A RoPA for HR processing is the part of your record of processing activities that documents how the organization handles the personal data of job applicants, employees, contractors and former staff. HR is often the most data-heavy function in a company and one of the most sensitive, since it holds payroll, health, performance and disciplinary information, yet its records are frequently the least complete part of the RoPA.
This guide explains what Article 30 requires, how to break HR into separate processing activities, what to record for each, where special category data and monitoring fit, and how to keep the record accurate as systems and suppliers change.
What Article 30 requires for HR records
Article 30 of the GDPR requires controllers to keep a record of processing activities under their responsibility. The record must include the controller’s identity and contact details, the purposes of the processing, a description of the categories of data subjects and personal data, the categories of recipients, transfers to third countries with the safeguards used, where possible the time limits for erasure, and where possible a general description of technical and organizational security measures. The UK Information Commissioner’s Office sets out its expectations in its guidance on documentation.
Article 30(5) exempts organizations with fewer than 250 employees, but only if the processing is occasional, is unlikely to result in a risk to individuals and does not involve special categories of data. Regular payroll and staff administration is not occasional, and HR files often include health data, so most employers cannot rely on the exemption for HR. Our guide to the RoPA exemption explains the conditions in detail.
Splitting a RoPA for HR processing into activities
A single entry called HR is too broad to be useful. Regulators expect records at the level of a distinct purpose, and the practical way to get there is to follow the employment lifecycle. Each of the activities below usually has a different purpose, lawful basis, set of recipients and retention period.
| Activity | Typical data | Typical recipients |
|---|---|---|
| Recruitment | CV, contact details, interview notes, references, right-to-work checks | Recruitment agency, applicant tracking provider |
| Onboarding and employment contract | Identity, address, bank details, emergency contact, contract | HR system provider, payroll provider |
| Payroll and tax | Pay, tax codes, deductions, bank details | Payroll provider, tax authority |
| Benefits and pensions | Salary, dependants, beneficiary details | Pension provider, insurer, benefits platform |
| Absence and health | Sickness records, fit notes, adjustments | Occupational health provider |
| Performance and development | Appraisals, training records, objectives | Learning platform, line managers |
| Discipline and grievance | Allegations, investigation notes, outcomes | Legal advisers, panel members |
| Equal opportunities monitoring | Ethnicity, disability, gender data, where collected | HR analytics, regulators |
| Leavers and references | Dates, role, exit interview notes | Prospective employers, archiving provider |
Free ROPA template and builder
Could you hand your records of processing to a regulator tomorrow?
Check whether Article 30 applies to you, add your processing activities from a library organized by department, complete every Article 30 content, and see which activities are missing a lawful basis, a transfer safeguard, a DPIA or an LIA. Free, with a record score and findings.
What to record in a RoPA for HR processing
For each activity, complete the same set of fields so that entries can be compared and reviewed. Keep the language plain and specific.
- Purpose. State the specific reason, such as paying employees or assessing candidates for a role.
- Lawful basis. Contract for payroll, legal obligation for tax and right-to-work checks, legitimate interests for some analytics and monitoring. Consent is rarely appropriate in employment because of the imbalance of power.
- Categories of data subjects. Applicants, employees, contractors, dependants, referees, emergency contacts.
- Categories of data. Identity, contact, financial, employment, performance and, separately, special category data.
- Recipients. Internal teams with access, and each external processor or independent controller.
- Transfers. Any transfer outside the EEA or UK, such as a global HR platform, with the transfer tool.
- Retention. A period for each record type, linked to a schedule.
- Security measures. A summary of access controls, encryption and other safeguards.
Handling special category and criminal data
Health data, trade union membership, ethnicity, religion and biometric data are special categories under Article 9, and each needs both an Article 6 basis and an Article 9 condition. For employment, the condition is commonly that processing is necessary to carry out obligations and exercise rights in the field of employment law, but you should record the actual condition you rely on. Criminal record checks are governed by Article 10 and national law. Record them as a separate activity with the legal basis for the check, since they are only permitted in specific circumstances and roles.
Recording processors and international transfers
HR runs on suppliers: payroll bureaus, applicant tracking systems, benefits platforms, learning systems, occupational health providers and cloud HR suites. List each one against the activities it supports, and note whether it acts as a processor or as an independent controller. Occupational health doctors and pension trustees are often controllers in their own right. Our guide to controller and processor entries in the RoPA explains how to record each role.
Global HR systems frequently involve transfers to the United States or India, either for hosting or for support access. Record the location of the data and of any remote access, and the transfer tool relied on. See international transfers in the RoPA for the fields to capture.
Retention periods in a RoPA for HR processing
Different records need different periods, and some are set by law. Payroll and tax records are kept for the period set by tax law. Unsuccessful applicant data should be kept only for a limited period, commonly six to twelve months, with the reason recorded. Disciplinary records often expire after a warning period. Health and safety records may need long retention. Do not keep everything indefinitely, and do not invent periods without a reason. Our guide to RoPA retention periods shows how to document the basis of each period.
Monitoring and analytics in the record
Employee monitoring, such as email screening, badge tracking, vehicle telematics, productivity software and CCTV, needs its own entries. Each has a different purpose, a different risk and often a different lawful basis. Where monitoring is intrusive, a DPIA is likely to be needed. Our article on legitimate interests and employee monitoring explains how to balance the interests involved. Record HR analytics too, such as attrition prediction or pay gap analysis, especially if the outputs feed decisions about individuals.
Who provides information for a RoPA for HR processing
HR staff know the processes but not always the systems, and IT teams know the systems but not the reasons. Run a short workshop with HR, payroll, IT and legal together, and validate the draft with the people who actually use the systems. Compare the results with the list of HR applications, the supplier contracts and the privacy notice for employees, which should tell the same story as the RoPA. Differences are findings to fix.
A short worked example
For payroll, an entry might read: purpose, paying employees and meeting tax obligations; basis, performance of the employment contract and legal obligation; data subjects, employees; data, name, employee number, address, bank details, salary, tax code and deductions; recipients, the payroll provider acting as processor and the tax authority as a recipient under law; transfers, none outside the UK and EEA; retention, the period required by tax law after the end of the tax year; security, role-based access, encryption and multi-factor authentication. Each field can be checked against evidence, which makes the entry useful for audits, for access requests and for incident response.
Keeping the RoPA for HR processing current
Review the HR entries, including any new starter or leaver tooling, when you change systems, add a supplier, start a new type of monitoring or change a policy, and at least annually. Ask the HR system owner to notify you of changes, and check the record against the supplier list. Our guide to the RoPA review process shows how to set the cycle and owners.
Using a ready structure
To avoid starting with a blank sheet, the RoPA Report and Workbook provides a structured report and a working register that you can populate with HR activities. You can also see completed entries in our RoPA example. Either way, a RoPA for HR processing should be specific enough that a new HR manager could read it and understand how staff data flows through the business.
RoPA for HR processing FAQ
Do I need a RoPA for HR data?
Yes, in most cases. The small-organization exemption does not apply where processing is regular, involves special category data or is likely to be risky, and HR processing usually meets at least one of those conditions.
Should HR be one entry or several?
Several. Split it by purpose along the employment lifecycle, such as recruitment, payroll, benefits, absence, performance and leavers, because each has different recipients and retention.
Can I rely on consent for employee data?
Rarely. Because of the imbalance between employer and employee, consent is often not freely given. Contract, legal obligation and legitimate interests are the more usual bases, with an Article 9 condition for special categories.
Are recruitment agencies and payroll providers processors?
Payroll providers usually are. Recruitment agencies are often independent controllers for their own candidates. Record the role after looking at who decides the purposes and means.
How long should applicant data be kept?
Only as long as needed, commonly six to twelve months after a decision, unless the person agrees to be kept on file. Record the period and the reason.