This document establishes guidelines for organizations in the safe handling of human resource management (HRM) data, ensuring responsible collection, management, protection, usage and disposal of personal information related to an organization’s workforce. This document applies to both for-profit and non-profit organizations of any size in all sectors. It applies to all sectors and organization sizes, covering data from current and former employees, contractors, applicants and other relevant individuals. This document pertains to data derived for, from, or used within HRM activities and processes.
This document covers the safe handling of HRM data, in any format, whether collected, maintained or used by a human resources department or an alternative party such as third parties, vendors or non-HR departments (e.g. finance, operations). This document concerns only the safe handling of HRM data; characteristics of the HRM data such as the quality, reliability and validity are not within the scope of this document (see ISO 30435). This document covers data related to any individual for whom information is utilized as part of the HRM data life cycle, including past and present employees, contractors, directors or board members, applicants, and formerly or indirectly associated individuals. It does not include privacy for customers, suppliers or other third parties when the data exists outside of HRM (see ISO/IEC 27001 and ISO/IEC 27002 for data privacy non-specific to HRM data and the ISO/IEC 38505 series related to data governance in general).
ISO 30439