Skip to content
Workly
Compliance

GDPR in HR: what employee data you may keep, for how long and how to protect it

GDPR for HR teams in Romania: legal grounds for processing employee data, special categories, retention periods, employee rights and practical security measures.

by Echipa Workly5 min read

Translated from Romanian. This article covers Romanian labour and tax law; the Romanian version is canonical and is updated first.

HR is, by definition, one of the most data-intensive functions in a company — and one of the most exposed under GDPR. Personnel files, payroll, time records, medical certificates: almost everything HR touches is personal data, and some of it belongs to special categories with stricter rules. Here is what matters in practice.

You cannot process employee data “because you are the employer”. You need a specific legal ground for each purpose. In HR, the usual ones are:

  • Legal obligation — the strongest and most common. Keeping the personnel file, reporting to the state register, withholding contributions, keeping time records: all are legal duties, so processing is justified.
  • Performance of the contract — paying the salary, managing leave, assigning equipment.
  • Legitimate interest — for example workplace security, with a documented proportionality test.
  • Consent — the weakest ground in employment. Because of the subordinate relationship, consent is generally not considered freely given, so it cannot be the basis for core HR processing. Reserve it for genuinely optional things (a photo on the website, participation in an event).

The practical consequence: do not build your HR data processing on consent forms. Build it on legal obligation and contract, and document that mapping. For the specific case of surveillance, see the article on monitoring employees.

Special categories

Some data receives stricter protection:

  • Health data — medical certificates, fitness-for-work assessments, disability certificates. HR should hold the conclusion (fit / fit with restrictions / unfit), not the diagnosis.
  • Trade union membership.
  • Biometric data used for identification — fingerprints, facial recognition. Because less intrusive alternatives exist for attendance (card, code, app), justifying biometrics is difficult.

Special-category data requires an additional condition beyond the legal ground, restricted access and, in practice, encryption.

Retention: the part most companies get wrong

GDPR requires that data be kept no longer than necessary. But HR data also falls under specific retention rules, which are the justification for keeping it:

  • Personnel files and employment contracts — very long retention, in the order of decades, because former employees need seniority certificates for pension files.
  • Payroll records — traditionally 50 years; Legea 36/2023 introduced a 5-year term for accounting documents, payroll sheets included, but destroying old payroll records on that basis is risky, since they remain the source of income certificates.
  • Recruitment data for candidates not hired — no legal retention period. Keep only for the duration of the recruitment process, or with consent for a future one.

The rule to apply: keep exactly as long as the special law requires, then delete. The legal retention period is what justifies keeping the data; after it expires, keeping it becomes hard to defend. The periods by document category are set out in the article on how long to keep personnel documents.

Employee rights

Employees may exercise their GDPR rights against you as employer:

  • access — a copy of the data you hold about them;
  • rectification of inaccurate data;
  • erasure, where no legal obligation requires retention;
  • restriction and objection, in the cases provided;
  • portability, in limited situations.

Separately, the Labour Code entitles the employee to certified copies of documents in their personnel file. Refusing or unduly delaying such a request is a problem on two fronts at once.

Practical measures

  • Role-based access — a team manager does not need to see payroll data or medical certificates.
  • Encryption for identifiers and special-category data.
  • Defined retention per document category, with actual deletion at expiry.
  • Records of processing activities — the register describing what you process, why and for how long.
  • Data processing agreements with suppliers who touch employee data (payroll providers, HR software, occupational health services).
  • Breach procedure — a personal data breach may require notification within a short deadline.
  • Staff training — most incidents come from an email sent to the wrong recipient, not from hacking.

The most common incidents in HR

  1. A payslip sent to the whole team instead of one person.
  2. The payroll sheet circulated for signatures, exposing everyone’s salaries.
  3. Medical certificates stored in folders accessible to all.
  4. Candidate CVs kept indefinitely, with no ground.
  5. Attendance data collected excessively (continuous location, biometrics) without a proportionality test.

How Workly helps

Workly treats HR data protection as a design constraint, not a feature. Personal data is encrypted, with role-based access so that salary and health data reach only the people who need them operationally. Retention is configurable per document category, with automatic purging at expiry — which is precisely what GDPR requires and what manual processes never do.

Documents with expiry dates (fitness-for-work certificates, disability certificates, authorisations) are tracked with alerts, and every issued document stays in an auditable history: who issued it, to whom and when. Payslips and certificates are delivered individually through the platform, with authentication, removing the most common incident of all — the email sent to the wrong recipient.

One thing stays true regardless: no tool relieves you of the responsibility to set your own policies — what data you collect, for what purpose and for how long. But a system that applies those policies automatically makes compliance far more realistic in day-to-day practice.


Informational article, accurate at the date of publication. Not legal advice. Retention periods and data protection obligations depend on the specific case — consult a data protection specialist for your own processing map.

Want to see Workly in action?

We'll show you how time tracking, payroll and the rest of the modules work for your company, in a short demo.

Request a demo