Anonymization of employment documents for HR departments
Human Resources produces more documents with personal data than any other department: payslips, contracts, sick-leave notes, disciplinary files, appraisals. The problem starts when they have to be shared with someone outside —an auditor, a buyer, the workers’ representatives, an advisor— and the whole folder gets sent. anonimiza.do leaves each document with the data that recipient needs and nothing more, recognises Spanish identifiers and records every operation.
Which employment documents carry personal data
For every person on the payroll, an HR department handles daily:
- Payslips: name, DNI or NIE, Social Security number, professional category and contribution group, seniority, workplace, salary and deductions, IBAN when the payment account is shown.
- Employment contracts, annexes, extensions, settlements and dismissal or sanction letters, with date and place of birth, nationality, address and applicable collective agreement.
- Temporary incapacity notes and maternity or paternity reductions: health data, even if indirectly.
- Disciplinary files, performance appraisals and working-time records.
- Attached documents: criminal-record certificates in certain sectors, training certificates, medical check-up reports, confidentiality agreements.
- The spreadsheets exported from the payroll system itself, with macros, connections and the network path embedded as metadata.
When you must anonymize before sharing
Paying salaries, filing contributions or answering the Labour Inspectorate have their own legal basis and go with full data. What requires anonymization is secondary use, and in HR it is more frequent than it looks:
External labour or financial audit
The auditor needs to verify total payroll, contribution bases and categories, not each employee’s name or ID number. If the work can be done with anonymized data, that is the option that best meets minimisation; if specific payslips must be cross-checked, pseudonymize and sign the processing agreement.
Equal-pay audit (Royal Decree 902/2020)
Mandatory for companies with more than 50 employees. The auditor analyses gaps by sex, category and seniority and does not need names: deliver the dataset already aggregated by homogeneous groups, widening any group with fewer than five people per sex so that nobody can be re-identified.
Collective redundancies and furloughs
Workers’ representatives are entitled to enough information to negotiate, and the documentation may end up before the public employment service or a court. It is not fully anonymized, but it is minimised: internal pseudonyms or initials with age and seniority are enough to verify the selection criteria.
Due diligence, financing and investors
Whoever buys or finances a company needs seniority, salary, category and potential severance, not each worker’s identity. Deliver it anonymized, with selective de-anonymization of key positions only if the acquirer justifies it.
Internal training and case studies
Using real payslips or files to train the HR team or during onboarding is processing without a legal basis. Examples are anonymized first or generated synthetically.
Employment litigation and outsourcing
In court proceedings, the data of employees who are not a party is anonymized before the document is filed. When a service is outsourced, the contractor receives only the data needed to deliver it.
What data must be handled in a payslip or a contract
The Spanish payslip is highly standardised: sensitive data always sits in the same positions, which makes it easy to detect and just as easy to miss in a manual review.
- Direct identifiers: full name, DNI or NIE, Social Security number, employee number, IBAN, address, date and place of birth.
- Employment data that identifies by combination: professional category, contribution group, seniority, position, workplace and salary. In a small department, three of them together point to a single person.
- Indirect health data: temporary incapacity notes, maternity or paternity leave, medical check-ups, disability certificates for tax deductions.
- Special categories in attached documents: criminal records, union membership in collective bargaining.
- File metadata: the PDF produced by the payroll software and the spreadsheet exported from the HR system embed the worker’s name, the author and the network path where they were generated.
Recommended process before transferring employment documents
- Get the scope in writing: which documents the recipient requests, for what purpose and what they need to extract.
- Choose the technique by purpose: irreversible anonymization when identity is not needed (equal-pay audit, due diligence, training); reversible pseudonymization when cross-checking with the original must remain possible (compliance audit, collective bargaining).
- Sign the GDPR art. 28 processing agreement with the auditor or advisor, and disclose the transfer in the corporate privacy policy.
- Prepare the cleaned set: payslips, contracts and notes processed by data type; spreadsheets processed column by column; metadata removed; groups with fewer than five people aggregated.
- Deliver through a secure channel with expiry and log the transfer —recipient, date, documents, technique and legal basis— in the record of processing activities.
- Supervise use and demand a destruction certificate at the end; document retention if the auditor keeps a copy under its own obligation.
What anonimiza.do brings to an HR department
- Detects the 20 data types in the catalogue —name, NIF and NIE, Social Security number, IBAN, address, dates, amounts— and validates NIF, NIE, Social Security and IBAN by check digit, which in an employment document full of similar numbers is what avoids redacting too much or too little.
- Custom data types described in plain language, such as “employee number” or “contribution account code”, with no rules to program and nothing to train.
- Spreadsheets processed column by column and batches in ZIP: the staff list and a month’s payslips come out in a single pass. OCR for anything that arrives scanned.
- Two modes depending on the transfer: irreversible anonymization, or reversible pseudonymization with stable tokenization that keeps each worker traceable within the batch without revealing who they are; plus k-anonymity verification for the equal-pay audit dataset.
- Removes file metadata before download: author, software used, dates and path.
- Audit log for every document processed: the evidence of diligence that GDPR requires you to prove before the data protection authority.
- Data always in the European Union (AWS Frankfurt), with optional deployment in the AWS Spain region; Spanish National Security Framework (ENS) MEDIUM category and a data processing agreement.
- Free plan of 3 documents a month with no card; Professional plan with OCR, batches and API to integrate with the HR system.
Try for free: 3 documents a month
Frequently asked questions
Do I have to anonymize the documents the Labour Inspectorate requests?
No. The administrative request is sufficient legal basis and the inspector is entitled to the complete documents within the deadline. What you should do is limit the delivery to exactly what is required and not send whole folders.
Should I anonymize or pseudonymize contracts for an audit?
It depends on whether the auditor needs to cross-check specific records. In an equal-pay audit or a due diligence they work with aggregated data: full anonymization. In a compliance audit they usually need to verify specific contracts: pseudonymization with an internal code, a processing agreement, and the mapping table stays in HR.
Do I have to notify each worker before transferring their data to the auditor?
Not individually, as long as the transfer is foreseen in the corporate privacy policy that workers have known since hiring. The duty to inform is met through the general channel, not case by case.
Can I email the contracts to the auditor if they are encrypted?
Encryption is an advisable technical measure, but it replaces neither the legal basis nor the processing agreement. You need all three, and a channel with expiry is better than email.
How long must payslips be kept and what happens afterwards?
Spanish labour rules set a minimum of four years for contribution documents and up to five for income-tax related ones. After that, they are securely destroyed or anonymized if you want to keep them for statistical use.
What do I do with the files left with the auditor when the work ends?
They are destroyed as agreed in the processing agreement, and you ask for the destruction certificate. If the auditor must keep a copy under its own obligation, the agreement documents the purpose and the period. Without that closure, the company loses control of its data.