five doors in the vault · GDPR up to 4% of global revenue · 72-hour breach window
Data privacy & security at enterprise scale
HRIS systems contain SSNs, comp data, family information, medical records — making them a top ransomware target. Senior HR partners with the CISO and legal on the full data lifecycle, not just the collection consent at hire.
The vault — five doors, five rules
01
Collect
Minimum necessary. Justify each field. Retention limits set at collection — not when someone asks for them later.
02
Store
Encryption at rest and in transit. Access logs that someone actually reviews. Network segmentation between HR data and the rest of the business.
03
Use
Purpose limitation — use data only for the purpose disclosed at collection. New use case requires new consent or a new lawful basis.
04
Share
Vendor DPAs (Data Processing Agreements). Cross-border transfer mechanisms (SCCs, EU-US DPF). Need-to-know access for employees.
05
Delete
Auto-delete per retention schedule. Right-to-erasure (GDPR Article 17, CCPA equivalent) honored within statutory window.
The compliance regimes that actually have teeth
GDPR (EU): applies to EU employees regardless of HQ location. Penalties up to 4% of global revenue. 72-hour breach notification window. €746M Amazon fine (2021), €1.2B Meta fine (2023) prove the enforcement is real. 20+ US state privacy laws — CCPA, CPRA, VCDPA, CTDPA, UCPA, more landing each year. Cross-border transfer mechanisms — Standard Contractual Clauses, EU-US Data Privacy Framework (DPF). Senior HR carries this map.
a distinction the SPHR exam tests
Privacy is rights and consent. Security is safeguards. They\'re different functions.
Privacy lives with legal and HR. Security lives with the CISO. Both fail when treated as the same thing — “we have GDPR consent so we\'re fine” ignores ransomware risk; “we\'re ISO 27001 certified” ignores collection consent. Senior HR partners with both and tabletop-rehearses breach response before it\'s real.
Exam Traps
Privacy ≠ security
Privacy is rights and consent. Security is safeguards. Senior HR understands both, partners with CISO and legal.
Cross-border transfers require mechanism
EU-US data transfer needs SCCs or adequacy decision (DPF). Senior HR ensures HR data flows comply.
Vendor risk extends liability
HR vendors processing data create vicarious risk. Senior HR runs vendor due diligence and DPA contracts.
Employee monitoring rules vary
EU requires consent and proportionality. US varies by state. Senior HR designs monitoring with legal counsel.
HRIS = top breach target
HR systems contain SSNs, comp, family data. Among top targets for ransomware. Senior HR funds security investment.
Privacy by design + breach response
Build privacy controls into systems. Pre-rehearse breach response. Senior HR partners with CISO on tabletops.
Only collect data needed. Justify each field. Retention limits set at collection.
At-rest and in-transit encryption. Access logged and monitored.
Use only for the purpose collected. New use requires new consent.
Vendor DPAs. Cross-border mechanisms. Need-to-know access.
Auto-delete per retention schedule. Right-to-erasure honored.
Ready to test your SPHR knowledge?
1,500+ practice questions written by certified professionals.
Start Practicing SPHR