compliance made easy: GDPR and the company's internal policies

In our experience, HR teams and other employees in the company all have a very positive view of the introduction of a digital personnel file.

This step speeds up many processes, creates transparency and simplifies collaboration at all levels. But the devil’s in the details. Especially when it comes to compliance with legal regulations such as the General Data Protection Regulation (GDPR) or internal company policies. 

the five core principles of the GDPR

  • Earmarking: Personal data may only be processed for specific and legitimate purposes 
  • Data minimization: The processing must be appropriate for the purpose at hand and limited to the necessary scope. 
  • Accuracy: The data must be factually correct and kept up to date, corrected or deleted. 
  • Memory limitation: The data must be stored in a form that allows the data subject to be identified only for as long as is necessary for the purpose of processing.
  • Integrity and confidentiality: Personal data must be protected from unauthorized and unlawful processing as well as loss and damage.

This is precisely where the digital personnel file in SAP really shows its full potential. Audit-proof archiving and compliance with social legislation are also included here. This involves minimum and maximum retention periods as well as access rights and deletion periods for stored documents, which are automatically deleted at the end of the retention period.  

book your exploration call

Let our easy experts advise you. Together we will find the right solution for you.

controlled access to the personnel file in SAP

Modern applications for personnel files in the context of SAP answer the question of who can access the personnel file and with what access rights directly via SAP’s own authorization system. easy Employee File for SAP Solutions obtains the relevant rights from the SAP authorization system, i.e. from the leading SAP HCM/ERP system.

An important part of the GDPR is the “need-to-know” principle. It states that personal data in a company may only be collected for a specific purpose and may only be viewed by those employees who actually need it to complete a task. 

a role and rights-based authorization concept simplifies control

Supposedly, the simplest solution for creating an authorization concept would be to define exactly what access to personal data each employee should have. In practice, however, this would mean creating an exact description of the access rights for each individual employee, and that complicates the matter. 

To simplify this, it has become common practice to define a set of roles in the authorization concept that are assigned to the relevant employees. These roles are based on the functions and processes that play a role in the authorization concept. You not only need to include employees in different positions but also applications with access to HR documents.

creating a GDPR-compliant authorization concept for HR

This guide will show you how to develop and establish GDPR-compliant work processes in HR using an authorization concept. The focus is on both practical relevance and practicability.


read the whole story

However, the implementation of this concept must be seamlessly embedded in the technical infrastructure that hosts the digital personnel file.