Why HR is where PDPA risk concentrates
A company's customer database gets most of the PDPA attention. The employee file is often riskier: it holds identity documents, bank details, family information, health records, performance reviews, disciplinary history — and increasingly biometric data from time clocks.
It is also the data most likely to be requested in a dispute. An employee in a termination claim may ask what the company holds about them, and how it was used.
1. Lawful bases: consent is usually not the answer
Most HR processing rests on bases other than consent:
| Processing | Usual lawful basis |
|---|---|
| Payroll, contracts, leave | Performing the employment contract |
| Tax, social security, labour records | Legal obligation |
| Security, CCTV, IT monitoring | Legitimate interests, balanced against employees' rights |
| Optional programmes, photos for marketing | Consent |
Consent given by an employee to an employer is rarely treated as fully free, and can be withdrawn. Relying on it for processing the company actually needs creates a problem the day an employee withdraws.
2. Sensitive data
Some categories need explicit consent or a specific legal exception:
- Health data — medical certificates, pre-employment health checks, sick leave details
- Biometric data — fingerprint or face-scan time clocks, access control
- Criminal records — background checks
- Religion, ethnicity, disability
For each, identify the basis, limit who can see it, and set a retention period. Offer an alternative where consent is the basis — a card for employees who decline biometric attendance, for example.
3. The employee privacy notice
Employees need a notice explaining:
- What data is collected and from where
- Why, and on what lawful basis
- Who it is shared with — payroll providers, insurers, the parent company
- Whether it is transferred abroad
- How long it is kept
- How employees can exercise their rights
This is separate from the customer privacy notice on the website. See PDPA compliance checklist for the wider programme.
4. Job applicants
Applicants are data subjects before they are employees:
- Tell them how their data is used in the application process
- Collect only what the selection needs
- Do not run background or health checks before they are relevant
- Keep CVs of unsuccessful applicants only for a stated period, or with consent for a talent pool
5. CCTV and workplace monitoring
CCTV is generally acceptable for security and safety with:
- Visible notices at entrances and monitored areas
- A defined purpose and retention period
- Restricted access to recordings
- No cameras in private areas
Monitoring email, devices and internet use needs a written policy, a clear purpose, and proportionality. Monitoring everything, permanently, without telling employees, is the pattern that fails.
Using CCTV or monitoring data for purposes beyond those notified — performance management, for example — should be decided in advance and reflected in the notice.
6. Sharing with the parent company and vendors
- Parent company access and HR systems hosted abroad are cross-border transfers and need a lawful basis and adequate safeguards
- Payroll providers, HR software, insurers and recruiters are processors or separate controllers; put data processing terms in their contracts
- Record who receives employee data and why
7. Employee requests and disputes
Employees can ask for access to their data, correction, and in some cases deletion. Requests often arrive during a dispute. Have a procedure: verify identity, locate data across systems, respond within the time the law allows, and take advice where the request overlaps with a claim.
8. Breaches
- Assess risk immediately
- Where the breach is likely to affect individuals' rights, notify the regulator without delay, within seventy-two hours of becoming aware where feasible
- Where the risk is high, inform affected employees with the steps being taken
- Keep a record of every breach, notified or not
9. Retention
Set retention periods for each category and apply them. Labour and tax law require some records to be kept; beyond that, data kept "just in case" is risk without a purpose.
HR checklist
- Map the employee data held, where it sits and who can access it
- Assign a lawful basis to each processing activity
- Identify sensitive data and its basis; offer alternatives where consent is used
- Issue an employee privacy notice and an applicant notice
- Review CCTV and monitoring against a written policy
- Put data processing terms in vendor and intra-group arrangements
- Set retention periods and a request-handling procedure
- Prepare a breach response plan
Read next
- PDPA compliance checklist
- Work rules every employer needs
- The Thai labour compliance audit
- For an HR data review, talk to our team