This article explains how Personio protects your data and where to find security and compliance documentation. Personio is committed to maintaining the highest standards of security. As a SaaS solution, we continuously update our product and services to address any vulnerabilities we identify.
You can find comprehensive security information and real-time system updates in our Trust Center and on our Status Page. We also highlight major new features launched on our Product Updates page, which you can access in Personio under Support > What's new.
Personio Trust Center
Personio publishes all security and compliance documentation in the Personio Trust Center.
How to access the Trust Center
- Go to trust.personio.com and click Request Access.
- Fill out your details and submit your request.
- Once you receive access, follow the instructions, and sign the NDA.
- Start your review.
What's in the Trust Center
The Trust Center contains all legal, security, and compliance documentation for Personio, including:
- Security certifications and audit reports.
- GDPR compliance audit report.
- Data Processing Agreement (DPA).
- Technical and Organizational Measures (TOM).
- Data Protection Officer (DPO) information.
- Subprocessors list.
- Infrastructure, data storage, and security information (including encryption, hosting, backups, and access controls).
- Security and data protection policies.
- GDPR compliance templates (including Data Protection Impact Assessment (DPIA) and list of processing activities).
- AI security, training data and bias, governance, and employee AI usage information.
The Personio General Terms and Conditions (GTC) and privacy policy are not part of the Trust Center. For your contract terms, including notice periods and cancellation information, see the GTC. For information on how Personio handles personal data, see the privacy policy.
Personio settings for data protection
Personio provides a set of product controls to help you meet your data protection obligations. We recommend reviewing and configuring these settings for your organization.
Secure your Personio account
Personio creates new customer instances with industry best practices in mind. You can take additional steps to further secure your account:
Security and authentication
- Overview of the Security & Authentication area
- Enable single sign-on (SSO) authentication
- Enable two-factor authentication (2FA)
Managing roles and permissions
- Overview of employee roles and permissions
- Define employee roles with the least privilege access principles
- Overview of Workforce Planning
Logging / Audit trail
Data export / deletion / retention in Personio
- Export company data
- Create and manage data retention policies
- Manage data retention policies for documents
- Manage data retention in Recruiting
Restrict Personio Support access to your account
In compliance with GDPR, Personio employees cannot access your account by default. When access is necessary — for example, to support account setup or resolve service requests — Personio limits access to a small number of teams on an ad-hoc basis. Personio logs all access.
Account Owners can grant Personio Support access to allow our team to log in to your account and troubleshoot directly. Account Owners can revoke access at any time.
Additional security steps you can take
You can take additional steps to further secure your account:
- Define employee roles with the least privilege access principles.
- Enable single sign-on (SSO) authentication.
- Enable two-factor authentication (2FA).
- Set up regular password changes for your employees.
- Use the security token feature, which alerts users to unusual session activities. Personio turns on this feature by default.
Manage email notifications
You can control whether Personio sends system email notifications to users in your account. When enabled, users can choose which notifications to receive. If you turn off this option, Personio doesn't send system email notifications to any user.
Opt in or out of subcontractors
You can opt in or out of specific subcontractors (also referred to as subprocessors in Personio) in the Data Protection tab. To access the Data Protection tab, follow these steps:
- Go to Settings.
- In the Data governance section, click Data protection.
Opting out turns off the associated feature in your account.
Data retention management for documents
If your organization stores documents in Personio, you can set rules for when you must review documents for deletion. These policies help you manage sensitive HR data and support compliance with GDPR and other requirements. To access your data retention policies, follow these steps:
- Go to Settings.
- In the Data Governance section, click Data retention.
Find out more about data retention policies.
More information
- For questions about how Personio handles data privacy across its AI features, see the frequently asked questions about AI data privacy and security.