Can managers access employee salary data under the GDPR?
Privacy & Data Protection

Can managers access employee salary data under the GDPR?

July 01, 2026 · 5 min read

Balancing managerial needs and data protection requirements

In multinational organisations, questions often arise around access to employee remuneration data.

A recurring scenario is the following: a team manager requests access to salary information relating to the members of their team in order to prepare salary reviews, budget forecasts, or remuneration increases. The HR department, however, refuses to share this information, citing data protection constraints.

This situation raises an important issue: how to reconcile managerial responsibilities with GDPR obligations while structuring it in a compliant, controlled and operationally workable manner?

Is remuneration data “sensitive” under the GDPR?

Salary and remuneration data qualify as personal data and are often perceived as particularly sensitive within organisations. However, they do not fall under the “special categories of personal data” within the meaning of Article 9 of the GDPR. As a result, there is no general prohibition on sharing such data internally, provided that GDPR principles are respected.

When access is justified?

A manager may access remuneration data of their team where this is necessary to perform their role. This typically includes:

preparing salary reviews and increases, managing team budgets, ensuring equal pay and equal treatment, monitoring compliance with internal and legal obligations.

The key issue is lawful structuring of access, not access itself.

To be lawful under the GDPR, such access must meet three key requirements.

1. A Clearly Defined Purpose

The processing must serve a specific, explicit, and legitimate purpose.

In practice, this means that access to remuneration data should be strictly linked to tasks such as salary management, compensation review processes, or ensuring fairness across the team.

2. Strict Data Minimisation

Only data that is strictly necessary for the purpose may be shared.

Managers do not need full payroll documentation. Instead, HR can provide:

structured or consolidated tables (fixed salary, variable pay, bonuses), salary ranges or benchmarking grids, aggregated or partially anonymised data, where appropriate.

Information unrelated to the purpose (such as bank details, addresses, or personal circumstances) must not be disclosed.

3. Confidentiality and Access Control

Access to remuneration data must be strictly controlled.

Managers should:

be formally authorised to access such data, be bound by confidentiality obligations, use the data exclusively for the defined purpose.

Appropriate security measures should also be applied, including restricted access and secure communication channels.

Can HR refuse to share salary information?

HR cannot refuse to share remuneration data as a matter of principle where access is necessary for a manager to fulfil their responsibilities.

However, HR plays a key role in ensuring compliance and may legitimately:

define the scope of the data shared, control the format (e.g. summary tables instead of individual payslips), implement access controls and traceability, ensure alignment with internal data protection documentation.

The objective is structured disclosure, not unrestricted access.

Structuring a compliant approach

To avoid uncertainty and reduce risk, organisations should implement clear internal rules governing access to employee data. This is essential in the drafting of the data protection strategy of the company or group).

This can include:

clear definition of access rights by role specifying the permitted purposes (salary reviews, equality analysis, etc.), standardising data formats (tables, ranges, anonymised data where possible), implementing appropriate security measures, documented internal procedures alignment with privacy notices and internal policies

Legal basis and transparency

In most cases, the internal sharing of remuneration data with managers relies on:

the legitimate interest of the employer (effective compensation management, equal pay), and the performance of the employment relationship.

Employees must be clearly informed that their data may be shared with their management for these purposes, in accordance with GDPR transparency requirements.

Alignment With Internal Policies

In many organisations, existing data protection or employee privacy policies already cover:

payroll and remuneration processing, career and performance management, internal recipients of data (including management functions), confidentiality and restricted access obligations.

Where necessary, these policies can be refined to provide greater clarity and transparency.

How we can assist you

Access to employee data sits at the crossroads of legal compliance, internal governance and operational efficiency. This is where structuring makes the difference.

Our firm supports companies and international groups in the design and implementation of robust GDPR-compliant data governance frameworks. We intervene concretely to:

define and structure access rights to employee data design and draft internal policies and procedures aligned with GDPR principles establish controlled data-sharing mechanisms (scope, format, confidentiality) secure sensitive HR data flows in a manner that withstands regulatory scrutiny

Let's talk

Building your next step together.

Tell us about your project, and we will contact you to schedule a meeting and answer your questions.