Skip to content
Skillsify
Back to registry
HRv1.0.00 installs

hr-data-privacy-compliance

Govern employee and candidate data privacy: PDPL/GDPR compliance for HR, consent, retention schedules, data-subject requests, breach response, and HR-vendor due diligence. Use when the user asks about employee/candidate data protection, PDPL or GDPR for HR, data retention for resumes, or privacy compliance of HR systems.

SchemaLintTrigger

Install

npx skillsify add hr-data-privacy-compliance

HR holds the most sensitive data in the company — IDs, salaries, health, biometrics — and consent is a weak legal basis in employment because of the power imbalance. This skill builds the governance program around that reality: a data inventory that hunts down shadow HR data in manager spreadsheets and chat groups, a retention schedule with automated deletion, data-subject-request workflows with statutory response timelines, vendor due diligence covering processing agreements and cross-border transfers, and a breach-response runbook. It insists on verifying current PDPL and GDPR text rather than asserting requirements from memory.

Quality report

Should trigger

  • How long can we keep rejected candidates' resumes under PDPL?
  • Build a data retention schedule for HR records
  • An employee filed a data access request, what's the process?
  • Create a vendor security questionnaire for our ATS provider
  • Draft a breach response runbook for HR data

Should not trigger

  • Design a performance review cycle
  • Write interview questions for a data analyst

Files

SKILL.md
---
name: hr-data-privacy-compliance
description: "Govern employee and candidate data privacy: PDPL/GDPR compliance for HR, consent, retention schedules, data-subject requests, breach response, and HR-vendor due diligence. Use when the user asks about employee/candidate data protection, PDPL or GDPR for HR, data retention for resumes, or privacy compliance of HR systems."
---

# HR Data Privacy & Compliance

## Purpose
HR holds the most sensitive data in the company (IDs, salaries, health, performance, biometrics). This skill builds a compliant data-governance program. Verify current regulation text (Saudi PDPL & Implementing Regulations, GDPR) — do not assert legal requirements without checking current sources; flag for legal counsel.

## Data inventory & mapping (step 1)
For each HR data category (recruitment, employment, payroll, health, performance, biometrics, monitoring):
- What is collected, where stored (HRIS, spreadsheets, email, vendor SaaS), who accesses, legal basis, retention period, cross-border transfers.
- Eliminate shadow HR data (manager spreadsheets, WhatsApp groups with CVs).

## Legal bases & consent
- Employment contract necessity / legal obligation covers most core processing; consent is weak basis in employment (power imbalance) — use only where truly optional (photos, testimonials).
- Candidate data: explicit consent for retention beyond the process; easy withdrawal.
- Sensitive data (health, biometrics): stricter conditions; minimize collection.

## Retention schedule (example — adapt to local law)
| Data | Retention |
|---|---|
| Rejected candidates (no consent) | end of process + 6–12 months |
| Candidates (with consent) | 12–24 months, then re-consent or delete |
| Employment records | duration + statutory period (varies; often 5–10 years) |
| Payroll/tax records | per tax law (often 5–10 years) |
| CCTV/access logs | 30–90 days typical |
Automate deletion in HRIS; document deletions.

## Data subject rights handling
- Access/correction/deletion requests: intake channel, identity verification, response SLA (PDPL/GDPR timelines), exemption handling, log.
- Employees: define what's disclosable (their file) vs not (references about others, investigation material).

## Security & vendors
- Access control: role-based, least privilege; HR-data access log; MFA.
- Vendor due diligence (ATS, payroll, survey tools): DPA (data processing agreement), hosting location / cross-border transfer mechanism, breach notification terms, deletion-on-exit, subprocessors list, security certifications.
- Monitoring transparency: any workplace monitoring (email, devices, location) must be disclosed, proportionate, and legally grounded.

## Breach response
Detect → contain → assess (what data, how many people, sensitivity) → notify authority & individuals where required (within statutory timelines) → document → remediate. Run an annual tabletop drill.

## Deliverables
- HR data inventory template
- Retention schedule table
- Privacy notices: candidate privacy notice + employee privacy notice (bilingual on request)
- DSR (data subject request) workflow
- Vendor security questionnaire
- Breach response runbook

Related skills

HRVerified

candidate-experience-designer

Design the end-to-end candidate journey and communication templates: application, scheduling, prep, updates, rejection, and offer-stage messaging that protects employer brand. Use when the user asks for rejection email templates, candidate communication sequences, interview prep packs, or improving candidate experience/NPS.

0 installs · v1.0.0

HRVerified

employer-branding-evp

Build employer brand and Employee Value Proposition: EVP definition, careers-page content, recruitment marketing, review-site management, and talent-audience campaigns. Use when the user asks to improve employer brand, write a careers page, define an EVP, respond to Glassdoor/Indeed reviews, or run recruitment marketing.

0 installs · v1.0.0

HRVerified

hiring-bias-auditor

Audit hiring pipelines, job ads, screening criteria, and AI-recruiting tools for bias and legal/compliance risk (disparate impact, EU AI Act high-risk rules, PDPL/GDPR candidate data). Use when the user asks to check fairness of a hiring process, audit an AI screening tool, review adverse-impact metrics, or make recruitment compliant.

0 installs · v1.0.0