Protect employee and client records across every engagement.
Redact interviews, reviews, and reports before they are shared or summarized.
Where sensitive data leaks out
HR teams and consultants work with employee files, candidate data, and client deliverables. Meeting notes and documents routinely pass through AI tools, quietly exposing personal data to third parties.
Omit apps for hr and consulting
Employee files are the hardest GDPR case, not the easiest
HR data is often treated as low risk because it is internal. The opposite is true. Personnel files routinely contain special category data under Article 9: health information from sickness records and occupational health reports, trade union membership, and sometimes biometric data from access systems. Special category data needs two things at once, an Article 6 lawful basis and a separate Article 9(2) condition, and consent is a weak choice for both in an employment context because the power imbalance undermines whether it was freely given. Add the storage limitation principle, which requires defined and documented retention periods per category, and the sensitive contexts of disciplinary proceedings and workplace monitoring, and HR becomes the function where careless sharing does the most damage.
Two bases, not one, for special category data
An Article 6 basis such as contract performance or legal obligation, plus an Article 9(2) condition, typically employment law obligations. Consent rarely carries the weight because an employee cannot refuse an employer freely.
Retention has to be defined per category, and documented
Payroll, tax, parental leave and disciplinary records all attract different periods, often set by local law rather than by preference. Storage limitation is not satisfied by keeping everything indefinitely in case it is needed.
An appropriate policy document is expected
Where special category data is processed, the record of processing must note the condition relied on, and a policy document should set out how the principles are met and how retention and erasure work in practice.
The documents this actually applies to
Personnel files and performance reviews
PERSON, ADDRESS, DATE_OF_BIRTH, national insurance and tax numbers, salary
Shared with line managers, external counsel and consultants, usually in full because extracting the relevant part by hand is tedious. Redacting to the recipient's actual need is the difference between disclosure and over-disclosure.
Recruitment and candidate records
PERSON, EMAIL, PHONE, ADDRESS, DATE_OF_BIRTH, education history
CVs are the most commonly pasted document in any organisation, straight into AI tools for summarising or scoring. Note that recruitment screening is one of the categories the EU AI Act treats as high risk, so this is also where AI Act obligations meet HR practice first.
Disciplinary, grievance and investigation files
PERSON, health references, witness identities, ORGANIZATION
Witness identity is the acute problem. An investigation report often has to be shared with the subject while protecting the people who spoke, and that is a per-entity decision rather than a whole-document one.
Occupational health and sickness records
PERSON, health conditions, DATE_OF_BIRTH, medical practitioner names
Squarely Article 9 special category data. Line managers usually need the adjustment and the timescale, not the diagnosis, and redaction is how you give them the first without the second.
Sharing an investigation note with a line manager
Before
Following the grievance raised by Aisha Rahman on 4 May, witness Tom Bradley confirmed the incident. Aisha is receiving treatment for anxiety and has been signed off until 18 June.
After
Following the grievance raised by [PERSON_1] on 4 May, witness [PERSON_2] confirmed the incident. [PERSON_1] is receiving treatment for [HEALTH_1] and has been signed off until 18 June.
The manager still learns that the grievance was corroborated and when the absence ends, which is what they need to run a team. They do not learn the diagnosis, which is special category data they have no basis to receive, or the witness identity. Consistent tokens mean [PERSON_1] is the same person in both sentences, so the note still reads as a narrative rather than a redaction puzzle.
Evidence for the record of processing
Where special category data is processed, the record of processing activities must note the condition relied on and demonstrate that the principles were met. The per-run report gives you the operational half of that: what personal data was present, what was removed and what was retained, for each document actually shared. It turns a written retention policy into evidence that the policy was applied, which is the part most HR functions cannot produce when asked.
What records teams ask first
Further reading
- What Is PII? Definition, Examples, PII vs PHI
PII means information that identifies a person, but four different laws draw that line in four different places, and the same email address can be in scope under one and arguable under another. Here is each definition, what counts as an example of each, and where PII ends and PHI begins.
- Is ChatGPT Confidential?
It depends which ChatGPT, and the honest answer for every tier is the same: confidentiality there is a contractual promise, not an architectural guarantee. A 2025 court order proved the difference in the most concrete way available.
- How to Redact a Word Document
Highlighting text in black is not redaction, and neither is deleting it with track changes on. Omit removes the value from the file itself, across headers, footers, comments, footnotes, tracked deletions and document properties, entirely offline.
- Redaction vs Anonymization vs Pseudonymization
Four words that get used interchangeably and mean four different things, with four different legal consequences. Here is what each one actually does to your data, which regulation defines it, and which one your tool is really performing.
Keeping personal data on-device supports GDPR obligations for employee and client information, with an audit report for every redaction run.