Skip to content

Hire-to-Retire and the Digital Employee File

The employee lifecycle as one governed process, with a digital employee file underneath it and retention rules applied rather than remembered.

What hire-to-retire actually is

Hire-to-retire is every record a person generates from the day they apply to long after they leave: the application, the contract, payroll, working time, absence, appraisals, the leaving paperwork, and the years of retention that follow.

It is treated as an HR workflow and it is really a records problem. The workflow ends when someone leaves. The file does not, and almost every obligation that attaches to it applies after the person has gone.

Single fine for personnel notes kept on a network drive
EUR 35.26mSingle fine for personnel notes kept on a network driveHamburg Data Protection Commissioner, 2020
Govern one personnel file, and at least one is not measured in years
Several clocksGovern one personnel file, and at least one is not measured in yearsThe periods are your counsel’s to set
Lower HR labour cost at top-performing organisations than at their peers
44%Lower HR labour cost at top-performing organisations than at their peersThe Hackett Group, 2024

What it is costing you now

Recruitment holds one set of documents, HR operations another, payroll a third, and the leaver’s file is whatever survives in a folder after the person has gone. Nobody designed that. It is what happens when each stage is automated on its own.

The cost surfaces in three places.

  • At an audit

    When nobody can produce the current contract for a named person inside an hour.

  • At deletion

    When nobody is willing to delete anything because they cannot tell what the rule is, so everything is kept forever, which is itself the breach.

  • Every working day

    In the time people spend looking for documents that exist but cannot be found.

One personnel file, several clocks, and they do not agree with each other.

We do not publish retention periods. They are your counsel’s to set, they differ by record and by country, and at least one of them changed while this site was being written. What follows is the shape of the problem, which is what determines whether a system can hold it.

Scope before duration

  1. Should it be in the file at all?

    Swiss employment law is narrower here than most policies assume. Filtered when a record is created, it costs nothing. Filtered at review, years later, it is the project nobody funds twice.

  2. How long may it stay?

    Your counsel’s to set, per record and per country. Answered first, it is answered for a file that holds half of what it should not.

Ask what may be held before you ask how long.

The same person generates records that are governed separately

  1. Payroll and tax records

    Governed by tax law, and the clock usually starts from an entry rather than from the end of employment. Someone who left years ago can still be inside it.

  2. Accounting documents

    Governed by commercial and tax law, on a period that is not the same as the payroll one and that has changed in living memory.

  3. Working-time records

    Governed by working-time law, on a much shorter period, and usually expressed as a minimum rather than a maximum. Keeping them longer is a decision, not compliance.

  4. Social-insurance records

    Governed by social-insurance law, and this is the one that is not measured in years at all.

  5. Everything in the Swiss entities

    Governed by Swiss law on its own periods, which are not the German ones. A group with staff in both runs two sets and the differences fall on whoever holds the file.

Lengths are illustrative. Where a clock starts, whether it has an end, and whether the periods agree: that is the shape a system has to hold.

One of them is a condition, not a duration

At least one clock in a German personnel file does not run for a number of years. It runs until something happens, and until it happens nobody can say when the record may go. A retention policy written purely as a table of years cannot express that, which means it is silently wrong about that category from the day it is signed. It has to be modelled as a condition the system evaluates, not as a date it counts down to.

Which is where we come in, and where we do not

We are not your legal advisers and this page is not advice. The periods, the scope rule and the conditional clock are for your counsel to determine. What we do is make sure whatever they determine is what actually happens: applied per record type rather than per folder, evaluated as a condition where the rule is conditional, suspended by a legal hold that covers the affected records and only those, and evidenced afterwards. A retention policy nobody executes is a document establishing what you knew you should have done.

What uncontrolled personnel records cost once

EUR 35,258,707.95

Hamburg Commissioner for Data Protection, 1 October 2020

A single fine, for notes on several hundred employees’ private lives kept on a network drive since at least 2014 and readable by up to fifty managers. It surfaced because a configuration error exposed them company-wide for a few hours. The failure was not a breach of a system: it was records nobody had a rule for, in a place nobody had classified.

Start with the file, not the workflow

A digital employee file is one governed record per person: contracts, certificates, appraisals, correspondence, with retention and access applied as rules rather than by whoever maintains the folder.

That ordering matters. A workflow built over ungoverned folders inherits the problem it was bought to fix, and it does so at speed. The file first, then the processes on top of it, which then inherit its governance for free.

Employee records are personal data, so retention is an obligation rather than a housekeeping preference, under GDPR and the Swiss FADP. A file that applies its own retention is the practical form of that compliance.

ISO 15489 · GDPR · FADP

The test

How long does it take to produce every current document for one named employee?

Does a leaver’s file delete itself on schedule, without anyone remembering to do it?

Both are answerable in an afternoon, and both are usually the first time anyone has asked.

What you get

Four consequences of governing the file rather than the workflow. Open any of them for what it means in practice.

  1. A file that could survive the scope question, not just the duration one

    From scope being decided before duration.

    What it means in practice

    Most personnel policies answer how long. The question underneath it is whether the material was ever supposed to be in the file, and Swiss employment law is narrower on that than most groups assume. A file disposed of on schedule that should never have held half its contents has solved the second problem and not the first.

    Applying the filter when records are created rather than at review is the difference between a rule and an intention. The appraisal note about someone’s home life, the recruiter’s aside, the copy of a document nobody needed: cheap not to create, expensive to find later.

    Your employment counsel sets where that line falls, and a consent clause in the contract may not move it as far as people expect. Our part is that the line, wherever they draw it, is applied when a record is made rather than discovered years later.

  2. One file that satisfies two legal systems at once

    From the obligations being read together rather than in turn.

    What it means in practice

    A group operating in Switzerland and Germany has a Swiss scope rule and Swiss periods, and separately German periods drawn from four different bodies of law. Run as two policies, they disagree at every boundary and a shared services team improvises the difference.

    Read together, most of it resolves. Your advisers take the strictest scope rule and the longest applicable period per record type; the system then records which decision produced each rule, so a reviewer in either country is shown a basis rather than a habit.

    The exception is the clock that is not measured in years at all: it runs until an event occurs, so a policy written as a table of years is silently wrong about that category from the day it is signed. It has to be modelled as a condition the system evaluates.

  3. Disposal that happens, with a hold that actually holds

    From retention being enforced by the system rather than by intention.

    What it means in practice

    A retention policy nobody executes is a liability with a document attached: it establishes what you knew you should have done. Disposal that runs on schedule is the only version that reduces exposure rather than recording it.

    The part that has to work alongside it is the legal hold. A dispute, an investigation or a pending claim has to suspend disposal for the affected records and only those, and release cleanly afterwards. A hold that stops everything is a hold nobody will apply the second time.

    This is also the answer to the H&M case, which is on this page because it is a regulator’s own document rather than a vendor’s estimate. The failure there was not a breach of a system. It was records nobody had a rule for, in a place nobody had classified, for six years.

  4. Access you can prove, to a subject or to a regulator

    From the file being one record rather than several.

    What it means in practice

    A subject access request is answered from wherever the records actually are. When a personnel file is a folder, a shared drive, an inbox and a payroll system, the honest answer to "is that everything" is that nobody knows.

    Governing the file as one object makes the request a retrieval. It also makes the answer repeatable, which matters more than speed: the same request answered twice with different results is worse than a slow answer.

    The same applies to a works council or a Swiss employee representation asking what is held about a group of people. Being able to answer that without a project is the practical test of whether any of this is real.

Where this sits

The employee file is where this process meets every other record the business keeps, and the same questions apply to it. That underneath is Information Value Management: what the information behind it is worth, what it costs to hold, and what a change to either returns.

Information Value Management

We start with the file rather than the workflow, because a process built on folders nobody governs inherits the problem it was meant to fix.

Hire-to-retire, asked plainly

  • What is the hire-to-retire process?

    Hire-to-retire is the employee lifecycle treated as one process: recruitment, onboarding, every contractual change, absence and development, exit, and the retention period that runs after someone has left. The point of treating it as a single lifecycle is that the obligations are continuous even though the departments are not.

  • What is a digital employee file?

    The record underneath the process: one governed place holding contracts, certificates, appraisals and correspondence for each person, with retention and access rules applied by the system rather than by whoever maintains the folder. It is the difference between HR documents being stored and being managed.

  • What should hire-to-retire software actually do?

    Two capabilities worth paying for. Apply retention automatically, so a leaver file is deleted when it must be rather than kept indefinitely because nobody was sure. And scope access by role and by case, so a manager sees their own team's records and no others without anyone administering a list by hand.

  • How long do you keep employee records after someone leaves?

    It varies by jurisdiction and by document type, which is exactly why it should be a rule in a system rather than a decision someone makes each time. Contracts, payroll records and certificates typically carry different periods, and what is never defensible is keeping everything forever because deleting felt risky.

  • How does this relate to data protection?

    Employee records are personal data, and holding them past their purpose is a breach rather than an oversight. A digital employee file with retention applied is the practical form of that compliance, under GDPR and under the Swiss FADP.