PRIVACY

Employee onboarding data flow.

This GDPR data flow diagram maps the main systems involved in onboarding a new employee. Personal and tax details enter through an HR portal, then an onboarding service creates the employee record, logs the event and sends limited information to payroll and identity providers. Separating the external providers from HR systems makes the data disclosures visible for a vendor review. The flow can help an HR and privacy team ask where each category of data is stored, who receives it and which systems need access. Add local systems, actual data categories and retention rules before using the drawing in formal documentation. It supports privacy analysis but does not replace employment-law or data-protection advice.

UPDATED 2026-09-24
EXAMPLEEmployee onboarding data flow.
Make this diagram your own.

Open it in the AI editor with a prompt pre-filled — keep what works, change what doesn't.

CASE ANALYSIS

Scenario

Privacy review

Key decisions

  • Sensitive inputs: Personal and tax details enter through the HR portal.
  • External disclosures: Payroll and identity provisioning use separate processors.
  • Auditability: The service records an onboarding event.

When to reuse this

Use this DFD to map employee data before reviewing onboarding vendors and access controls.

FAQ

Frequently asked questions

Why is the identity provider external?01
The example treats account provisioning as a separate service so the boundary crossing is visible.
What belongs in HR records?02
The exact fields depend on the organization; the diagram simply identifies the store receiving the employee record.
Can this include benefits data?03
Yes. Add a benefits provider and label the specific enrollment data sent to it.
Open this example in the editor →

Tweak it with chat, export PNG/SVG, or fork it for your own use case.