# Data Protection Policy (DPP): What It Means for Global Hiring

> Machine-readable page from EOR Overview (https://eoroverview.com/), an independent research platform for Employer of Record services.
> Canonical page: https://eoroverview.com/glossary/data-protection-policy/
> Methodology: how providers are researched, scored and compared is documented at https://eoroverview.com/methodology/.
> Disclosure: EOR Overview is free to use. We may earn a referral fee from some providers; this never affects a rating or ranking position (https://eoroverview.com/disclosure/).

A data protection policy (DPP) is an internal document that sets out how an organization collects, stores, processes, and deletes personal information, covering employees, candidates, and contractors. For companies hiring across borders, the policy must do more than satisfy one regulator: it has to reconcile overlapping and sometimes conflicting privacy laws in every country where workers are based. Getting this wrong exposes the organization to fines, audit failures, and damaged relationships with the very talent it is trying to attract.

## Explanation

What a data protection policy actually covers

A DPP defines the rules your organization follows when touching personal data. In an HR and hiring context that means candidate CVs, background check results, employment contracts, payroll details, performance records, and anything else that identifies or could identify a living person.

The document typically covers:

 - Which categories of personal data are collected and why

 - The legal basis for each type of processing

 - How long data is kept and how it is deleted

 - Who inside and outside the organization can access it

 - How data subjects exercise their rights (access, erasure, portability)

 - How a breach is detected, contained, and reported

 - How data moves across borders

A DPP is an internal governance document. It is different from a privacy notice or privacy policy, which is the external-facing statement you give to candidates and employees explaining what you do with their data. Both documents are required under most modern privacy regimes, but they serve different audiences.

Data protection policy vs. privacy policy: a quick comparison

 
 
 Dimension
 Data Protection Policy
 Privacy Policy / Notice
 

 
 
 
 Audience
 Internal staff, auditors, regulators
 Employees, candidates, customers
 

 
 Purpose
 Operational rules for handling data
 Transparency about how data is used
 

 
 Legal requirement
 Implied or explicit under most privacy laws
 Explicitly required under GDPR, CCPA, LGPD, etc.
 

 
 Detail level
 Deep: procedures, roles, timelines
 Plain language: what, why, how long, rights
 

 

Why global hiring makes this harder

A domestic employer writes one DPP and maps it to one legal framework. A company hiring internationally faces a much more complex picture because every country where a worker is employed or even just works creates a potential regulatory obligation.

Consider a US company that hires employees in Germany, contractors in India, and remote workers in Brazil. Each jurisdiction carries its own requirements:

 - Germany (EU GDPR + German Federal Data Protection Act / BDSG): Works council involvement may be required before implementing monitoring tools. Employee data protections are among the strictest in Europe. A Data Protection Officer (DPO) is mandatory for organizations that process employee data at scale.

 - Brazil (LGPD): The Lei Geral de Proteção de Dados mirrors GDPR in structure but has its own enforcement authority (ANPD) and specific rules around sensitive data categories including health and biometric data.

 - India (DPDP Act 2023): The Digital Personal Data Protection Act is still being operationalized through rules, but it will require consent-based processing for most employee data and introduces significant obligations for cross-border transfers.

 - United States: No single federal employee privacy law. State laws vary considerably, with California's CPRA extending privacy rights to employees and job applicants.

Your DPP must either contain country-specific annexes or reference local addenda that address each jurisdiction's requirements. A single global template that ignores local law is not compliant, even if it is well-written.

How EOR arrangements interact with a DPP

When a company uses an Employer of Record, the EOR becomes the legal employer in the worker's country. This creates a three-party data relationship that most standard DPPs do not address clearly.

The data protection implications work like this:

 - The EOR collects and processes employee personal data to run payroll, file taxes, and manage statutory benefits. Under GDPR and similar laws, the EOR is likely a data controller for that processing.

 - The client company also receives and uses employee data (work output, performance, communications). It may be an independent controller or a joint controller depending on the arrangement.

 - A data processing agreement (DPA) between the EOR and the client company is not optional under GDPR - it is a legal requirement. Many EOR contracts include a DPA, but you should verify it covers the actual flows of data between the parties.

Before signing with an EOR provider, check:

 - Where does the EOR store employee data? Is it stored in the worker's country, in the EU, in the US?

 - What cross-border transfer mechanism covers data moving between the EOR, its systems, and your systems?

 - How does the EOR handle data subject rights requests from workers - and what is your obligation to respond?

 - What is the EOR's breach notification procedure, and how quickly will it notify you so you can meet your own regulatory deadlines?

Your DPP should document these answers and map the EOR relationship explicitly in your records of processing activities (ROPA).

Cross-border data transfers: the specific risk

Moving personal data from one country to another is the area where global hiring teams most often get into compliance trouble. Under GDPR, transferring employee data from an EU country to a country without an adequacy decision requires a lawful transfer mechanism - most commonly Standard Contractual Clauses (SCCs). The UK has its own equivalent (International Data Transfer Agreements / IDTA). Brazil, South Korea, Thailand, and other countries with modern privacy laws have parallel requirements.

Practically speaking, if your HR system, payroll platform, or applicant tracking system is hosted in the United States and you are employing people in the EU, you are conducting a cross-border transfer every time you process that data. Your DPP must identify these flows and specify the mechanism used to legitimize them.

SCCs are the most common tool, but they now require a Transfer Impact Assessment (TIA) that evaluates the legal regime in the destination country and whether it undermines the protections the SCCs are meant to provide. This is legal work - not something an HR generalist should complete alone without input from privacy counsel.

Key components of a DPP built for international hiring

A policy that actually works for a globally distributed workforce should contain at minimum:

 - Data inventory and ROPA: A record of every category of personal data processed, the legal basis, the purpose, the retention period, and where data is stored and transferred.

 - Legal basis mapping: For each processing activity, the specific legal ground (consent, contract performance, legitimate interest, legal obligation). Note that consent is a weaker basis for employee data in many EU countries because of the power imbalance inherent in employment.

 - Retention schedules: Specific timelines for each data category. Candidate data is often kept far longer than necessary. Many EU regulators have issued guidance capping unsuccessful candidate data retention at a few months absent explicit consent for a longer period.

 - Data subject rights procedures: Clear steps for handling access, rectification, erasure, and portability requests - with country-specific timelines where these differ from the GDPR default of one month.

 - Cross-border transfer mechanisms: Identification of all international transfers and the legal basis for each.

 - Third-party management: A process for vetting vendors and EOR partners, signing DPAs, and reviewing them when vendor subprocessors change.

 - Breach response: GDPR requires notification to the supervisory authority within 72 hours of becoming aware of a breach. Other regimes have different clocks. Your policy must specify who declares a breach, who notifies regulators, and who contacts affected individuals.

 - Country annexes: Addenda covering jurisdiction-specific requirements for each country where you employ or engage workers.

 - DPO designation: Under GDPR, certain organizations must appoint a Data Protection Officer. The DPP should identify whether this applies and who holds the role.

Contractor and misclassification risk

Data protection obligations vary depending on whether a worker is classified as an employee or an independent contractor. In practice, many companies handle contractor data exactly as they handle employee data - sharing it with the same systems, storing it in the same HR platforms - without considering whether the legal basis and data processing agreements are in place.

If a contractor is later reclassified as an employee (a common outcome in countries like Spain, France, or Germany), any gap in data protection compliance for that individual's data becomes the company's liability retroactively. Treating contractor data with the same policy rigor as employee data, and having a signed DPA with any agency or intermediary, reduces that exposure.

What changes country by country

 
 
 Country / Region
 Key data protection law
 Notable HR-specific requirement
 

 
 
 
 European Union
 GDPR
 DPO may be mandatory; works council consultation in some states; 72-hour breach notification
 

 
 United Kingdom
 UK GDPR + Data Protection Act 2018
 Own transfer mechanism (IDTA) post-Brexit; ICO enforcement independent of EU
 

 
 Brazil
 LGPD
 DPO required for most organizations; ANPD oversight; sensitive data category includes health and biometric
 

 
 India
 DPDP Act 2023
 Rules still being finalized; consent-based processing expected for most employee data; cross-border transfer restrictions
 

 
 China
 PIPL + DSL
 Strict localization requirements; cross-border transfer requires government assessment for large-scale data exports
 

 
 United States (California)
 CPRA
 Employee and job applicant rights expanded; right to know, delete, and opt out of sale/sharing
 

 
 Canada
 PIPEDA / provincial laws + Bill C-27 pending
 Quebec Law 25 in force with GDPR-like obligations; federal reform ongoing
 

 

Practical steps for HR and global hiring teams

 - Map your data before writing your policy. A policy written without knowing what data you actually collect and where it goes will not reflect reality and will not satisfy an audit.

 - Get legal input in each hiring country. Local counsel or a privacy specialist familiar with local employment law is needed to write country annexes. Generic templates create a false sense of security.

 - Include your EOR in the process. Ask your EOR provider to share its ROPA entries relevant to your employees, its DPA template, and its breach notification procedure before you finalize your policy.

 - Review data flows when adding a new country. Every time you expand hiring to a new market, treat it as a trigger for a DPP review, not an afterthought.

 - Train hiring managers, not just the legal team. The people who collect candidate data via ATS platforms, scheduling tools, and email are the ones most likely to create a compliance gap. Training should be practical and country-specific.

 - Set retention periods and act on them. Storing candidate data indefinitely is one of the most common GDPR findings. Set a retention schedule, build deletion into your ATS workflows, and document it.

The compliance cost of ignoring this

GDPR fines can reach 4% of global annual turnover or 20 million euros, whichever is higher. Brazil's LGPD sets penalties up to 2% of revenue in Brazil, capped per incident. China's PIPL carries criminal liability for serious violations. Beyond fines, regulators can restrict processing - which in practice can mean you are unable to legally operate your HR systems in a country until the issue is resolved.

For companies using EOR providers, a poorly defined data protection arrangement with the EOR can mean the client company shares liability for the EOR's data handling failures. The contract and DPA between the two parties determine where responsibility sits.

A DPP that takes global hiring seriously is not a compliance exercise for its own sake. It is the document that lets your legal, HR, and finance teams confidently answer the question regulators and enterprise clients increasingly ask: "Show us how you handle personal data across your international workforce."
