Skip to content

Protect employee and client records across every engagement.

Redact interviews, reviews, and reports before they are shared or summarized.

Where sensitive data leaks out

HR teams and consultants work with employee files, candidate data, and client deliverables. Meeting notes and documents routinely pass through AI tools, quietly exposing personal data to third parties.

Employee files are the hardest GDPR case, not the easiest

HR data is often treated as low risk because it is internal. The opposite is true. Personnel files routinely contain special category data under Article 9: health information from sickness records and occupational health reports, trade union membership, and sometimes biometric data from access systems. Special category data needs two things at once, an Article 6 lawful basis and a separate Article 9(2) condition, and consent is a weak choice for both in an employment context because the power imbalance undermines whether it was freely given. Add the storage limitation principle, which requires defined and documented retention periods per category, and the sensitive contexts of disciplinary proceedings and workplace monitoring, and HR becomes the function where careless sharing does the most damage.

Two bases, not one, for special category data

An Article 6 basis such as contract performance or legal obligation, plus an Article 9(2) condition, typically employment law obligations. Consent rarely carries the weight because an employee cannot refuse an employer freely.

Retention has to be defined per category, and documented

Payroll, tax, parental leave and disciplinary records all attract different periods, often set by local law rather than by preference. Storage limitation is not satisfied by keeping everything indefinitely in case it is needed.

An appropriate policy document is expected

Where special category data is processed, the record of processing must note the condition relied on, and a policy document should set out how the principles are met and how retention and erasure work in practice.

The documents this actually applies to

Personnel files and performance reviews

PERSON, ADDRESS, DATE_OF_BIRTH, national insurance and tax numbers, salary

Shared with line managers, external counsel and consultants, usually in full because extracting the relevant part by hand is tedious. Redacting to the recipient's actual need is the difference between disclosure and over-disclosure.

Recruitment and candidate records

PERSON, EMAIL, PHONE, ADDRESS, DATE_OF_BIRTH, education history

CVs are the most commonly pasted document in any organisation, straight into AI tools for summarising or scoring. Note that recruitment screening is one of the categories the EU AI Act treats as high risk, so this is also where AI Act obligations meet HR practice first.

Disciplinary, grievance and investigation files

PERSON, health references, witness identities, ORGANIZATION

Witness identity is the acute problem. An investigation report often has to be shared with the subject while protecting the people who spoke, and that is a per-entity decision rather than a whole-document one.

Occupational health and sickness records

PERSON, health conditions, DATE_OF_BIRTH, medical practitioner names

Squarely Article 9 special category data. Line managers usually need the adjustment and the timescale, not the diagnosis, and redaction is how you give them the first without the second.

Sharing an investigation note with a line manager

Before

Following the grievance raised by Aisha Rahman on 4 May, witness Tom Bradley confirmed the incident. Aisha is receiving treatment for anxiety and has been signed off until 18 June.

After

Following the grievance raised by [PERSON_1] on 4 May, witness [PERSON_2] confirmed the incident. [PERSON_1] is receiving treatment for [HEALTH_1] and has been signed off until 18 June.

The manager still learns that the grievance was corroborated and when the absence ends, which is what they need to run a team. They do not learn the diagnosis, which is special category data they have no basis to receive, or the witness identity. Consistent tokens mean [PERSON_1] is the same person in both sentences, so the note still reads as a narrative rather than a redaction puzzle.

Evidence for the record of processing

Where special category data is processed, the record of processing activities must note the condition relied on and demonstrate that the principles were met. The per-run report gives you the operational half of that: what personal data was present, what was removed and what was retained, for each document actually shared. It turns a written retention policy into evidence that the policy was applied, which is the part most HR functions cannot produce when asked.

What records teams ask first

Can we use this on candidate CVs before an AI screen?

Yes, and it is one of the strongest uses. Removing name, address, age and education institution before a model scores a candidate reduces the personal data exposed and removes some of the most common proxies for protected characteristics. Note that recruitment screening is treated as high risk under the EU AI Act, so this sits inside a regime with its own assessment duties rather than outside one.

How do we protect witnesses but still share an investigation report?

Policy is per entity type, so witness names can be tokenised while the subject's name is left in place. Consistent pseudonymisation keeps each witness distinguishable across the document, which matters when a report refers to several people repeatedly.

Is health data handled differently?

It should be, and Omit lets you treat it separately. Health entities can be removed outright while other identifiers are tokenised, which is usually the right shape: a manager needs to know an adjustment is required, not what the condition is.

Does this help with retention and erasure?

Partly, and it is worth being precise. Omit does not manage retention schedules. What it does is reduce how much personal data exists in the copies you share, so there is less to find and erase later. Retention itself remains a records management question.

Do consultants need a separate licence per client?

No. The licence is per user and perpetual, and because processing is local there is no per-client tenancy to configure. A consultant can work across engagements without any client data reaching a shared service.

Can employees be told what happens to their data?

That is your privacy notice rather than the tool, but the audit report makes it answerable. If an employee asks what was shared with an external adviser, the report for that run records exactly which fields were removed and which were retained.

Further reading

  • What Is PII? Definition, Examples, PII vs PHI

    PII means information that identifies a person, but four different laws draw that line in four different places, and the same email address can be in scope under one and arguable under another. Here is each definition, what counts as an example of each, and where PII ends and PHI begins.

  • Is ChatGPT Confidential?

    It depends which ChatGPT, and the honest answer for every tier is the same: confidentiality there is a contractual promise, not an architectural guarantee. A 2025 court order proved the difference in the most concrete way available.

  • How to Redact a Word Document

    Highlighting text in black is not redaction, and neither is deleting it with track changes on. Omit removes the value from the file itself, across headers, footers, comments, footnotes, tracked deletions and document properties, entirely offline.

  • Redaction vs Anonymization vs Pseudonymization

    Four words that get used interchangeably and mean four different things, with four different legal consequences. Here is what each one actually does to your data, which regulation defines it, and which one your tool is really performing.

Keeping personal data on-device supports GDPR obligations for employee and client information, with an audit report for every redaction run.

Handle people data with care.