on what basis, who receives it and for how long it is kept — which means someone has to know the answers, which is where most organisations discovered they did not.
The vendor map nobody had drawn
Run the exercise properly and the HR processor list is longer than the finance one. A typical mid-sized employer finds somewhere between eight and twenty parties holding employee personal data: payroll processing, benefits and insurance administration, pension or end-of-service schemes, recruitment agencies and job board platforms, background and reference screening, occupational health and medical testing, relocation and immigration support, learning management, engagement survey tools, expense and travel systems, and an HRIS with its own sub-processors. Three characteristics make this population harder to govern than the finance equivalent. It was bought departmentally. Survey tools, learning platforms and screening services are frequently procured on a credit card or a short order form, without a data processing agreement, a security review or a record in the vendor register. It includes the most sensitive categories. Health data, biometric access records, identity documents, salary, bank details, disciplinary records, dependants' details. A breach here has a different harm profile from a marketing list. Recruitment data outlives everything. Applicant records — including from people who were never employed — sit in agency systems and job platforms indefinitely, with no owner and no retention rule, and they are the flows most likely to surface in a complaint.
The retention collision
This is where HR privacy work gets genuinely difficult rather than merely tedious. Deletion rights are qualified, not absolute, and employment data is subject to statutory retention: tax records, payroll records, working time, labour and immigration files, occupational health, and evidence needed to defend a claim within its limitation period. The resolution is not deletion on request; it is a defensible retention schedule per data category, tied to the obligation or the limitation period that justifies it, with deletion actually executed when the period expires. Very few organisations had one, and even fewer executed it — which is why the honest finding of most HR data audits was not "we keep too little evidence" but "we have never deleted anything, including from people who left a decade ago". The hardest part is proving deletion across the vendor chain. A payroll bureau's backups, a screening provider's archive, an agency's candidate database and a former HRIS still under a data retention clause all contain copies, and a deletion request satisfied only in the primary system is not satisfied.
Practical Guidance for HR Vendor Compliance Review
- Inventory every party that touches employee data, including departmentally procured tools. Survey platforms, learning systems and screening services are the most commonly missing entries.
- Replace employee consent forms with a proper basis analysis. Contract, legal obligation and documented legitimate interests carry the weight; consent is fragile and withdrawable.
- Identify special category data explicitly and handle it separately. Health, biometric and disciplinary records need a second condition beyond the ordinary lawful basis.
- Build a retention schedule per category, anchored to a statutory period or a limitation period. Then actually run deletion against it.
- Treat candidate and applicant data as in scope. It is high volume, low ownership and the most frequent source of complaints from people with nothing to lose.
- Make deletion a contractual capability, not a clause. Ask each vendor to describe how they would delete one individual across primaries, backups and archives, and how long it takes.
- Give the employee privacy notice the same care as the customer one. It is the artefact a regulator will ask for first, and it forces the organisation to know its own flows.
- Route new HR tool purchases through a data review. The cheapest control here is a procurement gate, because the problem is created at purchase.
Map every recipient
Include departmental tools, agencies, informal intermediaries and internal shared services.
Assess the purpose and basis
Separate ordinary processing from records requiring additional legal conditions.
Set category-specific retention
Tie retention to applicable obligations and justified limitation periods.
Test deletion across copies
Ask providers to show what happens in primary systems, backups and archives.
Control new flows
Review new HR tools before purchase and make the employee notice reflect actual handling.
Qualitative summary of this article's source text, not a measured outcome or performance estimate.
The Regional Angle
Gulf employers hold a materially heavier employee data set than employers in most other markets, and the structure of regional employment is the reason. Residency is tied to employment, so the employer is an intermediary in a government process rather than merely a payer of salaries. That means the HR file routinely contains passport copies for the employee and dependants, visa and residency documentation, Emirates ID or Iqama numbers, labour cards, medical fitness and screening results, educational certificates with attestation, and in many cases accommodation details. This is a concentration of identity documentation rather than contact details, and the misuse profile is different — identity documents enable impersonation, fraudulent account opening and immigration fraud in ways an email address does not. A breach of a regional HR file is a more damaging event than the same volume of customer records, and very few regional risk registers reflect that. The intermediary layer is the single largest unmapped exposure. PROs, typing centres, visa agents, medical testing centres, recruitment agencies, insurance brokers and attestation services sit between the employer and the government processes, and they receive exactly this document set — frequently by email attachment or messaging app, from an HR administrator's personal device, with no processing agreement and no security assurance. In legal terms they are processors. In practice they are almost never in the vendor register, and a HR vendor compliance review that covers the payroll bureau and the HRIS and stops there has mapped the formal half of the flow while leaving the informal half untouched. The retention collision is sharper here too. Labour and immigration files must be retained under local requirements; end-of-service gratuity calculation depends on a complete service history; WPS and payroll records have their own retention; and where the group has European entities, the same employee's data may be subject to deletion expectations that the local obligation overrides. The answer is jurisdiction-specific schedules rather than a single global rule, and the schedule has to be written by someone who knows both regimes. Two further specifics. Regional data protection regimes have layered onto this rather than replaced it: Saudi PDPL, the UAE federal framework, and the separate DIFC and ADGM regimes each carry their own transfer conditions and rights, so a group with a Dubai head office, a DIFC entity and a Riyadh branch is running three parallel analyses for one HR process. And shared service centres are the most commonly missed scope case in the region — an internal HR service centre in Dubai or Cairo processing employee data for group entities elsewhere is a processor and, where the controller sits in another jurisdiction, a transfer. Nobody thinks of their own subsidiary as a vendor, which is exactly why it never appears on the vendor list.
The objection worth taking seriously
The strongest criticism is that employee privacy compliance has produced a large amount of documentation and very little change in how employees are actually treated. The evidence for it is uncomfortable. Employee privacy notices are long, legalistic and unread. Legitimate interest assessments are written to reach the conclusion the business requires. Retention schedules exist as documents while deletion is never executed, because nobody wants to be the person who destroyed the record that turns out to be needed in a tribunal. Monitoring of employees — email, messaging, device activity, location — has expanded substantially over the same period that privacy frameworks were adopted, which suggests the frameworks were not much of a constraint. And where the employment relationship is genuinely unequal, a set of rights that an employee must assert against their own employer is a weak protection in practice; the people most exposed are the least likely to exercise them. There is a fair counter-argument, and it is about capability rather than principle. The exercise forced organisations to answer questions they had genuinely never asked: which third parties hold our employees' identity documents, how long have we kept records of people who left, who in the organisation can see salary and medical data, and could we delete an individual if we had to. Those answers have value independent of any regulator, because they are the same answers needed for a breach response, a system migration, an outsourcing transition, an insurance application and now an AI deployment. Organisations that treated the work as an operational review of employee data handling got something durable. Organisations that treated it as a notice-drafting exercise got a notice. The defensible position is proportionality with honesty about it: do the small number of things that actually reduce harm — reduce who can see identity documents and medical data, stop sending them by email and messaging app, execute deletion on the oldest records, and put a procurement gate in front of new HR tools — and stop pretending that a longer privacy notice is a control.
Common Questions
Can employee consent ever be used?
Rarely, and only where the employee genuinely loses nothing by refusing — a voluntary benefit, an optional photograph, a non-work social activity. For anything the organisation requires in order to employ, pay or manage the person, consent is the wrong basis and a withdrawal would leave the processing unlawful.
Do we have to delete an ex-employee's records on request?
Not where a statutory retention or limitation period applies, which covers most of the file. The correct response is to explain the basis for retaining what you keep, delete what has no justification, and have a schedule that makes the distinction defensible.
Which HR vendor is most often missed?
The informal ones — recruitment agencies, screening providers, medical testing centres and, in this region, the PROs and typing centres that handle government paperwork. Departmentally purchased survey and learning tools come a close second.
How do AI features in HR systems change this?
They raise the stakes on the two weakest parts of the existing position: basis and retention. Screening, ranking, attrition prediction, sentiment analysis and performance summarisation are all processing of employee data for a new purpose, which needs its own basis and, where decisions are meaningfully automated and significant, additional protections including human involvement and an explanation. Retention gets harder rather than easier, because a model that has been fine-tuned on employee records, or a retrieval index built from HR documents, contains derived copies that a deletion routine written for a database will not reach — and those artefacts are exactly what makes a deletion claim to a regulator untrue. Three things worth doing before enabling any of it: require notification before AI features are switched on over your employee data, state explicitly whether your data can be used for model training or product improvement, and name embeddings, indexes and tuned weights in your deletion terms. The same questions apply to the HR shared service centre building its own retrieval index over employee files, which is where most organisations will meet this first.
HR Vendor Compliance Review — map every party holding identity documents and medical data, then fix retention and deletion before the notice.
