Skip to main content

Overview

GDPR requests helps people teams track subject access (SAR) and erasure work. Open GDPR requests (/hr/gdpr) for the queue and retention schedules, or use the person Audit tab to log a sensitive view.

Request queue

Create a request for a person with:
  • Type: SAR, erasure / anonymise, or other
  • Received and due dates (default due date is 30 days after received)
  • Optional summary
Update status and playbook notes from the request drawer. Erasure playbook notes on /hr/gdpr are for tracking steps. Automated anonymisation and membership deactivation run from Admin → Privacy center (/admin/privacy) after preview and approval.

Retention schedules

Each organisation gets default retain years for common record types:
  • Employee HR records (6)
  • Employee HR documents (6)
  • Leave requests (6)
  • Payroll (7)
These are playbook defaults. They do not delete data automatically.

Sensitive views

On a person’s Audit tab, use Log sensitive view to record that you opened sensitive HR information. Recent views appear under the field change audit trail.