skip to content

A departing employee bulk-exported an HR dataset. Who must you consult before examining their HRIS audit trail?

level: seniorimportance: nice to knowfreq 32%

answer

  1. the subject has rights an intruder does not
  2. HR owns the system and the context
  3. documented basis, necessity, proportionality
  4. local law, not headquarters policy
  5. preserve and constrain before you analyse

basics

~20 s

Examining a named employee's records needs HR as data owner, the privacy office for a documented lawful basis, counsel for the legal posture, and in several European jurisdictions consultation with the works council before behaviour-monitoring data is analysed.

solid answer

~50 s

The moment the subject is an employee, the investigation is also an employment matter and a processing of that person's personal data. Four parties gate it. HR owns the employment relationship and usually owns the HR platform's records, so they release the data and run the disciplinary track. The privacy office documents the lawful basis, necessity and proportionality, and scopes what you may look at: export and record-view events for one account over a defined window, not a general trawl. Counsel sets the posture and the jurisdiction question, because the employee's local law governs, not the headquarters' policy. And in jurisdictions such as Germany, employee representative bodies hold co-determination rights over systems capable of monitoring employee behaviour, so an existing works agreement covering security monitoring, or a fresh consultation, is required. Have that agreement in place before the incident: consultation takes days you do not have.

go deeper

for a junior

Know that investigating a named employee is different from investigating an intruder: HR and the privacy office are involved, the scope has to be narrow, and you do not go reading a colleague's activity on your own initiative.

for a middle

Explain the gates and what each contributes: HR as data owner and source of context, privacy for a documented and proportionate basis, counsel for posture and jurisdiction, and employee representatives where co-determination rights apply.

for a senior

Demonstrate the sequencing judgment: preserve and constrain immediately, analyse only within an approved scope, know the platform's retention window, and state honestly what an audit-trail export event does and does not prove.

for a principal

Own the pre-incident version: a standing works agreement and an approved investigation standard negotiated in calm times, so a live insider case is executed within an existing framework instead of negotiated during it.

## When the subject of the investigation is one of your own An external intruder poses no consent problem: nobody has a privacy interest in an adversary's session. A departing employee is the opposite case. Everything you want to examine, which records they viewed in the HR platform, which reports they exported, from which address, at what hour, is personal data about an identified person who has rights, a contract with you, and in many countries collective representation. The interview question is not whether you may investigate, it is who must agree first and what that does to your clock. ### The four gates **HR.** The HR business partner is both stakeholder and data owner. The HR platform's audit trail belongs to HR's system, so HR authorises the extract. HR also holds the context that reframes the alert entirely: the person resigned nine days ago, is serving notice, is joining a named competitor, or, equally likely, was told by their manager to pull that report for a legitimate handover. That last possibility is why you ask HR before you accuse anyone. Plenty of insider cases close as benign true positives, real activity, correctly detected, entirely authorised. **Privacy / the DPO.** Examining a named individual's activity is processing personal data, and it must have a documented basis, be necessary and be proportionate. The privacy office typically constrains the scope: this account, these event types, this date range, these named recipients of the output. A request to review everything the employee did for two years will be cut down, and correctly so, both because it is disproportionate and because a narrower scope is far easier to defend later. **Counsel.** Counsel sets the legal posture, decides whether the work is directed for legal advice, and answers the jurisdiction question. The employee's local employment and data protection law governs the examination. A global policy saying the company may monitor its systems does not by itself authorise what you want to do in every country the company operates in. **Employee representatives.** In several European jurisdictions, works councils hold co-determination rights over the introduction and use of technical systems capable of monitoring employee performance or behaviour; German law is the best-known example. In practice this is handled ahead of time through a standing works agreement covering security logging and the circumstances under which individual data may be examined. Where such an agreement exists, an incident is executed within it. Where it does not, you may be negotiating during the incident, and that is measured in days rather than hours. ### What this does to sequencing The hard part is that consultation runs on a slower clock than the risk. The response is to separate two decisions that people wrongly bundle: - **Preserving and constraining** does not require the same approvals as **analysing**. Placing a hold on the relevant records so retention does not consume them, and reducing what the account can still do, are protective steps that do not involve reading the subject's activity. - **Examining** is the step that carries the consultation requirement. That split lets you stop the situation getting worse while approvals move. It also means you must know your platform's retention: a SaaS HR system may hold detailed access events for a limited window, so an unpreserved trail can simply age out while you wait. ### What the trail can and cannot tell you A record-view or export event in an HR platform's audit trail proves that an account performed an action within the application at a time. It does not prove the person was at the keyboard, it does not tell you what the exported file contained beyond the object named, and it does not follow the file after export. A conclusion that data left the organisation needs corroboration from somewhere else, and the platform's own audit trail is frequently the only account you have, which is exactly why preserving it early matters. ### The likely outcome Cases like this often end declared as an incident, run under a counsel-directed engagement, and closed as an employment matter rather than a breach: the data stayed within the company's systems, or was recovered, or the export turns out to have been authorised. That is a legitimate ending, not a failure. What makes it defensible is that the examination was scoped, approved by the right parties and documented before it happened rather than justified afterwards.

  • The consultation will take days and the person is still employed. What do you do meanwhile?
    Separate preservation and constraint from analysis. Put a hold on the relevant audit records so retention does not consume them, and reduce what the account can still do, both of which are protective and do not involve reading the subject's activity. Then run the consultation for the examination itself. Say plainly to the business what risk that gap carries.
  • HR says the manager asked for that export as part of a handover. What changes?
    It becomes a benign true positive: the detection was correct, the activity was real, and it was authorised. You still document the verification, note who confirmed the authorisation and when, and close it. It is also a detection-tuning signal, since an approved handover export that looks identical to theft will recur every quarter.
  • Why is a global monitoring policy not enough to justify the examination?
    Because the employee's local employment and data protection law governs, not the headquarters' policy. A blanket clause in a global handbook does not override local requirements for a documented basis, proportionality, or consultation with an employee representative body where one holds co-determination rights over behaviour-monitoring systems.

saying these in an interview costs you the question

  • Says company-owned systems mean no approvals are needed
  • Requests the employee's entire two-year activity history
  • Confuses the works council with the data protection officer
  • Waits for approval without preserving records first
  • Treats an export event as proof the data left the company
  • Applies headquarters policy to an employee in another jurisdiction

context