Ciphr acts as both a data controller and a data processor, depending on the relationship. We provide secure systems and governance to support your compliance, while you remain responsible as the data controller for your employees' data.
GDPR compliance you can prove, not just promise
Every HR system holds sensitive data about real people. Pay records. Medical details. Disciplinary history. If a regulator, a board, or an auditor asks how that data is protected, "we're GDPR compliant" isn't an answer. Evidence is.
Ciphr gives UK HR and payroll teams GDPR compliance built on verified controls, UK-based governance and a dedicated data protection officer, not a compliance page written to sound reassuring.
HR GDPR compliance, built into every layer
We don't just tell you the data is protected. We show you how.
Our Trust Centre gives HR directors, DPOs and IT teams a direct view of the controls behind our approach to UK data protection: security architecture, certifications, audit evidence and AI governance documentation. So you can answer your own stakeholders directly, without a call to us first.
Standards that back it up
Ciphr holds ISO 27001 for information security, Cyber Essentials Plus for independently audited protection, ISO 9001 for quality management, and ISO 14001 for environmental management. Security testing runs through internal specialists and CREST-accredited external partners. Separately, an internal security forum, led by our director of information security and IT, reviews controls, policies and procedures on an ongoing basis to keep them effective.
GDPR compliance UK organisations can trust
Ciphr is a UK company, built around UK employment law, UK payroll cycles and the requirements of UK GDPR from the outset, not a global platform adapted for this market afterwards.
We act as both a data controller and a data processor, depending on how you work with us, and we're clear about which applies when. Our data protection officer provides ongoing oversight and accountability, and acts as a contact for any related queries.
"Having clear visibility into how suppliers manage data, including AI, is critical for HR and IT teams"
Claire Hawes
Chief people officer and data protection officer, Ciphr
Compliance that's implemented, not handed over
You won't be left to configure data protection settings on your own. Ciphr's implementation includes structured onboarding: a named team who will work with you to set up access controls, retention policies and reporting to match your organisation from the start.
Structured implementation from day one
Initiate, discover, realise, validate, deploy: Ciphr's five-step implementation process covers data migration, access configuration and user acceptance testing, so your data protection setup is checked and signed off before go live, not fixed after something goes wrong.
AI, governed properly
AI is now part of how organisations manage people data, and that raises new governance questions for DPOs and IT teams.
Live today: Ciphr's AI features don't train on your employee data, and don't make uncontrolled decisions about people. Every AI feature includes documentation explaining how it works and where human review applies.
On the roadmap: broader agentic AI capability, where the connected suite lets AI act on tasks like a leave request from start to finish. That's not live yet. When it ships, we'll say so plainly rather than describe it as if it's already here.
Trusted by organisations across the UK
Hundreds of UK organisations trust Ciphr to help them manage and protect employee data securely and in line with GDPR requirements.
"Ciphr really is first to market with a lot of its developments; I was a big fan of the GDPR data deletion and monitoring function."
Certitude
See how we do it
For a full view of our security practices, certifications and approach to data protection, visit the Trust Centre or talk to our team.
FAQs: Ciphr GDPR
We apply layered security measures, including encryption, monitoring, auditing, and regular penetration testing using both internal experts and external CREST-accredited partners.
Yes. Ciphr holds ISO 27001, Cyber Essentials Plus, ISO 9001, and ISO 14001 certifications, which support our structured approach to security and quality.
We use role-based access controls, defined permissions, and regular governance reviews to ensure only authorised users can access sensitive data.
Ciphr has a dedicated data protection officer (DPO) who oversees data protection practices and acts as a contact for any related queries.
We continuously review, test, and improve our systems, policies, and controls to respond to new risks and maintain strong data protection standards.
We take a controlled, transparent approach to AI. Our AI features are designed to support users, not replace decision-making, and we apply strict controls to how data is handled. Customer data is not used to train public AI models, and we continuously review and improve our governance in line with emerging risks and best practice.
The General Data Protection Regulation (GDPR), which came into effect on 25 May 2018, is a set of standards governing how personal data is collected, processed and stored across the EU. In the UK, these requirements are reflected in the UK GDPR alongside the Data Protection Act 2018. Organisations that process personal data must comply with the relevant legislation or risk significant fines.
HR is the keeper of significant amounts of employee personal data, but the onus for maintaining data in line with the GDPR is typically shared among HR and information security teams, and, of course, the appointed data protection officer (DPO). Employers must put in place policies and procedures to ensure employee (and applicant) data is collected, stored and processed in line with the GDPR's requirements, and that they respond to subject access requests (SARs) within the required timeframe.
Types of employee data covered by the GDPR can include, for example, job and pay records, addresses, next-of-kin information, details of any medical conditions or disabilities, the results of background checks or right to work checks, and any other personally identifiable information. Because HR, HR managers, and HR practitioners are usually the guardians of an organisation's employee records, they are responsible (alongside information security teams and the DPO) for compliance with the GDPR in relation to personal, sensitive employee data. HR practitioners and HR managers must ensure they have a lawful basis for collecting and storing data related to employees and job applicants, and that the data is stored only for the required and agreed period (if permissions for data have expired, consent must be captured again, or the data must be deleted or anonymised). They may also have to respond to subject access requests (SARs) from former or existing employees, who, under the GDPR, have a legal right to request a copy of all the personal data that the organisation holds about them.
Disclaimer
We would strongly recommend that you seek your own legal advice if you are unsure about the implications of data protection laws on your business. The information contained on this website is for general guidance purposes only. It should not be taken for, nor is it intended as, legal advice. While we have made every effort to ensure that the information provided on this document is correct and up to date, Ciphr makes no promises as to completeness or accuracy and the information is delivered on an “as is” basis without any warranties, express or implied. Ciphr will not accept any liability for errors or omissions and will not be liable for any damage (including, without limitation, damage for loss of business or loss of profits) arising in contract, tort or otherwise from the use of or reliance on this information, or from any action or decisions taken as a result of using this information.