View your own file Request with a deadline Every access recorded

Custom app for employee file access and access requests

An employee is entitled to see what has been recorded about them. In practice that means an email to HR, a folder someone assembles by hand, and an answer that takes weeks. With an app it is a screen, and that changes not only the convenience but also the quality of what is in the file.

Appfront
Live

What access means in practice

An personnel file contains data with widely differing retention periods. Application details are usually deleted within four weeks of the procedure. Data without a statutory period is generally kept for up to two years after employment ends. Wage tax statements and a copy of the identity document are kept for five years, and parts of the payroll administration for seven years.

This means that granting access is more than opening a folder. Some data should no longer be there, some should not be visible to everyone in HR, and some is special category data subject to separate rules. Anyone building access without that separation will either disclose too much or too little.

In practice, access is also a quality tool. Once employees can see their own file, it becomes clear how much is outdated, duplicated or incorrect. That is uncomfortable, but it is also the fastest clean-up programme available, because the corrections come from the one person who knows for certain what is right.

For organisations with people who have no fixed workplace there is another reason. Anyone working in care, construction or logistics has no desk and no company laptop. A file that can only be reached via an intranet is, for that group, in practice unreachable.

How we build this

The core question is what an employee may see and what they may not. That is a design question that is answered before building, not a setting added afterwards.

1
Determining what is visible

For each type of data, recording whether the employee can view it themselves, and if not, why not.

2
Secure sign-in

Access to your own file requires strong authentication, even when someone opens it on a personal phone.

3
Showing and logging access

What was viewed and when, because access to personnel data is itself a form of processing.

4
Submitting and tracking requests

A request for correction or deletion receives a deadline and a visible status, rather than disappearing into a mailbox.

What the app does in practice

Viewing your own file is the foundation of the whole. What else you need depends on your size and on how many people work without a fixed workplace.

Viewing your own file

What has been recorded about someone, sorted by type, with the retention period shown so it is clear how long it will remain.

Requesting a correction

If something is incorrect, the employee submits a request against the data item itself rather than in a separate message.

Request status

Received, in progress, completed, with a deadline visibly running for both sides.

Downloading documents

Retrieve payslips and statements without anyone having to send them.

Works on a personal phone

Secure sign-in, and no data left on the device when someone leaves the organisation.

Every access recorded

Who viewed the file, including within HR. That is exactly the answer an employee sometimes wants.

Who we build for

Who works with this differs by organisation. Four situations.

Employees without a fixed workplace

Care, construction and logistics: no desk, no company laptop, but a phone.

HR departments

At present they assemble files by hand for every request, and that is work nobody misses.

Privacy officers

They need to be able to show that access rights work in practice and are not just on paper.

Works councils

They are involved in agreements about staff data and want to know what employees can see themselves.

Not yet sure about a large project?

Test your idea first: a working prototype in 1 day

With OneDayBuild, we turn your idea into something tangible in one day for €1,150, so you can see whether further development is worth the investment. Decide to go ahead with the full build? Then we credit the full cost.

Explore OneDayBuild →

Technology and integrations

Retention periods change, new types of data are added and systems are replaced. Visibility, data types and retention periods should be configurable and not hard-coded into the app.

For organisations that want to follow up DPIAs with measures and owners, there is our DPIA workflow tool.

React Native or native iOS and Android Strong authentication, including on personal devices Visibility configurable per data type Requests with deadline and status Securely retrieve documents No data left on the device Integration with your HR and payroll system Access logged, including by administrators Roles for employee, HR and privacy Audit trail on every change

Why Appfront

Access is the quickest clean-up programme

As soon as people see their file, the errors surface. Those corrections come from the only people who know for certain.

Not everything should be visible

Special category data and notes from third parties call for careful judgement. That is design work, not a switch.

A phone is the only workplace for many people

A file behind an intranet is out of reach for field staff and care workers.

Access is itself a processing activity

Whoever views the file should be logged. Within HR too, and especially there.

Security and privacy

This is an app through which someone reaches their own personnel data, often on a personal device. That places high demands on sign-in and on what remains locally: we do not store file data on the device and ensure access lapses as soon as someone leaves the organisation. Special category data such as sickness absence we keep separate from the rest, with their own rights and their own visibility.

For this subject, the reliability of the record is the key point. When a complaint about the file arises, what was recorded at the time and who viewed it are what matter. We log access and changes in a tamper-proof way with time and person, and turn a correction into a visible correction alongside the original entry. How we handle security ourselves is set out in our information security policy.

Frequently asked questions about access to the personnel file

Not automatically. A file contains data of varying sensitivity, including special category data about sickness absence and sometimes notes involving others. Decide per data type whether the employee can view it themselves and why or why not; that is a design choice you make before building.

Those of the data type. Application data is usually deleted within four weeks of the procedure ending, data without a statutory period generally up to two years after leaving employment, a copy of an identity document five years, and parts of the payroll administration seven years. Showing those periods makes the file understandable.

It receives a deadline and a visible status: received, in progress, completed. The major difference from current practice is that the request is attached to the data item and does not disappear into a mailbox, so both sides can see where it stands.

Yes, provided it is set up securely. That means strong authentication, no file data left locally, and access that lapses as soon as someone leaves the organisation. For people without a fixed workplace, the personal phone is often the only realistic route.

Because viewing personnel data is itself a processing activity. When a complaint arises, the question is who viewed the file and when, and you can only answer that if you have kept a record. This applies to access within HR too, and especially there.

From the system in which they are monitored and carried out. We describe this on our page about retention and deletion software. See also our approach to building an app.

How long does it now take before someone can see their file?

Ask your HR department how much work it takes to compile one complete personnel file. If it's more than half an hour, that's why employees don't ask. We build this as a standalone app and as part of a broader app development project.

Edit content