Skip to main content

Use case

Encrypted Notes for HR and Recruiting Teams

HR teams handle some of the most sensitive personal data in an organisation, usually through the least controlled channel available: email. The compliance exposure is rarely the moment of sending — it is the copy that sits in a mailbox for the next seven years.

Last reviewed Reviewed by Inkrypt Security Team

What HR actually sends

  • Offer details — salary, equity, start dates — often to a personal email address before the candidate has a company account.
  • Payroll and bank details collected during onboarding.
  • Identity documents for right-to-work and background checks.
  • Portal credentials for benefits, payroll and pension systems.
  • Investigation notes and performance documentation with real consequences if they circulate.

Nearly all of it travels by email, and nearly all of it stays in at least two mailboxes indefinitely — the sender's and the recipient's, plus whatever archiving and e-discovery systems sit behind them.

Why the retention is the risk

Data-protection regimes including the GDPR are built around data minimisation and storage limitation: hold personal data only as long as you genuinely need it. An email archive is the direct opposite — it retains everything by default, forever, and its access list grows quietly as people change roles.

An expiring encrypted note inverts that default. The sensitive content lives for a window you choose, then stops existing in retrievable form. The email that remains contains a dead link and no personal data.

This is a risk-reduction measure, not compliance advice

We are not lawyers, and no tool makes an organisation compliant on its own. Whether this is appropriate for a given category of personal data is a decision for your data-protection lead or legal counsel. See our disclaimer.

Practical patterns

  1. Send the sensitive part separately from the friendly part

    The welcome email can be an ordinary email. The salary figure, bank details or document goes in the note. Keep personal data out of the email body and the subject line entirely.
  2. Never put identifying detail in the note name

    The name becomes the URL. onboarding-jane-smith-salary is visible in browser history and link previews before anyone enters a password.
  3. Give a realistic expiry

    Candidates read email on their own schedule. Two to seven days is usually right; an hour will simply generate a support request.
  4. Send the password by phone

    You are almost always already speaking to the person. Reading a four-word password aloud takes ten seconds and puts nothing in writing.
  5. Explain what the link is

    An unexplained link to a site the recipient does not recognise looks exactly like phishing. Say what it is and that a password will follow by phone — otherwise you are training people to click unexplained links.

Where this is the wrong tool

  • Anything requiring a signature. Use a proper e-signature platform with an audit trail.
  • Records you are legally required to retain. An expiring note is the opposite of a retention system.
  • Bulk personal data. Spreadsheets of employee records belong in an access-controlled HR system, not a note.
  • Anything needing proof of receipt. There are no accounts and no identities, so a view count cannot tell you *who* opened it.

A note on candidate experience

Candidates notice this. Being asked to open a password-protected note for a salary figure reads as an organisation that takes personal data seriously — provided it is explained. Unexplained, it reads as friction, or worse, as a phishing attempt. The explanation is not optional politeness; it is the difference between the two interpretations.

Frequently asked questions

Is this GDPR compliant?

No tool makes an organisation compliant by itself. Client-side encryption and expiry support the principles of data minimisation and storage limitation, but compliance depends on your lawful basis, your retention schedule and your overall processing. Consult your data-protection lead.

Can we prove a candidate received the note?

Not reliably. We record a view count so limits can be enforced, but there are no accounts, so a view cannot be attributed to a person. If you need proof of receipt, use a system built for it.

What if a candidate loses the password?

The note cannot be recovered — there is no key on our side to recover it with. Create a new note and share it again. It is a minor inconvenience and a direct consequence of the design.

Can we attach documents?

No. Inkrypt handles text only, so contracts and identity documents need a different channel. Text-based details — salary figures, portal credentials, reference numbers — work well.

Write your first encrypted note

No account, no email address, no download. Type a note, set a password, share the link.

Open the notepad