← All Blog articles

HR Departments And Preserving Employee Documents

HR departments can preserve employee documents by combining a sound retention process (where files are stored, who can access them, how long they are kept) with a way to show later that a file hasn't changed.

How HR Departments Can Preserve Employee Documents With Verifiable Timestamps?

HR departments can preserve employee documents by combining a sound retention process (where files are stored, who can access them, how long they are kept) with a way to show later that a file hasn't changed. A cryptographic hash anchored to a blockchain gives you that second part. It records that a file with an exact digital fingerprint existed at a given time, without storing the document or any employee data on the chain.

That distinction matters more than it sounds. Most of the work in HR record-keeping is about keeping things. Disputes, audits and tribunals often turn on something different: can you show this is the same document as it was then?

Keeping a document and proving it is unchanged are different problems

A personnel file sitting in an HRIS or a shared drive is retained. It is not necessarily verifiable. Anyone with edit rights can replace a PDF, and file metadata such as "last modified" can be altered or lost during a migration. If an employee says a warning letter was never issued in that form, or that a contract clause was added later, your word and your system logs are the usual answer. Logs are useful, but they sit inside systems you control, so a skeptical third party has little reason to treat them as independent.

An independent timestamp doesn't replace your records. It adds a layer that a third party can check without trusting your systems.

Which HR documents are worth timestamping?

Not everything in a personnel file needs this. The documents where "was this changed?" is most likely to come up are:

* signed employment contracts and amendments

* disciplinary notices and written warnings

* performance review records and improvement plans

* policy acknowledgments (handbook, code of conduct, data protection policies)

* termination and settlement paperwork

* training and certification records

* investigation reports and meeting minutes

For routine documents, your normal retention process is probably enough. Timestamping earns its keep on documents where a dispute is plausible.

How a timestamp works in this context?

The mechanism has four steps.

1- A hash function (SHA-256) processes the file and produces a fixed-length fingerprint. Change a single character, or even re-save a PDF in a different tool, and the fingerprint changes completely.

2- That fingerprint, not the document, is written to a blockchain.

3- The blockchain records when the entry was made, and that record can be checked by anyone.

4- Later, you hash the file again. If the result matches the recorded fingerprint, the file is identical to the one that existed at that time. If it doesn't match, something changed.

With Certelo, the hash is calculated locally in the browser. The employee document stays on the device and is not uploaded just to create the record. The hash is anchored on the Electra Protocol blockchain.

For a fuller explanation of the underlying process, see Certelo's guide to how blockchain timestamping works.

The privacy question HR will ask first

The immediate objection is reasonable: employee records are personal data, and blockchains are permanent. Isn't this a data protection problem?

The answer depends on what is written to the chain. In a hash-only model, the chain holds a 64-character fingerprint, not the contract, not the name, not the salary. Nobody can reconstruct a document from its hash.

Two cautions are worth stating honestly.

First, a hash of a highly predictable document can in theory be guessed. If someone can enumerate plausible versions of a document (a standard template with only a name and date filled in), they could hash their guesses and compare. For templated HR paperwork, talk to your data protection officer about whether to treat the hash as personal data, and consider how the files are prepared before hashing.

Second, the GDPR gives people rights such as erasure, and a blockchain entry cannot be deleted. Whether a hash alone falls within those rights is a legal question that depends on context and jurisdiction. This article cannot settle it. What the hash-only design does is keep the personal data itself off the immutable layer, so you can still delete or restrict the underlying file under your own retention rules. GDPR's storage limitation and data minimisation principles still apply to the documents you keep.

A practical workflow

Here is a hypothetical example, not a real customer case.

A company issues a written warning to an employee. After the document is finalized and signed, HR does the following:

1- Saves the final signed PDF in the personnel file as normal.

2- Creates a Certelo record from that exact file, which generates the SHA-256 hash locally.

3- Keeps the Certelo certificate or reference alongside the file, noting the date.

4- Records in the HR system that the document was timestamped.

Eighteen months later, the employee disputes the content. HR retrieves the stored PDF, hashes it again and checks it against the recorded fingerprint. A match shows the file is byte-for-byte the same as the one that existed when the record was created. It does not show the warning was fair, that it was delivered, or who wrote it.

The step people most often get wrong is timing. Timestamp the final version. A record of a draft proves only that the draft existed.

What this does not prove

It's easy to oversell this, so here are the limits.

It doesn't prove authorship:

A timestamp shows a file existed, not who made it.

It doesn't prove content is true or the document is valid:

An inaccurate letter can be timestamped as easily as an accurate one.

It doesn't replace signatures:

Whether a contract was properly signed and is enforceable is a separate matter.

It can't help with a file you no longer have:

The original must be preserved exactly. Converting, compressing or re-saving it changes the hash. Certelo verifies a fingerprint; it is not a storage system.

Legal weight varies:

How a court or tribunal treats a blockchain timestamp depends on the jurisdiction and the case. It is supporting evidence, and a lawyer should advise on how it fits your situation.

Retention rules still come first

A timestamp does nothing for you if you've deleted a record you were required to keep, or kept one you should have deleted. Retention periods vary by country, record type and sometimes by industry. In the US, for example, I-9 employment eligibility forms and certain payroll records have specific federal retention periods, and the EEOC has its own rules for personnel records. In the EU, national employment law and the GDPR both apply. Check your own jurisdiction's requirements, or ask counsel, before setting a schedule.

Build the schedule first, decide which documents need independent verification, and then add timestamping on top.

Verifying a record later

To check a document, hash the stored file again and compare the result with the recorded fingerprint. With Certelo you can do this with the original file, the hash or the certificate information. A mismatch means the file is not the one that was recorded. It doesn't tell you what changed, so keep prior versions where you can.

Some Questions

How long should HR keep employee documents?

It depends on the document type and the jurisdiction. There is no universal period. Use your local employment, tax and data protection rules, and set a retention schedule per record type.

Does Certelo upload employee documents?

No. The SHA-256 hash is calculated locally and the original file does not need to be uploaded to create the record.

Is putting employee data on a blockchain GDPR-compliant?

Documents themselves should not go on a blockchain. A hash-only approach keeps the data off-chain, but whether a given hash counts as personal data, and what that means for your obligations, is a question for your data protection officer or counsel.

Can a timestamp prove an HR document is authentic?

It can show the file existed in that exact form at or before the recorded time. It cannot show who wrote it or that its contents are accurate.

What happens if someone edits the file after it was timestamped?

The new file will produce a different hash, so it will not match the recorded fingerprint.

Do I need to timestamp every document in a personnel file?

Usually not. Focus on documents likely to be disputed, such as contracts, warnings, policy acknowledgments and settlement paperwork.

Does this replace our HRIS?

No. It sits alongside it. Your HR system stores and manages records; the timestamp adds independent evidence about specific files.

Written by Arthur