Reading time: 11 minutes
According to a Data Legal Drive survey, 40% of Data Protection Officers (DPOs) and legal professionals took advantage of the lockdown to bring their companies into compliance with the GDPR.
As a company based in France, you are required to process the personal data of your employees and job applicants. You must therefore implement a data processing policy that complies with the GDPR, which sets forth the rules for managing personal data in the context of human resources management.
The CNIL provides a set of guidelines to help companies ensure compliance, particularly with regard to data processing related to human resources management, such as pay stubs, training, and absences.
In fact, the lockdown has led to the implementation of new processes within companies—particularly remote work—making the implementation of an appropriate GDPR policy even more urgent.
This article explains how to manage and comply with the GDPR in the context of human resources management, and outlines the tools available to help you do so more easily. By doing so, you’ll avoid a fine of up to 4% of your company’s global annual revenue.
What is the GPRD?
The General Data Protection Regulation ( GDPR) aims to establish a framework for the processing of individuals’ personal data within the European Union.
Personal data are processed when they are collected, recorded, stored and so on.
For example: A personnel register
Personal data refers to anything that enables a person to be identified directly (surname, first name) or indirectly (telephone number, customer number, etc.). A combination of several pieces of information can also be used to identify a person.
For example: address, date of birth and sports activities.
Why is personnel management concerned by the GPRD?
Human resources management is subject to the GDPR because it involves handling the personal data of the company’s employees and job applicants. As such, the General Data Protection Regulation has taken effect, and the company must comply or face penalties.
The data controller must also ensure that its protocol complies with labor laws, collective bargaining agreements, and the company’s legal obligations.
What personnel management data is affected by the GPRD?
Employee identification
- Identity: surname, first name, gender, date of birth, family situation, etc.
- Professional status: place of work, internal identification number, etc.
- Its work authorization: serial number, type, …
Assessing candidates’ skills at the time of recruitment
- Resume
- Cover letter
Employee career and training follow-up
- Career information: recruitment date and conditions, career simulation, …
- Professional assessment: interview dates, results obtained, etc.
- Training: diplomas, certificates and attestations, …
- Medical check-up records: dates of check-ups, job suitability, etc.
Payroll and related legal obligations
- Social security number
- Compensation plan and basis of calculation
- Etc
Validation of acquired experience
- Date of validation request
- Title or certificate of qualification
- Etc
Management of workplace accident and occupational illness declarations, work stoppages and other authorized absences.
- Doctor’s contact details
- Date of accident
- Etc
Situations giving entitlement to special leave or delegation hours.
- Data linked to the exercise of an elective mandate
- Firefighter missions
- Etc
Professional tools or equipment available to the employee in the course of his or her duties.
- Internal directories and organization chart
- Business diaries
- Electronic messaging
- Etc
Management of social and cultural activities implemented by the employer
- Identity of employee and beneficiaries
- Revenue
- Etc
Professional elections and meetings of staff representative bodies.
- Convocation
- Reports
- Etc
The fight against discrimination, compulsory employment, etc.
Please note that the employee data collected must be up-to-date, of high quality, and limited in time.
6 ways to comply with the GPRD
Collect only the data you need
Data collection must meet specific objectives. In the context of personnel management, the objectives may be :
- Recruitment.
- Personnel administration.
- Payroll management and administrative formalities.
- Providing staff with professional tools.
- Work organization.
- Career and mobility monitoring.
- Training.
- Keeping mandatory registers, relations with employee representative bodies.
- Internal communications.
- Social welfare management.
- Audit, litigation and pre-litigation management.
As a data controller, you must obtain the consent of the persons concerned. However, because of the company/employee relationship, you have a legal basis for processing certain data in very specific situations.
These legal bases can be :
- Pre-contractual measures.
- Legitimate interest.
- Contract performance
- Legal obligation
Example 1: applications (resume and cover letter) are processed on the legal basis of pre-contractual measures
Example 2: management of internal directories and organization charts based on legitimate interest
Example 3: remuneration is calculated on the basis of contract performance
Example 4: the Nominative Social Declaration is based on the legal obligation.
Please note: Data collected for one purpose cannot be reused for another.
Transparency
A bond of trust is established between you and the person whose data you are processing. So you need to be clear about your intentions.
When processing personal data, you must inform the person of this action. There is no standard on how to keep the person informed.
Nevertheless, information must be “concise, transparent, comprehensible and easily accessible, in clear and simple terms”.
The CNIL provides a few examples of information notices to help you.
Respecting people’s rights
The persons whose data are processed have rights:
- The right to object to processing.
- The right of access, rectification and deletion.
- The right to limitation.
- The right to portability.
In the event of a request for consultation, rectification or deletion of data, you must be able to respond quickly.
Please note that the information covered by these rights does not include data for which consent has been given or data related to the contract.
Supervising data management
Personal data cannot be accessed by all company employees. Access authorizations must be established.
Within the company, authorized persons are bound by their mission or function.
For example: people responsible for human resources or payroll.
Other organizations linked to the company may also have access to data as part of their mission or function.
- Employee representative bodies.
- Social insurance organizations.
- The employer’s audit and financial control entities.
- Service providers (catering, document archiving, etc.).
- Cultural and social organizations (social and economic committees, etc.).
Please note that the transfer of data outside Europe is subject to a specific rule.
Anticipating Risks
You need to adapt data processing to specific situations, especially when sensitive data is involved, for example in the event of a work-related accident (social security number, etc.).
Ensuring data security
The company must ensure data security. To achieve this, it must implement a safety protocol.
- Raise user awareness through an IT charter, not forgetting to inform those involved in data processing.
- Authenticate users with correct logins and passwords.
- Manage authorizations , sort access and define the right profiles.
- Track access and manage incidents, data breach notifications, logging systems, etc.
- Securing workstations, locking procedures, antivirus, etc.
- Secure mobile computing, backup and encryption, synchronization, etc.
- Protect internal computer network, VPN, WPA2 protocol, etc.
ERP and GPRD: a winning duo?
The CNIL (French Data Protection Authority) offers a set of guidelines to support the protection of personal data relating to personnel management. What’s more, technological tools can provide real support in the compliance process.
This is particularly true ofERP (Enterprise Resource Planning), which helps your company comply with European regulations.
By centralizing data
The fact that data is centralized in a single information system makes it easier to manage.
Reliable, up-to-date data
As mentioned above, the data collected must be of high quality and up-to-date. In an ERP system, data is constantly updated through the daily activities of employees within the software.
Manage authorizations
Personal data cannot be accessible to everyone. It depends on the mission and function. Through security accesses, ERP allows you to define authorizations.
To classify data
Data is sorted and organized using the various modules contained in the software package.
Easy access
Employees can easily exercise their rights (consultation, modification, etc.) thanks to simplified access to their personal data.
Transparency
Employees have a global view of the data held on them by the company.
Access to the software package via an authentication system
What’s more, the ERP is accessible via an authentication system, which notifies the user in the event of an attempted breach. This ensures the security of user-specific data.
Our SaaS software is GDPR-compliant
Our SaaS ERP and HRIS software offers a wide range of features that simplify GDPR-related processes:
- Data centralization.
- Safety management.
- Fine-tuned management of rights by personal data.
- Anonymization and archiving features.
To conclude on personnel management and the GPRD
The General Data Protection Regulation is an essential point to take into account in your internal processes, the choice of your service providers and subcontractors, or the choice of your IT tools.
Failure to comply with the GPRD results in a fine of up to 4% of your company’s worldwide annual turnover.
To help you achieve compliance, the CNIL offers a number of tools, including a reference guide to the processing of personal data in personnel management.
IT tools such as ERP offer features to simplify your GPRD compliance.
Ensure your HR management system is GDPR-compliant with Veryswing
Protecting personal data and complying with legal obligations are not optional: they are at the heart of modern, responsible, and effective human resources management.
That is why our VSActivity (ERP), VSExperience (HRIS), and VSPortage (ERP) software solutions include a comprehensive HR module that helps you ensure your HR processes comply with the GDPR.
Organize and Secure Your HR Practices
With our solutions, you can:
-
Manage employee data in full compliance with regulations, from hire to termination;
-
Centralize your pay stubs, contracts, performance reviews, and HR documents in a secure environment;
-
Automate your HR processes while complying with management policies and the requirements for processing personal data;
-
Implement a clear and compliant GDPR policy without technical complexity.
Use the GDPR as a Driver of HR Performance
With simple, remotely accessible interfaces, our software makes it easy to:
-
Monitoring employee rights;
-
Management of retention periods;
-
Managing GDPR Compliance, Even While Working Remotely.
Why Choose Our Software for Your HR and GDPR Management?
With Veryswing’s solutions, you can:
-
Protect your teams’ personal data;
-
Build trust and transparency within the organization;
-
Automate your processes and reduce legal risks;
-
Comply with your legal obligations while saving time.
And that’s not all: our ERP systems are designed for consulting firms, software publishers, digital services companies, and umbrella companies alike. With them, you can manage:
-
Your sales management;
-
Your financial management;
-
Your HR management;
-
And employee hours and activities.
📩 Request your free demo today to discover how our software can help you transform your HR management while ensuring full GDPR compliance.