In many German companies the personnel file is the last paper folder left standing, and at the same time the record with the most special rules attached to it. A single file holds documents with very different retention periods side by side: payroll accounts must be kept until the end of the sixth calendar year following the last wage payment recorded (Income Tax Act), payroll records for social security until the end of the calendar year following the last audit (Social Code Book IV), working-time records for at least two years wherever the recording duty under the Minimum Wage Act applies. On top of that sits a permission model tighter than in any other archive, and a right of inspection for employees (Works Constitution Act) that a company has to be able to serve in everyday operation. This article describes the filing architecture behind all of it: which section carries which period, who may look into it, what gets logged, and how an inspection becomes a routine case instead of a special run.
Key takeaways
- A personnel file is not one record with one retention period but one record with many: the payroll account until the end of the sixth calendar year after the last wage payment (Income Tax Act), working-time records for at least two years wherever the recording duty under the Minimum Wage Act applies.
- Access is granted per section and per role, not per department. The yardstick is what is necessary for the employment relationship (Federal Data Protection Act) - a line manager rarely needs the same view as an HR administrator.
- Employees have the right to inspect the personnel files kept about them and may bring in a member of the works council (Works Constitution Act). Statements on the content of the file must be attached to it on request.
- A request under the General Data Protection Regulation has to be answered within one month of receipt; that period may be extended by a further two months. A prepared file view turns this into a routine case instead of a special run.
- Health data and other special categories do not belong in the general section: processing them is prohibited unless an exception applies (General Data Protection Regulation). They need their own section with a named group of individuals.
- A system that records access on a personal basis touches co-determination on technical devices (Works Constitution Act). The agreement is made before the first productive access, not after the first evaluation.
Why a personnel file sits differently from any other archive
In an accounting archive one period covers the whole stack: the documents listed in section 147 subsection 1 must be kept for ten, eight or six years depending on the document type (Fiscal Code), and the filing structure can follow that cut. A personnel file works differently. It is not a collection of similar records but a bracket around documents from several areas of law: employment contract and written statement of essential terms from employment law, payroll account and certificates from tax law, payroll records and contribution statements from social security law, working-time records from minimum wage law. Each origin brings its own retention period, and the periods do not run in step.
The second difference is the group of authorised people. In an accounting archive the question of who may read is usually answered by naming a department. In a personnel file it hangs on the individual: HR administration typically sees the complete file, a line manager needs an extract for an appraisal interview, payroll needs the pay-related documents and nothing else. Processing employee data is permitted where it is necessary for the decision on entering into an employment relationship, or after that for carrying it out or ending it (Federal Data Protection Act) - and necessity is a question per section, not per folder.
The third difference is the evidential position. A written warning, a draft reference, an instruction record, a receipt for equipment handed over: these documents sit in the file because they may be needed later - in proceedings, in an audit, in a discussion with the employee representatives. Digitising them shifts the question from the paper to the procedure: when did a document enter the file, who filed it, has it been unchanged since? That is the same question every orderly document archive has to answer (see Getting started with document management); in a personnel file the answer simply has immediate consequences for the people involved.
What belongs in the file and what belongs beside it
Which period hangs on which document
Retention periods are the part of the personnel file that is easiest to evidence and most often treated in the round. The rule of thumb "ten years, then delete" fits none of the sections. For the payroll account the statute says: payroll accounts must be kept until the end of the sixth calendar year following the wage payment last recorded (Income Tax Act). Payroll records for social security must be kept for each employee, separated by calendar year, and stored in order until the end of the calendar year following the last audit (Social Code Book IV) - so this period has no fixed end at all but hangs on the audit cycle. Working-time records must be kept for at least two years from the relevant reference date for the record - but this duty does not apply to every company: it falls on employers who employ people on a marginal basis under section 8 subsection 1 of Social Code Book IV or in the economic sectors and branches named in section 2a of the Act to Combat Undeclared Work; it does not apply to employment relationships under section 8a of Social Code Book IV (Minimum Wage Act). Applying the two years across every personnel file therefore borrows a period from a scope narrower than the actual record; as a uniform house rule that can make sense, but as a legal duty it then needs a different basis.
| Section of the file | Retention | What the period hangs on | Legal reference |
|---|---|---|---|
| Payroll account and wage records | until the end of the sixth calendar year | wage payment last recorded | Section 41 subsection 1 sentence 9 (Income Tax Act) |
| Payroll records for social security | until the end of the following calendar year | last audit under section 28p | Section 28f subsection 1 sentence 1 (Social Code Book IV) |
| Working-time records under minimum wage law | at least two years, only for the group covered by section 17 subsection 1 sentence 1 | relevant reference date for the record | Section 17 subsection 1 sentence 1 (Minimum Wage Act) |
| Accounting records with a personnel link | eight years | end of the calendar year in which they arose | Section 147 subsections 3 and 4 (Fiscal Code) |
| Documents from rejected applications | two-month deadline for claims | receipt of the rejection | Section 15 subsection 4 (General Equal Treatment Act) |
| every section in addition | only as long as the purpose requires | purpose of the processing | Article 5 paragraph 1 point e (General Data Protection Regulation) |
One uncomfortable consequence follows from that table: the file as a whole has no deletion date. Applying the longest period to the entire record keeps data longer than the purpose carries - and that runs against storage limitation, under which personal data must be kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which they are processed (General Data Protection Regulation). Applying the shortest period instead loses documents an audit would still like to see. The archive therefore needs sections, and each section carries its own period - technically the same approach as with any other record bound by retention rules (see Meeting retention periods digitally).
One section deserves particular attention because it usually arises outside the personnel file and still belongs to it: the working-time record. It accrues daily, it must be kept for at least two years wherever the recording duty under the Minimum Wage Act applies, and it is one of the few sets of personnel data generated continuously by machine. Where time tracking has a system of its own, the personnel file ends at that boundary - the retention period applies all the same, and the question of access arises there a second time (see Digital time tracking 2026: implementing the mandate).
Who is allowed to see which section
The permission model of a personnel file can be derived from a single sentence. Personal data of employees may be processed for the purposes of the employment relationship where this is necessary for the decision on entering into an employment relationship or, after entering into it, for carrying it out or ending it (Federal Data Protection Act). In practice the word "necessary" turns into a matrix: rows are the sections of the file, columns are the roles, and each cell holds read, write or a dash. A company that does not write this matrix down grants rights through groups that came from a different context - and then the management assistant sees the file because it happens to sit in the same directory node.
Roles are more stable than people. A deputising rule based on names rarely survives the first change of staff; a role with two holders does. Each role therefore needs not only a scope but also an answer to who grants it, who withdraws it and how often it is reviewed. The following split has proved workable in mid-size companies in our experience; it is a starting point for your own matrix rather than a template to adopt:
- HR administration: read and write in the general section, read in the pay section. It files documents, it does not delete - deletion is a separate, logged case with its own approval.
- Payroll: read and write in the pay section, no access to correspondence, warnings or application documents. The scope follows the task, not the hierarchy.
- Line manager: read on a defined extract for their own reports - contract data without pay, qualifications, objectives. No access to health information and none to application documents of other people.
- Management: read on a stated occasion rather than as a standing right. A permanent full access with no task behind it is the most common finding when a grown legacy system is reviewed for the first time.
- Administration: manages the system, not the content. Technical access to the database and the storage can rarely be excluded, so it is named, logged and limited to a few accounts (see Account access when staff join and leave).
- Employees themselves: read on their own file where the application offers a self-service view. That is the technical answer to the right of inspection and takes daily load off the HR team.
Permissions go stale faster than files do. A change of responsibility, parental leave, someone leaving: each of these events changes who may see which section, and none of them reports itself to the system. What works in practice is a fixed review - once a quarter a list per role, confirmed by the person who owns that role. The effort is a few minutes per role; the alternative is a set of permissions whose origin nobody can explain two years later.
What an access log has to deliver
A log answers two different questions, and they are easily blurred. The first is accountability: can the company show that it has implemented appropriate technical and organisational measures to ensure a level of security appropriate to the risk (General Data Protection Regulation)? For that it is enough that accesses are recorded and can be evaluated. The second is investigation: who opened the written warning on 14 March? That needs individual records - and those are exactly what turns the log itself into a record about employees.
A usable log entry contains four items and no more: the account, the timestamp, the document or section concerned, and the type of access - read, change, export, delete. Reading time, scrolling behaviour and screen time are not logged; such data answers neither of the two questions and pushes the log towards behavioural monitoring. Export deserves a line of its own, because it is the point at which data leaves the application and lands in a place where the matrix no longer applies.
The log itself needs a purpose, a retention period and a narrow group of readers. A few months for fault analysis is common, and anything longer only where there is a concrete, recorded occasion. Keeping the log indefinitely misses storage limitation at precisely the point where it was meant to be enforced - the same logic as for any other processing activity (see Data protection when digitising processes).
Permission matrix for the personnel file (extract)
Section HR Payroll Manager Admin
-----------------------------------------------------------------
Contract and statement write read read -
Pay and payroll account read write - -
Working time read read team -
Reviews and objectives write - write -
Warnings, correspondence write - - -
Applications (rejected) write - - -
Health (separate section) named - - -
System level - - - technical
Logged for every access:
account timestamp object action
-----------------------------------------------------------------
hr.clerk 2026-09-25T09:14:02Z file/1042/contract read
payroll 2026-09-25T09:31:47Z file/1042/pay/2026 write
hr.clerk 2026-09-25T11:02:10Z file/1042/full-view export
Not logged: reading time, scrolling behaviour, screen time.
Evaluation: only for a stated reason, under the agreed procedure.Who may evaluate the log and on what occasion is not a technical question but an agreement. A four-eyes rule works well: HR management requests the evaluation, it is approved together with the employee representatives, and the result is recorded. That gives the case the same shape as any other approval in the company - with a requester, a deadline, a deputy and a record (see Digitising approval workflows).
Serving the right of inspection in practice
Two rights meet in the personnel file, and both are older than any software. The first is in the Works Constitution Act: the employee has the right to inspect the personnel files kept about them, and may bring in a member of the works council for this purpose (Works Constitution Act). In addition: statements by the employee on the content of the personnel file must be attached to it at their request (Works Constitution Act). So a digital file must not only be readable but also able to hold a counter-statement that stays next to the document it refers to.
The second right comes from the General Data Protection Regulation. The controller provides a copy of the personal data undergoing processing, and provides information on action taken on a request without undue delay and in any event within one month of receipt; that period may be extended by two further months where necessary, taking into account the complexity and number of the requests (General Data Protection Regulation). The difference from the right of inspection matters in practice: inspection means looking, access means handing over - and what is handed over is not the folder but what is processed about the person (see Handling data subject access requests).
A view, not a copy
The inspection happens on a view that reads the same archive as the HR desk does. No second export is created - and therefore no second record that would later need its own permissions and its own deletion rule.
Released section by section
The view knows the sections of the file and shows those that belong to the person. Information about third parties - names in a piece of correspondence, for instance - stays redacted, because it is not the subject of the inspection.
The deadline sits on the case
The request is handled as a case with a date of receipt. The one-month period is therefore visible, and an extension becomes a reasoned decision with a date instead of an omission that only surfaces when someone asks again.
Counter-statement in context
A statement on the content of the file is attached to the document rather than appended to the end of the file. Whoever reads the warning later sees the statement beside it - the effect the paper attachment used to have.
Evidenced handover
What was handed over is in the log with a timestamp and a scope. When someone asks again months later, that is the only reliable answer; the recollection of those involved, in our experience, is not.
Separate sections stay separate
Special categories are not included simply because they happen to sit in the same file. Whether they form part of the response is a separate decision with its own reasoning and its own group of readers.
In practice the sticking point is rarely the technology but the responsibility. If a request for inspection reaches the HR team and nobody there can say with certainty which sections belong to it, a special run begins, with queries, interim states and postponed appointments. Half an hour of briefing per person involved and a one-page procedure replace that special run for good (see Training and rollout).
Health data and other special information
Part of what accrues in an HR department is subject to a stricter standard. Processing of personal data revealing, among other things, religious or philosophical beliefs or trade union membership, as well as the processing of data concerning health, is prohibited (General Data Protection Regulation) unless an exception applies. For the employment relationship the Federal Data Protection Act names such an exception: processing special categories is permitted where it is necessary to exercise rights or comply with legal obligations derived from labour law, social security law and social protection law, and where there is no reason to believe that the data subject's legitimate interest in excluding the processing prevails (Federal Data Protection Act).
For the archive this results in no list of prohibitions but in a separation. Records from workplace reintegration management, information about a severe disability, occupational health certificates and comparable documents sit in a section of their own with a named group of individuals - typically HR management and one named deputy, not the whole administration team. Technically that is no special case but the same matrix as above, only with a row that holds a dash almost everywhere. Organisationally it is the point where it becomes clear whether the matrix is lived or merely written.
file/<employee-number>/
01-contract/ contract, written statement, amendments
period: end of employment, then review
02-pay/ payroll account, certificates, deductions
period: sixth calendar year after last wage payment
03-social-security/ payroll records, contribution statements
period: calendar year after the last audit
04-time/ working-time records, leave, absence
period: two years where § 17 MiLoG applies
05-development/ reviews, objectives, qualifications
period: bound to purpose, reviewed yearly
06-correspondence/ warnings, instructions, correspondence
period: bound to purpose, reviewed yearly
07-applications/ documents from rejected applications
period: after the deadline for claims has passed
90-protected/ health, reintegration, severe disability
group: named individuals, separate log
period: its own rule per document type
Every section carries three entries: purpose, period, authorised group.
Without all three it is not a section but a folder.The application section is the special case with the shortest deadline. A claim under the General Equal Treatment Act must be asserted in writing within a period of two months, and in the case of an application that period starts with receipt of the rejection (General Equal Treatment Act). That produces no automatic deletion date, but it does give a reference point: once the deadline and a reasonable time for further steps have passed, the purpose for which the documents were held falls away. Where an application leads to a hire, the documents move into the contract section - and there the next chain begins, from the signed contract to the written statement of essential terms, which may be drawn up in text form and transmitted electronically provided the document is accessible to the employee, can be stored and printed, and the employer asks for confirmation of receipt on transmission (Act on Proof of Essential Conditions); on the question of form see Electronic signatures: which form is legally valid.
Settle co-determination early
A digital personnel file logs access, it knows processing states, and it can evaluate who opened what and when. That touches a co-determination matter: unless a statutory or collective provision applies, the works council has a right of co-determination on the introduction and use of technical devices designed to monitor the behaviour or performance of employees (Works Constitution Act). The Federal Data Protection Act additionally makes clear that the participation rights of employee representative bodies remain unaffected (Federal Data Protection Act). Whether a device is designed for that purpose is not decided by the company's intention alone - an application that records access on a personal basis is, in our experience, the standard case for participation rather than the exception.
A works agreement on the personnel file is shorter than many expect. It names the sections, the roles and the scope per role, it settles what is logged and what is not, it defines who may request an evaluation and under what procedure, and it states how long the log is kept. Everything else - storage locations, file formats, naming conventions - belongs in the process documentation and not in the agreement, because it changes more often than the negotiated position and would otherwise have to be renegotiated with every adjustment.
Where participation actually starts
From a paper folder to a managed file
The changeover rarely fails at the scanning. It fails because a paper folder has no sections, so the structure has to be decided for the first time during digitisation - for every case already on file. Making that decision while scanning means making it under time pressure and afresh for every sheet. The following order separates the decisions from the bulk work:
Step 1: define sections and periods
Before the first sheet comes the list of sections with purpose, retention period and authorised group for each. It fits on one page. Its basis is the periods from tax, social security and employment law, not the folder dividers that have grown over the years.
Step 2: review the stock and sort out
What is no longer needed today does not get scanned. This review is the moment when sorting out costs least; afterwards every superfluous document costs storage, permissions, a deletion decision and, in case of doubt, an explanation.
Step 3: capture with separator sheets
Scan section by section rather than whole files in one pass. Separator sheets carrying the section code save sorting on screen afterwards. Text recognition provides searchability but does not replace the classification (see Text recognition in practice).
Step 4: grant permissions and test them
The matrix is configured and then checked with test accounts: every role signs in and looks at what it actually sees. Only this counter-check shows whether the grants work; a configuration screen shows only the intention.
Step 5: conclude the works agreement
Sections, roles, logging and the evaluation procedure are agreed before the first productive access takes place. The draft comes out of steps 1 and 4 and is therefore already written when the negotiation begins.
Step 6: close the paper and rehearse the flow
The paper folder is closed, not destroyed straight away. A rehearsal covering one inspection and one access request shows whether the view holds up and whether the periods are stored correctly (see Document digitisation).
Before the first sheet comes the list of sections with purpose, retention period and authorised group for each. It fits on one page. Its basis is the periods from tax, social security and employment law, not the folder dividers that have grown over the years.
What is no longer needed today does not get scanned. This review is the moment when sorting out costs least; afterwards every superfluous document costs storage, permissions, a deletion decision and, in case of doubt, an explanation.
Scan section by section rather than whole files in one pass. Separator sheets carrying the section code save sorting on screen afterwards. Text recognition provides searchability but does not replace the classification (see Text recognition in practice).
The matrix is configured and then checked with test accounts: every role signs in and looks at what it actually sees. Only this counter-check shows whether the grants work; a configuration screen shows only the intention.
Sections, roles, logging and the evaluation procedure are agreed before the first productive access takes place. The draft comes out of steps 1 and 4 and is therefore already written when the negotiation begins.
The paper folder is closed, not destroyed straight away. A rehearsal covering one inspection and one access request shows whether the view holds up and whether the periods are stored correctly (see Document digitisation).
The time required is distributed differently from what people expect. The bulk work - reviewing, scanning, classifying - is plannable and can be sped up with extra hands. The decisions from steps 1, 4 and 5 cannot be sped up, because several parties hang on them and every round of coordination has its own rhythm. Setting the changeover date by scanning capacity means moving it twice, in our experience; setting it by the conclusion of the works agreement means meeting it.
The list of sections is the actual project
Deletion is part of filing
- Every section gets a deletion rule made of an event plus a period: last wage payment plus six calendar years (Income Tax Act), last audit plus one calendar year (Social Code Book IV), relevant reference date plus two years where section 17 Minimum Wage Act applies. Without an event no period can be calculated.
- The envisaged time limits for erasure of the different categories of data belong, where possible, in the record of processing activities (General Data Protection Regulation) - in other words in the same place as the purposes.
- The deletion run is recorded, not carried out silently. What was deleted, under which rule and at what time belongs in the process documentation (see Writing process documentation for audits).
- A deletion run needs a hold list for pending matters. As long as litigation, an audit or an open access request is running, the section concerned is suspended and the reason noted - with a date and the person who made the note.
- Backups are part of it. Deleting only the productive record leaves the job half done; the rule for backup generations belongs in the same procedure and the same documentation (see Operations and maintenance).
Deletion is the part of filing that does not happen without a trigger. A date in a calendar is not enough, because it points at one person; a rule in the system is not enough if nobody looks at its result. What works is a fixed run once a year with a proposal report: the system proposes, HR management decides, the result is recorded. That keeps the decision with a human and the calculation with the system - the split that, in our experience, holds up in a file with many different retention periods. Where the sections were cut correctly at the outset, this run is an hour of work a year (see Process analysis).
A personnel file is only digital once somebody can say who opened which section and when - and when it will be empty. Everything before that is a folder with a screen in front of it.
Sources and legal basis
Related Articles
Handling access requests: deadline, scope, data sources
An access request starts a one-month deadline: what the response has to cover, where the data actually sits and what should remain provable afterwards.
Own server or data centre: making the decision soberly
Cost over five years, availability, responsibility during incidents, data protection and getting data back — how mid-sized firms decide where their servers run.
Writing process documentation for tax audits
Process documentation under the German GoBD rules: the four required parts, how detailed it must be, how to keep it current and what its absence can mean.