EU compliance

Handling Employee GDPR Requests: Data Export & Erasure Rules

The email arrives on a Tuesday morning: "Please send me a copy of all the personal data you hold about me, and then delete it." Maybe it's from a contractor who left six months ago, maybe from someone still on the team. Either way a clock has started (under GDPR you generally have about a month to respond), and the worst reaction is to panic and start deleting things.

The good news: if your systems were built with these requests in mind, most of the work is mechanical. The judgment calls sit in one place, the retention carve-outs, and those are decided by law, not by the delete button.

A scoping note first: this is a mechanics guide, not legal advice. Deadlines, exemptions and retention periods differ by country and by the kind of data, so run your specific case past your counsel or data protection officer.

Two requests hiding in one email

That one sentence invokes two separate rights.

The right to access. A person can ask what personal data you hold about them and get a copy in a usable, machine-readable format. Employees, former employees, contractors and even job candidates can all ask.

The right to erasure. A person can ask you to delete their personal data. It isn't absolute: where the law requires you to keep something (tax records, say), that obligation wins, and you say so instead of pretending otherwise.

They often arrive together, but the order is strict: export first, erase second. You can't produce a copy of data you've already destroyed.

What the export has to cover

More than the profile page. It includes the personal record, leave requests and the reasons typed into them, balances and how they moved, time entries and their notes, schedules, documents, notifications.

The trap is data outside the main system: the spreadsheet a manager kept, the CSV export sitting on a laptop, the notes file from a performance conversation. Every side copy is something you must find, include, and later erase. That's the practical argument for a single system of record: with the deadline running, you search one place, not five.

Erasure is not a delete button

"We deleted your data" honestly means "we deleted everything the law lets us delete." Three categories routinely survive an erasure request, legitimately:

  • Financial history. Payroll, tax and accounting records carry retention periods measured in years, set by national law. The numbers stay; the name doesn't have to.
  • Compliance evidence. If someone signed your security policy, that signature is the company's proof of a working control. The defensible pattern is a tombstone: keep the fact of the signature, strip the personal details.
  • The audit trail. That an approval happened matters to the integrity of everyone else's history. The wording that names the erased person can go; the event stays.

So the honest mental model is scrub, not drop. Personal fields get cleared or replaced with placeholders, uploaded files get purged, and the history the business legitimately needs remains, pointing at an anonymized reference instead of a hole.

The agent-era wrinkle

One more check for 2026: every access path. If an AI assistant can read your HR system (increasingly, it can), the erasure has to hold there too. The sane architecture is an agent that acts as the person who connected it, through exactly the permission checks the web app uses, so scrubbed data is scrubbed for everyone. If your vendor's AI integration is a separate pipeline with its own copy of the data, ask about that now, not mid-request.

The checklist

  1. Verify identity. Don't send an employment history to whoever emails asking for one; confirm it's really the person, via the address on file for instance.
  2. Acknowledge and date it. Reply that you've received it and note when the clock started.
  3. Export. Produce the copy and deliver it securely.
  4. Confirm scope. Access, erasure, or both? Tell them, before you run anything, what will be retained and why.
  5. Erase. Once, irreversibly, after the export is delivered.
  6. Document. Write down what was removed, what was kept, and under which legal obligation. This record is what protects you later.

Where SquadBear fits

The export is self-serve: anyone can request their own from the account menu, under My settings → My data → Request data export. It prepares in the background, pings your inbox when ready, and downloads as one JSON file: profile, balances, the full balance ledger, requests, time entries, schedules, teams, linked identities, notifications, audit trail and sessions. Uploaded documents are listed by metadata rather than bundled in. An admin can trigger the same export on someone's behalf from the profile's Data rights tab.

With an assistant connected, the employee-side version is one sentence:

"Export my personal data."

Erasure is admin-only (and an admin can't erase themself). It runs from that same Data rights tab and clears or placeholders the name, email, title, country, manager link, custom fields, emergency contacts, and the sensitive free text: leave reasons, time-entry notes, health check-in answers. Uploaded files are deleted, along with the login account and its sessions. What stays is the carve-out list: the balance ledger under a placeholder name, the audit trail with identifying wording blanked, and acknowledgment signatures kept as compliance evidence with the typed name and device details cleared. Anonymous health-check answers need nothing: the link to the person was destroyed when the run closed. Connected agents go through the same checks as the web app, so the erasure holds on every surface.

Since there's no undo, ask before you click:

"Before I erase this former employee, explain exactly what personal data that removes and what stays in SquadBear afterward."

Marta works the checklist

A contractor who left Northlake six months ago emails asking for their data and its deletion. Marta confirms the request came from the address on file and replies with the date. From the contractor's profile (People → Manage people, then the Data rights tab) she requests the export and sends the JSON securely, with a note on what will be retained: financial history and one signed policy acknowledgment. Once the contractor confirms, she runs Erase personal data and writes a short file note citing the retention grounds. Last year's leave totals still add up; the contractor's name appears nowhere. Elapsed: four days of a month-long clock, most of it waiting for the confirmation.

Be ready before the email

The first request shouldn't be the day you find out where your employee data lives. Start free and look at the Data rights tab on a real profile, or ask the demo what an erasure keeps.

Related reading: how to roll out a policy people actually read, whose signature records are the tombstones above, and your AI summary shouldn't require a copy of everything on keeping employee data inside your own boundary.

Totaely Purba
Written by

Totaely Purba

People Operations & HR Lead at SquadBear

Specializing in European labor compliance, absence policy architecture, and modern AI-assisted workforce workflows.