Guide
Updated 2026-07-23 · A plain-English working guide for founders and HR at 5–200-person IT teams
There is no small-company exemption: if you employ people in the EU, GDPR applies to their data on day one. For employee data, though, the demands are more mundane than the consultancy industry suggests:
One note up front: this guide is orientation, not legal advice — national law adds specifics on top of GDPR.
You can't protect what you haven't listed. One hour, three columns — what, where, who can see it:
What you almost certainly hold: identity and contact details; contracts and salary history; national IDs, permits and bank details; time-off records including sick leave (health-adjacent); performance notes, reviews and 1-on-1 records; candidate CVs from every role you ever opened; and wellbeing data if you survey the team.
Where it actually lives: at most small companies, "several places" — an HR system or master spreadsheet, the accountant's payroll file, and the shadow copies: CVs in inboxes, a salary sheet exported "just for this meeting". The shadow copies are where GDPR problems live — nobody controls or deletes them.
Who can see it: the deciding question. A link-shared spreadsheet has one access level — everyone. Role-gating (HR sees salaries, a manager their team's leave, an employee themselves) is the structural difference between a system and a folder.
The finding is usually the same: the master data is fine; the copies are the problem — the argument for one role-gated system of record.
Day-to-day GDPR for employee data comes down to five habits — all boring, all checkable:
Do these five, and the remaining 10% — records of processing, breach basics, national quirks — is an afternoon with counsel, not a crisis.
Sooner or later someone asks — from curiosity, in a dispute, or on the way out. It's an Article 15 access request, and you have one month to answer.
The answer has two halves: a copy of their data — profile, contract, pay history, leave, reviews — and the context: what you use it for, who it's shared with (payroll provider, accountant), how long you keep it, and their rights to correction, deletion where applicable, and complaint.
Handled well, it's a non-event: pull the export, walk through it together, correct anything wrong on the spot — rectification is the most common real outcome. Handled badly, it's three weeks of grepping inboxes — signaling exactly the disorder the person suspected.
Two traps. The request covers what you hold, including the shadow copies — one more reason salary sheets shouldn't circulate by email. And other people's data isn't included: a colleague's note about the requester needs care before disclosure — worth a lawyer's ten minutes.
Most of this guide is mechanized in Helia rather than promised:
Helia HR provides the tooling and the records; it is not legal advice and does not, by itself, make you compliant. Retention minimums, works-council rules and enforcement practice vary by country — confirm the specifics with qualified counsel where you employ people.

Usually not — a DPO is mandatory only for public authorities, large-scale systematic monitoring, or large-scale special-category processing, which a typical small IT employer doesn't hit. But "no DPO required" doesn't mean "nobody's job": name one owner for privacy questions, and check your national law — some countries add stricter thresholds.
No — and trying weakens your position. Consent must be freely given; an employee facing their employer rarely can refuse freely, so regulators treat blanket employee consent as invalid. Rely on contract and legal obligation for core HR data; save consent for genuinely optional extras, like a photo on the website.
There's no single EU answer — payroll and tax records carry national minimums (often years), while data with no legal reason to exist should go much sooner. Set a period per category with your accountant or counsel, write it down, and automate the deletion so the policy is real.
Fully. Candidate data carries the same rights — and is usually the least-controlled pile in the company. Keep rejected candidates only with a stated retention window (with consent if kept for future roles), and delete on schedule.
Helia HR combines the HR basics with the capacity matrix, bench view, timesheets and client invoicing IT services teams actually run on. Start free, no card. GDPR-grade security, role-gated PII, audit-logged access.