What data security and GDPR standards should an HR system meet?

S

By Stephanie Coward

Managing Director, HCM

There is no UK GDPR certification scheme for HR software.

That said, your HR software should support compliance, not make it harder, helping you maintain data security and adhere to UK GDPR standards, such as those laid out in Article 5 and Article 32.

This can make buying HR software harder; there’s no badge to look out for, and instead you must ascertain whether the functionality can support data security and UK GDPR.

This guide sets out the standards HR software should meet, covering the retention periods that apply to UK employment records, what security certifications to look out for and the questions that establish whether a system meets the standard.

Why GDPR-certified HR software doesn’t exist

With UK GDPR, the obligation is on the data controller.

From an HR perspective, employee data is the main area you need to be aware of in relation to UK GDPR, making the employer the data controller in this scenario.

As such, your HR software vendor is a processor acting on your instructions and can’t transfer those obligations onto itself.

This is why, despite using the same HR system, some businesses will be compliant while others won’t.

So, while the onus is on the employer to ensure compliance, this doesn’t mean that HR software has no role to play.

The data security features within an HR system should support your processes.

Three areas to assess when looking at HR software include:

  • Accreditations that evidence a managed approach to security
  • Contractual commitments in the data processing agreement
  • Specific system capabilities, such as access controls, audit trails, retention rules and data extraction

UK GDPR principles that apply to an HR system

UK GDPR Article 5 outlines seven principles, each something an HR system either supports or obstructs.

  • Lawfulness, fairness and transparency: you need a lawful basis for every category of employee data you collect and be completely open about what you are doing with the information. 
  • Purpose limitation: you must specify why you’re collecting the data and only use it for that exact reason.
  • Data minimisation: only collect the data you genuinely need.
  • Accuracy: data must be accurate and up to date, and mistakes must be fixed or deleted quickly. 
  • Storage limitation: you should not hold onto personal data any longer than necessary for your original purpose. 
  • Integrity and confidentiality: data must be kept secure using proper technical and organisational safeguards to prevent breaches, theft or loss.
  • Accountability: it’s your responsibility to comply with these rules, and you must be able to prove compliance with records and policies.

A point worth focusing on because it’s so often got wrong is that consent is rarely the right lawful basis for employee data.

Consent must be freely given.

But the imbalance of power in an employment relationship means it’s usually not.

Instead, most employee data sits in one of these other lawful bases:

  • Contractual necessity: you need the data to employ the person, for example, bank details to pay them or a home address to send a contract.
  • Legal obligation: the law requires you to hold it, including right-to-work evidence, payroll records for HMRC and pension enrolment records.
  • Legitimate interests: you have a genuine business reason that does not override the employee’s own rights, which could be reviewing absence patterns to manage workload, provided you have assessed and recorded that reasoning.
  • Recognised legitimate interest: added on 5 February 2026, covering a closed list of public interest purposes such as safeguarding or crime prevention, so it rarely applies to everyday HR data.

Most HR data falls into the first two bases.

Consent is best kept for things an employee can genuinely decline without consequence, such as using their photograph on the website or joining an optional benefit scheme.

In practical terms, what this means is that an HR system that asks employees to consent to core processing is solving the wrong problem.

What the HR system should do instead is let you record the lawful basis against each category of data you hold, so you can evidence the decision later.

Lizzy Barry, HR Director at IRIS Software Group, told us:  “I once heard about a payroll manager who was organising the Christmas party and accidentally sent out the final payroll file to the entire Christmas party invite list. Horrendous and possibly one of the worst things they could have done.”

UK GDPR technical and organisational measures

UK GDPR Article 32 requires the use of proper technical and organisational steps to keep data safe.

In an HR context, that means features such as:

  • Data encryption in transit and at rest, covering backups as well as live data.
  • Role-based access control, restricting HR data at a field level as well as record level, so users only see what their role requires.
  • Multi-factor authentication (MFA) and single sign-on (SSO) to add an extra layer of security.
  • Audit trails of who viewed and changed what, and when, with a defined log retention period.
  • Data backups, which are tested regularly, and the provider states how fast they can restore your system and how much recent data could be lost.
  • Breach detection and notification, with the 72-hour reporting obligation to the ICO in mind – your vendor needs to tell you fast enough for you to meet it.
  • Penetration testing and vulnerability management, with a stated cadence.
  • Secure development and change management, ensuring any software updates don’t quietly widen access.
  • Internal access offboarding, which also covers the vendor’s own staff.

HR data incidents are often access-control failures rather than external attacks.

This could be:

  • Managers who can still see a team they moved away from eighteen months ago.
  • Manually sending data files across via a vulnerable method such as email.
  • A leaver account staying live.

Encryption is necessary and gets the most attention, but data access is often where the recurring risk sits.

UK GDPR special category data in HR systems

Some of an organisation’s most sensitive data sits in HR, attracting extra requirements under Article 9.

Article 9 protects information revealing or concerning:

  • Racial or ethnic origin
  • Political opinions
  • Religious or philosophical beliefs
  • Trade union membership
  • Genetic data
  • Biometric data used to uniquely identify a person
  • Health data
  • Sex life or sexual orientation

The golden rule of Article 9 in employment is purpose limitation.

You can’t collect sensitive data ‘just in case’.

Every sensitive field in an HR database must map directly to a legal obligation under UK employment law or a vital health and safety requirement.

Absence records are the category most often overlooked, because they sit inside everyday workflows.

For example, a return-to-work note recorded by a line manager is health data, and it shouldn’t be visible to everyone with access to the absence module.

The ICO has published specific guidance on handling workers’ health information, which is worth reading alongside its general employment guidance.

How an HR system supports data subject rights

Both employees and former employees can exercise rights to:

  • Access
  • Rectification
  • Erasure
  • Restriction
  • Portability
  • Objection

When looking at HR software, a useful way to think about this is as a system capability rather than a legal topic.

If a subject access request arrives, can you carry out a reasonable and proportionate search of everything you hold about the person, and produce it within the statutory deadline?

That question is harder than it looks.

Employee data is typically split across areas in HR; a single person may have records in recruitment, core HR, payroll, performance and learning.

All of these areas capture personal data.

Candidate notes, appraisal comments, capability records and training histories carry the same rights as a payslip.

This scenario emphasises the importance of having a shared employee record in your HR system.

Separate systems joined by spreadsheets make subject access requests a manual exercise, creating a real risk of you missing something.

Whereas a single employee record that connects the different areas of HR makes answering a subject access request far easier.

Data retention and storage limitation

Many organisations struggle with data retention and storage limitation because it requires someone to manually decide and configure it.

UK employment records carry a range of retention periods, with several changing in 2026.

Record typeRetention periodSource
Right to work check evidenceDuration of employment, plus two years after it ends.Home Office, Employer’s guide to right to work checks (26 June 2025)
Annual leave and holiday pay recordsSix years from the date each record was made.Working Time Regulations 1998, reg 16B (inserted by Employment Rights Act 2025), in force 6 April 2026
Unsuccessful candidate recordsNo statutory period. Commonly set at 6 to 12 months, aligned to the tribunal claim window.No statutory requirement. Reflects the tribunal claim window under the Employment Rights Act 2025, s.152 and Sch.12 (in force 1 October 2026).
Payroll records (PAYE)Three years after the end of the tax year they relate to.Income Tax (PAYE) Regulations 2003, reg 97 (SI 2003/2682)
Pension auto-enrolment recordsSix years, except opt-out notices, which are four years.Pensions Act 2008; The Pensions Regulator, Detailed guidance 9: Keeping records

Issues with data retention regularly crop up when multiple systems which don’t integrate are used.

If leavers’ records are deleted in HR but remain in other platforms, like learning or payroll, you’ve not met the storage limitation.

A transitional point worth flagging on candidate data.

The tribunal claim window will be extended from three months to six months on 1 October 2026, but only where the relevant date falls on or after that day.

Claims arising before then keep the three-month limit.

As such, there will be a period where both windows are live, and a single six-month retention rule will be over-cautious for older applications rather than wrong.

Security certifications: what they do and don’t prove

Certifications are useful evidence for a vendor’s commitment to data security.

It’s worth being aware of what each one covers.

CertificationWhat it evidencesWhat it doesn’t evidence
ISO 27001An independently audited information security management system within a defined scope.That your own configuration, access grants or retention settings are compliant.
ISO 9001A quality management system covering documented processes, defined responsibilities and continual improvement, within a stated scope.Anything about security or data protection. It’s a quality standard, not an information security one.
Cyber Essentials and Cyber Essentials PlusBaseline technical controls in five areas. Standard certification is a self-assessment reviewed by a licensed certification body. Plus adds hands-on testing of live systems.Anything about data processing terms, sub-processors or where data is held.
SOC 2 Type IIThat defined controls operated effectively across a period, not just on one day.UK GDPR compliance specifically. It’s a US attestation framework.

None of these is a UK GDPR certification, and there is currently no ICO-approved UK GDPR certification scheme covering HR software.

Rather, the value of these certifications is that they evidence that a vendor approaches security deliberately rather than informally.

Two things to check on any certificate you are shown:

  • Whether the certificate covers the specific platform you’re buying, as it may cover one platform or data centre and not the product you are buying.
  • Whether the certification is still in date and not lapsed.

What to ask your HR software vendor

When assessing an HR software vendor, ask these questions:

  • Where is data stored, and does any of it leave the UK?
  • Who are your sub-processors, and how are we notified when that list changes?
  • What does your standard data processing agreement commit you to?
  • Can you provide your ISO 27001 or Cyber Essentials certificate?
  • Can access be restricted, and is this at field level or only at record level?
  • What is captured in audit trails, and does this include read access?
  • How long are audit trail logs retained?
  • How do retention rules delete data, who can configure them and what happens to linked modules?
  • Can we export everything held about one individual across every module and connected system?
  • What is your breach notification process, and how quickly will you tell us?
  • When was your last penetration test, and will you share the summary?

How does IRIS approach HR data security?

IRIS Cascade and Staffology HR both feature a range of data security capabilities to help you comply with UK GDPR.

  • Access controls: IRIS Cascade and Staffology HR apply role-based permissions, so salary, sickness and disciplinary records are visible only to the people who need them.
  • Audit trails: IRIS Cascade and Staffology HR timestamp changes and approvals against the employee record, so you can show who did what and when.
  • Retention: IRIS Cascade and Staffology HR support configurable retention periods, so data is removed when it expires rather than accumulating indefinitely.
  • Subject access requests: IRIS Cascade and Staffology HR hold HR records against a single employee record, so the data they hold can be located and exported rather than assembled by hand.
  • Right-to-work and document expiry: IRIS Cascade and Staffology HR can be configured to hold right-to-work documentation, visa expiry dates and professional certifications against the employee record, with automated renewal reminders.
  • Breach investigation: access logs within IRIS Cascade and Staffology HR help you establish what was accessed, by whom and when.
  • Accreditation: IRIS Cascade and Staffology HR hold ISO 27001 and Cyber Essentials certifications for information security, alongside ISO 9001 for quality management.

One caveat applies to any vendor, including us.

Where recruitment or learning data sits in a connected system, those records form part of a subject access response too.

Ask what a single export actually covers before you rely on it.

For more information on UK workforce compliance, check out our guide.

This blog is general guidance and not legal or tax advice. Every effort has been made to ensure the content is accurate at the time of writing, but details are subject to change. If you require legal advice, please consult a qualified professional.

Data security and GDPR standards for HR systems

Frequently asked questions (FAQs)

At minimum, your HR system should offer: data encryption, role-based access controls, multi-factor authentication, audit trails and tested backups. Certifications such as ISO 27001 also evidence a commitment to cyber security.

No, there is no GDPR-certified HR software. UK GDPR places obligations on the employer as data controller, not on the software. A vendor can support or hinder compliance, but can’t outright provide it.

What you can assess are:

  • Security accreditations
  • Contractual commitments
  • Specific capabilities around access, retention and extraction

HR records that can be classified as special category data include:

  • Health records
  • Sickness absence reasons
  • Occupational health reports
  • Disability and adjustment records
  • Trade union membership
  • Equality monitoring data such as ethnicity or religion

It varies by record type. Right to work evidence is kept for the duration of employment plus two years. Annual leave and holiday pay records must be kept for six years from the date each record was made. There is no statutory period for unsuccessful candidate data, though many organisations keep it for 6 to 12 months to cover the tribunal claim window.

No, UK GDPR does not require UK-only storage. However, transfers outside the UK need an adequate safeguard. Many organisations seeking HR software still specify UK data residency, which is a procurement choice rather than a legal requirement.

A data processing agreement should cover:

  • Purpose and scope of processing
  • Security measures
  • Sub-processor use and notification of changes
  • Breach notification timescales
  • Audit and inspection rights
  • International transfer safeguards
  • What happens to your data at the end of the contract, including deletion or return

Stephanie Coward

Managing Director, HCM

Stephanie Coward is Managing Director for HCM at IRIS, where she leads the strategy, innovation and growth of the organisation’s HR and payroll portfolio. She is responsible for positioning IRIS as a trusted partner to HR professionals and ensuring its solutions support the evolving needs of modern workforces.

With more than 25 years’ experience in the technology sector, Stephanie brings deep commercial and operational expertise, with a passion for improving the employee experience through technology.

Stephanie is committed to advancing IRIS’ HCM offering and helping organisations build more resilient, empowered workforces.