Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

RoPA for HR processing table of recruitment payroll benefits and absence with purposes and retention

RoPA for HR Processing Guide 2026

A RoPA for HR processing is the part of your record of processing activities that documents how the organization handles the personal data of job applicants, employees, contractors and former staff. HR is often the most data-heavy function in a company and one of the most sensitive, since it holds payroll, health, performance and disciplinary information, yet its records are frequently the least complete part of the RoPA.

This guide explains what Article 30 requires, how to break HR into separate processing activities, what to record for each, where special category data and monitoring fit, and how to keep the record accurate as systems and suppliers change.

What Article 30 requires for HR records

Article 30 of the GDPR requires controllers to keep a record of processing activities under their responsibility. The record must include the controller’s identity and contact details, the purposes of the processing, a description of the categories of data subjects and personal data, the categories of recipients, transfers to third countries with the safeguards used, where possible the time limits for erasure, and where possible a general description of technical and organizational security measures. The UK Information Commissioner’s Office sets out its expectations in its guidance on documentation.

Article 30(5) exempts organizations with fewer than 250 employees, but only if the processing is occasional, is unlikely to result in a risk to individuals and does not involve special categories of data. Regular payroll and staff administration is not occasional, and HR files often include health data, so most employers cannot rely on the exemption for HR. Our guide to the RoPA exemption explains the conditions in detail.

Splitting a RoPA for HR processing into activities

A single entry called HR is too broad to be useful. Regulators expect records at the level of a distinct purpose, and the practical way to get there is to follow the employment lifecycle. Each of the activities below usually has a different purpose, lawful basis, set of recipients and retention period.

ActivityTypical dataTypical recipients
RecruitmentCV, contact details, interview notes, references, right-to-work checksRecruitment agency, applicant tracking provider
Onboarding and employment contractIdentity, address, bank details, emergency contact, contractHR system provider, payroll provider
Payroll and taxPay, tax codes, deductions, bank detailsPayroll provider, tax authority
Benefits and pensionsSalary, dependants, beneficiary detailsPension provider, insurer, benefits platform
Absence and healthSickness records, fit notes, adjustmentsOccupational health provider
Performance and developmentAppraisals, training records, objectivesLearning platform, line managers
Discipline and grievanceAllegations, investigation notes, outcomesLegal advisers, panel members
Equal opportunities monitoringEthnicity, disability, gender data, where collectedHR analytics, regulators
Leavers and referencesDates, role, exit interview notesProspective employers, archiving provider

Free ROPA template and builder

Could you hand your records of processing to a regulator tomorrow?

Check whether Article 30 applies to you, add your processing activities from a library organized by department, complete every Article 30 content, and see which activities are missing a lawful basis, a transfer safeguard, a DPIA or an LIA. Free, with a record score and findings.

Build your free ROPA →  or  View premium report sample

What to record in a RoPA for HR processing

For each activity, complete the same set of fields so that entries can be compared and reviewed. Keep the language plain and specific.

  • Purpose. State the specific reason, such as paying employees or assessing candidates for a role.
  • Lawful basis. Contract for payroll, legal obligation for tax and right-to-work checks, legitimate interests for some analytics and monitoring. Consent is rarely appropriate in employment because of the imbalance of power.
  • Categories of data subjects. Applicants, employees, contractors, dependants, referees, emergency contacts.
  • Categories of data. Identity, contact, financial, employment, performance and, separately, special category data.
  • Recipients. Internal teams with access, and each external processor or independent controller.
  • Transfers. Any transfer outside the EEA or UK, such as a global HR platform, with the transfer tool.
  • Retention. A period for each record type, linked to a schedule.
  • Security measures. A summary of access controls, encryption and other safeguards.

Handling special category and criminal data

Health data, trade union membership, ethnicity, religion and biometric data are special categories under Article 9, and each needs both an Article 6 basis and an Article 9 condition. For employment, the condition is commonly that processing is necessary to carry out obligations and exercise rights in the field of employment law, but you should record the actual condition you rely on. Criminal record checks are governed by Article 10 and national law. Record them as a separate activity with the legal basis for the check, since they are only permitted in specific circumstances and roles.

Recording processors and international transfers

HR runs on suppliers: payroll bureaus, applicant tracking systems, benefits platforms, learning systems, occupational health providers and cloud HR suites. List each one against the activities it supports, and note whether it acts as a processor or as an independent controller. Occupational health doctors and pension trustees are often controllers in their own right. Our guide to controller and processor entries in the RoPA explains how to record each role.

Global HR systems frequently involve transfers to the United States or India, either for hosting or for support access. Record the location of the data and of any remote access, and the transfer tool relied on. See international transfers in the RoPA for the fields to capture.

Retention periods in a RoPA for HR processing

Different records need different periods, and some are set by law. Payroll and tax records are kept for the period set by tax law. Unsuccessful applicant data should be kept only for a limited period, commonly six to twelve months, with the reason recorded. Disciplinary records often expire after a warning period. Health and safety records may need long retention. Do not keep everything indefinitely, and do not invent periods without a reason. Our guide to RoPA retention periods shows how to document the basis of each period.

Monitoring and analytics in the record

Employee monitoring, such as email screening, badge tracking, vehicle telematics, productivity software and CCTV, needs its own entries. Each has a different purpose, a different risk and often a different lawful basis. Where monitoring is intrusive, a DPIA is likely to be needed. Our article on legitimate interests and employee monitoring explains how to balance the interests involved. Record HR analytics too, such as attrition prediction or pay gap analysis, especially if the outputs feed decisions about individuals.

Who provides information for a RoPA for HR processing

HR staff know the processes but not always the systems, and IT teams know the systems but not the reasons. Run a short workshop with HR, payroll, IT and legal together, and validate the draft with the people who actually use the systems. Compare the results with the list of HR applications, the supplier contracts and the privacy notice for employees, which should tell the same story as the RoPA. Differences are findings to fix.

A short worked example

For payroll, an entry might read: purpose, paying employees and meeting tax obligations; basis, performance of the employment contract and legal obligation; data subjects, employees; data, name, employee number, address, bank details, salary, tax code and deductions; recipients, the payroll provider acting as processor and the tax authority as a recipient under law; transfers, none outside the UK and EEA; retention, the period required by tax law after the end of the tax year; security, role-based access, encryption and multi-factor authentication. Each field can be checked against evidence, which makes the entry useful for audits, for access requests and for incident response.

Keeping the RoPA for HR processing current

Review the HR entries, including any new starter or leaver tooling, when you change systems, add a supplier, start a new type of monitoring or change a policy, and at least annually. Ask the HR system owner to notify you of changes, and check the record against the supplier list. Our guide to the RoPA review process shows how to set the cycle and owners.

Using a ready structure

To avoid starting with a blank sheet, the RoPA Report and Workbook provides a structured report and a working register that you can populate with HR activities. You can also see completed entries in our RoPA example. Either way, a RoPA for HR processing should be specific enough that a new HR manager could read it and understand how staff data flows through the business.

RoPA for HR processing FAQ

Do I need a RoPA for HR data?

Yes, in most cases. The small-organization exemption does not apply where processing is regular, involves special category data or is likely to be risky, and HR processing usually meets at least one of those conditions.

Should HR be one entry or several?

Several. Split it by purpose along the employment lifecycle, such as recruitment, payroll, benefits, absence, performance and leavers, because each has different recipients and retention.

Can I rely on consent for employee data?

Rarely. Because of the imbalance between employer and employee, consent is often not freely given. Contract, legal obligation and legitimate interests are the more usual bases, with an Article 9 condition for special categories.

Are recruitment agencies and payroll providers processors?

Payroll providers usually are. Recruitment agencies are often independent controllers for their own candidates. Record the role after looking at who decides the purposes and means.

How long should applicant data be kept?

Only as long as needed, commonly six to twelve months after a decision, unless the person agrees to be kept on file. Record the period and the reason.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.