The State of HR Data Governance 2026
How the GDPR, India's DPDP Act and the EU AI Act overlap on the employee record, the six controls that satisfy all three, and the failure modes that show up in every organisation.
The employee record is now the subject of three overlapping regimes with different starting assumptions. This report sets out where they diverge, where they converge, and what an HR function should actually build.
It is an orientation for practitioners, not a legal summary. It contains no thresholds, exemptions or penalties, all of which are jurisdiction-specific and subject to change.
1. Where the regimes differ
The General Data Protection Regulation offers several lawful bases and treats consent as a weak one in employment, because the imbalance of power makes it difficult to argue consent was freely given. Most employment processing therefore rests on the contract, a legal obligation, or legitimate interests with a balancing assessment.
India's Digital Personal Data Protection Act 2023 is consent-forward by design, with notice and consent central, while setting out defined legitimate uses for which consent is not required. Employment purposes are among them.
The trap runs both ways. A global policy that requires employee consent for everything produces weak compliance in Europe. One that assumes consent is never relevant does not fit India. The same processing needs different documentation in each place.
On individual rights the two overlap substantially and not completely. The DPDP Act's nomination right, allowing an individual to appoint someone to exercise their rights in the event of death or incapacity, has no direct GDPR equivalent and requires a mechanism rather than a policy statement.
2. Where the AI Act arrives
Annex III of Regulation (EU) 2024/1689 classifies AI systems used in employment and worker management as high risk. Obligations were to apply from 2 August 2026 and now apply from 2 December 2027, deferred by Regulation (EU) 2026/1744, in force 27 July 2026.
This is a separate regime from data protection with overlapping subject matter. Where a decision about an individual is made solely by automated means with legal or similarly significant effects, data protection law imposes its own requirements independently.
The overlap is heaviest on exactly the systems HR functions are deploying fastest: candidate screening, performance and potential scoring, flight-risk prediction, and monitoring or evaluation of behaviour.
3. The six controls that satisfy most of it
The encouraging finding is that the operational work required by three different regimes is largely the same work. Six controls carry most of the load.
A lawful basis record by processing category, per jurisdiction. Not per system. Systems change; processing purposes do not, and a record organised by system has to be rebuilt at every migration.
A retention schedule by record type with the legal reason for each period. Most organisations hold a policy expressing a general principle and no schedule, which means retention is decided informally by whoever is clearing a system. Employment creates genuine long-tail obligations and they differ by jurisdiction.
A data flow map that includes exports and reports. Mapping exercises consistently reveal that employee data reaches more places than anyone listed, usually through a manager's monthly export rather than a documented integration.
One rights-request process built to the widest set of rights. With jurisdiction-specific timescales and exceptions applied inside it, and rehearsed. Volume is low enough in most organisations that the process is only exercised occasionally, which is exactly why it fails when it is needed.
An automated decision register. Every system that influences a decision about an individual, with its classification, its override rate, its last test date and a named accountable person. This one document answers questions from all three regimes.
Logging from the point of deployment. The obligation that cannot be met retrospectively, and therefore the one to act on first regardless of any date.
Five of the six are documents. That is the nature of an evidence regime, and it is why the work is usually underestimated: it does not look like work until somebody asks for the file.
4. The failure modes
Four recur, and none involves deliberate misuse.
Special category data in general-purpose fields. An absence reason typed into free text inherits that system's access model, which is far broader than the data warrants. This is probably the most common data protection exposure in HR and it is created by well-meaning people doing their jobs.
Purpose drift. A system installed for security is quietly used for productivity. The processing purpose changed; the documentation did not.
Undocumented exports. The monthly spreadsheet nobody in IT knows about, which becomes a live issue at every migration and every vendor change.
Consent used as a shortcut. Asking employees to consent feels respectful and produces a weak legal position, because consent that cannot be freely refused is not consent. Legitimate interests with a documented balancing assessment is usually both more honest and more robust.
5. What to do in the next twelve months
- Build the automated decision register first. It is the shortest document with the widest coverage.
- Turn on logging for anything that produces a recommendation about a person, today, whatever your compliance date.
- Produce the retention schedule. A principle is not a schedule.
- Map the flows, including exports, and use a migration or vendor change as the occasion if you need one.
- Add a structured reason field to pay, performance and promotion decisions. It only works prospectively.
- Rehearse a rights request end to end, with a stopwatch, before you receive one that matters.
Scope of this report. It covers the EU GDPR, India's DPDP Act 2023 and the EU AI Act because those are the regimes reaching Magrofy Inc's own operating footprint and those of most of our readers. It does not cover United States federal or state law, United Kingdom-specific requirements beyond a reference to the Data (Use and Access) Act 2025, or sector-specific regimes. Take qualified advice for each jurisdiction in which you employ people.
Our coverage of vendors, products and workplace regulation is journalism. Nothing on this site is legal, employment or procurement advice. This report reviews the published record and sets out a framework; it is not original survey data and we do not present it as such.
References
Every figure and legal citation in this article is drawn from the sources below. Where an instrument is proposed rather than in force we say so in the text.
- European Union, Regulation (EU) 2016/679, the General Data Protection Regulation. eur-lex.europa.eu/eli/reg/2016/679/oj
- Government of India, The Digital Personal Data Protection Act, 2023, data protection framework. meity.gov.in/data-protection-framework
- European Union, Regulation (EU) 2024/1689, the AI Act, Annex III on employment and worker management. artificialintelligenceact.eu/annex/3
- European Union, Regulation (EU) 2026/1744, the Digital Omnibus on AI, in force 27 July 2026. eur-lex.europa.eu/eli/reg/2026/1744/oj/eng
- European Commission, AI Act policy page, application dates, updated 27 July 2026. digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai
- Information Commissioner's Office, Guide to PECR, under review following the Data (Use and Access) Act 2025, page dated 20 August 2025. ico.org.uk/.../guide-to-pecr
How we work. This report was researched and written by the HR Hubs Media editorial team. We do not republish press releases. Every number and legal citation is checked against a primary source, named and linked above. Corrections are made openly on the article itself, never by silent edit. If you believe something here is wrong, write to info@hrhubsmedia.com and tell us what and why.