The Hidden Liability in Your HR Database

Where the Retention Periods in This Article Come From

The specific timeframes below, six to twelve months for rejected candidates, six to ten years for payroll, come from two places: Article 5 of the GDPR itself, which sets the storage limitation principle but deliberately avoids naming fixed periods, and the country-level guidance that fills that gap. The UK figures are drawn from the ICO's storage limitation guidance and the CIPD's retention factsheet, which lists statutory minimums (tax and payroll law) alongside CIPD's own practitioner recommendations for the records GDPR leaves undefined, disciplinary notes, performance reviews, unsuccessful applications.

That split matters because GDPR does not hand HR teams a table of numbers to copy. It sets a principle, don't keep data longer than the purpose requires, and leaves the "how long" to a mix of national tax law, employment law, and professional guidance. A payroll record has a hard floor set by statute; a rejected candidate's CV does not, which is why guidance on that figure varies more between sources and why we've flagged it as a defensible range rather than a fixed rule.

One caveat worth stating plainly: retention periods are set at the national level even under a single EU-wide regulation, so a figure that holds in the UK or Ireland may not hold in Germany or France. Anything in this article should be checked against local statute before it goes into a live policy, not treated as a drop-in number.

Human Resources teams manage vast quantities of sensitive personal information, ranging from initial candidate applications to post-employment tax records. In the European regulatory landscape, holding this data without a defined purpose or expiration date constitutes a significant compliance risk. According to DLA Piper’s GDPR Fines and Data Breach Survey, fines issued for data protection violations exceeded €2.4 billion in 2023 alone, with improper data retention ranking among the top cited infringements. For HR leaders, the challenge is not merely storing data securely but knowing precisely when to destroy it.

Many organisations operate under the misconception that keeping records indefinitely protects them from future legal disputes. In reality, excessive data retention increases the surface area for potential breaches and violates the storage limitation principle outlined in Article 5 of the GDPR. When a data subject requests erasure, your team must be able to locate and delete every instance of their information across all systems. Failure to execute this efficiently can result in regulatory penalties that far outweigh the administrative cost of maintaining a clean database. A strong policy transforms data retention from a legal liability into a structured operational asset.

Key Insight

Organisations that fail to implement automated data deletion protocols face a 40% higher risk of non-compliance during regulatory audits, according to 2024 compliance benchmarking data.

Defining Compliant Data Retention in 2026

Data retention in an HR context refers to the structured practice of storing employee and candidate records for a specific period based on legal necessity, business need, or consent, followed by secure deletion. It is distinct from data storage, which focuses on security and accessibility during the active lifecycle of the record. In 2026, this definition has evolved beyond simple file management to encompass dynamic data flows across multiple platforms, including applicant tracking systems, payroll providers, and performance management tools. A compliant policy dictates not only how long data is kept but also the legal basis for holding it during that timeframe.

The importance of this framework has intensified as cross-border employment becomes standard and regulatory scrutiny increases. HR teams must navigate conflicting requirements where local labour laws may mandate keeping payroll records for seven years, while privacy regulations demand minimisation. Without a clear GDPR recruitment complete guide aligned strategy, organisations risk holding candidate data long after the legitimate interest for processing has expired. Effective retention policies balance the need for historical reporting with the individual’s right to privacy, ensuring that data is not kept ‘just in case’ but rather because a specific statutory or contractual obligation exists.

Core Components of a Retention Strategy

Building a compliant framework requires categorising data based on its sensitivity and the legal grounds for processing. HR records generally fall into three distinct buckets: recruitment data, active employee records, and post-employment archives. Each category carries different risks and retention timelines. Recruitment data, for example, often relies on consent or legitimate interest, whereas payroll data is held due to statutory tax obligations. Understanding these distinctions prevents the blanket application of retention periods that may be too short for legal compliance or too long for privacy safety.

Recruitment and Candidate Data

Candidate information is where retention schedules break down fastest. The moment a hiring decision is made, the legitimate interest for holding onto unsuccessful applicants starts eroding. Most European jurisdictions land on six to twelve months as a defensible window against discrimination claims, but only if consent was obtained for future opportunities in the first place. Talent pools raise a separate problem: consent there needs to be refreshable and specific to the person, not a blanket checkbox from three years ago. A dedicated candidate database guide approach helps here, keeping active prospects walled off from archived applications so old CVs don't quietly resurface in a live pipeline.

Active Employee Records

Once someone is hired, the calculus changes. Performance reviews, disciplinary records, health and safety documentation, these now answer to contractual and legal necessity rather than recruiting logic. Some of it has to survive employment plus a statutory tail; other material, like informal meeting notes, has no business sticking around that long. The line that matters is between core personnel files and transient operational chatter. Blur it, and a routine subject access request turns into a much bigger job, because now there's more data in scope, and more of it exposed if a breach ever happens.

Post-Employment Archives

After someone leaves, the legal basis shifts again. Payroll records commonly need to survive six to ten years for tax purposes, the exact figure depends on the country. What changes immediately, though, is access. The day someone exits, their record should move behind role-based controls, archived apart from active staff data. Skip that step and former employee data has a habit of turning up where it shouldn't, in a marketing list, an internal directory search, somewhere nobody intended, and each of those is its own privacy violation.

Automated Retention Scheduling

Treegarden allows HR teams to set custom retention rules for different data categories, automatically flagging records for review or deletion based on local compliance laws. Treegarden ATS ensures no record outstays its legal welcome.

Implementing a Retention Schedule

Developing a policy requires a systematic audit of current data holdings followed by the establishment of clear deletion protocols. HR teams cannot rely on manual spreadsheets to track expiration dates across thousands of records. The implementation process must be integrated into the daily workflow of the HR department, ensuring that data lifecycle management happens automatically rather than as an annual cleanup exercise. This reduces the administrative burden and minimises the risk of human error during the deletion process.

  1. Start with the audit, not the policy. Most teams want to skip straight to writing retention periods, but you can't set a deletion date for data you don't know you have. Walk through every system that touches employee or candidate information, cloud storage, local drives, the ATS, the payroll provider, and anything a manager has stashed in a personal spreadsheet. Shadow IT is where the unauthorised copies live, and it's usually bigger than people expect.
  2. Once you know what you're holding, attach a legal basis to each category before you attach a number. Consent, contract, or legal obligation, pick one per data type and write down the actual regulation behind it if it's statutory. Skipping this step is how organisations end up defending a retention period they can't justify when a regulator asks why.
  3. Retention periods follow from the legal basis, not the other way round. A CV held on legitimate interest might run 12 months; payroll data tied to tax law runs 7 years regardless of preference. If the company operates across borders, the rule is simple: whichever jurisdiction's law is strictest wins, and that period applies company-wide unless you're prepared to run separate schedules per country.
  4. Finally, get deletion out of anyone's manual to-do list. Configure the HRIS or ATS to flag records as they approach expiration and let a script handle the anonymisation or deletion once the clock runs out. The part people forget is the audit trail, log every deletion, because "the record is gone" and "we can prove we deleted it compliantly" are two different things to a regulator.

Audit Trail Requirement

Always log the deletion of personal data. Regulators may ask for proof that data was destroyed compliantly, not just that it is missing from the system.

Once the schedule is defined, communication is key. Hiring managers and HR administrators must understand why data is being deleted. If a recruiter wants to keep a candidate profile for three years without renewed consent, the policy must empower the compliance officer to override this request. Training sessions should highlight the risks of data hoarding, using real-world examples of fines related to excessive retention. Regular reviews of the policy ensure it adapts to changing laws, such as new AI regulations affecting how candidate data is processed.

Metrics and Risk Management

To validate the effectiveness of a data retention policy, HR teams must track specific compliance metrics. These indicators provide visibility into how well the organisation adheres to its own rules and where risks are accumulating. Without measurement, retention policies remain theoretical documents rather than operational controls. Integrating these metrics into broader HR analytics efficiency metrics allows leadership to see compliance as a function of operational health.

  • Data Age Distribution: the share of records past their defined retention date. Zero is the goal; anything under 2% still counts as a healthy control environment.
  • Deletion Latency: how long records sit around after they expire before someone actually deletes them. If this number keeps growing, it usually means a workflow bottleneck, not a policy problem.
  • Subject Access Request (SAR) cost. Every extra year of retained data makes erasure requests slower and more expensive to fulfil, so this metric is a decent proxy for how bloated your database has become.
  • Consent Renewal Rate: for candidate databases that run on consent, what fraction of profiles are still valid and unexpired. When this drops, it's a signal to run a re-engagement campaign or start purging.

Compliance Dashboards

Visualise data age and retention risks in real-time. The Treegarden platform provides dashboards that highlight records approaching expiration, enabling proactive management.

ROI in this context is primarily risk avoidance rather than revenue generation. The cost of implementing automated retention tools is negligible compared to the potential fines and legal fees associated with a data breach involving outdated records. Furthermore, leaner databases improve system performance and reduce storage costs. By treating data retention as a continuous improvement process, HR teams can demonstrate due diligence to regulators. This proactive stance often mitigates penalties should a breach occur, as authorities recognise the effort made to minimise data exposure.

Common Pitfalls and Best Practices

Even well-intentioned HR departments often stumble on specific nuances of data retention. Avoiding these common errors ensures the policy remains strong under scrutiny. The following areas represent the most frequent points of failure observed during compliance audits across Europe.

1. Indefinite ‘Just in Case’ Storage

This is the single most common violation: no defined end date. A recruiter keeps a CV "just in case" a similar role opens up next year, and multiplied across thousands of candidates, that habit quietly invalidates the original legal basis for holding the data at all. The fix isn't complicated, just unpopular: a hard stop date on every record, after which it's either deleted or the candidate is asked for fresh consent.

2. Ignoring Backup Systems

Teams delete from the live system and call it done, forgetting the backups. But if a candidate exercises their right to erasure, that data has to disappear from backups too, or at minimum stay inaccessible if a backup is ever restored. Write the backup rotation cycle into the policy explicitly. Otherwise a routine disaster-recovery restore can quietly bring deleted personal data back to life.

3. Mixing Data Categories

Health records sitting in the same folder as general contact details is a retention headache waiting to happen, because health data carries stricter security requirements and a shorter shelf life. Segregate special category data into its own encrypted, access-restricted location with a retention schedule that runs independently of everything else.

4. Lack of Vendor Oversight

Background check providers and other third-party processors hold your data too, and their retention habits become your liability. Vendor contracts need deletion clauses that mirror internal policy, word for word if possible. Skip the verification step and you're on the hook for whatever the vendor does, or fails to do, after the contract ends.

Vendor Due Diligence

Regularly audit third-party processors to confirm they adhere to your retention schedule. Request deletion certificates for offboarded vendor data.

Frequently Asked Questions

How long should we keep unsuccessful candidate CVs?

Generally, unsuccessful candidate data should be kept for 6 to 12 months to defend against potential discrimination claims. Beyond this period, you must obtain renewed consent to keep the data for future opportunities, otherwise it should be securely deleted.

Does GDPR require us to delete employee data immediately after they leave?

No. GDPR allows data retention when there is a legal obligation, such as tax or labour laws requiring payroll records to be kept for 6 to 10 years. However, access should be restricted, and data not required for legal purposes should be deleted.

Can we keep a talent pool of past applicants indefinitely?

No. Consent for talent pools expires. Best practice is to refresh consent every 12 to 24 months. If a candidate does not respond to a consent renewal request, their data must be removed from the active talent pool.

What happens if we accidentally keep data too long?

If you discover data has been retained beyond its schedule, delete it immediately and document the incident. Proactive self-correction is viewed favourably by regulators compared to hiding the error until an audit occurs.

Do backup tapes need to comply with retention schedules?

Yes. While technical deletion from backups may be complex, policies must ensure that restored backups do not reintroduce expired data. Some organisations use immutable backups with strict rotation cycles to manage this risk.

Effective data retention is a continuous process that protects your organisation from regulatory risk and operational bloat. By implementing structured policies and using automation, your team can ensure compliance without sacrificing efficiency. Start building your compliant retention workflow today by exploring Treegarden platform, designed to keep your HR data secure, organised, and legally sound.

Sources

  1. Regulation (EU) 2016/679 (GDPR), Article 5, official consolidated text on EUR-Lex, defines the storage limitation principle that underpins every retention period discussed in this article
  2. ICO, Storage Limitation Principle, UK Information Commissioner's Office guidance on justifying and documenting retention periods, plus the requirement to review data on request
  3. CIPD, Retention of HR Records factsheet, statutory and recommended retention periods by record type, including the impact of the Employment Rights Act 2025