Legal sends over the DPIA questionnaire on a Tuesday. Question 14: list the special categories of personal data processed in this system. The payroll manager writes “none.” She has no reason to think otherwise. Payroll is names and numbers.
Then open the November register for Germany.
There is a column for Kirchensteuer, church tax, withheld at 8 percent of income tax in Bavaria and Baden-Württemberg and 9 percent everywhere else. That column tells you whether the employee is Catholic, Protestant, or neither. Two columns over, union dues deducted at source. Then Entgeltfortzahlung, continuation of pay during illness, with the date the sick period began. Then an adjustment tied to a recognised Schwerbehinderung.
Article 9(1) of the GDPR prohibits, subject to exceptions, processing personal data “revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership,” along with data concerning health. Three of those categories sit in that spreadsheet. And the spreadsheet went out as an email attachment to four people, one of whom left the company in September.
The register is more sensitive than the HRIS and less protected
The same file holds the IBAN, the home address, the national identifier, and garnishment orders that reveal a court judgment. Nobody emails the general ledger around as an .xlsx. Everybody emails the payroll variance report.
How a regulator prices employee data is a matter of public record. The ICO fined Interserve Group £4.4 million in October 2022 after finding that personal data of up to 113,000 current and former employees had been compromised across four HR databases, including national insurance numbers, bank details and special category data on ethnic origin, disability and sexual orientation. A phishing email was forwarded by an employee working from home and opened by a colleague, and the ICO found that the alert the company’s own anti-virus software raised was not sufficiently investigated.
Consent is the wrong lawful basis, and your DPO already knows
Payroll teams reach for consent because it feels respectful. It is the weakest thing available.
The EDPB’s Guidelines 05/2020 are direct: given the imbalance of power between employer and employee, consent is presumed not freely given in the employment context. Then the mechanics. Consent can be withdrawn at any time under Article 7(3). If consent were your basis, an employee could withdraw it on the 12th and you would have to stop withholding income tax. You cannot. That obligation is not theirs to release.
The right bases are unremarkable. Article 6(1)(b), performance of the employment contract, covers calculating and paying the agreed wage. Article 6(1)(c), legal obligation, covers the withholding, the filings and the record keeping. For the Article 9 data the gateway is Article 9(2)(b): processing necessary for employment and social security obligations “in so far as it is authorised by Union or Member State law or a collective agreement.” German tax law authorises the church tax deduction, German employment law the sick pay, and the collective agreement itself usually authorises the union dues.
Article 88 then lets each member state add its own employment rules, so the record of processing activities has to be per country, not one row that says “payroll.”
Getting the file out of the EEA in 2026
Standard contractual clauses under Implementing Decision (EU) 2021/914 are the workhorse, and two failure modes recur. The wrong module gets signed, usually Module Two where the relationship is really processor to sub-processor. And Annex II, the technical measures, stays boilerplate. Annex II is the part a supervisory authority reads first.
Binding corporate rules are stronger and almost nobody has them. The EDPB’s public register lists 244 approved sets across the entire European economy, 183 for controllers and 61 for processors. Approval runs through a lead authority, an EDPB opinion and a national decision, and takes years. If a vendor claims BCRs, ask for the national approval decision.
The EU-US Data Privacy Framework is valid and it is under pressure. The General Court dismissed Philippe Latombe’s annulment action on 3 September 2025; he appealed to the Court of Justice on 31 October 2025, no hearing date set as of mid-2026. On 31 July 2026 the EDPB asked the Commission to review the adequacy decision after the US Supreme Court’s ruling in Trump v. Slaughter, arguing that its assumptions about the independence of US oversight bodies may no longer hold.
Practical read: rely on the DPF today for a certified recipient, but keep signed SCCs behind it.
What is a transfer impact assessment?
A documented judgment, structured by the EDPB’s Recommendations 01/2020 (version 2.0, 18 June 2021), on whether the destination country’s law and practice would undermine your transfer tool. For payroll: name the data categories and recipients, say whether encryption keys stay in the EEA, and state what happens when a foreign authority serves a request. One per provider. Then an invalidation is a paperwork event, not a payroll outage.
Who needs to see net pay, and how long you have to keep it
Data minimisation under Article 5(1)(c) cuts risk faster than any other control, because it removes data from circulation rather than adding a lock. So ask who needs net pay by named individual. Finance needs employer cost by cost centre. A manager approving a bonus needs the gross, not the net and not the IBAN. An approver reviewing a variance needs to see that employee 40771 moved 34 percent against her own history, and why. Not the name.
The distinction is architectural, not procedural. A calculation engine needs tax residency, elections and numbers. It does not need to know who the person is. HR Blizz’s gross-to-net engine is stateless for that reason: it calculates without storing a personal employee record, and its AI checks see an employee ID and figures, never a name. That describes the calculation layer, not the platform around it. A payroll system holds employee records somewhere, because payslips, self-service and statutory filings all need a name, so the question for any vendor is which components hold identity and which hold only identifiers.
Minimisation hits its limit at the exit door. Someone leaves in March and asks in April to be erased. The answer is mostly no: Article 17(3)(b) disapplies erasure where processing is necessary for compliance with a legal obligation, and payroll retention is statutory.
Those obligations differ by country and by document. In the UK, regulation 97 of the Income Tax (PAYE) Regulations 2003 sets three years after the end of the relevant tax year, though most employers hold six because of limitation periods and holiday pay claims. In Germany, the Lohnkonto runs six years under §41(1) EStG, remuneration records survive until the end of the calendar year following the last social security audit under §28f SGB IV, and accounting vouchers dropped from ten years to eight on 1 January 2025 under the Fourth Bureaucracy Relief Act. In the US, the FLSA requires three years under 29 CFR 516, the IRS four years after the tax is due or paid, and ERISA six years after the Form 5500 filing. In India, ESI registers run five years from the last entry and Payment of Wages registers three.
So the answer is restriction, not deletion. Move the statutory minimum into a locked archive with no operational access, delete everything outside it, and tell the employee exactly which fields you keep, under which law, and until when. That last sentence turns a complaint into a closed ticket.
The two questions an auditor asks, and the call that comes on a Friday
The first: who changed this employee’s bank account, when, and what was it before. If the answer involves reconstructing it from email, you have a finding. A field-level change log with old value, new value, user and source is table stakes, and it has to survive corrections and off-cycle runs.
The second: name every party that touches this data. In an aggregator model that gets uncomfortable, because the register passes to a different local partner in each country and each has its own sub-processors. Your Article 28 sub-processor list is the real perimeter, and it is usually longer than the contract suggests. June 2023 made the point at scale. A ransomware group exploited a zero-day in a widely used managed file transfer product, as CISA documented at the time, and among the organisations caught was a payroll provider, which put employee data belonging to its large corporate clients in the attackers’ hands. The vector sat two links down the chain from the employer.
So read a vendor’s SOC 2 from the scope statement, not the opinion. Confirm the audited system is the one your payroll runs on, not an adjacent product, and check the period: a Type 2 for last calendar year says little about the migration they finished in March. Check whether sub-service organisations sit under the carve-out method, which excludes their controls entirely; if so, ask those parties for their own reports. For ISO 27001, read the certificate’s scope statement and ask for the Statement of Applicability. A certificate scoped to a data centre is not one scoped to your payroll application.
Then the clock. Article 33 gives you 72 hours from becoming aware of a breach, not from finishing the investigation, and awareness includes the moment your provider tells you something happened. DLA Piper’s February 2026 analysis put breach notifications across Europe at 443 per day, up 22 percent year on year. IBM’s 2026 Cost of a Data Breach report put the global average at $4.99 million, up 12 percent. The Digital Omnibus proposal of 19 November 2025 would move that to 96 hours, but the data half of that package is stuck: member states could not agree a mandate, and the Cyprus presidency handed the file to Ireland in late June 2026 with no Council position. Plan on 72.
The vectors are boring and repetitive. A register emailed as an attachment. A bank file dropped on SFTP with the password in the same thread. Access that was correct before the reorg and over-broad after it, because leavers came off the HRIS and never the payroll application. A local partner that works your file in a spreadsheet and keeps the spreadsheet.
Five things to close before the quarter ends
1. Pull the access list for every payroll system and country folder, line by line, and remove anyone who cannot justify seeing net pay by name.
2. Kill the email attachment path, and make the old route technically impossible rather than discouraged.
3. Get each provider’s current sub-processor list, with country and role, and reconcile it against your SCCs and transfer assessments.
4. Write a retention schedule per country and document type, statutory citation beside each period, plus the standard erasure response that quotes it.
5. Run a 72-hour drill. Given a call at 4pm on a Friday, who assesses, who drafts the Article 33 notification, who signs it.
If you cannot answer the auditor’s two questions without a week of archaeology, fix that before the policy document. Talk to us about how HR Blizz handles payroll data across 160+ countries, including field-level audit trails and a single native engine rather than a chain of local ones.
One caveat on all of the above: the retention periods and lawful bases described here are general information, not legal advice, and your DPO and local counsel own the final position.
FAQ
Q: Does a payroll file contain GDPR special category data?
In most European countries, yes. Church tax withholding reveals religious affiliation, union dues deducted at source reveal trade union membership, and sick pay or disability-related adjustments reveal health data. All three fall within Article 9(1) of the GDPR, which means you need an Article 9 condition as well as an Article 6 lawful basis.
Q: Can we rely on employee consent to process payroll data?
No. The EDPB’s Guidelines 05/2020 treat consent as presumptively not freely given in the employment relationship because of the imbalance of power, and consent is withdrawable at any time under Article 7(3), which is incompatible with statutory withholding. Use Article 6(1)(b) for contract performance and Article 6(1)(c) for legal obligations, with Article 9(2)(b) for special category data.
Q: Is the EU-US Data Privacy Framework still valid in 2026?
It remains valid. The EU General Court dismissed the Latombe annulment action on 3 September 2025, but that decision was appealed to the Court of Justice on 31 October 2025, and on 31 July 2026 the EDPB asked the European Commission to review the adequacy decision following Trump v. Slaughter. Keep standard contractual clauses and a transfer impact assessment in place as a fallback.
Q: How do we handle an erasure request from a former employee when we have to keep payroll records?
Article 17(3)(b) removes the right to erasure where processing is necessary for compliance with a legal obligation, and payroll retention periods are statutory: three years after the end of the tax year for UK PAYE records, six years for the German Lohnkonto, three years under the US FLSA. Restrict rather than delete: archive the statutory minimum with no operational access, delete everything else, and tell the employee which fields you are keeping, under which law, and until when.