تخطَّ إلى المحتوى
Skillsify
العودة إلى السجلّ
الموارد البشريةv1.0.00 تثبيت

hr-data-privacy-compliance

Govern employee and candidate data privacy: PDPL/GDPR compliance for HR, consent, retention schedules, data-subject requests, breach response, and HR-vendor due diligence. Use when the user asks about employee/candidate data protection, PDPL or GDPR for HR, data retention for resumes, or privacy compliance of HR systems.

المخطّطالفحص الساكنTrigger

التثبيت

npx skillsify add hr-data-privacy-compliance

تحتفظ الموارد البشريّة بأكثر بيانات الشّركة حساسيّة — الهويّات والرواتب والصحّة والبيومترية — والموافقة أساس قانونيّ ضعيف في علاقة العمل بسبب اختلال موازين القوّة. تبني هذه المهارة برنامج الحوكمة على هذه الحقيقة: جرد بيانات يتعقّب بيانات الموارد البشريّة الخفيّة في جداول المديرين ومجموعات الدردشة، وجدول احتفاظ مع حذف آليّ، ومسارات طلبات أصحاب البيانات بمهل النظام، وعناية واجبة للمورّدين تشمل اتّفاقيّات معالجة البيانات والنقل العابر للحدود، ودليل استجابة للاختراقات. وتُصرّ على التحقّق من نصوص PDPL وGDPR الحاليّة بدل الجزم بالمتطلّبات من الذاكرة.

تقرير الجودة

يجب أن تُستدعى

  • How long can we keep rejected candidates' resumes under PDPL?
  • Build a data retention schedule for HR records
  • An employee filed a data access request, what's the process?
  • Create a vendor security questionnaire for our ATS provider
  • Draft a breach response runbook for HR data

يجب ألّا تُستدعى

  • Design a performance review cycle
  • Write interview questions for a data analyst

الملفّات

SKILL.md
---
name: hr-data-privacy-compliance
description: "Govern employee and candidate data privacy: PDPL/GDPR compliance for HR, consent, retention schedules, data-subject requests, breach response, and HR-vendor due diligence. Use when the user asks about employee/candidate data protection, PDPL or GDPR for HR, data retention for resumes, or privacy compliance of HR systems."
---

# HR Data Privacy & Compliance

## Purpose
HR holds the most sensitive data in the company (IDs, salaries, health, performance, biometrics). This skill builds a compliant data-governance program. Verify current regulation text (Saudi PDPL & Implementing Regulations, GDPR) — do not assert legal requirements without checking current sources; flag for legal counsel.

## Data inventory & mapping (step 1)
For each HR data category (recruitment, employment, payroll, health, performance, biometrics, monitoring):
- What is collected, where stored (HRIS, spreadsheets, email, vendor SaaS), who accesses, legal basis, retention period, cross-border transfers.
- Eliminate shadow HR data (manager spreadsheets, WhatsApp groups with CVs).

## Legal bases & consent
- Employment contract necessity / legal obligation covers most core processing; consent is weak basis in employment (power imbalance) — use only where truly optional (photos, testimonials).
- Candidate data: explicit consent for retention beyond the process; easy withdrawal.
- Sensitive data (health, biometrics): stricter conditions; minimize collection.

## Retention schedule (example — adapt to local law)
| Data | Retention |
|---|---|
| Rejected candidates (no consent) | end of process + 6–12 months |
| Candidates (with consent) | 12–24 months, then re-consent or delete |
| Employment records | duration + statutory period (varies; often 5–10 years) |
| Payroll/tax records | per tax law (often 5–10 years) |
| CCTV/access logs | 30–90 days typical |
Automate deletion in HRIS; document deletions.

## Data subject rights handling
- Access/correction/deletion requests: intake channel, identity verification, response SLA (PDPL/GDPR timelines), exemption handling, log.
- Employees: define what's disclosable (their file) vs not (references about others, investigation material).

## Security & vendors
- Access control: role-based, least privilege; HR-data access log; MFA.
- Vendor due diligence (ATS, payroll, survey tools): DPA (data processing agreement), hosting location / cross-border transfer mechanism, breach notification terms, deletion-on-exit, subprocessors list, security certifications.
- Monitoring transparency: any workplace monitoring (email, devices, location) must be disclosed, proportionate, and legally grounded.

## Breach response
Detect → contain → assess (what data, how many people, sensitivity) → notify authority & individuals where required (within statutory timelines) → document → remediate. Run an annual tabletop drill.

## Deliverables
- HR data inventory template
- Retention schedule table
- Privacy notices: candidate privacy notice + employee privacy notice (bilingual on request)
- DSR (data subject request) workflow
- Vendor security questionnaire
- Breach response runbook

مهارات ذات صلة

الموارد البشريةمُوثَّقة

candidate-experience-designer

Design the end-to-end candidate journey and communication templates: application, scheduling, prep, updates, rejection, and offer-stage messaging that protects employer brand. Use when the user asks for rejection email templates, candidate communication sequences, interview prep packs, or improving candidate experience/NPS.

0 تثبيت · v1.0.0

الموارد البشريةمُوثَّقة

employer-branding-evp

Build employer brand and Employee Value Proposition: EVP definition, careers-page content, recruitment marketing, review-site management, and talent-audience campaigns. Use when the user asks to improve employer brand, write a careers page, define an EVP, respond to Glassdoor/Indeed reviews, or run recruitment marketing.

0 تثبيت · v1.0.0

الموارد البشريةمُوثَّقة

hiring-bias-auditor

Audit hiring pipelines, job ads, screening criteria, and AI-recruiting tools for bias and legal/compliance risk (disparate impact, EU AI Act high-risk rules, PDPL/GDPR candidate data). Use when the user asks to check fairness of a hiring process, audit an AI screening tool, review adverse-impact metrics, or make recruitment compliant.

0 تثبيت · v1.0.0