/

Compliance

GDPR for people data, without the legalese

Lena Frost

Lena Frost

Security & Compliance

·

9 min read

GDPR for people data, without the legalese

Employee data, handled the way GDPR actually intends.

The short version

GDPR isn’t a checklist you finish, it’s a posture you keep. For employee data it comes down to a few habits: collect only what you need, be clear about why, keep it accurate, and let people see and correct their own records.

Most of the risk in people data isn’t malice. It’s drift: stale access, forgotten exports, a spreadsheet emailed once and never deleted.

Make the right thing the easy thing

Field-level permissions and an audit log turn compliance from a policy nobody reads into a default nobody has to think about.

Tags

GDPR

Compliance

Data

Share

Lena Frost

Written by

Lena Frost

Leads security and compliance at Northwind. Translates regulation into sensible defaults engineers and HR can actually live with.

Create a free website with Framer, the website builder loved by startups, designers and agencies.