Saltar al contenido
Skillsify
Volver al registro
Recursos humanosv1.0.00 instalaciones

hr-data-privacy-compliance

Govern employee and candidate data privacy: PDPL/GDPR compliance for HR, consent, retention schedules, data-subject requests, breach response, and HR-vendor due diligence. Use when the user asks about employee/candidate data protection, PDPL or GDPR for HR, data retention for resumes, or privacy compliance of HR systems.

EsquemaAnálisisTrigger

Instalación

npx skillsify add hr-data-privacy-compliance

RRHH guarda los datos más sensibles de la empresa —identificaciones, salarios, salud, biometría— y el consentimiento es una base legal débil en el empleo por el desequilibrio de poder. Esta skill construye el programa de gobernanza sobre esa realidad: un inventario que rastrea los datos de RRHH en la sombra (hojas de cálculo de managers, grupos de chat), un calendario de retención con borrado automatizado, flujos de solicitudes de interesados con plazos legales, diligencia debida de proveedores con DPA y transferencias transfronterizas, y un runbook de brechas. Insiste en verificar el texto vigente de PDPL y GDPR en vez de afirmar requisitos de memoria.

Informe de calidad

Debería activarse

  • How long can we keep rejected candidates' resumes under PDPL?
  • Build a data retention schedule for HR records
  • An employee filed a data access request, what's the process?
  • Create a vendor security questionnaire for our ATS provider
  • Draft a breach response runbook for HR data

No debería activarse

  • Design a performance review cycle
  • Write interview questions for a data analyst

Archivos

SKILL.md
---
name: hr-data-privacy-compliance
description: "Govern employee and candidate data privacy: PDPL/GDPR compliance for HR, consent, retention schedules, data-subject requests, breach response, and HR-vendor due diligence. Use when the user asks about employee/candidate data protection, PDPL or GDPR for HR, data retention for resumes, or privacy compliance of HR systems."
---

# HR Data Privacy & Compliance

## Purpose
HR holds the most sensitive data in the company (IDs, salaries, health, performance, biometrics). This skill builds a compliant data-governance program. Verify current regulation text (Saudi PDPL & Implementing Regulations, GDPR) — do not assert legal requirements without checking current sources; flag for legal counsel.

## Data inventory & mapping (step 1)
For each HR data category (recruitment, employment, payroll, health, performance, biometrics, monitoring):
- What is collected, where stored (HRIS, spreadsheets, email, vendor SaaS), who accesses, legal basis, retention period, cross-border transfers.
- Eliminate shadow HR data (manager spreadsheets, WhatsApp groups with CVs).

## Legal bases & consent
- Employment contract necessity / legal obligation covers most core processing; consent is weak basis in employment (power imbalance) — use only where truly optional (photos, testimonials).
- Candidate data: explicit consent for retention beyond the process; easy withdrawal.
- Sensitive data (health, biometrics): stricter conditions; minimize collection.

## Retention schedule (example — adapt to local law)
| Data | Retention |
|---|---|
| Rejected candidates (no consent) | end of process + 6–12 months |
| Candidates (with consent) | 12–24 months, then re-consent or delete |
| Employment records | duration + statutory period (varies; often 5–10 years) |
| Payroll/tax records | per tax law (often 5–10 years) |
| CCTV/access logs | 30–90 days typical |
Automate deletion in HRIS; document deletions.

## Data subject rights handling
- Access/correction/deletion requests: intake channel, identity verification, response SLA (PDPL/GDPR timelines), exemption handling, log.
- Employees: define what's disclosable (their file) vs not (references about others, investigation material).

## Security & vendors
- Access control: role-based, least privilege; HR-data access log; MFA.
- Vendor due diligence (ATS, payroll, survey tools): DPA (data processing agreement), hosting location / cross-border transfer mechanism, breach notification terms, deletion-on-exit, subprocessors list, security certifications.
- Monitoring transparency: any workplace monitoring (email, devices, location) must be disclosed, proportionate, and legally grounded.

## Breach response
Detect → contain → assess (what data, how many people, sensitivity) → notify authority & individuals where required (within statutory timelines) → document → remediate. Run an annual tabletop drill.

## Deliverables
- HR data inventory template
- Retention schedule table
- Privacy notices: candidate privacy notice + employee privacy notice (bilingual on request)
- DSR (data subject request) workflow
- Vendor security questionnaire
- Breach response runbook

Skills relacionadas

Recursos humanosVerificada

candidate-experience-designer

Design the end-to-end candidate journey and communication templates: application, scheduling, prep, updates, rejection, and offer-stage messaging that protects employer brand. Use when the user asks for rejection email templates, candidate communication sequences, interview prep packs, or improving candidate experience/NPS.

0 instalaciones · v1.0.0

Recursos humanosVerificada

employer-branding-evp

Build employer brand and Employee Value Proposition: EVP definition, careers-page content, recruitment marketing, review-site management, and talent-audience campaigns. Use when the user asks to improve employer brand, write a careers page, define an EVP, respond to Glassdoor/Indeed reviews, or run recruitment marketing.

0 instalaciones · v1.0.0

Recursos humanosVerificada

hiring-bias-auditor

Audit hiring pipelines, job ads, screening criteria, and AI-recruiting tools for bias and legal/compliance risk (disparate impact, EU AI Act high-risk rules, PDPL/GDPR candidate data). Use when the user asks to check fairness of a hiring process, audit an AI screening tool, review adverse-impact metrics, or make recruitment compliant.

0 instalaciones · v1.0.0