Hi,
Okay if that's the case then my recommendation would be to use an Active Directory group to restrict access to HR data and then enable ABE (Access based enumeration) on the share so the only users who will be able to see the HR data folder are users who are a member of the HR Active Directory group. Users who are no in the AD group won't be able to see the folder in the CIFS share and if they somehow knew what the UNC path was and attempted to connect to they will recieve an "access denied" error message in windows explorer.
https://library.netapp.com/ecmdocs/ECMP1196891/html/GUID-F28FF706-D2ED-4D86-93B8-2017C9E43937.html
What version of data ONTAP are you running (7-Mode or clustered data ONTAP)
/matt
If this post resolved your issue, help others by selecting ACCEPT AS SOLUTION or adding a KUDO.