The personnel file and the GDPR: what you may keep

Organizing checklist personnel file data

An employer must keep records of its employees, and at the same time may only process personal data that are necessary for the employment relationship. Those two obligations meet in the personnel file, and the practical question is always the same: what may go in, what may not, and how long may it stay there.

What may be kept

Data necessary for the performance of the employment contract and for compliance with statutory obligations: name and address details, date of birth, the citizen service number, a copy of the identity document verified at the start of employment, the contract and its amendments, salary and payroll data, appraisals and correspondence about performance, training records, absence dates, and records relating to warnings or disciplinary matters.

The citizen service number and the identity document copy sit in the file because tax and social security legislation requires them; that same requirement is what makes them lawful. Asking for an identity document copy for any other purpose is not permitted.

What may not be kept

Health data are the main trap. When an employee reports sick, the employer may record that the employee is absent, from what date, and what the expected duration is, together with what the employee can and cannot do at work and any adjustments needed. The employer may not record the nature of the illness, the diagnosis, the treatment or the medication, even where the employee volunteers it. That information belongs to the company doctor, whose file is separate and to which the employer has no access.

Equally out of place are data about religion, political opinion, trade union membership, ethnic origin and sexual orientation, unless a specific statutory exception applies; notes about an employee’s private life that have no bearing on the work; and unstructured personal impressions recorded by managers, which employees are entitled to see and which read very differently in a dispute than they did when written.

How long may data be kept?

The GDPR sets no fixed periods; the rule is that data may not be kept longer than necessary. In practice two lines are used: most personnel data are removed within about two years of the end of employment, while data required for tax purposes – payroll records, the identity document copy, the wage tax statement – are kept for seven years, because the tax authority requires it.

Applications from candidates who are not hired are normally destroyed within four weeks, or up to a year with the candidate’s consent. A retention schedule that sets these periods per category, and is actually applied, is what turns compliance from an aspiration into evidence.

The employee’s rights

Employees have the right to see their file, to have inaccurate data corrected, and in defined circumstances to have data erased. A request for access is a right, not a hostile act, and it must be answered within a month. In practice these requests often arrive at the start of a dispute, which is a good reason to keep files that can be shown without embarrassment.

Practical checklist

Keep one file per employee with a defined structure, so that it is clear what is in it. Restrict access to those who need it, and log who has access. Keep sickness data with the company doctor and out of the personnel file. Apply the retention periods on a fixed date each year rather than case by case. And record the whole of this in the processing register, which is the first document a supervisory authority will ask for.

Advice

We review personnel file practice, draft retention schedules and privacy statements for employees, and advise where an access request arrives in the middle of a dispute. Please contact Law & More; our employment and privacy lawyers work together on these questions.

Need Legal Assistance?

Contact Law & More for expert guidance on your legal matters. Our multilingual team is ready to help.

Related articles

This article is about arbitral awards under the New York Convention. For court judgments, see

Almost every company with a Dutch-facing website publishes a privacy policy — a privacyverklaring or

The Autoriteit Persoonsgegevens (AP) is the Dutch Data Protection Authority: the independent supervisory authority that

If your employer does not comply with the applicable collective labour agreement, the terms of

Explore the implications of losing a residence permit and understand why it matters for individuals

When an employee in the Netherlands calls in sick, the employer’s ability to monitor them

Stay Updated on Dutch Law

Subscribe to our newsletter for the latest legal insights, regulatory updates, and practical advice.