HR Management
Personio
EU-Made Report an error0–5 in half steps. 5 means the rubric's top anchor is met on the evidence.
by Personio SE & Co. KG · www.personio.de
Report an error on this page Is this your product? →
Read this page as one judge. Each weighs the same scores by what they care about.
The panel's verdict
Personio SE & Co. KG of Munich is the DACH incumbent in HR Management, judged on three captured developer API reference pages. The bench scores highest where structure is visible: core HR records and time and absence each scored 4 from all six judges, on a multi-entity model of persons, employments, org units, legal entities, cost centres and salary bands, and on absence types, approvals, certificate uploads and per-employee attendance as documented API objects. Employee data governance is the weakest area at 1-2, with no public information on a data-processing agreement, retention, deletion or audit logging. Judges split on payroll readiness, 1-3 — a single module named Payroll Integrations (Compensations) reads to some as a documented interface and to others as a name on a module list — and on recruiting and onboarding, 2-4, where an evidenced applicant data model meets an unevidenced join path into employment. Sovereignty scored 2-3: a German contracting entity and a.de domain, with no hosting region or subprocessor documented in the captures. Persona-weighted totals range 2.5 to 3.3, and no price appears in the captured pages.
Speaks for it
- Core HR records scored 4 across the bench, on a multi-entity API model of persons, employments, org units, legal entities, cost centres, salary bands and document management.
- Time and absence scored 4 across the bench, with absence types, approvals, certificate uploads and per-employee attendance as documented API objects.
- Absence and attendance periods emit created, updated and deleted events, which judges credited for near-real-time sync.
- Recruiting endpoints are documented with cursor-based pagination, limits up to 200, time and email filters, and a dedicated recruiting read scope.
- The vendor of record is Personio SE & Co. KG of Munich, with the developer API served from a.de domain.
Held against it
- Employee data governance scored 1-2, and no public information appears on a data-processing agreement, retention periods, executable deletion or audit logging.
- Payroll readiness scored 1-3; the only payroll evidence in the captures is a module named Payroll Integrations (Compensations), with no named payroll system or export format appearing.
- No public information appears on effective-dated change history, contract versioning, e-signature or field-level permissions in the personnel file.
- No public information appears on entitlement calculation, carry-over, public-holiday calendars or the German working-time recording duty.
- No public information appears on hosting region, data-centre provider or subprocessors, and no price of any kind appears in the captured pages.
Best for
- You need a structured core HR record — persons, employments, org units, legal entities, cost centres and salary bands — exposed through a documented API.
- You record absences and working time per employee and want approvals and sickness certificates captured as first-class objects with change events.
- Your recruiting priority is pulling jobs, applications and candidate data programmatically, with filters and pagination.
Avoid if
- Your month-end depends on a payroll handoff documented beyond a module name; payroll readiness scored 1-3.
- Your works council must review a signable data-processing agreement, retention rules and audit logs before go-live; employee data governance scored 1-2.
- You rely on custom attributes and tags from the recruiting API; the reference itself notes the Candidates and Applications API does not return them.
- You need webhook events when an absence is approved or a certificate uploaded; notifications are sent on timerange changes only.
The scores
Digital personnel file & data model
Show reasoningHide reasoning
How this is scored
The system of record: employee master data, the digital personnel file, org structure, custom fields, and whether history is kept rather than overwritten.
0 — A contact list with job titles; no document storage, no org structure, no history — changes overwrite what was there.
3 — Employee records with document upload, but a flat structure: no org chart, few or no custom fields, and no dated history of contract or salary changes.
5 — Digital personnel file with structured document types, an org chart, custom fields, and change history on the core employment fields.
8 — Complete record: versioned contract and compensation history with effective dates, document templates with e-signature, org structure supporting multiple entities and cost centres, and granular field-level permissions.
10 — The file is the single source of truth an auditor could work from: full effective-dated history on every field, retention rules per document type, delegated administration per entity, and export that reproduces the record intact.
The People Lead
The developer reference shows a genuinely structured data model — persons and employments as separate objects, org units, legal entities, cost centres, workplaces and salary bands, plus a document management module — which is well past a flat list. But nothing captured shows effective-dated change history on contracts or compensation, custom fields on employee records, or document templates with signature, and it is exactly that history that makes a personnel file true rather than merely current. 2
The Payroll Officer
The captured developer pages treat Persons, Employments, Document Management, Org Units, Legal Entities, Cost Centres and Salary Bands as first-class API objects, so the record has a real org spine rather than being a contact list. But we found no public information on whether contract and salary changes keep effective-dated history — the thing that decides whether a backdated raise reconciles in payroll — nor on document templates, e-signature or field-level permissions. 2
The Works Council Advocate
The API model names Document Management, Persons, Employments, Org Units, Legal Entities, Cost Centres and Salary Bands, so a structured personnel data model clearly exists across multiple entities. But I found no public information on dated change history, contract versioning, e-signature or field-level permissions, and I cannot co-decide on a file whose treatment of history is undocumented. 2
The Data Protection Officer
The documented API shows a real data model — document management, employments, compensations, salary bands, org units, legal entities, cost centres and workplaces — which is more than a flat contact list, and custom attributes are at least implied for recruiting data. But I found no public information on effective-dated history of contract or salary changes, document templates with e-signature, or field-level permissions, so the personnel file cannot be called a system of record for people who cannot decline the processing. 2 3
The IT Integrator
The documented API exposes Persons, Employments, Org Units, Legal Entities, Cost Centers, Workplaces and Salary Bands plus a Document Management module — a structured, multi-entity data model I can actually read programmatically, which is what making the HR system the source of truth needs. But the captured pages are API reference only: we found no public information on document types, effective-dated change history, contract templates, or field-level permissions in the personnel file. That lands between a flat record store and a full digital personnel file. 2
The Skeptic
The API module list shows the bones of a real system of record — Document Management, Persons, Employments, Org Units, Legal Entities, Cost Centres, Salary Bands — which is more than a flat contact list. But the captured pages show nothing on change history, effective dating, contract versioning, e-signature or field-level permissions; I found no public information on any of it, so I credit structure without evidenced history. 2
Payroll handoff
Show reasoningHide reasoning
How this is scored
Whether the month closes cleanly into payroll — DATEV, Lohn und Gehalt, an in-house system or an external tax adviser — and how much of that is automated rather than re-typed.
0 — No payroll path stated at all; whatever leaves the system leaves as a spreadsheet somebody retypes.
3 — Generic CSV export said to be usable for payroll, with no named payroll system, no defined format and no handling of mid-month changes.
5 — A named payroll integration or a documented export format for at least one major system (e.g. DATEV LODAS/Lohn und Gehalt), covering the recurring monthly fields.
8 — Certified or vendor-maintained integration with a named payroll provider, covering variable pay, absences and mid-month joiners and leavers, with a documented pre-payroll check.
10 — Payroll is a first-class part of the product: maintained bidirectional integrations with several named systems, an auditable approval and lock step before transmission, retro-accounting for backdated changes, and the tax adviser given their own access.
The People Lead
A payroll integrations area covering compensations is named in the API surface, so a handoff exists in some form. We found no public information on which payroll systems it connects to, what format the transfer takes, or how mid-month joiners and leavers are handled — for closing the month without retyping, that is barely more than a promise. 2
The Payroll Officer
The only payroll signal is a Payroll Integrations module covering compensations in the API list; we found no public information on which payroll system this feeds, in what format, or how variable pay, absences and mid-month joiners and leavers are handed over. As far as the captured pages show, the payroll path is a name on a module list rather than a documented handover. 2
The Works Council Advocate
The only payroll evidence in the captured material is an API surface listing Payroll Integrations under Compensations. I found no public information on any named payroll system, export format, handling of mid-month joiners and leavers, or a pre-payroll check, so the month-end handoff remains entirely open from what I can inspect. 2
The Data Protection Officer
A payroll integrations API module covering compensations is documented, which is a stated path for pay-relevant data. But no payroll system is named and no export format is defined; I found no public information on DATEV or Lohn und Gehalt handoff, a pre-payroll check, or how mid-month joiners and leavers are handled. 2
The IT Integrator
The API surface lists a Payroll Integrations module covering Compensations, so compensation data can leave the system through a documented interface rather than a retyped spreadsheet. We found no public information in the captured pages on any named payroll system, a defined export format, or handling of mid-month joiners and leavers, so it stays at the level of a stated but unnamed payroll path. 2
The Skeptic
The only payroll statement in the captures is a module in the API list named 'Payroll Integrations (Compensations)' — an object a developer could query, not a maintained connector to a named payroll system. No DATEV or other named system, no export format, no mid-month joiner or leaver handling and no pre-payroll check appears anywhere in what was captured; that is thinner than even a generic export claim. 2
Absence & working-time
Show reasoningHide reasoning
How this is scored
Vacation, sickness and working-time recording — including whether the product meets the German recording duty (BAG 2022, ArbZG) rather than merely offering a timer.
0 — No absence or time handling; both live in a spreadsheet elsewhere.
3 — Vacation requests with an approval step, but entitlement is manual, carry-over is not handled and there is no working-time recording.
5 — Automatic entitlement and carry-over, sickness recording, an absence calendar, and basic working-time capture with a report per employee.
8 — Configurable per country and contract: pro-rata entitlement, public-holiday calendars per location, break and rest-period rules, overtime accounts, and an export the employer can hand to a labour inspection.
10 — Working-time recording built as a legal obligation rather than a feature: tamper-evident records, documented compliance with the ArbZG recording duty, works-council-configurable monitoring limits, and shift or on-call models handled without add-ons.
The People Lead
Absence periods with approvals and certificate uploads are referenced, absence types are their own configurable objects, and attendance periods with projects mean working time is actually captured — that clears a mere request list. What we found no public information on is the part I would chase people for: automatic entitlement, carry-over, public-holiday calendars per location, and the German recording duty. 1 2
The Payroll Officer
Absence periods with types, approvals and certificate uploads are documented alongside attendance periods per employee, so working time is captured rather than merely requested. We found no public information on automatic entitlement or carry-over, public-holiday calendars per location, or any statement on the German working-time recording duty — the first questions a labour inspection would ask me. 1 2
The Works Council Advocate
Absence periods, absence types, attendance periods and employee-created requests are documented with created, updated and deleted events, so this is more than a vacation list and working-time capture exists. But I found no public information on automatic entitlement, carry-over, sickness recording or any statement on the German recording duty — and, the questions I must ask, nothing on tamper-evident records or works-council-configurable monitoring limits. 1 2
The Data Protection Officer
Absence periods with types, approval and certificate-upload activity, and per-employee attendance periods are documented, so requested time off, sickness evidence and working-time capture all exist in the data model. I found no public information on automatic entitlement and carry-over, per-location public-holiday calendars, an export fit for a labour inspection, or any documentation of the German recording duty, and nothing evidences tamper-evident records. 1 2
The IT Integrator
Absence periods, absence types, attendances and projects are first-class API objects with create, update and delete events, and the event notes reference approvals and sickness certificate uploads — so vacation approval, sickness capture and working-time recording exist and can sync to my systems in near-real time. We found no public information on automatic entitlement, carry-over, public-holiday calendars, break rules, or the German working-time recording duty in the captured pages. 1 2
The Skeptic
This is the best-evidenced area: absence periods with types, approvals and certificate uploads, attendance periods for working time, and the vendor positioning itself as the source of truth for absences created by HR or employees. Missing is everything that makes it compliant rather than merely present — no entitlement calculation, no carry-over, no public-holiday or break rules, and nothing on the German working-time recording duty or tamper-evidence of records. 1 2
Recruiting & onboarding
Show reasoningHide reasoning
How this is scored
The join path — vacancy to signed contract to a person who has an account, equipment and a plan on day one.
0 — Neither applicant tracking nor onboarding exists; hiring happens in a shared inbox.
3 — A basic applicant list with statuses, or an onboarding checklist — one of the two, without the handover between them.
5 — Applicant tracking with a careers page, structured stages and rejection handling, plus a checklist-driven onboarding that carries the hired candidate over into an employee record without re-entry.
8 — Multi-posting to named job boards, interview scheduling and scorecards, GDPR-conscious applicant retention and deletion, e-signed contracts, and onboarding that triggers tasks in IT and payroll.
10 — The whole join is one governed flow: approval-gated requisitions with budget, structured and bias-conscious evaluation, automated applicant deletion at the stated deadline, and provisioning driven from the record so day one needs no HR intervention.
The People Lead
Recruiting is evidenced as a real data model — jobs, applications, candidates and categories, with custom attributes and tags on candidates. We found no public information on a careers page, structured stages, rejection handling, e-signed contracts or any onboarding into an employee record, so I can only see half of the join path. 2 3
The Payroll Officer
The recruiting API exposes applications, candidates and jobs with filters, scopes and pagination, so an applicant tracking data model plainly exists. We found no public information on a careers page, structured stages and rejection handling, or any onboarding flow that carries the hired person into an employee record without re-entry. 2 3
The Works Council Advocate
Read endpoints for jobs, candidates and applications show an applicant data layer exists, with pagination and filters, though the pages show no applicant statuses. I found no public information on structured stages, rejection handling, applicant retention or deletion, e-signed contracts, or any onboarding handover into an employee record, so the join flow is unevidenced beyond the applicant list itself. 2 3
The Data Protection Officer
Applications, candidates, jobs and categories are documented as API objects with filters and pagination, so applicant tracking exists at the data-model level. I found no public information on a careers page, structured stages, rejection handling, e-signed contracts or any onboarding handover — and, decisively for me, nothing on applicant retention or deletion that executes at a stated date. 2 3
The IT Integrator
Applications, Candidates and Jobs endpoints are documented with cursor-based pagination, time and email filters, and a scoped recruiting-read permission — the applicant data is genuinely integration-ready, though the reference itself warns that the Candidates and Applications API does not return custom attributes and tags. We found no public information on careers pages, stages, onboarding, contract signing, or anything that provisions an account on day one; the join path past the application record is invisible in the captured pages. 2 3
The Skeptic
The recruiting API exposes candidates, applications, jobs and categories with working pagination and filtering, so applicant tracking exists as a data model. But no careers page, structured stages, rejection handling, scheduling, scorecards or e-signature appears in the captures, and there is not one word about onboarding or the handover into an employee record — the only candid limitation note is that applications return neither custom attributes nor tags. 2 3
Employee data protection & co-determination
Show reasoningHide reasoning
How this is scored
How the product handles the most sensitive personal data a company holds — retention, deletion, role separation, subject rights — and whether it can pass a works council (BetrVG §87) rather than merely a procurement checklist.
0 — No stated retention or deletion handling, no role model beyond admin-or-not, and no DPA offered on the site.
3 — A DPA exists on request and roles are coarse; retention and deletion are described as something the customer arranges themselves.
5 — A signable DPA is published, roles are configurable per module, applicant and employee retention periods are stated, and deletion can be executed rather than only promised.
8 — Field-level access control with an audit log of who read what, configurable retention per data category with automatic deletion, documented subject-rights support, and monitoring or analytics features that can be switched off for co-determination.
10 — Built for the works council to say yes: published processing documentation and subprocessor list, per-entity data separation, tamper-evident audit trail, evaluation and behavioural-analysis features off by default with their scope documented, and a data-protection impact assessment the customer can build on.
The People Lead
The OAuth scopes, down to a dedicated recruiting read permission, show permissioning finer than admin-or-not, but that is interface plumbing. We found no public information on a DPA, retention periods, executable deletion, field-level access or an audit log — nothing here I could bring to a works council conversation. 2 3
The Payroll Officer
The only governance signal is that API access is scoped per module, such as read access for recruiting — fine for tokens, not a role model for the most sensitive data a company holds. We found no public information on retention periods, deletion that can actually be executed, a signable data-processing agreement, audit logging, or anything a works council could review. 2
The Works Council Advocate
This is the criterion my vote turns on, and I found no public information on any of it: no data-processing agreement, no stated retention or deletion, no role separation for employee data, no audit log of who read what, and no indication whether monitoring or analytics features can be switched off. The single signal is scoped API access — a recruiting read-only scope — which is technical permissioning, not co-determination. 2 3
The Data Protection Officer
The only governance signal is scoped, module-level API access with separate read scopes, which is more than admin-or-nothing for the interfaces. I found no public information on a signable data-processing agreement, stated retention periods, deletion that executes, an audit log of who read what, or monitoring features that can be switched off for the works council; that no data-processing agreement appears in the captured pages is a finding I record as such. 2 3
The IT Integrator
The only governance signal in the captured pages is scoped OAuth access — a recruiting-read scope alongside Bearer and JWT authentication — which is least-privilege design at the API layer and I give it credit. We found no public information on a data processing agreement, retention periods, deletion execution, audit logging, or role separation within the product, so there is nothing here a works council could review. 2 3
The Skeptic
On retention, deletion, role separation, audit logging and a data-processing agreement the captured pages say nothing at all — I found no public information on any of it. The only access control evidenced is API-level Bearer or JWT authentication with fine-grained scopes such as a recruiting read permission, which governs developer access, not HR users reading personnel files. 2 3
European sovereignty
panel opinion
Show reasoningHide reasoning
How this is scored
Where the data lives, who the contracting entity is, who the subprocessors are, and whether the answer is documented rather than assumed. Independently sourced by the sovereignty pipeline; scored here as the buyer would weigh it.
0 — US-headquartered vendor, US contracting entity, hosting region unstated or US, subprocessors not named.
3 — EU hosting is offered as an option but the contracting entity is non-EU, or the subprocessor list is incomplete or absent.
5 — EU hosting stated as standard and an EU contracting entity, but the subprocessor chain includes non-EU providers without an explained safeguard.
8 — EU or DACH hosting with a named data-centre provider, an EU contracting entity, the full subprocessor list published, and any non-EU processing named with its legal basis.
10 — Sovereign end to end and evidenced: vendor, contracting entity, hosting and every subprocessor in the EU, certification of the data centres published, and an on-premises or private-cloud option for buyers who need it.
The People Lead
The vendor is recorded as a Munich-based German company, which is a start. But nothing captured documents hosting region, a data-centre provider or a single subprocessor, and no sovereignty attributes are on record, so I would treat where the data lives as undocumented rather than European by assumption. 1 2 3
The Payroll Officer
The vendor is a Munich company, Personio SE & Co. KG, serving its API from a German domain, and there my comfort ends. We found no public information on hosting region, the contracting entity, or a single named subprocessor, so I cannot verify from this material where the employee data behind a payroll handover actually lives. 2
The Works Council Advocate
The vendor and contracting entity are German — Personio SE & Co. KG, Munich — and the API is served from a.de domain, which sits above the US-vendor floor. But I found no public information on hosting region, the data-centre provider, or the subprocessor list, so I cannot verify from public material where employee data is processed or by whom. 2
The Data Protection Officer
The vendor and contracting entity are German — Personio SE & Co. KG, Munich — and the captured documentation sits on German domains. But I found no public information on hosting region, the data-centre provider, or a published subprocessor list, and for data about people who cannot decline the processing, an undocumented subprocessor chain is not something I can accept at face value. 2 3
The IT Integrator
The vendor of record is Personio SE & Co. KG of Munich — an EU contracting entity — and the developer endpoints sit on a.de domain. No sovereignty attributes are on record for this vendor, and we found no public information on hosting region, data-centre provider, or any subprocessor in the captured pages, leaving the subprocessor chain undocumented. 2
The Skeptic
The contracting entity is a German company seated in Munich, which places it above a US-entity floor. But I found no public information on hosting region, data-centre provider or a single named subprocessor in any captured page, and nothing on sovereignty is documented beyond that German address. 1 2 3
Pricing transparency
not rated — the vendor publishes no price
Show reasoningHide reasoning
How this is scored
Whether an HR lead can compute the real annual invoice for their headcount — including the modules they actually need — from public pages alone.
0 — No public prices at all; every tier is a sales conversation.
3 — An entry price per employee exists, but the modules most buyers need are unpriced, or a minimum headcount, setup fee or mandatory onboarding package is not stated publicly.
5 — Per-employee prices are public for the main tiers with the billing period stated, but at least one commonly needed module (payroll, time, recruiting) hides in an unpriced bundle.
8 — Every tier and module priced publicly with per-employee maths, billing period, minimum term and VAT treatment stated; only genuinely custom enterprise work lacks a number.
10 — Complete price computability: a calculator or table that produces the annual invoice for a given headcount and module selection, including setup, minimums and renewal terms.
The People Lead
The captured pages are developer references, and we found no public information on pricing, tiers, billing periods, minimums or setup fees. I cannot compute even a rough annual invoice for four hundred people from this. 1 2 3
The Payroll Officer
Not one of the captured pages carries a price of any kind. We found no public information on per-employee pricing, tiers, billing period, minimum terms or setup fees, so no HR lead could compute an annual invoice from this material. 1 2 3
The Works Council Advocate
No price appears in any captured page — no per-employee figure, no tier, no billing period, no setup fee or minimum headcount. From public material an HR lead cannot compute any part of the annual invoice. 1 2 3
The Data Protection Officer
No price of any kind appears in the captured pages. I found no public information on per-employee pricing, tiers, billing period, minimums or setup fees, so no HR lead could compute even a starting annual invoice from what is published. 1 2 3
The IT Integrator
All three captured pages are developer API reference and none contains a price, a tier, a billing period, a minimum term or a setup fee — we found no public information on pricing at all in what was captured. An HR lead cannot compute any part of an invoice from these pages. 1 2 3
Where this could be wrong
- Evidence ages. The oldest capture behind this page is from 1 Oct 2026. Vendors change pricing and policies without notice; every fact reflects its source as of the capture date shown in the registry.
- AI can misread a source. Extraction and judgement are automated; a citation guarantees traceability, not infallibility. If something here is wrong, say so — no account needed, every report is decided within 5 business days, and accepted corrections are published.
What we left out
A claim that does not survive our checks costs us the claim, not the page. This is what was taken off this one.
- We found no public information on pricing on the pages we read (developer.personio.de/docs/attendance-and-absence-events, developer.personio.de/reference/get_v2-recruiting-jobs, developer.personio.de/reference/get_v2-recruiting-applications). If the vendor publishes it somewhere else, send us the page. Know more? Tell us
- We found no public information on compliance on the pages we read (developer.personio.de/docs/attendance-and-absence-events, developer.personio.de/reference/get_v2-recruiting-jobs, developer.personio.de/reference/get_v2-recruiting-applications). If the vendor publishes it somewhere else, send us the page. Know more? Tell us
- 11 integrations facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
Sources (3)
The pages every claim on this page was read from — each one checked, dated, and kept verifiable.
- 1 Absence & working-time — found from sitemap developer.personio.de Checked 1 Oct 2026 Details →
- 2 Recruiting & onboarding — found from sitemap developer.personio.de Checked 1 Oct 2026 Details →
- 3 Recruiting & onboarding — found from sitemap developer.personio.de Checked 1 Oct 2026 Details →