Helia HR

Guide

GDPR for HR data at a small IT company: the practical version

Updated 2026-07-23 · A plain-English working guide for founders and HR at 5–200-person IT teams

What GDPR actually asks of a 20-person employer

There is no small-company exemption: if you employ people in the EU, GDPR applies to their data on day one. For employee data, though, the demands are more mundane than the consultancy industry suggests:

  • A lawful basis you can name. For core HR data — contract, pay, time off, tax IDs — the basis is almost always performing the employment contract or a legal obligation (payroll, tax, labour law). Consent is mostly the wrong tool — more in the FAQ.
  • Minimization. Hold what you need to run employment, not what might someday be interesting. The birthday list is defensible; the "personality notes" column is not.
  • Access rights. People are entitled to know what you hold and get a copy — within a month of asking.
  • Retention with an end. "Forever, in a folder" is not a retention policy. Payroll records carry legal minimums; most other data deserves a written maximum.
  • Security appropriate to the risk. Access control, logging, knowing where the data physically lives.

One note up front: this guide is orientation, not legal advice — national law adds specifics on top of GDPR.

The HR-data map: what you hold, where, who sees it

You can't protect what you haven't listed. One hour, three columns — what, where, who can see it:

What you almost certainly hold: identity and contact details; contracts and salary history; national IDs, permits and bank details; time-off records including sick leave (health-adjacent); performance notes, reviews and 1-on-1 records; candidate CVs from every role you ever opened; and wellbeing data if you survey the team.

Where it actually lives: at most small companies, "several places" — an HR system or master spreadsheet, the accountant's payroll file, and the shadow copies: CVs in inboxes, a salary sheet exported "just for this meeting". The shadow copies are where GDPR problems live — nobody controls or deletes them.

Who can see it: the deciding question. A link-shared spreadsheet has one access level — everyone. Role-gating (HR sees salaries, a manager their team's leave, an employee themselves) is the structural difference between a system and a folder.

The finding is usually the same: the master data is fine; the copies are the problem — the argument for one role-gated system of record.

The five practices that cover 90%

Day-to-day GDPR for employee data comes down to five habits — all boring, all checkable:

  1. Role-gated access with a log. Salary and documents visible to HR and the person, not everyone with a link — and every access leaves a trace. The log deters casual snooping and is your evidence of control if anyone asks.
  2. Retention enforced by the system, not by memory. Decide how long each category lives, write it down, and make deletion mechanical — a cleanup that depends on someone remembering doesn't happen.
  3. Export-on-request in minutes, not weeks. Requests are rare — but assembling the answer by hand from six tools turns a routine request into a project.
  4. Candidate consent and cleanup. Recruiting data is the most-forgotten pile: tell applicants what you store and why, keep a retention end-date, delete on schedule — the recruitment guide covers it end to end.
  5. Processor agreements and knowing where data lives. Every tool that touches employee data on your behalf — HR system, payroll, email — is a processor and needs a data-processing agreement (DPA); EU-hosted data makes the transfer questions dramatically simpler.

Do these five, and the remaining 10% — records of processing, breach basics, national quirks — is an afternoon with counsel, not a crisis.

When an employee asks: "what do you have on me?"

Sooner or later someone asks — from curiosity, in a dispute, or on the way out. It's an Article 15 access request, and you have one month to answer.

The answer has two halves: a copy of their data — profile, contract, pay history, leave, reviews — and the context: what you use it for, who it's shared with (payroll provider, accountant), how long you keep it, and their rights to correction, deletion where applicable, and complaint.

Handled well, it's a non-event: pull the export, walk through it together, correct anything wrong on the spot — rectification is the most common real outcome. Handled badly, it's three weeks of grepping inboxes — signaling exactly the disorder the person suspected.

Two traps. The request covers what you hold, including the shadow copies — one more reason salary sheets shouldn't circulate by email. And other people's data isn't included: a colleague's note about the requester needs care before disclosure — worth a lawyer's ten minutes.

How Helia HR does this

Most of this guide is mechanized in Helia rather than promised:

  • Tenant isolation, EU hosting. Every table is guarded by row-level security — one company's data is structurally separated, not filtered by convention. Data lives in the EU (Frankfurt), and the data-processing agreement is published at /security/dpa for your processor records.
  • Role-gated PII with a visible promise. Sensitive fields on the employee profile are labeled exactly as they behave: "HR-only · access logged." Six roles decide who sees what; reads and writes of personal data land in a GDPR audit log.
  • Export-on-request, built in. A per-employee GDPR export produces a structured file of everything held — profile, compensation history, time off, assignments, reviews, 1-on-1s, exit records, assets, relevant audit entries. Employees can self-serve their own account export, and an organization-wide export means you can leave Helia with everything — portability without lock-in.
  • Deletion and retention that actually run. Personal records are soft-deleted (the audit trail survives); retention runs on its own — mood check-ins, for example, are erased after 12 months.
  • Candidates covered end to end. Careers-page applicants give explicit consent with a 12-month retention window; a nightly job erases CVs and archives candidates past the window; consent can be recorded for hand-added candidates; sourced candidates get an automatic Article 14 notice that their data was collected.
  • Engagement without surveillance. Pulse-survey answers are stored unattributed — identities and answers live in separate tables by design — and results only appear above a minimum response count.

Helia HR provides the tooling and the records; it is not legal advice and does not, by itself, make you compliant. Retention minimums, works-council rules and enforcement practice vary by country — confirm the specifics with qualified counsel where you employ people.

Employee directory in Helia with role-gated PII fields and audit-logged access

FAQ

Do we need a Data Protection Officer at 20 people?

Usually not — a DPO is mandatory only for public authorities, large-scale systematic monitoring, or large-scale special-category processing, which a typical small IT employer doesn't hit. But "no DPO required" doesn't mean "nobody's job": name one owner for privacy questions, and check your national law — some countries add stricter thresholds.

Can we just get employees to consent to everything?

No — and trying weakens your position. Consent must be freely given; an employee facing their employer rarely can refuse freely, so regulators treat blanket employee consent as invalid. Rely on contract and legal obligation for core HR data; save consent for genuinely optional extras, like a photo on the website.

How long should we keep a leaver's file?

There's no single EU answer — payroll and tax records carry national minimums (often years), while data with no legal reason to exist should go much sooner. Set a period per category with your accountant or counsel, write it down, and automate the deletion so the policy is real.

Do rejected candidates' CVs really count?

Fully. Candidate data carries the same rights — and is usually the least-controlled pile in the company. Keep rejected candidates only with a stated retention window (with consent if kept for future roles), and delete on schedule.

Run HR and delivery ops in one system

Helia HR combines the HR basics with the capacity matrix, bench view, timesheets and client invoicing IT services teams actually run on. Start free, no card. GDPR-grade security, role-gated PII, audit-logged access.