News & Resources

Beware, Payroll Analytics Requires Data Security: 5 Steps to Achieve Best Practices

BY: Jim Medlock, CPP, and Mark Thornton, CPA, CPP | 06/26/26

When you are developing and using payroll analytics, care must be taken with the data, as it may include personally identifiable information (PII), protected health information (PHI), or organizational confidential information. Data privacy principles require that you limit who has access to the data.

What Is Data Privacy?

Data privacy refers to the rights and obligations of individuals and organizations regarding the collection, use, retention, disclosure, and disposal of personal information. Data privacy is a risk management issue that affects all organizations.

The Generally Accepted Privacy Principles (GAPP), issued by the American Institute of CPAs, helps organizations assess privacy-related risks and to develop sound privacy policies and practices. Compliance with privacy laws also requires payroll professionals to have a general understanding of the scope of these laws and regulations, as well as the requirements each imposes.

Compliance requirements may include the following:

  • Understanding what personal information is covered: Different privacy laws may define personal information differently. Understanding what the law covers in each applicable jurisdiction helps to ensure compliance.
  • Obtaining employee consent: Some privacy laws require that employees provide consent before their personal information can be collected and processed. As part of the onboarding process, every organization must ensure it has obtained employee consent before collecting and processing employee data.
  • Providing transparency: Many privacy laws require organizations to provide employees with transparency regarding how their personal information is being used. Your company’s employees should be adequately informed about how their data is being used and who has access to it.

"How to provide and/or restrict access to data that contains PPP, PHI, or confidential data can be determined by the type and timing of the analysis you are performing."
Data Privacy Best Practices

The first steps in ensuring data privacy are to understand the following:

  • What data is held
  • How data is handled
  • Where data is stored

When documenting data, create an inventory of the data that identifies the required data privacy protection for specific data elements. The inventory must include all PII, PHI, and confidential data.

Collecting or using only the necessary data is key to successful payroll analytics. Analytical processes that acquire more data than necessary increase the risk of inappropriate use of PII, PHI, and confidential data, and can result in analytics that do not provide the necessary answers. When developing data collection plans, the burden on those performing the analysis should be considered.

5 Steps to Data Access Best Practices

To minimize the issues with data access, a best practice is to develop data access policies that do the following:

  • Include the scope
  • Are understandable
  • Are easy to build
  • Can be audited
  • Are efficient
  • Are monitored

To achieve these best practices, many organizations use the following five steps:

1. Make Access Controls Compliant and Easy to Build

Access controls define who can access certain data. When using self-service data access, controls must provide access without violating compliance standards, which means access must be easy to implement.

Developing access controls that are compliant requires understanding and applying the requirements of laws, regulations, company standards, and ethical standards which must be easily understood. The European Union’s (EU) General Data Protection Regulation (GDPR) requires the development of a governance plan that includes access controls.

2. Use Attribute-Based Access Controls Rather Than Role-Based Access Controls

This allows carefully defining access based on the analysis assignments. Grant attribute-based access control, which is based on a combination of the following:

  • The user’s department, job role, and management level
  • The data the user needs to access to perform assigned analytics
  • The context (how timely the analysis is required to be performed and the location and availability of the data required)
  • How the data required for the assigned analytics will be accessed (will it be read to be used as a data input, new data being written from the analysis, edited as the results of the analysis, or deleted as it is not needed in the future)

3. Centralize Data Access and Policy Management With a Data Security Platform

Using a data security platform enables centralized, consistent policies, whether data is stored on-premises or in the cloud. Centralization ensures the segregation of duties within the data security platform. A data security platform can help identify sensitive data (PII, PHI, and other confidential data) and provide centralized reporting.

4. Ensure Data Security Solutions Do Not impact Queries and Other Analytical Tools

The security solution should not be in the data path, as it can cause performance issues during analytical processing. Ensuring the data is available when needed should not be restricted by the security solution.

5. Automate Data Security Solutions

The complexity of data security is difficult to manually manage. Automated data security tools can learn patterns in the data, which may lead to the data being classified as identifiable, classified, or private.

Conceptual illustration of data security as a lock above a computer chip.Review Appropriate Data Access

Those who perform analytics require access to data that is relevant to their assignments. With constant changes in employees and assignments, data access permissions require continuous review and updates to access rights for sensitive data, including PII, PHI, and confidential data.

Many organizations have automated the review and assignment of data access based on the roles of new hires, transfers, and terminations.

Ensure Data Access Security

With complex, structured, semi-structured, and unstructured data gathered using various methods, and data from timekeeping, payroll, and HRIS applications, ensuring adequate security is key to successful data management. Given the complexity of the numerous data types, many organizations are moving their data to the cloud since storing data on premises can be difficult due to data types, security requirements, and advanced analytics being performed.

Data security risks arise from many sources, especially when the data contains PII, PHI, or other confidential information. Eliminating or minimizing the possibility of data threats accessing data remains difficult.

Organizations face the challenge of how to provide and/or restrict access to data that contains PII, PHI, or other confidential data. Traditionally, data access has been granted based on each employee’s role.

Due to constantly changing roles and specific data access requests, managing data access while ensuring appropriate security can be challenging. To minimize the issues with data access, a best practice is to develop data access policies that include the following:

  • The scope
  • Are understandable
  • Are easy to build
  • Can be audited
  • Are efficient
  • Are constantly monitored

Payroll analytics cannot be successfully performed without data controls built around data privacy, access controls, and security.


Jim Medlock, CPP, serves as PayrollOrg’s President and works as a Payroll Compliance Educator with Medlock & Associates. A former Education Advisor for PayrollOrg, he is an active volunteer across numerous committees and groups, including the Ask an Expert Committee, Board of Contributing Writers, Board of Directors, Certification Item Development Task Force (CIDTF), CPO Forum Community, the Federal Issues and State and Local Topics Subcommittees of the Government Relations Task Force (GRTF), National Speakers Bureau, and the Best Practices Subcommittee of the Strategic Payroll Leadership Task Force (SPLTF). He has also been featured on PayrollOrg’s “PayTalk” Podcast®. Medlock received PayrollOrg’s Team Member Legend Award in 2018 and was honored as Payroll Man of the Year in 1991.

Mark Thornton, CPA, CPP, is the Payroll Tax Supervisor at Southern Company. He is a member of PayrollOrg’s Board of Directors and volunteers on PayrollOrg’s Finance and Audit Committee and National Speakers Bureau. He was also a guest on PayrollOrg’s “PayTalk” Podcast® and received PayrollOrg’s Meritorious Service Award in 2022.


PAYTECH July 2026 coverFor more articles like this, read PAYTECH magazine (available in both printed and digital formats), free for PayrollOrg members!

PayrollOrg (PAYO), is the leader in payroll education, publications, and training. This nonprofit association conducts more than 300 payroll training conferences and seminars across the country each year and publishes a complete library of resource texts and newsletters. Representing more than 20,000 members, PAYO is the industry’s highly respected and collective voice in Washington, D.C. Get more information at www.payroll.org.

Not a member of PAYO? Check out the many benefits you get when you join!

25 Ask Payden Button