HR Technology, Learning & Development

Who Can Access Your HR Data?

The greatest threat to HR data often isn’t a sophisticated cyberattack; it’s an outdated permission, an unnecessary copy, or a confidential file sitting somewhere nobody thought to check. As employee information spreads across increasingly complex storage environments, simply knowing who can access it becomes a challenge in its own right.

Sending an email to the wrong person is a classic HR mishap, usually harmless, occasionally even funny. But when the misdirected file contains IP, financial information, customer data, or HR records, the consequences can be serious. HR occupies a unique position: it holds some of the most sensitive data in the organization yet is also on the hook for managing the fallout when that data goes astray.

Of course, many organizations work hard to prevent this from happening, but human nature dictates that errors will inevitably happen. Sometimes, weak file permissions are part of the problem. For example, if someone accidentally sends HR information to the wrong recipient, it shouldn’t reveal anything if access is restricted to the appropriate individuals or groups.

But think about it from the HR team perspective. They are responsible for large volumes of sensitive, frequently changing data, covering everything from basic employee records to payroll, performance and disciplinary cases, employee health information; the list is extensive. This information often resides within various IT systems and locations and is controlled by access permissions that have accumulated over time as people come and go or change roles.

These issues can easily accumulate as HR information grows, and additional copies emerge over time. In larger organizations, sensitive files may be spread across thousands or even millions of documents in different storage environments. It can easily become very difficult to establish where that information is held, whether every copy is still needed and who can access it.

Permission Blindspots

To an extent, these problems are a direct consequence of the contemporary digital workplace. When a manager changes roles or leaves the organization, for example, access to HR information should be removed in line with defined rules and timescales. When that does not happen, ‘permission drift’ can leave people with access rights that no longer reflect their responsibilities.

HR professionals will almost certainly be familiar with asking questions like: Why do we have three copies of this employee review? Why can someone who moved roles months ago still access this document? Which version of this payroll file is the current one? Or who else can see this information?

The problem is not just that access controls are absent or out of date; organizations may simply lack the levels of visibility required to confirm permissions are working as required. Scale is a big part of the problem because, in smaller organizations, HR and IT may be able to identify where sensitive information is stored and manually review access permissions regularly.

That process becomes far harder when HR data is spread across a large, complex data estate, with files held in different locations, sometimes in different countries and with masses of duplication created for different purposes over time.

Keeping HR Data Under Control

At this point, what might appear to be a process issue is a technology issue too. HR cannot apply access policies reliably if the storage tools it is provided with cannot show who owns a file or who can open it. It needs a way to examine data alongside the metadata that provides this context, including where files are held and who can access them.

But with proper visibility in place, teams can identify sensitive HR information across the wider data estate rather than relying on assumptions about where it should be held. They can also establish who can access each and every file and continually assess whether that access remains appropriate.

This much clearer view of the data estate provides a firmer basis for removing permissions that are no longer needed. It can also help HR and IT teams identify files that should no longer be retained.

HR data governance cannot be treated as a one-off exercise, however. Inevitably, employees change roles and leave the organization, while sensitive information continues to be added to the wider data estate. Access rights and retention decisions therefore need to be reviewed on an ongoing basis as part of regular HR and IT processes.

Linda De Schrijver is Global HR Manager at Datadobi. De Schrijver is a human resources manager with over 20 years of experience working for hardware and software companies. The majority of her experience has been with IT companies; she specializes in developing the overall strategy and implementation for acquiring and retaining world-class talent for start-up companies. Linda has advised several companies over her career, including EMC BDG, SD Worx, and USG. She has degrees in Communications and Public Relations.

Leave a Reply

Your email address will not be published. Required fields are marked *