Workday acts in two distinct roles: as a data controller when collecting your information through its own website and marketing, and as a data processor handling employee data on behalf of your employer. Which role applies determines where you must go to exercise your privacy rights.
This analysis describes what Workday's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
If you are an employee using Workday at work, your employer, not Workday, is typically the controller of your HR data, which means you may need to direct privacy requests to your employer rather than to Workday directly.
Interpretive note: The document was truncated before operative clauses were visible; the controller-processor distinction is inferred from Workday's known business model and the statement's general framing rather than from explicit document language.
This structural distinction affects where employees must go to access, correct, or delete their personal data. Employees whose HR data is processed through Workday may find that Workday is not the right contact for exercising their data rights, as those rights must be addressed through the employer who controls the data.
How other platforms handle this
Where ZipRecruiter processes your Personal Data in the capacity of a service provider (data processor), and you seek access, or want to correct, amend, or delete your Personal Data...we will provide you with the data controller's contact information, so you can contact them directly.
If you choose to reveal any personal information about yourself to other users, you do so at your own risk. We strongly encourage you to use caution in disclosing any personal information online.
When you are asked to provide information, you may decline to do so; but if you choose not to provide information that is necessary to provide some of our Services, you may not be able to use those Services.
"At Workday, we believe privacy is a fundamental right, regardless of where you live. When you connect with Workday, we understand you are trusting us to handle your personal information appropriately. That is why we are committed to transparency about how we collect, use, and share that information.Excerpt from Workday's Privacy Statement
(1) REGULATORY LANDSCAPE: GDPR Articles 4, 24, and 28 establish distinct obligations for controllers and processors.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Ad personalization controls removed. Contact scanning added. Advertiser data partnerships quietly dropped. A timeline of every change.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
If you are an employee using Workday at work, your employer, not Workday, is typically the controller of your HR data, which means you may need to direct privacy requests to your employer rather than to Workday directly.
This structural distinction affects where employees must go to access, correct, or delete their personal data. Employees whose HR data is processed through Workday may find that Workday is not the right contact for exercising their data rights, as those rights must be addressed through the employer who controls the data.
ConductAtlas has identified this type of provision across 289 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Workday.