Join our Newsletter — 33% off our NHI Course

What do organisations get wrong about retaining and securing employee personal data?

A common mistake is keeping employee information longer than the law allows or treating retention as a purely administrative issue. Another is relying on informal controls instead of a documented security programme with managerial, technical, operational, and physical safeguards. The article also notes that employers should be able to demonstrate compliance, not simply claim it. Documentation and execution must align.

Where employee data retention goes wrong

Retaining employee personal data is not just a filing decision. The main failure is scope creep: records stay live long after the business purpose has ended, then spread across HR, payroll, IT, legal, and backup systems without a clear retention basis. Once that happens, deletion becomes difficult, and the organisation can no longer explain why each dataset still exists.

Retention also goes wrong when teams treat all employee data as one category. Some records may need to be kept for tax, employment, or dispute purposes, while other fields should be minimised or deleted earlier. If the retention schedule does not distinguish between data types, organisations either over-retain or delete too early, both of which create compliance risk.

For employee personal data, the retention decision should be tied to a documented purpose, a lawful basis where required, and a deletion trigger. That is why GDPR matters here: it turns retention from a convenience choice into a test of purpose limitation, minimisation, storage limitation, and security of processing.

Why informal security controls fail

A second common mistake is assuming that employee records are safe because they sit inside familiar business systems. In practice, personal data is exposed whenever access is broad, logging is weak, exports are uncontrolled, or backups and shared drives are treated as invisible storage. Security has to follow the data wherever it is copied, not just where it was first entered.

Informal controls also fail because they depend on memory and local habits. If managers, HR staff, or IT administrators can decide ad hoc who may see a record, then access rules become inconsistent and hard to audit. A documented programme should define who can access what, how exceptions are approved, how changes are reviewed, and what evidence proves the control operated.

That is the practical value of a control framework. NIST SP 800-53 Rev 5 Security and Privacy Controls is useful because it separates access control, audit, configuration management, and privacy-related safeguards into auditable requirements rather than informal expectations.

How to prove compliance, not just claim it

Employers often say they have a retention policy, but the real test is whether the policy is operating in systems and records. If a record should be deleted after a defined period, there should be a repeatable process that removes it from primary systems, downstream copies, and retention repositories, with exceptions tracked and approved. If access is restricted, the organisation should be able to show logs, role assignments, and review outcomes.

Documentation matters because it creates the bridge between policy and execution. A retention schedule, disposal workflow, access review record, and exception register are not bureaucracy, they are the evidence that the organisation can demonstrate control when challenged by auditors, regulators, or employees. Without that evidence, even a well-intentioned policy is hard to defend.

For broader privacy governance, NIST Privacy Framework is a useful reference because it helps organisations translate privacy obligations into repeatable governance, control, and risk-management practices.

Risk and Threat Considerations

Over-retained employee data increases both compliance exposure and breach impact. The longer records remain accessible, the more opportunities exist for unauthorised disclosure, insider misuse, or accidental sharing through reports, exports, backups, and test environments. The risk is not only that the data exists, but that the organisation loses control of where copies live and who can reach them.

Failure mechanism: Retention drift allows personal data to persist beyond its lawful or operational purpose, while weak access governance and unmanaged copies expand the number of places an attacker or insider can reach.

Impact: The organisation can face avoidable privacy violations, larger incident scope, harder deletion, and weaker evidence that it handled employee data with appropriate safeguards.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 sets the technical controls, while GDPR defines the regulatory obligations.

Framework Control / Reference Relevance
GDPR Art.5 — Processing Principles Employee data retention turns on purpose limitation, minimisation, and storage limitation.
Art.25 — Data Protection by Design and by Default Security and minimisation should be built into employee-data workflows, not added informally.
Art.32 — Security of Processing The question concerns whether employee data is secured with appropriate technical and organisational controls.
Recommendation — Align retention periods to documented purpose and delete records when the purpose ends. Embed minimisation, default access limits, and deletion triggers into HR and IT processes. Apply appropriate technical and organisational safeguards to protect employee personal data.
NIST SP 800-53 Rev 5 AU-2 — Event Logging Demonstrating access and deletion requires audit evidence of who accessed and changed records.
AC-2 — Account Management Employee data access must be governed and reviewable, not left to informal discretion.
MP-6 — Media Sanitization Retention mistakes often persist in backup media, exports, and copies that still contain personal data.
Recommendation — Log access, export, review, and deletion events for employee records. Review and remove unnecessary access to employee personal data on a defined cadence. Sanitize or destroy employee data copies when retention ends.

Practitioner Guidance

What to prioritise: Start with a record inventory that distinguishes employee data by purpose, retention period, system of record, and downstream replica. The first control gap to close is usually not deletion tooling, it is the absence of an authoritative schedule that tells teams what should be kept, for how long, and why.

What to verify: Check whether the organisation can produce evidence for three things: the retention decision, the access decision, and the disposal decision. If any one of those is missing, the control is not yet operational, even if the policy exists on paper.

Practitioner takeaway: The strongest retention programme is one that can explain every surviving record, restrict access to it, and prove its eventual disposal with evidence rather than assumption.