Custom software for retention periods and purging personnel files
A personnel file is not a folder with a single expiry date. Application data must go within weeks, data without a statutory period after two years, the copy of the identity document after five years, and parts of the payroll administration only after seven. Four retention periods in one file, and a single delete button cannot separate them.
Which retention periods sit in one file
Application data is generally deleted no later than four weeks after the end of the procedure. If you want to keep it longer, for example for a future vacancy, you need the applicant's consent.
For data in the personnel file that has no statutory retention period, the rule is: keep it until two years after the employee leaves. If the data is no longer needed earlier, delete it straight away; the period is an upper limit, not a target.
In addition, some data carries its own statutory period. You keep wage tax declarations and a copy of the identity document for five years after employment ends. Parts of the payroll administration must be retained for seven years after the employee leaves.
And there is an exception that overrides everything: if there is a labour dispute with the employee or legal proceedings, you may keep data for longer. This means a cleansing round cannot run blindly; whoever runs it must know which files are on hold and why.
How we build this
The key is the type of data, not the file. As long as everything sits in one folder, the only options are to delete the entire file or keep the entire file, and both are wrong.
Define each type: application, employment terms, absence, identity document, payroll administration.
Include the legal basis, so you can later explain why something was kept for so long.
End of procedure, termination of employment, or something else. The starting point determines the deletion date.
What was deleted, when, and on what basis. This is what you show if someone asks whether you really did it.
What the software actually does
The structure by data type holds everything together. What else you need depends on your size and on how many systems contain personnel data.
Retention period per data type
Four weeks, two years, five years or seven years, with the legal basis stated alongside each type.
Starting point per file
The clock starts at the end of the procedure or on termination of employment, and that moment is recorded.
Hold in the event of a dispute
If a conflict or legal proceeding is underway, the file is excluded from purging until it is concluded.
Purge proposal in advance
What is due next month, so someone can review it before anything disappears.
Evidence of deletion
Which type of data was deleted from which file, and when, without retaining the deleted content itself.
Across systems
Personnel data is rarely held in one place. The schedule also applies to the systems around it.
Who we build for
Who works with this differs by organisation. Four situations.
HR departments
They manage the files and are the ones who carry out the purging, usually alongside all their other work.
Privacy officers
They are asked whether the retention policy is actually enforced, which is not the same as whether it exists.
Payroll administrators
They deal with the longest retention periods and with data that cannot simply be deleted.
Organisations with many temporary staff
High staff turnover means many files quietly passing their retention period.
Test your idea first: a working prototype in 1 day
With OneDayBuild, we turn your idea into something tangible in one day for €1,150, so you can see whether further development is worth the investment. Decide to go ahead with the full build? Then we credit the full cost.
Explore OneDayBuild →Technology and integrations
Periods change and new data types emerge. Types, periods and starting points should be configurable rather than hard-coded.
For employers who want to manage and comply with retention periods for personnel files, there is our software for personnel file retention periods.
If you carry out DPIAs regularly and want pre-screening, risks and advice from the DPO in one workflow, there is our DPIA workflow tool.
If you want to track, per supplier, which personal data is processed and under which agreements, there is our processor agreement register.
Why Appfront
One file, four periods
A delete button at file level is always wrong: too early for payroll administration, or too late for everything else.
The period is an upper limit
If data is no longer needed earlier, you delete it straight away. We build that as a rule, not as an option.
A dispute stops the clock
In the event of a conflict or proceeding, you may keep data for longer. A purge round that doesn't know this will delete exactly the wrong thing.
Policy is not practice
The question in an audit is not whether you have written down retention periods, but whether they are being observed.
Security and privacy
By definition, this system deals with employees' personal data, and sometimes with special categories such as health data related to absence. That data shouldn't be visible to the same people as the rest of the file. We set up access per role and per data type, separate absence from HR, and log every access, including by administrators. Integrations run through secure connections to your existing software.
For this topic, the reliability of the moment is what matters. In a complaint, what counts is whether you acted according to your own policy at that time. We record cleaning rounds in an unalterable way, with timestamp and person, without retaining the deleted content, and any correction appears as a visible correction alongside the original entry. How we handle security ourselves is set out in our information security policy.
Frequently asked questions about retention periods for personnel data
Generally up to four weeks after the end of the application process at the latest. If you wish to keep the data longer for a future vacancy, you need the applicant's own consent.
For data without a statutory retention period, the guideline is up to two years after the employee leaves. If the data is no longer needed earlier, you delete it straight away; the period is an upper limit, not a target.
Wage tax statements and a copy of the identity document are kept for five years after employment ends. Parts of the payroll administration must be retained for seven years after the employee leaves.
Yes. If there is an employment dispute with the employee or legal proceedings, you may keep the data for longer. In practice, your cleaning process needs to know which files are excluded for that reason.
By recording which type of data was deleted, from which file and when, without retaining the deleted content itself. That last part is the pitfall: a log that quotes the deleted data undoes the deletion.
No. This is specifically about retention periods and deletion. Monitoring contracts, certificates, leave and working hours is a different subject; for that we have a page on HR compliance software.
Are there still files on people who left three years ago?
Search your system for employees who left more than two years ago and check what remains of them. If you find more than payroll records and the legally required documents, your policy is not being applied. We build this as a standalone application or as part of a broader custom software project.