Guide · June 17, 2026
Employee timekeeping and payroll data under the PDPL: what to do?
Guide to handling employee timekeeping, payroll, performance and health data under the PDPL: legal bases, transparency, security.
Quick answer
What is employee timekeeping and payroll data under the PDPL?
Employee timekeeping and payroll data under the PDPL covers all information about workers that a business collects and processes in HR management: clock-in/out times, shifts, payroll, bonuses, deductions, KPI evaluations, leave records, and any health data if applicable. According to the Personal Data Protection Law (Law 91/2025/QH15), all of this is personal data, and in some cases it is sensitive data.
A practical example: a company uses a fingerprint scanner for timekeeping, payroll software to calculate wages, internal forms to evaluate performance, and pre-employment medical checkups. Each data source has different purposes, retention periods, and access levels; you should not lump them together and let multiple departments view them at will.
What legal bases allow a company to process employee data?
A business should only process employee data when there is an appropriate legal basis. In the employment relationship, common bases include: necessity to perform the employment contract; compliance with legal obligations on labor, social insurance, and tax; or consent in situations beyond these minimum needs.
Practical note: not every case requires consent. For example, a company needs to collect a bank account number to pay salaries, or keep timekeeping data to calculate working time; these are typically necessary to perform the contract and manage HR. But if you use that data for other purposes, such as behavioral analytics beyond the HR scope or sharing with partners, you must reassess the processing basis under the regulations.
For health data, the sensitivity is higher. Only collect it when truly necessary for recruitment, occupational safety, insurance, periodic health checkups, or related legal obligations. If HR keeps detailed medical records without a clear purpose, the compliance risk increases significantly.
Define processing purposes:
clearly state whether data is used for timekeeping, payroll, performance evaluation, benefits administration, or legal compliance.
Map a legal basis to each purpose:
distinguish what is necessary for the employment contract, what is a legal obligation, and what requires separate consent.
Minimize data:
only collect fields that are necessary; for example, timekeeping should not include off-hours data unless there is a legitimate purpose.
Limit access rights:
HR, accounting, and direct managers should only see the parts of the data needed for their work.
Keep evidence of compliance:
retain internal notices, consent forms if any, access logs, and data retention policies.
How should a company be transparent with employees?
The business must inform employees clearly from the outset, before or at the time of data collection. The notice should state: the types of data collected, purposes, legal bases, data recipients, retention periods, employees’ rights, and a contact channel for requests to access, correct, or delete data in accordance with the regulations.
In SMEs, a common mistake is to include only a vague line in the employee handbook like “the company may process personal data as required by law.” This is not clear enough for employees to understand which data is used for timekeeping, which for payroll, and which for evaluations. It’s better to separate by each HR process.
If the company uses third-party software for timekeeping or payroll, it should also state that a processor may handle data on the company’s behalf, and that the company remains responsible for managing purpose, scope, and data security.
How to secure timekeeping, payroll, evaluation, and health data?
Businesses should apply security based on risk: the more sensitive the data, the tighter the controls. For HR data, implement role-based access control, encryption at rest and in transit, multi-factor authentication for HR/payroll systems, and access logging.
Some very practical steps:
- Separate payroll files from the company’s shared folders.
- Do not send payroll statements over unencrypted internal email to too many people.
- Do not store timekeeping files or health information in public drives.
- For health data, only authorized HR/OS&H/medical units should have access.
- Have a process to delete or redact data when the retention period ends.
If a data leak occurs, the business must assess the impact and notify the data breach within 72 hours from discovery, as required. Many companies overlook this, assuming only customer data breaches need to be reported.
Should we obtain employee consent?
You can, but consent should not be used as a “blanket permit” for all HR activities. In the employment relationship, much data is processed because it is necessary for the contract or to comply with legal obligations. Only purposes beyond that scope should use a separate, clear, and demonstrable consent mechanism.
Example: the company wants to use employee photos on recruitment webpages, internal videos, or share data for a partner benefits program. These situations should have a separate consent mechanism, distinct from the employment contract.
Quick checklist for HR and IT
- Review all employee data sources: timekeeping, payroll, KPI, health records.
- Create a “purpose – legal basis – access – retention period” table.
- Update transparent notices for employees.
- Review contracts with HR/payroll software vendors.
- Set up role-based access, access logs, backups, and an incident response process.
Short notice template for employees
You can use this template as a foundation and adapt it to your context:
"The Company processes your personal data to manage the employment relationship, including timekeeping, payroll, bonuses, deductions, performance evaluations, legal compliance, and benefits administration. Data may be shared with HR software providers, accountants, insurers, and state authorities as required by law. You have the right to request access, updates, or other processing in line with the Company’s policy."
- Yes. They are personal data because they are linked to an identified individual; certain information such as bank accounts, tax records, and health may require stricter controls under the regulations.
- Not always. If the data is necessary for the employment contract or legal obligations, it can be processed on the appropriate legal basis; purposes beyond that scope should use separate consent.
- Only when genuinely necessary for the job and under clear access controls. The principle is to minimize access rights and avoid letting too many people see payroll data.
- Assess severity, contain the impact, remediate, and notify the data breach within 72 hours from discovery, as required. Consult a lawyer if the incident involves sensitive data.
If you are standardizing cookie banners, consent logging, or DSAR processes for HR, consent.vn can help you design flows that fit real-world operations.
Source: the Personal Data Protection Law (Law 91/2025/QH15) thuvienphapluat.vn; Decree 13/2023/ND-CP thuvienphapluat.vn; Ministry of Public Security (A05) bocongan.gov.vn
Get started — set up in 5 minutes.
Need help with PDPL compliance?