GDPR and payroll administration

Summary

Payroll administration involves the processing of a large amount of personal data, and as an employer, you are the data controller. If you use a payroll agency, the agency is the data processor, and a written data processing agreement is a legal requirement. You must have a lawful basis for processing, inform your employees, store data securely and only for as long as necessary, and be able to manage a data breach.

Short answer

The GDPR and payroll administration are inextricably linked: when you process payroll, you handle a large amount of personal data about your employees – names, national insurance numbers, bank account numbers, salaries, absences and more. As an employer, you are the data controller and are responsible for ensuring that the data is processed lawfully and securely. If you use a payroll agency, the agency acts as the data processor, and a written data processing agreement must be in place.

What personal data is processed as part of payroll?

Payroll administration involves a wide range of personal data. Most of this is general information such as name, address, national identity number, bank account number, salary, pension and tax details. However, it may also include sensitive personal data – for example, health information relating to sick leave or details of trade union membership. Sensitive personal data is subject to stricter requirements and necessitates a specific legal basis for processing.

Are you a data controller or a data processor?

The roles are crucial because the requirements differ. The person in charge the purpose and the funds The data controller for the processing is you, as the employer. A payroll agency that processes your payroll on your behalf and in accordance with your instructions is the data processor. Please note that neither SKAT nor the bank are your data processors – they process the information as independent data controllers.

The data processing agreement is a legal requirement

If you outsource payroll processing to a payroll agency, a data processing agreement is required under the GDPR. The agreement must be in writing and must, as a minimum, describe the purpose of the processing, the categories of data being processed, the duration of the processing, the security measures in place, the use of any sub-processors, and what happens to the data when the collaboration ends. The absence of such an agreement constitutes in itself a breach that may result in a fine or an enforcement order.

The responsibility is yours

Even when you use a payroll agency, it is still you, as the data controller, who bear overall responsibility for ensuring compliance with the rules. You must be able to document this – for example, by keeping a record of your processing activities and by monitoring, to a certain extent, that the data processor is complying with the agreement.

Basis for processing

All processing of personal data requires a lawful basis. In the context of payroll, the basis is typically that the processing is necessary to fulfil the employment contract and to comply with a legal obligation – for example, reporting to the tax authorities. Sensitive information requires a separate legal basis, and the processing of CPR numbers is regulated separately under the Data Protection Act. Consent is rarely the appropriate legal basis in an employment relationship, as it can be withdrawn.

Duty to provide information and employees’ rights

You must inform employees about the processing – what information you process, for what purpose, on what legal basis, for how long it is stored, and how to lodge a complaint with the Data Protection Authority. This is typically set out in a privacy policy or staff handbook. Employees also have the right to access their own data, the right to have incorrect data rectified and, in certain cases, the right to erasure.

Storage and deletion

Personal data may only be retained for as long as there is a legitimate purpose. However, payslips form part of the accounting records, which, under the Bookkeeping Act, must be retained for 5 years. Once the purpose and the retention obligation cease to apply, the data must be deleted or anonymised. Ensure you have clear deletion policies – including for former employees.

Security and data breaches

You must have appropriate technical and organisational security measures in place: restricted access to payroll data – so that only those employees who need to see it can do so – and secure transmission, so that, for example, National Insurance numbers are never sent in a standard, unencrypted email. If a personal data breach occurs, it must, as a general rule, be reported to the Danish Data Protection Agency without undue delay and no later than within 72 hours if the breach poses a risk to data subjects.

We can help you with GDPR and payroll administration

At Dansk Løn Service, we act as your data processor when we process your payroll. This means a clear data processing agreement, secure data handling and established procedures for storage and deletion – so you can have peace of mind when it comes to the GDPR and payroll administration. Contact us to have a chat about your setup.

The rules have been simplified here. GDPR compliance should be properly verified – seek guidance from a data protection officer or a solicitor if in doubt.

Call me back

Find out more about how we help create Increased bottom line through optimised payroll processes.

Yes please, I would like to receive a call.

  • Dette felt er til validering og bør ikke ændres.
  • By submitting this form, you agree to the processing of your data in accordance with our privacy policy.

Scroll to Top