Aller au contenu
Skillsify
Retour au registre
Ressources humainesv1.0.00 installations

hr-data-privacy-compliance

Govern employee and candidate data privacy: PDPL/GDPR compliance for HR, consent, retention schedules, data-subject requests, breach response, and HR-vendor due diligence. Use when the user asks about employee/candidate data protection, PDPL or GDPR for HR, data retention for resumes, or privacy compliance of HR systems.

SchémaAnalyseTrigger

Installation

npx skillsify add hr-data-privacy-compliance

Les RH détiennent les données les plus sensibles de l'entreprise — identités, salaires, santé, biométrie — et le consentement est une base légale fragile dans l'emploi à cause du rapport de force. Cette skill construit le programme de gouvernance sur ce constat : un inventaire qui traque les données RH fantômes (tableurs de managers, groupes de messagerie), un calendrier de conservation avec suppression automatisée, des workflows de demandes des personnes avec délais légaux, une due diligence des fournisseurs couvrant DPA et transferts transfrontaliers, et un runbook de violation. Elle insiste pour vérifier le texte actuel du PDPL et du RGPD plutôt que d'affirmer les exigences de mémoire.

Rapport de qualité

Devrait se déclencher

  • How long can we keep rejected candidates' resumes under PDPL?
  • Build a data retention schedule for HR records
  • An employee filed a data access request, what's the process?
  • Create a vendor security questionnaire for our ATS provider
  • Draft a breach response runbook for HR data

Ne devrait pas se déclencher

  • Design a performance review cycle
  • Write interview questions for a data analyst

Fichiers

SKILL.md
---
name: hr-data-privacy-compliance
description: "Govern employee and candidate data privacy: PDPL/GDPR compliance for HR, consent, retention schedules, data-subject requests, breach response, and HR-vendor due diligence. Use when the user asks about employee/candidate data protection, PDPL or GDPR for HR, data retention for resumes, or privacy compliance of HR systems."
---

# HR Data Privacy & Compliance

## Purpose
HR holds the most sensitive data in the company (IDs, salaries, health, performance, biometrics). This skill builds a compliant data-governance program. Verify current regulation text (Saudi PDPL & Implementing Regulations, GDPR) — do not assert legal requirements without checking current sources; flag for legal counsel.

## Data inventory & mapping (step 1)
For each HR data category (recruitment, employment, payroll, health, performance, biometrics, monitoring):
- What is collected, where stored (HRIS, spreadsheets, email, vendor SaaS), who accesses, legal basis, retention period, cross-border transfers.
- Eliminate shadow HR data (manager spreadsheets, WhatsApp groups with CVs).

## Legal bases & consent
- Employment contract necessity / legal obligation covers most core processing; consent is weak basis in employment (power imbalance) — use only where truly optional (photos, testimonials).
- Candidate data: explicit consent for retention beyond the process; easy withdrawal.
- Sensitive data (health, biometrics): stricter conditions; minimize collection.

## Retention schedule (example — adapt to local law)
| Data | Retention |
|---|---|
| Rejected candidates (no consent) | end of process + 6–12 months |
| Candidates (with consent) | 12–24 months, then re-consent or delete |
| Employment records | duration + statutory period (varies; often 5–10 years) |
| Payroll/tax records | per tax law (often 5–10 years) |
| CCTV/access logs | 30–90 days typical |
Automate deletion in HRIS; document deletions.

## Data subject rights handling
- Access/correction/deletion requests: intake channel, identity verification, response SLA (PDPL/GDPR timelines), exemption handling, log.
- Employees: define what's disclosable (their file) vs not (references about others, investigation material).

## Security & vendors
- Access control: role-based, least privilege; HR-data access log; MFA.
- Vendor due diligence (ATS, payroll, survey tools): DPA (data processing agreement), hosting location / cross-border transfer mechanism, breach notification terms, deletion-on-exit, subprocessors list, security certifications.
- Monitoring transparency: any workplace monitoring (email, devices, location) must be disclosed, proportionate, and legally grounded.

## Breach response
Detect → contain → assess (what data, how many people, sensitivity) → notify authority & individuals where required (within statutory timelines) → document → remediate. Run an annual tabletop drill.

## Deliverables
- HR data inventory template
- Retention schedule table
- Privacy notices: candidate privacy notice + employee privacy notice (bilingual on request)
- DSR (data subject request) workflow
- Vendor security questionnaire
- Breach response runbook

Skills associées

Ressources humainesVérifiée

candidate-experience-designer

Design the end-to-end candidate journey and communication templates: application, scheduling, prep, updates, rejection, and offer-stage messaging that protects employer brand. Use when the user asks for rejection email templates, candidate communication sequences, interview prep packs, or improving candidate experience/NPS.

0 installations · v1.0.0

Ressources humainesVérifiée

employer-branding-evp

Build employer brand and Employee Value Proposition: EVP definition, careers-page content, recruitment marketing, review-site management, and talent-audience campaigns. Use when the user asks to improve employer brand, write a careers page, define an EVP, respond to Glassdoor/Indeed reviews, or run recruitment marketing.

0 installations · v1.0.0

Ressources humainesVérifiée

hiring-bias-auditor

Audit hiring pipelines, job ads, screening criteria, and AI-recruiting tools for bias and legal/compliance risk (disparate impact, EU AI Act high-risk rules, PDPL/GDPR candidate data). Use when the user asks to check fairness of a hiring process, audit an AI screening tool, review adverse-impact metrics, or make recruitment compliant.

0 installations · v1.0.0