Digital Employee Records: What Is Kept, Where, and Who May See It
Back to blog
product·September 12, 2026·4 min read·By Yehonatan Saadia

Digital Employee Records: What Is Kept, Where, and Who May See It

An operational description of a digital employee file: which documents accumulate, why they scatter across systems, who may see what, and what happens when somebody leaves.

Key takeaways

  • An employee file is not one folder - it scatters across payroll, email, signed documents and operational systems.
  • The practical problem is not what is kept but that nobody knows where all of it is.
  • View permissions are the difference between "data exists" and "data is exposed".
  • Departure day is the critical checkpoint, and at most businesses it passes with no check at all.
  • What is kept and for how long is settled with legal counsel and the accountant, not in an internal procedure.

This is an operational description of how a digital employee file behaves, not legal or employment-law advice. What must be kept, for how long, and what may be asked for all go to legal counsel and the accountant. What can be described: documents about an employee accumulate in four different places, and that is what turns every question about them into a search.

Why the file scatters by itself

Nobody decides to spread documents about an employee across five systems. It happens because each document is created somewhere else: the employment contract is signed in a signature system, the tax form goes to whoever handles payroll, payslips sit in the payroll product, leave notices are in WhatsApp, and an equipment handover confirmation is in email.

The result is that every document has a sensible home and the file as a whole has none. That is also why "what do we hold on this person" cannot be answered in a minute even at an eight-person business - not because anything was hidden, but because there was never a list.

The four places employee data sits

The placeWhat is usually thereWho actually reaches it
Payroll systemPayslips, employment data, bank detailsBookkeeper, accountant
Signed documentsContract, annexes, acknowledgementsWhoever ran the signing, usually the owner
Mailboxes and chatMessages, approvals, requestsEverybody who was in the thread
Operational systemsShifts, tasks, accessDirect managers

The third row is the problematic one. Employee information sitting in an email thread or a WhatsApp group is not managed in any way: it has no permissions, no expiry, and it stays with everybody who was there - including after that person changed role or left.

What is worth holding in one place

There is no need to centralise everything; what is worth centralising is a list that points at everything. One employee record holding:

  • The basic identifying details and the start date.
  • A link to wherever each signed document lives.
  • A list of the access and systems granted to the employee.
  • A list of equipment issued in their name.
  • Who the direct manager is, and when that changed.
  • The date the record was last reviewed.

The third item pays for itself immediately, and it is also the only one on the list nobody keeps. Without an access list, closing access on departure day becomes a memory exercise, and memory always misses the system opened a year ago for a single project.

Permissions: the difference between existing and exposed

Employee data is not dangerous because it exists but because it is reachable by somebody with no reason to see it. Three failures recur:

  1. A shared payroll spreadsheet on a drive the whole team can see, because it was once convenient.
  2. A manager who left still holding access to a system with employee data.
  3. An outside supplier - an accountant or consultant - with broader access than required.

The third is the least discussed and the easiest to fix: a supplier's access should be scoped to what they need, and in their own name rather than an employee's. That is also what makes it possible to know who saw what, which is precisely the question that arises when something leaks.

Departure day: the check nobody runs

On the day somebody leaves, three things usually happen: equipment comes back, the mailbox is closed, and payroll is finalised. What is not done is going through the access list - because, as noted, there is not one.

The procedure that works is a short check against the record, covering five things: system access, access to external services, equipment, documents the employee holds, and authorisations with outside bodies such as the Tax Authority. That last item is the forgotten one, and it belongs to the same review described in the Tax Authority's online services.

What remains after departure - which documents, and for how long - is a question for legal counsel and the accountant. What is operational is that one decision exists, is applied identically to every employee, and that somebody can state what it is.

What happens on the first day

The same record used on departure day is built on the first day, and there it is cheap. A new employee typically receives between five and ten kinds of access in their first week - email, the operational system, a shared drive, and often an external tool or two - and each is granted by a different person, with no record.

What is needed is not a formal onboarding process but one line: who granted which access and when. Five minutes in the first week, and departure day turns from a memory exercise into a list you work through.

It has an immediate second benefit: it answers "who has access to this system" without opening the system. That question comes up far more often than people expect - when changing supplier, when something breaks, and when reviewing subscription costs.

How does this connect to an access request?

An employee or former employee can make a request about the data held on them, and that is exactly where a scattered file turns from an administrative nuisance into a timeline problem. A business that does not know where the data sits will not answer within a reasonable window.

So the work on an orderly employee record is not separate from the process described in handling an access or deletion request - it is its first stage, and at a small business it is also the only stage requiring real effort.

Sources

#employee records#personal data#permissions#record keeping#operations

Frequently asked questions

Do you need dedicated HR software?

At a ten-person business, no. What is needed is one record per employee pointing at everything else, and that works fine in a spreadsheet - as long as it is permission-limited and not sitting on a shared drive.

Who needs access to employee files?

Whoever runs payroll and whoever manages the employee, at different scopes. What does not work is access by seniority or by job title, because it produces exposure with no use.

What about employee data in WhatsApp?

Operationally, what matters is moving decisions and approvals into a managed place rather than leaving them in chat. What may be retained from such correspondence, and for how long, is a matter for legal counsel.

Should you keep a copy of an ID document?

That is a distinctly legal question settled with counsel, not in an internal procedure. What is operational is knowing exactly where each identifying document is held, so that any decision is capable of being carried out.

Keep reading

Related service

MVP Development

Turn an idea into a validated product in weeks, not months.

Learn more

About the author

Yehonatan Saadia

Freelance automation, web & MVP developer

I'm Yehonatan Saadia, a senior developer who builds business automation, custom websites, and MVPs for small and mid-sized companies across the US, Europe, and Israel. These guides come from real client work, not theory.

Work with me

Have a project like this?

Tell me what you're trying to automate or build and I'll tell you the fastest reliable way to ship it.