PrepSolution
SPHRHigh-YieldHR Information Management 10%

five doors in the vault · GDPR up to 4% of global revenue · 72-hour breach window

Data privacy & security at enterprise scale

HRIS systems contain SSNs, comp data, family information, medical records — making them a top ransomware target. Senior HR partners with the CISO and legal on the full data lifecycle, not just the collection consent at hire.

The vault — five doors, five rules

01

Collect

Minimum necessary. Justify each field. Retention limits set at collection — not when someone asks for them later.

02

Store

Encryption at rest and in transit. Access logs that someone actually reviews. Network segmentation between HR data and the rest of the business.

03

Use

Purpose limitation — use data only for the purpose disclosed at collection. New use case requires new consent or a new lawful basis.

04

Share

Vendor DPAs (Data Processing Agreements). Cross-border transfer mechanisms (SCCs, EU-US DPF). Need-to-know access for employees.

05

Delete

Auto-delete per retention schedule. Right-to-erasure (GDPR Article 17, CCPA equivalent) honored within statutory window.

The compliance regimes that actually have teeth

GDPR (EU): applies to EU employees regardless of HQ location. Penalties up to 4% of global revenue. 72-hour breach notification window. €746M Amazon fine (2021), €1.2B Meta fine (2023) prove the enforcement is real. 20+ US state privacy laws — CCPA, CPRA, VCDPA, CTDPA, UCPA, more landing each year. Cross-border transfer mechanisms — Standard Contractual Clauses, EU-US Data Privacy Framework (DPF). Senior HR carries this map.

a distinction the SPHR exam tests

Privacy is rights and consent. Security is safeguards. They\'re different functions.

Privacy lives with legal and HR. Security lives with the CISO. Both fail when treated as the same thing — “we have GDPR consent so we\'re fine” ignores ransomware risk; “we\'re ISO 27001 certified” ignores collection consent. Senior HR partners with both and tabletop-rehearses breach response before it\'s real.

Exam Traps

Privacy ≠ security

Privacy is rights and consent. Security is safeguards. Senior HR understands both, partners with CISO and legal.

Cross-border transfers require mechanism

EU-US data transfer needs SCCs or adequacy decision (DPF). Senior HR ensures HR data flows comply.

Vendor risk extends liability

HR vendors processing data create vicarious risk. Senior HR runs vendor due diligence and DPA contracts.

Employee monitoring rules vary

EU requires consent and proportionality. US varies by state. Senior HR designs monitoring with legal counsel.

HRIS = top breach target

HR systems contain SSNs, comp, family data. Among top targets for ransomware. Senior HR funds security investment.

Privacy by design + breach response

Build privacy controls into systems. Pre-rehearse breach response. Senior HR partners with CISO on tabletops.

1
Collect — minimum necessary

Only collect data needed. Justify each field. Retention limits set at collection.

2
Store — encrypted vault

At-rest and in-transit encryption. Access logged and monitored.

3
Use — purpose limitation

Use only for the purpose collected. New use requires new consent.

4
Share — controlled access

Vendor DPAs. Cross-border mechanisms. Need-to-know access.

5
Delete — retention compliance

Auto-delete per retention schedule. Right-to-erasure honored.

Vault. Collect → store → use → share → delete. Privacy by design.
reading is not enough, you gotta practice

Ready to test your SPHR knowledge?

1,500+ practice questions written by certified professionals.

Start Practicing SPHR
Reviewed by Megan O., PrepSolution Content Editor, Senior HR
Sources verified against HRCI 2026 standards
Updated May 2026