What employee data you actually hold, and in how many places
Echipa HR 365 · reviewed 2026-09-05 · 5 min read
The first problem is not what you are allowed to hold, but that you do not know how many places you hold it in. In a mid-sized company, the same data about one employee usually lives in seven to nine different places: the HR system, accounting, a physical file, two or three spreadsheets, somebody’s email archive, and a chat group.
The five categories, by who needs to see them
The useful classification is not by document type but by who has a reason to open it. Split that way, access decisions make themselves.
| Category | Examples | Who has a reason to see it |
|---|---|---|
| Identity and contact | Name, phone, address, emergency contact | HR, the direct manager for contact |
| The employment relationship | Post, department, manager, tenure, schedule | HR, managers, largely the whole company |
| Money | Salary, allowances, benefits, deductions | A narrow HR circle, accounting, the manager only if they decide the budget |
| Health and absence | Certificates, job adaptations, leave types | A narrow HR circle; the manager learns only that somebody is away, not why |
| Review and discipline | Reviews, conversation notes, sanctions | HR, the direct manager, their own boss |
The third column is the one applied badly in practice. Most often, categories three and four circulate more widely than they should — not out of bad faith, but because they live in the same file as category one, and the file gets sent whole.
Where the data ends up without anyone deciding
- In email attachments. A table sent once stays in five people’s mailboxes, indefinitely.
- In files downloaded locally, “so I can work on them at home”. They stay on that laptop after the person leaves.
- In chat groups, as screenshots. The hardest form of leakage to trace.
- In exports made for a one-off report, saved in the shared folder “Reports 2024”.
- With vendors: outsourced accounting, occupational health, benefits platforms.
How you build the inventory, in an hour
Four questions, asked in turn
- HR — Which systems contain employee data? Write them all down, including the “temporary” ones.
- HR — Which files exist outside the systems? Search the shared folder for words like “personnel”, “salaries”, “export”.
- IT or the administrator — Who has access to each of them, right now? Not who should — who actually does.
- HR — Which vendors receive data, and exactly what? Accounting, occupational health, benefits, recruitment platforms.
The third question almost always produces the biggest surprise: folders shared with the whole company, inherited from an old structure, or people who left still appearing on an access list. Both are fixed in minutes once discovered.
What you do with the copies
The practical rule: a category of data has one official home. Any other appearance is a copy, and copies are either deleted or explicitly justified. Not all can be removed — accounting needs its own — but each has to have a reason and an owner.
The best moment to reduce the number of copies is when you introduce a system: the old files become redundant then and can be closed without argument. Keep them “to be safe” for another year and you have two sources that diverge, with no way of knowing which is right.
Where to start
Search the shared folder for “salaries”, “personnel” and “export”. What you find in five minutes is usually enough to make the access discussion concrete.
Then check the access list for the HR system and remove the people who have left. It is the fastest fix in this whole article and the most often postponed.
The data that goes to vendors
The part of the inventory done most rarely, because the data is no longer with you and it is easy to assume it is no longer your problem. It is: if a benefits platform holds your employees’ names and addresses, that data went there because you sent it.
| Vendor | What they usually receive | What would be enough |
|---|---|---|
| Outsourced accounting | The whole personnel file | Only the fields payroll needs |
| Occupational health | The full list, with contact details | Name, post, location |
| Benefits platform | Identification and contact data | Depends on the benefit; rarely everything |
| Recruitment platform | Candidate CVs | What the process needs, with a declared retention period |
The third column is the useful exercise: for each vendor, ask what they actually need to deliver the service. It is usually less than they receive, and the difference is sent because exporting everything was simpler.
The inventory is a routine, not a one-off
An inventory done once describes the company as it was then. What keeps it current is a single rule: every new system, every new vendor and every recurring export gets added to the list the moment it appears, not at the next review. It costs one line and stops the list becoming, within two years, a fiction.
One home for personnel data, with access by category
The data sits in one system where each category has its own access circle, and opening the sensitive ones leaves a trace — so exports “for one report” are no longer the only route.
You can create an account in a few minutes and use every module for 7 days, no card required.