Employee Data Protection and AI Tools: Rules HR Must Follow
Every AI tool that touches employee data brings data protection duties with it. These eight rules cover most of what HR needs to get right.
Short answer
To comply with data protection when using AI tools, HR should establish a lawful basis other than consent where possible, limit data to what is necessary, apply extra protection to special category data such as health, avoid solely automated decisions with significant effects unless an exception and safeguards apply, carry out data protection impact assessments for higher-risk uses, put strong data processing agreements in place with vendors, enforce retention limits, and enable employees to exercise their rights, including access to data and inferences about them.
Key takeaways
- Eight rules cover most HR AI data protection duties.
- Special category data needs an additional legal condition.
- Inferences generated by AI can themselves be personal data.
- Vendor contracts must address model training, location and deletion.
Eight rules
| Rule | What it requires |
|---|---|
| 1. Lawful basis | Identify and document a lawful basis; avoid relying on employee consent where it is not freely given |
| 2. Minimisation | Use only data necessary for the purpose; pseudonymise where possible |
| 3. Special category data | Meet an additional condition for health, biometric, ethnicity and similar data |
| 4. Automated decisions | Avoid solely automated decisions with legal or similarly significant effects unless an exception and safeguards apply |
| 5. Impact assessments | Conduct DPIAs for processing likely to be high risk |
| 6. Vendors | Data processing agreements; restrictions on model training; security; location |
| 7. Retention | Keep data and AI outputs only as long as needed |
| 8. Rights | Enable access, correction, objection and human review |
A DPIA outline for HR AI
- Describe the processing: purpose, data, AI system, people affected.
- Assess necessity and proportionality.
- Identify risks to employees: bias, inaccuracy, intrusion, security, loss of control.
- Define measures: minimisation, oversight, transparency, testing, access controls.
- Consult the data protection officer and, where appropriate, employees.
- Record the decision and review date.
Under the EU AI Act, deployers of high-risk systems should use information from providers to support these assessments. See EU AI Act employer obligations.
Vendor contract essentials
- Processing only on your documented instructions.
- No training of vendor models on your data without explicit agreement.
- Data location and international transfer safeguards.
- Security standards and breach notification.
- Sub-processor controls.
- Deletion or return of data at contract end.
- Audit and information rights.
AI inferences are personal data
When AI produces scores, predictions or labels about an employee, such as an attrition risk or skills profile, these outputs are generally personal data. Employees may have rights to access and correct them. Treat them with the same care as source data. See how AI predicts attrition.
This is general information, not legal advice. Employee privacy and monitoring law varies significantly by country and state; take qualified advice for your jurisdictions.
Related guides
- AI and Employee Data Privacy: A Guide for HR
How AI changes the privacy picture for employee data, the principles that apply and practical safeguards.
- How to Protect Employee Data When Using AI: A Practical Playbook
Ten practical controls for protecting employee data across HR AI tools.
- EU AI Act Employer Obligations: Deployer Duties Explained
Each deployer duty for high-risk HR AI explained, with practical actions for HR.
- AI Policy for Employees: Why You Need One and What It Should Cover
Why an employee AI policy is essential, what it covers and who owns it.
Frequently asked questions
What data protection rules apply to HR AI tools?
Lawful basis, data minimisation, extra protection for special category data, limits on solely automated decisions, impact assessments, vendor contracts, retention limits and employee rights.
Are AI-generated scores about employees personal data?
Generally yes. Scores, predictions and labels about identifiable employees are personal data and may be subject to access and correction rights.
What should an HR AI vendor contract include?
Processing only on instructions, no model training on your data without agreement, data location and transfer safeguards, security, breach notification, sub-processor controls, deletion at end and audit rights.
Can HR use AI for solely automated decisions?
Under the GDPR, solely automated decisions with legal or similarly significant effects are restricted unless an exception applies, with safeguards including the right to human intervention.
