SKILL.md
---
name: hr-data-privacy-compliance
description: "Govern employee and candidate data privacy: PDPL/GDPR compliance for HR, consent, retention schedules, data-subject requests, breach response, and HR-vendor due diligence. Use when the user asks about employee/candidate data protection, PDPL or GDPR for HR, data retention for resumes, or privacy compliance of HR systems."
---
# HR Data Privacy & Compliance
## Purpose
HR holds the most sensitive data in the company (IDs, salaries, health, performance, biometrics). This skill builds a compliant data-governance program. Verify current regulation text (Saudi PDPL & Implementing Regulations, GDPR) — do not assert legal requirements without checking current sources; flag for legal counsel.
## Data inventory & mapping (step 1)
For each HR data category (recruitment, employment, payroll, health, performance, biometrics, monitoring):
- What is collected, where stored (HRIS, spreadsheets, email, vendor SaaS), who accesses, legal basis, retention period, cross-border transfers.
- Eliminate shadow HR data (manager spreadsheets, WhatsApp groups with CVs).
## Legal bases & consent
- Employment contract necessity / legal obligation covers most core processing; consent is weak basis in employment (power imbalance) — use only where truly optional (photos, testimonials).
- Candidate data: explicit consent for retention beyond the process; easy withdrawal.
- Sensitive data (health, biometrics): stricter conditions; minimize collection.
## Retention schedule (example — adapt to local law)
| Data | Retention |
|---|---|
| Rejected candidates (no consent) | end of process + 6–12 months |
| Candidates (with consent) | 12–24 months, then re-consent or delete |
| Employment records | duration + statutory period (varies; often 5–10 years) |
| Payroll/tax records | per tax law (often 5–10 years) |
| CCTV/access logs | 30–90 days typical |
Automate deletion in HRIS; document deletions.
## Data subject rights handling
- Access/correction/deletion requests: intake channel, identity verification, response SLA (PDPL/GDPR timelines), exemption handling, log.
- Employees: define what's disclosable (their file) vs not (references about others, investigation material).
## Security & vendors
- Access control: role-based, least privilege; HR-data access log; MFA.
- Vendor due diligence (ATS, payroll, survey tools): DPA (data processing agreement), hosting location / cross-border transfer mechanism, breach notification terms, deletion-on-exit, subprocessors list, security certifications.
- Monitoring transparency: any workplace monitoring (email, devices, location) must be disclosed, proportionate, and legally grounded.
## Breach response
Detect → contain → assess (what data, how many people, sensitivity) → notify authority & individuals where required (within statutory timelines) → document → remediate. Run an annual tabletop drill.
## Deliverables
- HR data inventory template
- Retention schedule table
- Privacy notices: candidate privacy notice + employee privacy notice (bilingual on request)
- DSR (data subject request) workflow
- Vendor security questionnaire
- Breach response runbook