[codicts-css-switcher id=”346″]

Global Law Experts Logo
gdpr hr france

Our Expert in France

RGPD (GDPR) for HR in France 2026: Practical Steps for Employers, HR Teams and the CSE

By Global Law Experts
– posted 2 hours ago

GDPR HR France compliance sits at the intersection of European data protection law and French labour law, and in 2026 it remains one of the most demanding operational challenges facing employers and their HR teams. Personnel data, from recruitment files and payroll records to performance reviews, health information and monitoring logs, is among the most sensitive categories any organisation processes, and it is governed simultaneously by the EU General Data Protection Regulation (Regulation (EU) 2016/679), the French Data Protection Act (Loi Informatique et Libertés), the Code du travail and the supervisory oversight of the CNIL.

This guide translates those overlapping obligations into concrete steps for employers, in-house counsel and members of the Comité Social et Économique (CSE), covering lawful bases, DPIAs, retention schedules, consultation duties and breach response. The aim throughout is practical: what to record, when to consult, and how to act quickly when something goes wrong.

Who this is for and what it covers: HR managers, in-house counsel and CSE members applying the RGPD to personnel data in France in 2026. It sets out lawful bases by HR activity, DPIA triggers, retention schedules, CSE consultation steps, breach response and ready-to-adapt templates. Every legal duty is cited to a primary source, the GDPR text, the CNIL, Legifrance or the Ministère du Travail.

Quick legal overview: GDPR and the French context

The starting point for any GDPR HR France analysis is the EU General Data Protection Regulation, Regulation (EU) 2016/679, which applies directly across all Member States. It is complemented in France by the Loi Informatique et Libertés (Loi n°78-17 of 6 January 1978, as amended), which sets out national implementation rules and confirms the supervisory role of the CNIL (Commission nationale de l’informatique et des libertés) as France’s data protection authority. Employers must read both instruments together: the GDPR provides the framework of principles and rights, while the French Act and the Code du travail add national detail, particularly where worker privacy, employee representation and collective protections are concerned.

Article 88 of the GDPR is central to the employment context. It expressly permits Member States to provide, by law or collective agreement, more specific rules to protect employees’ rights and freedoms in the processing of their personal data. France has used this latitude, which is why HR data processing cannot be assessed by reference to the GDPR alone, French labour law and CNIL guidance must always be layered on top.

Key statutory references to cite

Several GDPR articles recur constantly in HR practice, and it is worth committing them to memory:

  • Article 6. The six lawful bases for processing, the foundation for every HR activity.
  • Article 9. Special categories of data (including health and trade union membership), which are prohibited unless a specific condition applies.
  • Article 30. The obligation to maintain records of processing activities.
  • Articles 33 and 34. The rules on notifying the supervisory authority and affected individuals following a personal data breach.
  • Article 88. Member State rules for the employment context.

How French labour law interacts with the GDPR

French labour law reinforces and, in places, exceeds the protections in the GDPR. The Code du travail imposes duties of proportionality and transparency on employers who monitor staff, and it gives the CSE information and consultation rights that are triggered whenever data processing affects working conditions or collective interests. For HR teams, this means that a processing operation which is lawful under the GDPR may still be unlawful, or at least premature, if the employer has failed to consult the CSE or has monitored employees without proportionate justification. Getting GDPR HR France compliance right therefore requires a joint reading of data protection and labour obligations from the outset.

Which employee data may be processed, lawful bases and restrictions

Employers process a wide range of personnel data across the employment lifecycle. Understanding what falls within scope is the first step to lawful GDPR HR France processing. Common categories include:

  • Identity data. Name, date of birth, nationality, national identifiers where legally required.
  • Contact data. Home address, personal and professional telephone numbers, email addresses.
  • Contractual data. Job title, salary, bank details, working time records, leave.
  • Performance data. Appraisals, objectives, training records, disciplinary history.
  • Health data. Sick leave, occupational health assessments, workplace accident records.
  • Monitoring data. CCTV footage, access logs, geolocation data from vehicles or devices.

Each category must be tied to a purpose and a lawful basis, and each must respect the principle of data minimisation, collect only what is necessary for the stated purpose. The CNIL’s guidance on the RGPD applied to human resources makes clear that employers should not gather data “just in case”, and that the necessity of each field on a form or in a system should be capable of justification.

Lawful bases explained

Article 6 of the GDPR sets out the lawful bases available to employers. In the HR context, four are relevant in practice:

  • Performance of a contract (Art. 6(1)(b)). The natural basis for processing needed to manage the employment contract, paying salary, administering leave, providing tools to do the job.
  • Legal obligation (Art. 6(1)(c)). Processing required to comply with French law, such as social security declarations, tax reporting and mandatory occupational health records.
  • Legitimate interests (Art. 6(1)(f)). Available for some processing, for example, certain security or IT administration purposes, but it requires a documented balancing test and does not override employees’ rights.
  • Consent (Art. 6(1)(a)). Rarely appropriate in employment, for the reasons set out below.

Choosing the right basis matters because it determines which employee rights apply and how the processing must be documented. HR teams should record the lawful basis for each processing activity in their register (see Article 30 below), and should not switch bases opportunistically.

Special categories of data, health, trade union membership and the Article 9 routes

Health data, trade union membership, and other special categories under Article 9 are prohibited unless a specific condition applies. In HR, the most common route is Article 9(2)(b), processing necessary to carry out obligations in the field of employment and social protection law. Occupational health records, sick leave management and disability accommodation typically rely on this. Because the CNIL treats health data as high-risk, access should be strictly limited, ideally confined to occupational health professionals and a minimal number of HR staff on a need-to-know basis, with enhanced security. Trade union membership data is similarly sensitive and should never be recorded beyond what is strictly necessary for administering rights such as delegated hours.

Practical steps for HR: records, DPIA, retention, consent and security

Turning legal principles into daily practice is where most GDPR HR France programmes succeed or fail. The following steps form a workable operational framework that HR teams can implement and audit.

Step 1, Data mapping and inventory

Begin by mapping every HR processing activity. A useful inventory captures, for each activity: the purpose; the categories of data and data subjects; the lawful basis; the recipients (including payroll providers and other processors); any transfers outside the EU; the retention period; and the security measures in place. This mapping is not merely good housekeeping, it directly feeds the record of processing activities and reveals where DPIAs or CSE consultation may be required. Template fields should be standardised across departments so that new processing can be assessed consistently.

Step 2, Determine the lawful basis per activity

Using the mapping, assign a lawful basis to each processing activity rather than to HR as a whole. Recruitment, payroll, performance management, disciplinary records and occupational health each warrant separate analysis. The comparison table later in this guide illustrates how the analysis typically resolves for the most common activities.

Step 3, Identify DPIA triggers and run a data protection impact assessment

A DPIA (analyse d’impact relative à la protection des données) is required under Article 35 of the GDPR where processing is likely to result in a high risk to individuals’ rights and freedoms. In HR, the classic triggers are systematic monitoring of employees, profiling, and processing of health data at scale. Whenever HR proposes to introduce employee monitoring, video surveillance, keystroke or activity logging, vehicle geolocation, or productivity analytics for remote workers, a DPIA should be completed before deployment, having regard to the CNIL’s published lists of processing that does and does not require a DPIA.

A short-form HR DPIA should describe the processing and its purpose, assess necessity and proportionality, identify risks to employees, and set out the mitigating measures. Because monitoring also engages collective protections, the DPIA and the CSE consultation should be prepared in parallel.

Step 4, Apply minimum technical and organisational measures

Article 32 of the GDPR requires security appropriate to the risk. For HR systems handling sensitive personnel and health data, minimum measures should include:

  • Access controls. Role-based access so that only authorised HR staff can view specific data categories, with health data segregated.
  • Encryption. Encryption of data at rest and in transit, particularly for payroll and health records.
  • Logging. Audit logs recording who accessed which records and when, to support both security and breach investigation.
  • Processor controls. Written data processing agreements with payroll bureaus, benefits administrators and HRIS vendors, as required by Article 28.

Step 5, Draft fair processing notices and privacy clauses

Transparency is a core GDPR obligation. Employers must provide clear information notices to both job candidates and employees, explaining what data is processed, why, on what basis, for how long, who receives it and what rights individuals have. A candidate privacy notice should be provided at the point of application; an employee notice should be provided at hiring and updated when processing changes. Any template should carry a disclaimer that it must be adapted to the organisation and reviewed by counsel.

Step 6, Handle consent correctly

Consent is the most misused lawful basis in employment. The CNIL’s HR guidance is clear that consent is generally not valid where there is a clear imbalance of power between the parties, and the employment relationship is the paradigm case of such imbalance. Because an employee cannot freely refuse without fearing consequences, consent will rarely meet the GDPR’s “freely given” standard. HR should therefore default to contract performance, legal obligation or, where appropriate, legitimate interests, and reserve consent for genuinely optional matters such as publishing an employee’s photograph on a public website. Where consent is used, employees must be able to withdraw it as easily as they gave it, and withdrawal must be honoured promptly.

Step 7, Maintain records of processing activities (Article 30)

Article 30 requires controllers to maintain a record of processing activities. Organisations with fewer than 250 employees are, in principle, exempted, but the exemption does not apply where the processing is likely to result in a risk to rights and freedoms, is not occasional, or involves special categories of data. Because HR routinely processes health and disciplinary data on a continuous basis, the practical position for most employers is that the record is mandatory. The HR record should list each processing activity, its purpose, the data categories, recipients, retention periods and security measures, mirroring the data map from Step 1.

Step 8, Set retention periods

Personnel data must not be kept longer than necessary. Retention periods should be tied to a legal or evidential rationale, for example, the limitation periods for employment claims, or statutory obligations to retain payroll and social security records. Unsuccessful candidates’ CVs, performance records, disciplinary files and health data each warrant distinct retention rules. The suggested retention schedule below provides a starting point that must be adapted to the organisation’s specific legal exposure and to the applicable current CNIL guidance.

CSE obligations: when, how and what to consult

A distinctive feature of GDPR HR France compliance is the role of the CSE. Under the Code du travail, the CSE must be informed and consulted on projects affecting working conditions, and the Ministère du Travail’s guidance confirms the committee’s information and consultation functions. Where data processing introduces or changes employee monitoring, or otherwise affects the collective interests of staff, the employer’s GDPR project and its labour-law consultation obligations run together.

What information must be provided to the CSE

When consulting on a data-processing project, the employer should give the CSE a minimum dataset sufficient for it to form a reasoned opinion. This typically includes: the categories of personal data concerned; the purposes of the processing; the lawful basis relied on; the recipients and any processors; the retention periods; the technical and organisational safeguards; and, crucially, any DPIA carried out. Providing the DPIA is not merely good practice, it demonstrates that the employer has assessed the impact on employees before deploying the processing.

Timing: ordinary consultation versus prior consultation for projects

Consultation must take place before the decision is implemented. For significant projects, a reorganisation, the introduction of surveillance technology, or a new monitoring system, the CSE must be consulted in advance so that its opinion can genuinely influence the outcome. Implementing employee monitoring first and consulting afterwards exposes the employer to challenge both under labour law and under the GDPR, and may render evidence obtained through the monitoring inadmissible in later disputes. HR should therefore build the CSE consultation timeline into any project plan from the design stage.

Practical tips for meeting minutes, confidentiality and documentation

Document the consultation carefully. The agenda should list the data-processing item explicitly, the information provided should be recorded, and the CSE’s opinion should be minuted. Where the employer shares sensitive commercial or security information, it may designate that information confidential, and members are bound by a corresponding duty of discretion. Well-kept minutes serve a dual purpose: they evidence compliance with the Code du travail and they support the accountability principle under the GDPR by showing that employees’ representatives were engaged before processing began.

Responding to an employee data breach in France, CNIL notification and employer checklist

Even well-run HR functions suffer data breaches, a misdirected payroll file, a lost laptop, or unauthorised access to personnel records. A structured incident response is essential, and it is one of the areas where GDPR HR France obligations bite hardest because of the short deadlines involved.

Step 1, Triage and containment

The immediate priority is to stop the breach and limit the damage. Practical containment steps include isolating the affected account, revoking compromised credentials, disabling access to affected systems and preserving logs for investigation. Speed matters, because the clock for notification begins once the employer becomes aware of the breach.

Step 2, Assess severity and data affected

Identify which categories of personal data are involved, how many employees are affected, and the likely consequences for them. A breach involving payroll or health data is more serious than one involving a single business contact detail, and the severity assessment drives the notification decisions that follow.

Step 3, Notify the CNIL where required

Under Article 33 of the GDPR, the controller must notify the supervisory authority, the CNIL in France, without undue delay and, where feasible, no later than 72 hours after becoming aware of the breach, unless the breach is unlikely to result in a risk to individuals’ rights and freedoms. The CNIL’s dedicated breach-notification procedure sets out how to declare a violation and what information to include: a description of the breach, the categories and approximate number of individuals affected, the likely consequences, and the measures taken or proposed. Where notification is not made within 72 hours, the employer must explain the delay.

Step 4, Notify affected employees and inform the CSE

Where a breach is likely to result in a high risk to individuals, Article 34 requires the controller to communicate the breach to the affected employees without undue delay. The communication must describe the breach in clear language, give the contact point for more information, and set out the likely consequences and the measures taken. In parallel, the CSE should be informed where the breach affects working conditions or the collective interests of staff, an obligation that flows from the committee’s role under the Code du travail.

Step 5, Record the breach and capture lessons learned

The GDPR requires controllers to document every breach, including those not notified to the CNIL, together with the facts, effects and remedial action. An incident log should capture the timeline, the decision-making on notification, and the corrective measures implemented to prevent recurrence. This record is both a compliance obligation and a valuable tool for improving HR data security over time.

Practical tools: templates, comparison table and retention schedule

The following tools translate the guidance above into working documents for HR. Each template should carry the disclaimer: Template to be adapted to your organisation, consult counsel.

Choosing a lawful basis, recruitment vs performance vs disciplinary

HR activity Typical lawful basis When consent may be acceptable Special categories involved? Suggested retention (France) Consult CSE?
Recruitment Steps prior to contract / legitimate interests (Art. 6(1)(b)/(f)) Only for optional data or extended retention of an application Rarely, avoid collecting health data Unsuccessful candidate CVs kept only for a limited period unless the candidate agrees to longer retention Not usually, unless part of a broader recruitment tool with monitoring
Onboarding Performance of a contract / legal obligation (Art. 6(1)(b)/(c)) Only for genuinely optional items (e.g. staff photo) Possibly, health for occupational fitness (Art. 9(2)(b)) Duration of employment plus applicable limitation periods No
Performance management Performance of a contract / legitimate interests (Art. 6(1)(b)/(f)) Not appropriate, do not rely on consent No Retained for the employment relationship and relevant evidential periods Only where linked to systematic monitoring or profiling
Disciplinary records Performance of a contract / legal obligation (Art. 6(1)(b)/(c)) Not appropriate No Retained for the limitation periods applicable to the sanction No, unless part of a monitoring programme
Occupational health Employment and social protection law (Art. 9(2)(b)) Not appropriate Yes, health data, strictly access-controlled Retained per statutory occupational health rules Where a new health app or monitoring is introduced

Suggested retention schedule for HR data

Data type Retention rationale Practical approach
Unsuccessful candidate CVs No ongoing purpose once the role is filled Delete after a short period unless the candidate consents to retention in a talent pool
Employment contracts and payroll Statutory retention and evidential needs Retain for the periods required by tax, social security and labour law
Performance and disciplinary files Evidential value during and after employment Align to applicable limitation periods, then delete
Health and occupational records Occupational health obligations Retain per occupational health rules, with strict access controls

How to adapt templates to your organisation

These structures are starting points, not finished policies. Every organisation should adjust retention periods to its own legal exposure and to current CNIL guidance, tailor privacy notices to its actual processing, and map its own systems and processors. A pilot review of one high-risk activity, such as employee monitoring, is often the fastest way to surface gaps and refine the templates before rolling compliance out across all HR processes. Where the analysis is finely balanced, an employer should seek a compliance review before deploying new processing.

Conclusion and next steps for GDPR HR France compliance

Sound GDPR HR France compliance is a continuous discipline, not a one-off project, and it rewards employers who build data protection and CSE consultation into every HR decision from the design stage. If you do five things this week, do these: map your HR processing activities and confirm the lawful basis for each; check that your record of processing under Article 30 is complete; identify any monitoring or health-data processing that needs a DPIA and a CSE consultation; test your breach response against the 72-hour notification deadline; and review your candidate and employee privacy notices against the CNIL’s HR guidance.

Taken together, these steps put employers, HR teams and the CSE on firm ground and reduce the risk of enforcement, disputes and reputational harm. For deeper support, see the supporting guides on recruitment, CSE consultation and breach response, and consider a full compliance review.

Need Legal Advice?

This article was produced by Global Law Experts. For specialist advice on this topic, contact Henri Guyot at aerige, a member of the Global Law Experts network.

Sources

  1. CNIL, La CNIL et les ressources humaines
  2. CNIL, Notifier une violation de données personnelles
  3. EUR-Lex, Regulation (EU) 2016/679 (General Data Protection Regulation)
  4. Legifrance, Code du travail (Consolidated)
  5. Legifrance, Loi n°78-17 (Informatique et Libertés)
  6. Ministère du Travail, Le comité social et économique (CSE)
  7. European Data Protection Board (EDPB), Guidelines & best practices

FAQs

What employee data can employers lawfully process under the RGPD in France?
Employers may process identity, contact, contractual, performance, disciplinary and, with safeguards, health data, provided each activity has a clear purpose and a lawful basis under Article 6 of the GDPR. Special categories such as health rely on Article 9(2)(b). The CNIL’s HR guidance requires data minimisation, so only data genuinely necessary for the stated purpose should be collected.
Recruitment typically relies on steps prior to a contract or legitimate interests; performance management on contract performance or legitimate interests; and disciplinary records on contract performance or legal obligation, all under Article 6 of the GDPR. Consent is generally inappropriate in these contexts because of the imbalance in the employment relationship identified by the CNIL.
Only rarely. The CNIL’s HR guidance states that consent is generally not valid where there is a clear imbalance of power, which the employment relationship inherently involves. Employers should default to contract performance, legal obligation or legitimate interests, reserving consent for genuinely optional processing such as publishing an employee’s photograph, and must allow withdrawal at any time.
Under the Code du travail and Ministère du Travail guidance, the CSE must be informed and consulted before implementing projects affecting working conditions or introducing employee monitoring. HR should provide the data categories, purposes, lawful basis, safeguards and any DPIA, and consult in advance so the committee’s opinion can influence the decision.
Contain the breach, assess the data and individuals affected, and notify the CNIL under Article 33 of the GDPR without undue delay and, where feasible, within 72 hours, unless the breach is unlikely to result in a risk. Follow the CNIL’s breach-notification procedure, inform affected employees under Article 34 where the risk is high, involve the CSE where relevant, and document everything. This is a core part of GDPR HR France breach readiness.
Only for as long as there is a purpose. Once a role is filled, unsuccessful candidates’ CVs should be deleted after a short period, unless the candidate agrees to retention in a talent pool. This reflects the storage-limitation principle and the CNIL’s guidance on recruitment data.
Yes. Health data is a special category under Article 9 of the GDPR and may generally be processed only under Article 9(2)(b) for employment and social protection obligations. Access should be strictly limited to occupational health professionals and a minimal number of HR staff, with enhanced security, as the CNIL treats such data as high-risk.
corporate law firm indonesia
By Global Law Experts

posted 50 minutes ago

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

RGPD (GDPR) for HR in France 2026: Practical Steps for Employers, HR Teams and the CSE

Send welcome message

Custom Message