Staff profile deletion using data pseudonymisation

Created by Alex C, Modified on Mon, 22 Dec, 2025 at 7:45 PM by Alex C

If you want to completely remove staff or staff asks to be removed you would need to achieve is a way to be able to keep a certain set of logs within the system for future reference such as the job history, payroll, evaluation, consent, etc. All this information is very important to your agency. The payment information and consent are required for a minimum time required by law.

This is where we use data pseudonymisation. The GDPR defines pseudonymization as the processing of personal data in such a way that the data can no longer be attributed to a specific data subject without the use of additional information. To pseudonymize a data set, the additional information must be kept separately and subject to technical and organizational measures to ensure non-attribution to an identified or identifiable person. In sum, it is a privacy-enhancing technique where directly identifying data is held separately and securely from processed data to ensure non-attribution. Further reading: https://goo.gl/SAuBm6

Thus this method can ensure that a set of pay data and consent logs can remain within the system and cannot be attributed to any single person and will remain anonymous until paired with additional information stored elsewhere to be able to identify those records.

Once everything apart from the logs, such as payroll data and consent are deleted, the backups for this user will expire after 30 days, thus never being able to retrieve this person's personal information again.

From the staff archive, you can delete staff using a data pseudonymisation deletion process. This means that all the personal data from the profile will be deleted making it totally anonymous and leaving behind the following:

  • Staff id
  • Consent, opt-in log
    • In case it needs to be referenced in the future
  • Notes
  • Job history
  • Payroll history
    • If they have worked before
  • Status change history
  • Contact history

All of the above will have no reference to any personal information of the removed staff. Upon deletion, you will be prompted to download a file to your desktop with the person's name and his staff id. This MUST be kept somewhere away from the database and to be used as required to pull up the above info about that person in the database by searching using the Staff ID.

Please note that you cannot ever retrieve personal information from a staff profile once it has been deleted.

Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article