A stressed man looks at stock market data on his computer screen in an office setting. A stressed man looks at stock market data on his computer screen in an office setting.

HR Data Privacy and Generative AI: An Illusion?

The rise of generative AI platforms in the workplace is radically transforming how we work: automated drafting, data analysis, code generation. But one major risk persists and must be fully understood by every HR department: HR data privacy. When employee files, payroll data or disciplinary notes meet a chatbot, is confidentiality anything more than an illusion?

The relative transparency of AI models

Behind every generative AI sits a large language model hosted on remote servers. When users interact with these models, their prompts — and every piece of data pasted into them — transit through infrastructure owned by major technology players. Even when providers guarantee advanced security protocols, the simple fact that data passes through those servers means it is, one way or another, accessible to a third party. The transparency reports published by vendors describe policies, not proofs: what actually happens to a prompt after it is sent remains, for the customer, an act of trust.

Why HR data is a special case

HR data is among the most sensitive an organization holds: health information, salaries, evaluations, disciplinary records, union membership. Under the GDPR and equivalent laws, much of it enjoys special protection, and feeding it to an external AI service without a proper legal basis, data processing agreement and impact assessment is not a grey area — it is a violation waiting for a complaint. The everyday scenario is not a hack; it is a well-meaning HR officer pasting an employee’s file into a chatbot to “draft a letter faster”. That single paste can constitute an unauthorized transfer.

HR data privacy risks when generative AI enters the workplace

Ranking the platforms: transparency and enterprise guarantees

The gap between consumer and enterprise offers is where the real decision lies. Consumer versions of AI assistants may use conversations for model training, retain them for extended periods, and offer no contractual guarantees. Enterprise plans (and EU-hosted options) typically commit to no training on customer data, shorter retention, encryption and audit rights — for a price. The practical ranking that matters for an HR department is not “which model is smartest” but which offer provides: a signed data processing agreement, EU hosting or adequacy safeguards, no-training commitments, and retention controls. Anything less belongs nowhere near employee data.

Companies facing the dilemma

Prohibit generative AI and employees will use it secretly on personal devices — shadow AI is already the norm in organizations that banned it. Authorize it without a framework and you industrialize leakage. The way out is neither ban nor laissez-faire but an explicit HR data privacy policy: which tools are approved (enterprise versions only), which data categories may never be entered (a one-page list every employee can memorize), and which use cases are encouraged. Companies that provide a safe, approved tool kill most of the shadow usage overnight.

Trusting AI embedded in business software

The subtler frontier: AI features arriving silently inside the tools HR already uses — the HRIS that summarizes, the ATS that drafts, the office suite that “assists”. Each embedded feature routes data somewhere, under terms buried in an updated contract annex. HR data privacy due diligence must evolve accordingly: where does the AI processing happen, is customer data used for training, can the feature be disabled, and who is accountable if it leaks? “It came with the software” will not be a defense in front of a regulator.

An unavoidable risk?

Total risk elimination would mean total abstinence, and abstinence is no longer realistic. The mature position treats HR data privacy as a managed risk: approved tools with contractual guarantees, a clear never-list, training that explains the why and not just the rules, periodic audits of actual usage, and local or self-hosted models for the most sensitive workflows. Generative AI can absolutely serve HR — drafting, summarizing, analyzing — provided the data it touches was chosen, not pasted by accident. Between illusion and paranoia, there is governance. This article is also available in French.

Inscrivez vous à la newsletter

c’est simple, facile et discret

×