Every Irish employer holds employee data. Names, addresses, PPS numbers, bank details, sick leave records, disciplinary notes – the list grows quickly. However, it is important to consider if you actually have a lawful basis for holding all of it?
Since the General Data Protection Regulation “GDPR” came into force on 25th May 2018, alongside the Irish Data Protection Act 2018, the answer matters more than ever. The Data Protection Commission has made it clear that employers are expected to know exactly what personal data they hold, why they hold it, and how long they are entitled to keep it. Getting this wrong does not just risk a fine, it erodes employee trust and creates real legal exposure when disputes arise.
This guide breaks down what employee data Irish employers can legally collect and retain, the legal bases that apply, the retention periods set out in Irish legislation, and the practical steps you should be taking right now.
What Counts as Employee Personal Data?
Under GDPR, personal data is any information that relates to an identifiable living person. In an HR context, which covers far more than most employers realise. The obvious categories include names, home addresses, dates of birth, PPS numbers, contact details, and bank account information. However, it also extends to performance reviews, disciplinary records, absence patterns, training records, CCTV footage of employees, and even work email addresses where they identify the individual.
The Irish Data Protection Commission “DPC” has specifically addressed the question of work emails. An address like jsmith@company.ie may constitute personal data because it identifies the account holder. However, the content of professional emails sent in a work capacity is generally not considered the employee’s personal data, a distinction that matters significantly when handling subject access requests.
Then there is a higher-risk category. GDPR defines “special category data” as information relating to racial or ethnic origin, political opinions, religious beliefs, trade union membership, health, sexual orientation, and genetic or biometric data. In practice, this means medical certificates, occupational health reports, sick leave records, and even diversity monitoring data all fall into this bracket. Processing this data requires stronger justification, and employers should be especially careful about collecting more than is strictly necessary.
What Legal Basis Do You Need?
You cannot collect or process employee data simply because it seems useful. Under Article 6 of GDPR, every piece of data you hold must be linked to a specific legal basis. In an employment context, the DPC’s workplace guidance identifies several that commonly apply.
Contractual Necessity
If processing is required to fulfil the employment contract, this basis applies. The most straightforward example is processing an employee’s bank details to pay their salary. It also covers processing needed to administer benefits or entitlements set out in the contract. The key point: the contract must be between the employer and the employee directly. A contract with a third-party provider does not satisfy this requirement.
Legal Obligation
Irish employers are required by law to hold certain employee records. Providing payroll data to Revenue, maintaining working time records under the Organisation of Working Time Act 1997, and retaining payslips for National Minimum Wage Act compliance are all grounded in legal obligation. The DPC expects employers to be transparent about which specific laws they are relying on – a vague reference to “compliance” is not sufficient.
Legitimate Interests
This is the broadest basis, but also the one the DPC urges the most caution around. An employer might rely on legitimate interests for things like performance management records, internal investigations, or CCTV for security purposes. However, the employer must carry out a balancing exercise, weighing their business interest against the employee’s right to privacy. Where the processing involves systematic monitoring or high-risk activities, a Data Protection Impact Assessment is strongly recommended.
A Note on Consent
Many employers default to consent as their legal basis for holding employee data. The DPC has been clear that this is problematic due to the inherent power imbalance in the employer-employee relationship, consent in the workplace is rarely considered “freely given” in the way GDPR requires. In most cases, employers should be relying on one of the other legal bases above rather than asking employees to sign consent forms that may not hold up to scrutiny.
How Long Can You Keep Employee Data?
GDPR’s storage limitation principle is clear, hold data for no longer than necessary. However, “necessary” in an Irish employment context is shaped by a patchwork of specific legislation, each with its own retention period. Here are the key ones every employer should know.
Working time records, including hours worked, breaks, and annual leave, must be retained for three years under the Organisation of Working Time Act 1997.
Payslips and records demonstrating National Minimum Wage compliance carry a three-year statutory period under the National Minimum Wage Act 2000, though Revenue’s requirements for payroll and tax records extend to six years under the Taxes Consolidation Act 1997.
Records relating to parental leave and force majeure leave must be kept for eight years under the Parental Leave Act 1998 and workplace accident records should be retained for ten years from the date of the incident, as required by the Safety, Health and Welfare at Work (General Application) Regulations 1993 (S.I. No. 44/1993).
Written terms of employment must be held for the duration of employment and for at least one year after termination as per the Terms of Employment (Information) Act 1994. However, in practice, many employers choose to retain contracts for six years post-termination, in line with the general limitation period under the Statute of Limitations Act 1957, in case there is a requirement to defend against any post-employment potential claims.
For unsuccessful job applicants, the DPC considers a retention period of one full year to be appropriate, long enough to address any discrimination claims under the Employment Equality Acts, where the time limit is typically six months but that can be extended to twelve months for exceptional reasons.
Where legislation gives no specific retention period, the burden falls on the employer to justify any continued storage. Performance review records, internal investigation files, and training records should all be covered by a clear, documented retention policy.
Employee Privacy Notices and Acceptable Use Policies
Transparency is a core GDPR principle, and the DPC expects Irish employers to do more than just comply behind the scenes. Every employer should provide employees with a clear Employee Privacy Notice, setting out what data is collected, the legal basis for processing, who it may be shared with, how long it will be retained, and how employees can exercise their rights.
The DPC has also moved from recommending to expecting employers to have an “Acceptable Use Policy” in place. This should clearly state how business IT systems, email, internet, and devices can be used for personal purposes, and the extent to which the employer may monitor usage. Without such a policy, employees may reasonably assume they have a right to privacy in their use of work systems and any monitoring could be found disproportionate.
Beyond policies, the DPC’s guidance highlights the importance of the purpose limitation principle. Data collected for one reason cannot simply be repurposed for another. The DPC used a pointed case study in its guidance: an employer who collected car park and building access data for security purposes could not then use that data to verify time and attendance. If you want to use data for a new purpose, you need a fresh legal basis and must inform the employee.
What Rights Do Employees Have Over Their Data?
Under GDPR, employees have the right to access their personal data (through a “subject access” request), the right to have inaccurate data corrected, and in some circumstances, the right to have data erased or to restrict its processing. Employers must respond to a subject access request within one month. If the request is complex, that deadline can be extended by a further two months, but the employee must be informed of the delay within the original timeframe.
In practice, subject access requests are where many employers may come unstuck. The process typically falls to HR, often with support from IT, legal, and line managers. Getting it right means having a clear internal process: acknowledge the request, identify all relevant data, review it for any exemptions, and deliver it within the deadline. Every request should be logged for compliance purposes.
One practical step the DPC recommends is providing employees with access to an HR self-service portal, so they can see what data the employer holds about them in real time. This does not remove the obligation to respond to formal requests, but it reduces friction and demonstrates good faith.
Employee Monitoring: Where the Line Falls
Technology has made it easy to monitor employees, email surveillance, internet tracking, GPS on company vehicles, keystroke logging, screen capture software. However, the DPC has drawn a clear line here, any monitoring must be proportionate to the employer’s legitimate interest, and employees must know it is happening.
The DPC recognises that employers have a legitimate interest in protecting their business, resources, and reputation, however it warns that employee monitoring software is particularly intrusive by its nature and recommends that employers seek less intrusive alternatives where possible. Covert surveillance is generally unlawful and should only be considered where a crime has been committed or is reasonably suspected.
With the EU AI Act now in force, employers using AI-powered monitoring or performance assessment tools face additional obligations. AI systems used in recruitment screening, performance evaluation, task allocation, and promotion or termination decisions are classified as high-risk under the Act, and emotion recognition in the workplace is now prohibited outside of medical contexts. Irish employers should be reviewing their HR technology stack with this in mind.
What Happens If You Get It Wrong?
The consequences of non-compliance go beyond DPC fines, though those can be substantial. Holding personal data without a lawful basis, retaining it beyond justifiable periods, or failing to respond to employee data requests can all create exposure in employment disputes heard at the Workplace Relations Commission.
WRC inspectors have the power to enter any place of work, inspect employment records, take copies, and remove records where necessary. Failing to produce records when requested is a criminal offence. And in an unfair dismissal or discrimination case, the absence of properly maintained records almost always works against the employer.
There is also the reputational dimension. Data breaches involving employee information damage trust internally at a time when retention and engagement are already challenging for many Irish businesses.
Practical Steps for Irish Employers
Compliance is not a one-off exercise. It requires systems, policies, and regular review. Here are the steps that separate compliant employers from those operating on assumptions.
- Conduct a data audit: Map every category of employee data you hold, where it is stored, and who has access to it.
- Identify your legal basis: For each category, document the specific legal basis under Article 6 of GDPR. If you are relying on consent, reconsider whether another basis applies.
- Create a data retention policy: Set clear retention periods aligned with Irish legislation and document the reasoning. Apply it consistently.
- Issue an Employee Privacy Notice: Ensure every employee has been provided with a notice that clearly explains what data you hold, why, and for how long.
- Implement an Acceptable Use Policy: Cover email, internet, devices, and any monitoring – and make sure employees are aware of it.
- Establish a process for subject access requests: Know who handles them, how data is gathered, and how you will meet the one-month deadline.
- Review your HR technology: If you use monitoring software, CCTV, or AI-powered tools, assess whether they comply with GDPR and the EU AI Act.
- Train your team: GDPR compliance is not just an HR responsibility. Line managers, IT staff, and anyone handling employee data need to understand the basics.
Getting This Right Matters
Employee data compliance is not a box-ticking exercise, it is about building a workplace that respects privacy, operates transparently, and can withstand scrutiny. The DPC’s guidance has made the expectations clear. Irish employers who take the time to get their data practices right will find themselves better protected, more trusted, and far less likely to find themselves on the wrong side of a WRC hearing or a DPC investigation.
If you are unsure whether your current data practices stand up, an HR audit is the best place to start.
HRP Group works with Irish businesses to review HR documentation, data policies, and compliance frameworks, giving you a clear picture of where you stand and what needs to change.
Get in touch with our team at info@hrpgroup.ie or call 01 676 0006 to book a free HR consultation.


