GDPR HR France compliance sits at the intersection of European data protection law and French labour law, and in 2026 it remains one of the most demanding operational challenges facing employers and their HR teams. Personnel data, from recruitment files and payroll records to performance reviews, health information and monitoring logs, is among the most sensitive categories any organisation processes, and it is governed simultaneously by the EU General Data Protection Regulation (Regulation (EU) 2016/679), the French Data Protection Act (Loi Informatique et Libertés), the Code du travail and the supervisory oversight of the CNIL.
This guide translates those overlapping obligations into concrete steps for employers, in-house counsel and members of the Comité Social et Économique (CSE), covering lawful bases, DPIAs, retention schedules, consultation duties and breach response. The aim throughout is practical: what to record, when to consult, and how to act quickly when something goes wrong.
Who this is for and what it covers: HR managers, in-house counsel and CSE members applying the RGPD to personnel data in France in 2026. It sets out lawful bases by HR activity, DPIA triggers, retention schedules, CSE consultation steps, breach response and ready-to-adapt templates. Every legal duty is cited to a primary source, the GDPR text, the CNIL, Legifrance or the Ministère du Travail.
The starting point for any GDPR HR France analysis is the EU General Data Protection Regulation, Regulation (EU) 2016/679, which applies directly across all Member States. It is complemented in France by the Loi Informatique et Libertés (Loi n°78-17 of 6 January 1978, as amended), which sets out national implementation rules and confirms the supervisory role of the CNIL (Commission nationale de l’informatique et des libertés) as France’s data protection authority. Employers must read both instruments together: the GDPR provides the framework of principles and rights, while the French Act and the Code du travail add national detail, particularly where worker privacy, employee representation and collective protections are concerned.
Article 88 of the GDPR is central to the employment context. It expressly permits Member States to provide, by law or collective agreement, more specific rules to protect employees’ rights and freedoms in the processing of their personal data. France has used this latitude, which is why HR data processing cannot be assessed by reference to the GDPR alone, French labour law and CNIL guidance must always be layered on top.
Several GDPR articles recur constantly in HR practice, and it is worth committing them to memory:
French labour law reinforces and, in places, exceeds the protections in the GDPR. The Code du travail imposes duties of proportionality and transparency on employers who monitor staff, and it gives the CSE information and consultation rights that are triggered whenever data processing affects working conditions or collective interests. For HR teams, this means that a processing operation which is lawful under the GDPR may still be unlawful, or at least premature, if the employer has failed to consult the CSE or has monitored employees without proportionate justification. Getting GDPR HR France compliance right therefore requires a joint reading of data protection and labour obligations from the outset.
Employers process a wide range of personnel data across the employment lifecycle. Understanding what falls within scope is the first step to lawful GDPR HR France processing. Common categories include:
Each category must be tied to a purpose and a lawful basis, and each must respect the principle of data minimisation, collect only what is necessary for the stated purpose. The CNIL’s guidance on the RGPD applied to human resources makes clear that employers should not gather data “just in case”, and that the necessity of each field on a form or in a system should be capable of justification.
Article 6 of the GDPR sets out the lawful bases available to employers. In the HR context, four are relevant in practice:
Choosing the right basis matters because it determines which employee rights apply and how the processing must be documented. HR teams should record the lawful basis for each processing activity in their register (see Article 30 below), and should not switch bases opportunistically.
Health data, trade union membership, and other special categories under Article 9 are prohibited unless a specific condition applies. In HR, the most common route is Article 9(2)(b), processing necessary to carry out obligations in the field of employment and social protection law. Occupational health records, sick leave management and disability accommodation typically rely on this. Because the CNIL treats health data as high-risk, access should be strictly limited, ideally confined to occupational health professionals and a minimal number of HR staff on a need-to-know basis, with enhanced security. Trade union membership data is similarly sensitive and should never be recorded beyond what is strictly necessary for administering rights such as delegated hours.
Turning legal principles into daily practice is where most GDPR HR France programmes succeed or fail. The following steps form a workable operational framework that HR teams can implement and audit.
Begin by mapping every HR processing activity. A useful inventory captures, for each activity: the purpose; the categories of data and data subjects; the lawful basis; the recipients (including payroll providers and other processors); any transfers outside the EU; the retention period; and the security measures in place. This mapping is not merely good housekeeping, it directly feeds the record of processing activities and reveals where DPIAs or CSE consultation may be required. Template fields should be standardised across departments so that new processing can be assessed consistently.
Using the mapping, assign a lawful basis to each processing activity rather than to HR as a whole. Recruitment, payroll, performance management, disciplinary records and occupational health each warrant separate analysis. The comparison table later in this guide illustrates how the analysis typically resolves for the most common activities.
A DPIA (analyse d’impact relative à la protection des données) is required under Article 35 of the GDPR where processing is likely to result in a high risk to individuals’ rights and freedoms. In HR, the classic triggers are systematic monitoring of employees, profiling, and processing of health data at scale. Whenever HR proposes to introduce employee monitoring, video surveillance, keystroke or activity logging, vehicle geolocation, or productivity analytics for remote workers, a DPIA should be completed before deployment, having regard to the CNIL’s published lists of processing that does and does not require a DPIA.
A short-form HR DPIA should describe the processing and its purpose, assess necessity and proportionality, identify risks to employees, and set out the mitigating measures. Because monitoring also engages collective protections, the DPIA and the CSE consultation should be prepared in parallel.
Article 32 of the GDPR requires security appropriate to the risk. For HR systems handling sensitive personnel and health data, minimum measures should include:
Transparency is a core GDPR obligation. Employers must provide clear information notices to both job candidates and employees, explaining what data is processed, why, on what basis, for how long, who receives it and what rights individuals have. A candidate privacy notice should be provided at the point of application; an employee notice should be provided at hiring and updated when processing changes. Any template should carry a disclaimer that it must be adapted to the organisation and reviewed by counsel.
Consent is the most misused lawful basis in employment. The CNIL’s HR guidance is clear that consent is generally not valid where there is a clear imbalance of power between the parties, and the employment relationship is the paradigm case of such imbalance. Because an employee cannot freely refuse without fearing consequences, consent will rarely meet the GDPR’s “freely given” standard. HR should therefore default to contract performance, legal obligation or, where appropriate, legitimate interests, and reserve consent for genuinely optional matters such as publishing an employee’s photograph on a public website. Where consent is used, employees must be able to withdraw it as easily as they gave it, and withdrawal must be honoured promptly.
Article 30 requires controllers to maintain a record of processing activities. Organisations with fewer than 250 employees are, in principle, exempted, but the exemption does not apply where the processing is likely to result in a risk to rights and freedoms, is not occasional, or involves special categories of data. Because HR routinely processes health and disciplinary data on a continuous basis, the practical position for most employers is that the record is mandatory. The HR record should list each processing activity, its purpose, the data categories, recipients, retention periods and security measures, mirroring the data map from Step 1.
Personnel data must not be kept longer than necessary. Retention periods should be tied to a legal or evidential rationale, for example, the limitation periods for employment claims, or statutory obligations to retain payroll and social security records. Unsuccessful candidates’ CVs, performance records, disciplinary files and health data each warrant distinct retention rules. The suggested retention schedule below provides a starting point that must be adapted to the organisation’s specific legal exposure and to the applicable current CNIL guidance.
A distinctive feature of GDPR HR France compliance is the role of the CSE. Under the Code du travail, the CSE must be informed and consulted on projects affecting working conditions, and the Ministère du Travail’s guidance confirms the committee’s information and consultation functions. Where data processing introduces or changes employee monitoring, or otherwise affects the collective interests of staff, the employer’s GDPR project and its labour-law consultation obligations run together.
When consulting on a data-processing project, the employer should give the CSE a minimum dataset sufficient for it to form a reasoned opinion. This typically includes: the categories of personal data concerned; the purposes of the processing; the lawful basis relied on; the recipients and any processors; the retention periods; the technical and organisational safeguards; and, crucially, any DPIA carried out. Providing the DPIA is not merely good practice, it demonstrates that the employer has assessed the impact on employees before deploying the processing.
Consultation must take place before the decision is implemented. For significant projects, a reorganisation, the introduction of surveillance technology, or a new monitoring system, the CSE must be consulted in advance so that its opinion can genuinely influence the outcome. Implementing employee monitoring first and consulting afterwards exposes the employer to challenge both under labour law and under the GDPR, and may render evidence obtained through the monitoring inadmissible in later disputes. HR should therefore build the CSE consultation timeline into any project plan from the design stage.
Document the consultation carefully. The agenda should list the data-processing item explicitly, the information provided should be recorded, and the CSE’s opinion should be minuted. Where the employer shares sensitive commercial or security information, it may designate that information confidential, and members are bound by a corresponding duty of discretion. Well-kept minutes serve a dual purpose: they evidence compliance with the Code du travail and they support the accountability principle under the GDPR by showing that employees’ representatives were engaged before processing began.
Even well-run HR functions suffer data breaches, a misdirected payroll file, a lost laptop, or unauthorised access to personnel records. A structured incident response is essential, and it is one of the areas where GDPR HR France obligations bite hardest because of the short deadlines involved.
The immediate priority is to stop the breach and limit the damage. Practical containment steps include isolating the affected account, revoking compromised credentials, disabling access to affected systems and preserving logs for investigation. Speed matters, because the clock for notification begins once the employer becomes aware of the breach.
Identify which categories of personal data are involved, how many employees are affected, and the likely consequences for them. A breach involving payroll or health data is more serious than one involving a single business contact detail, and the severity assessment drives the notification decisions that follow.
Under Article 33 of the GDPR, the controller must notify the supervisory authority, the CNIL in France, without undue delay and, where feasible, no later than 72 hours after becoming aware of the breach, unless the breach is unlikely to result in a risk to individuals’ rights and freedoms. The CNIL’s dedicated breach-notification procedure sets out how to declare a violation and what information to include: a description of the breach, the categories and approximate number of individuals affected, the likely consequences, and the measures taken or proposed. Where notification is not made within 72 hours, the employer must explain the delay.
Where a breach is likely to result in a high risk to individuals, Article 34 requires the controller to communicate the breach to the affected employees without undue delay. The communication must describe the breach in clear language, give the contact point for more information, and set out the likely consequences and the measures taken. In parallel, the CSE should be informed where the breach affects working conditions or the collective interests of staff, an obligation that flows from the committee’s role under the Code du travail.
The GDPR requires controllers to document every breach, including those not notified to the CNIL, together with the facts, effects and remedial action. An incident log should capture the timeline, the decision-making on notification, and the corrective measures implemented to prevent recurrence. This record is both a compliance obligation and a valuable tool for improving HR data security over time.
The following tools translate the guidance above into working documents for HR. Each template should carry the disclaimer: Template to be adapted to your organisation, consult counsel.
| HR activity | Typical lawful basis | When consent may be acceptable | Special categories involved? | Suggested retention (France) | Consult CSE? |
|---|---|---|---|---|---|
| Recruitment | Steps prior to contract / legitimate interests (Art. 6(1)(b)/(f)) | Only for optional data or extended retention of an application | Rarely, avoid collecting health data | Unsuccessful candidate CVs kept only for a limited period unless the candidate agrees to longer retention | Not usually, unless part of a broader recruitment tool with monitoring |
| Onboarding | Performance of a contract / legal obligation (Art. 6(1)(b)/(c)) | Only for genuinely optional items (e.g. staff photo) | Possibly, health for occupational fitness (Art. 9(2)(b)) | Duration of employment plus applicable limitation periods | No |
| Performance management | Performance of a contract / legitimate interests (Art. 6(1)(b)/(f)) | Not appropriate, do not rely on consent | No | Retained for the employment relationship and relevant evidential periods | Only where linked to systematic monitoring or profiling |
| Disciplinary records | Performance of a contract / legal obligation (Art. 6(1)(b)/(c)) | Not appropriate | No | Retained for the limitation periods applicable to the sanction | No, unless part of a monitoring programme |
| Occupational health | Employment and social protection law (Art. 9(2)(b)) | Not appropriate | Yes, health data, strictly access-controlled | Retained per statutory occupational health rules | Where a new health app or monitoring is introduced |
| Data type | Retention rationale | Practical approach |
|---|---|---|
| Unsuccessful candidate CVs | No ongoing purpose once the role is filled | Delete after a short period unless the candidate consents to retention in a talent pool |
| Employment contracts and payroll | Statutory retention and evidential needs | Retain for the periods required by tax, social security and labour law |
| Performance and disciplinary files | Evidential value during and after employment | Align to applicable limitation periods, then delete |
| Health and occupational records | Occupational health obligations | Retain per occupational health rules, with strict access controls |
These structures are starting points, not finished policies. Every organisation should adjust retention periods to its own legal exposure and to current CNIL guidance, tailor privacy notices to its actual processing, and map its own systems and processors. A pilot review of one high-risk activity, such as employee monitoring, is often the fastest way to surface gaps and refine the templates before rolling compliance out across all HR processes. Where the analysis is finely balanced, an employer should seek a compliance review before deploying new processing.
Sound GDPR HR France compliance is a continuous discipline, not a one-off project, and it rewards employers who build data protection and CSE consultation into every HR decision from the design stage. If you do five things this week, do these: map your HR processing activities and confirm the lawful basis for each; check that your record of processing under Article 30 is complete; identify any monitoring or health-data processing that needs a DPIA and a CSE consultation; test your breach response against the 72-hour notification deadline; and review your candidate and employee privacy notices against the CNIL’s HR guidance.
Taken together, these steps put employers, HR teams and the CSE on firm ground and reduce the risk of enforcement, disputes and reputational harm. For deeper support, see the supporting guides on recruitment, CSE consultation and breach response, and consider a full compliance review.
This article was produced by Global Law Experts. For specialist advice on this topic, contact Henri Guyot at aerige, a member of the Global Law Experts network.
posted 10 minutes ago
posted 26 minutes ago
posted 40 minutes ago
posted 57 minutes ago
posted 1 hour ago
posted 2 hours ago
posted 2 hours ago
posted 2 hours ago
posted 2 hours ago
posted 2 hours ago
posted 3 hours ago
posted 3 hours ago
No results available
Find the right Legal Expert for your business
Send welcome message