0% found this document useful (0 votes)
9 views24 pages

Data Protection Depth

The Data Protection Act 2018 (DPA) replaced the Data Protection Act 1998 and aligns with the General Data Protection Regulation (UK GDPR), requiring all organizations to comply fully without exemptions. The DPA outlines principles for processing personal data, individual rights, and the responsibilities of data controllers, emphasizing transparency and accountability. Organizations must also conduct data protection impact assessments and ensure lawful bases for processing personal data, while individuals have rights to access, rectify, and erase their data.

Uploaded by

laurenclohessy
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
9 views24 pages

Data Protection Depth

The Data Protection Act 2018 (DPA) replaced the Data Protection Act 1998 and aligns with the General Data Protection Regulation (UK GDPR), requiring all organizations to comply fully without exemptions. The DPA outlines principles for processing personal data, individual rights, and the responsibilities of data controllers, emphasizing transparency and accountability. Organizations must also conduct data protection impact assessments and ensure lawful bases for processing personal data, while individuals have rights to access, rectify, and erase their data.

Uploaded by

laurenclohessy
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Published on Croner-i ([Link]

uk)
CIPD HR-inform Pro > Business principles (hri) > Data protection: In-depth

Data protection: In-depth


Summary
On 25 May 2018, the Data Protection Act was replaced by the General Data
Protection Regulation (UK GDPR). There are no exemptions based on a size or
sector — all organisations must comply with its requirements in full or face a hefty
potential fine. On the whole, the rights individuals enjoy under the UK GDPR are the
same as before but with some significant enhancements.

In Practice
Purposes of the Data Protection Act 2018
The Data Protection Act 2018 (DPA) represents the UK’s third generation of data
protection law, aiming to modernise all laws surrounding data protection and
ensure their effectiveness in coming years following the UK’s exit from the
European Union in 2019. The DPA extends to England and Wales, Scotland and
Northern Ireland.

The purpose of the Act is to instruct and inform upon appropriate regulatory actions
for the processing of all information relating to individuals. It has also been
introduced to make provision for a direct marketing code of practice and for
connected purposes.

Within the modern workplace, computers and the internet allow organisations to
store vast amounts of data about individual employees. The DPA sets out how
personal information should be processed to protect individual rights and allows
employees to be aware of, and have some control over, the nature of the data held
about them.

The Act updates and replaces existing provisions highlighted within the existing
Data Protection Act 1998. Although it partly transposes provisions highlighted
within the General Data Protection Regulation (GDPR), it also contains additional,
amended content for adoption within the UK national context.

Therefore, whilst organisations should look to the GDPR for most legal obligations,
the regulation provides limited opportunity to modify how a Member State should
apply the law within their country, such as in areas like academic research,
financial services and child protection. As a result, the GDPR and DPA should be
read in conjunction with one another.

The DPA governs general data covered by the GDPR and all other data.

General Data Protection Regulation

The General Data Protection Regulation (GDPR) provides a framework for data
protection applicable to all EU member states. Enforceable from 25 May 2018, the
UK Government has confirmed that its provisions will continue to apply regardless
of Brexit.

The GDPR applies to controllers and processors of data in the same manner as with
the DPA. As such, personal data that is covered by the DPA is also covered by the
GDPR.

The Principles of the DPA


The DPA sets out seven principles which govern the processing of personal data.
These are to be understood by all those who are involved in the processing and
require accuracy and care. The principles are outlined below.

All personal data must be processed fairly, lawfully and transparently.

Personal data must be obtained only for specified, explicit and lawful purposes
and must not be processed in any manner incompatible with the purposes for
which it was collected.

Personal data must be adequate, relevant and not excessive in relation to the
original purpose for which it was processed.

Personal data must be accurate, kept up to date and every reasonable step
taken to ensure that any inaccurate data is erased or rectified without delay.

Personal data must not be kept for any longer than is necessary for the
purpose it was collected.

Personal data must be processed in a manner that ensures appropriate


security, using technical or organisational measures. These measures should
include protection against unauthorised or unlawful processing and against
accidental loss, destruction or damage.

In addition, the data controller must be able to demonstrate that they take
responsibility for what they do with personal data, ie accountability.

Processing of Personal Data


The DPA covers all forms of personal data, which is defined as information relating
to identified or identifiable living individuals. The information is classed as personal
where the focus is on the individual or where a significant amount of information is
revealed about them.

For the purposes of the DPA, data protected includes:

computerised data

data collected through processing equipment such as CCTV systems

manual records that are part of a relevant filing system.

The term “data processing” relates to all the routine aspects of handling the
information, from the initial collection of the data about the individual through to
the organisation, change, disclosure and its final destruction.

The DPA specifies additional provisions that apply to “special categories of personal
data” alongside data which relates to criminal convictions and offences. Under the
GDPR, employers must restrict the processing of these special categories of data to
what is necessary and adopt an appropriate company policy for this situation. This
data includes:

an individual’s racial or ethnic origin

political opinions
religious or philosophical beliefs

trade union membership

data generated for the purpose of uniquely identifying an individual

data concerning health

data concerning sex life or orientation.

The GDPR and DPA work in conjunction to protect individuals with regard to the
processing of personal data, requiring that:

personal data is processed lawfully and fairly on the basis of the data subject’s
consent

data subject can obtain information about the processing of their personal
data and rectify inaccurate personal data

the Information Commissioner’s Officer (ICO) is given responsibility for


monitoring and enforcing the provisions of the GDPR and DPA.

When carrying out functions under the GDPR and the DPA, the ICO must have
regard to the importance of securing an appropriate level of protection for personal
data, taking account of the interests of data subjects, controllers and other matters
of general public interest.

Lawful Basis for Processing


Personal data can only be processed where there is a lawful basis to do so and
organisations must determine the lawful basis before processing begins. The
appropriate lawful basis needs to be identified in certain pieces of documentation
as a result of a data subject’s right to be informed, eg in privacy notices and
responses to subject access requests.

There are six lawful bases.

Consent

Legitimate interests

Performance of a contract

Legal obligation

Vital interests

Public task.

See our How to guide on determining a lawful basis for processing HR data for
more information on each basis.

Consent
Unless another lawful basis applies, organisations generally use that of consent to
process the data of their employees. However, the rules on obtaining consent are
much more stringent under GDPR than they were under previous rules.

Consent must be freely given, informed and unambiguous. It requires positive opt
in meaning that organisations cannot use default methods including pre-checked
boxes. Employees must be given detailed information on what their consent is
being obtained for; the types of processing activity and the name of the controller.
Blanket consent to cover many different aspects of processing will not be sufficient.

Documents used to obtain consent should be separate from other terms and
conditions in order to ensure data subjects are acutely aware of the consequences
of their actions.

Data subjects must be informed of their right to withdraw their consent at any time
and there must be no repercussions from withdrawal.

You may choose to make use of the template consent forms in our model
documents section.

The ICO recognises that the free giving of consent may be compromised by the
employer-employee relationship in that employers are in a position of power over
individuals and so employees may feel they have no choice but to provide consent
in order to gain or continue employment. Because of this, the ICO recommends
organisations avoid relying on consent as a lawful basis unless there is evidence
that it has been freely given.

See our “How to” guide on determining a lawful basis for processing HR data for
more information on how and when to use consent as a lawful basis.

Individual Rights

Data subjects have the following rights regarding their personal data.

The right to be informed

Individuals should receive certain information about the processing of their data,
such as the categories of data and the purpose of processing. The information must
be concise, transparent and written in clear and plain language. A fee cannot be
charged for providing this.

The right of access

Individuals have the right to access their personal data and other supplementary
information. A fee can only be charged in certain circumstances (see Access to
data).

The right to rectification

Individuals have the right to rectify their personal data if it is inaccurate or


incomplete. A request for rectification must be responded to within one month, or
three months, if the request is complex.

The right to erase or “the right to be forgotten”

Individuals can request removal or deletion of personal data where there is no


compelling reason to keep processing the data. This includes where consent is
withdrawn.

The right to restrict processing

Individuals have the right to restrict or block processing of personal data in specific
circumstances, including where the accuracy of the data is questioned. The
personal data can continue to be stored but no further processing can take place.
The right to data portability

Individuals can obtain their personal data for personal use across different services.
A fee cannot be charged and requests must be responded to without delay and
within one month, or three months, if the request is complex.

The right to object

Individuals have the right to object to the processing of personal data in specific
circumstances, including for processing on the basis of a legitimate interest or
direct marketing.

Rights in relation to automated decision making and profiling

Individuals have rights regarding decisions made without human intervention that
have a significant effect on the individual. This right does not apply to all
automated decisions, including where these are authorised by law.

Data Protection Impact Assessments


Organisations must, in certain circumstances, carry out a data protection impact
assessment to help them identify the most effective way to comply with their data
protection obligations.

An impact assessment must be carried out when an organisation:

uses new technologies

processing is likely to result in a high risk to the rights and freedoms of


individuals. This can include systematic and extensive processing activities;
large scale processing of special categories of data (currently known as
“sensitive” data) or large scale systematic monitoring of public areas.

An impact assessment should include:

a description of the processing operations and the purposes, including, where


applicable, the legitimate interests pursued by the controller

an assessment of the necessity and proportionality of the processing in


relation to the purpose

an assessment of the risks to individuals

the measures in place to address risk, including security and to demonstrate


compliance.

The Right to Be Informed and Privacy Notices

As part of the enhanced accountability provisions, organisations have a general


obligation to implement measures to show that data protection is a primary
concern in processing activities.

A privacy notice can be used as part of a data protection compliance system. A


notice under GDPR needs to be more detailed than under previous provisions; the
ICO recommends that organisations:

include concise, transparent, intelligible and easily accessible information on


how data is processed
write in clear and plain language

provide it free of charge.

When the data is obtained directly from the data subject, the GDPR requires the
following to be included in a privacy notice.

Identity and contact details of controller and the controller’s Data Protection
Officer.

The purpose of the processing.

The legitimate interests of the controller of third party where applicable.

The categories of personal data.

Recipient or categories of recipient of the personal data.

Details of transfers to third country and safeguards.

Retention period or criteria used to determine the retention period.

The existence of each of the data subject’s rights.

The right to withdraw consent at any time.

The right to lodge a complaint with a supervisory authority.

The source of the personal data and whether it came from a publicly
accessible source.

The existence of automated decision making, including profiling and


information about how decisions are made, the significance and the
consequences.

You may choose to make use of the employee privacy notice and the job applicant
privacy notice in our model documents section.

Subject Access Requests

Employees have the right to access their data under data protection laws and this
is known as a subject access request. Under the DPA 2018 the administrative
system changed.

Employees have a right to know whether or not their employer is processing


personal data about them. If the employer is processing data, the employee has a
right to know:

the purposes of the processing

the categories of personal data concerned

the recipients or categories of recipients to whom data has been or will be


disclosed

the period during which personal data will be retained

information on the source of the data

information regarding complaints and disputes: the right to complain to a


supervisory authority, the right to request rectification or erasure of personal
data, to object to processing of data or to restrict that processing

information on any safeguards where personal data is transferred outside the


EEA.

It is a common misconception that employees have a right to see a copy of


documents; this is not the case. They have a right see their personal data.
However, a request is likely to be most easily dealt with by providing copies of
documents. These may need to go through a process of redaction before being
sent due to the identification of another person.

Organisations have a duty to be fair, transparent and facilitate the request.


Information must be provided in a concise, transparent, intelligible and easily
accessible form, using clear and plain language. It is an offence to alter or erase
information with the intention of preventing disclosure, unless the data would have
been altered or erased even if no subject access request would have been made.

Whilst organisations have a duty to facilitate the request, they are not required to
do anything which is unreasonable or disproportionate to the importance of
providing access to the information. This has been made clear in the Data (Use and
Access) Act 2025 which provides that organisations only have to make reasonable
and proportionate searches when someone asks for access to their personal
information.

Organisations are expected, however, to make extensive efforts to find and


retrieve the information requested.

The request must be complied with without delay, and within one month of receipt
at the latest (this can be extended by a further two months where requests are
complex or numerous but this must be explained to the requester).

Organisations are no longer able to charge a standard £10 fee for complying with a
request. A “reasonable fee” can be charged only where a request is “manifestly
unfounded or excessive, particularly if it is repetitive”, or where further copies of
the same information is requested.

Refusal to comply with a request is permitted when the request is “manifestly


unfounded or excessive”. It is the responsibility of the organisation to demonstrate
this and they must carefully evaluate the particular circumstances of each request.

A request may be manifestly unfounded if the following applies.

The individual clearly has no intention to exercise their right of access — for
example, an individual makes a request, but then offers to withdraw it in
return for some form of benefit from the organisation.

The request is malicious in intent and is being used to harass the organisation
with no real purposes other than to cause disruption — for example, the
individual has explicitly stated, in the request itself or in other
communications, that they intend to cause disruption.

The request makes unsubstantiated accusations against the organisation or


specific employees.

The individual is targeting a particular employee against whom they have


some personal grudge.

The individual systematically sends different requests to the organisation as


part of a campaign, such as once a week, with the intention of causing
disruption.
It should never just be assumed that the request is “manifestly unfounded”. All
requests must be considered carefully and in the context in which they are made.
The use of the word “manifestly” demonstrates that there is an obvious or clear
quality to the request being unfounded. A genuine situation, where an individual
wishes to exercise their rights, will not make the request unfounded.

For example, if an individual is of the belief that the information held about them is
inaccurate, despite the fact that a previous investigation conducted by the
organisation found the information to be accurate yet they continue to request its
correction, their latest request may be confused on the grounds that it is
“manifestly unfounded”.

A request may be excessive if the following applies.

It repeats the substance of previous requests and a reasonable interval has


not elapsed.

It overlaps with other requests.

In determining whether a request is “excessive” the particular circumstances


should be taken into account. The request will not necessarily be excessive just
because of the following.

The individual has requested a large amount of information. In this situation,


organisations should consider asking them for more information to help locate
what they want to receive.

The individual wanted to receive a further copy of information they have


requested previously. In this situation, a controller can charge a reasonable
fee for the administrative costs of providing this information again and it is
unlikely that this would be an “excessive” request.

The individual made an overlapping request relating to a completely separate


set of information.

The individual previously submitted requests which have been manifestly


unfounded or excessive.

When determining if a reasonable interval has taken place, organisations should


consider the following.

The nature of the data — this could include whether it is particularly sensitive.

The purposes of the processing — these could include whether the processing
is likely to cause detriment (harm) to the requester if disclosed.

How often the data is altered — if information is unlikely to have changed


between requests, organisations may not need to respond to the same
request twice. However, if this information has been deleted since the last
request the individual should be informed.

If the organisation is able to clearly outline the reason(s) that the request is
“manifestly unfounded or excessive”, the requester must be informed without
undue delay of the refusal to comply, and within one month at the latest. An
organisation’s reasons for refusal must be given, together with information on the
employee’s right to complain to the Information Commissioner or to take legal
proceedings.

A subject access request may be refused if the information requested falls into one
of the exemptions permitted by the legislation.
Confidential references.

Information that the organisation is required to publish by law.

Personal data processed for the purpose of prevention or detection of crime,


the capture or prosecution of offenders and the assessment or collection of
tax.

Management planning or management forecasting.

A record of intentions in negotiations with the employee.

In relation to core regulatory activities.

Legal privilege.

Health and education records.

Social work records.

Other, less common, exemptions also apply.

An employee may complain to the Information Commissioner if they believe their


right of access under the GDPR has been infringed. If the Information Commissioner
is clear that an infringement has taken place, it may serve an assessment notice on
the employer and has the power to enter the employer’s premises, view
documents, see the employer’s data processing procedures and speak to the
workforce. A penalty notice may be served on the employer if an assessment notice
is not complied with. The complaint may be escalated to the Information Tribunal if
the Information Commissioner fails to deal with the complaint adequately.

Courts have the power to make an order for the purposes of securing compliance if
an infringement has occurred.

See our “How to” guide on managing subject access requests for further practical
assistance.

Accessing Medical Reports

Under the Access to Medical Reports Act 1998, an employer may have access to
reports on an employee that has been provided by a medical practitioner if they
are in connection with their employment. In this situation, an employee must give
their consent for the employer to be given such access. Medical information of this
nature will also amount to “sensitive personal data”.

The employee maintains the right to withhold their consent or to wish to see the
report before it goes to the employer. However, the employer can be denied access
to the report if the medical specialist believes it could cause them harm or would
reveal information about another person.

The provisions of the Act do not cover reports from independent doctors who have
been requested to examine the employee, such as an occupational health
specialist.

Intercepting Telecommunications

Under the Telecommunications (Lawful Business Practice) (Interception of


Communications Regulations), employers could potentially be allowed to intercept
private electrical communications if proven to be for “legitimate business persons”.
All data collected as part of such an exercise would still be applicable to the
provisions of the DPA.

Collection and Storage of Information


All organisations should maintain clear policies on the nature and source of the
information that is to be gathered, kept and maintained about them and how it will
be used and stored. Employees should also be made fully aware of their rights
under the DPA, including their right of access. Furthermore, they should be able to
check and update their basic information at least on an annual basis.

Collection of Data for Recruitment

Under the DPA, employers must take special care with all information collected
during the recruitment process. Only data which is relevant to the purpose of
recruitment can be collected, with additional sensitive data only permitted if the
additional condition is satisfied (see Processing of personal data above).

If an employer intends to use social media to garner information about an


applicant, they should take care to comply with data protection principles and the
relevant provisions of the Employment Practices Data Protection Code. This is
outlined below.

Information obtained from social media sites should only be used as part of
the recruitment process when there is a proper reason to do so.

Only information that is relevant to the recruitment decision should be


considered.

The applicant should be informed in advance if their social webpage is to be


looked at as part of the recruitment process.

The application should also be able to make representations in relation to the


content of their social media page.

Data Relating to Criminal Records

The Rehabilitation of Offenders Act 1974 allows for applicants with spent
convictions to not disclose them when applying for jobs, unless the job is exempt
from the provisions of the act. In 2014, the Act was amended, decreasing the
length of time needed for the disclosure of convictions.

As such, employers are not permitted to force applicants to provide this information
provided the conviction is spent, nor to obtain or provide a copy of their criminal
record. However, in situations where the job is exempt from this, such as
undertaking work with children or vulnerable adults, the applicant should be made
fully aware of the vetting process that is to be undertaken.

GDPR rules for sensitive data does not apply to information about criminal
allegations, proceedings or convictions. Separate safeguards for the processing of
this data are set out in Article 10, which outlines that the data must be processed
in an official capacity. The result is that employers are unable to carry out criminal
records checks as a matter of course, unless they are recruiting for a role where
checks are authorised by law.

However, the DPA does authorise the use of criminal records checks by
organisations other than those with vested authority, if the data is necessary for
performing or exercising employment law obligations or rights. To carry out this
type of data processing, the organisation must have a clear policy in place that
explains all procedures for securing compliance with the GDPR and also for the
erasure and retention of the data. Under this provision, an employer could also
request a criminal records check if the employee has provided their consent.

Storage of Data Relating to Sickness

All employees are fully entitled to access their own sickness records, disciplinary or
training records, appraisal or performance review notes, emails or wood-processed
documents, email logs, audit trails, information held in general personnel files and
interview notes. Employers should ensure that this information is readily available
and should note that employees do not have to provide a reason for the request.

In storing data related to the employee’s health, one of the conditions for
processing sensitive personal data must be satisfied. Any information in regard to
sickness or injury should only be disclosed for legal reasons or following an
employee providing their explicit consent to the disclosure.

Storage of Data Relating to Equal Opportunities

Processing of data about the individual’s racial origin may be lawful if it is done for
the purposes for equal opportunity monitoring as between different groups of
people, with the aim of promoting, enabling and maintaining equality in the
workplace. The individual’s consent must be provided and the data must not be
used for anything other than equality monitoring.

Sharing Data for Fraud Purposes


Personal data can be shared with third-parties only when the information relates to
ongoing investigations. Certain bodies, such as the police, have the right to access
information without permission from the individual if it relates to an ongoing crime.

Mergers and Acquisitions

When merging with a separate operation, it is a requirement of TUPE for the new
company to provide employee liability information. However, when undertaking
this process, organisations should practice three areas.

Ensuring that all personal information provided from the new company on its
employees has been obtained with full permission from each individual. If not,
another legal basis for processing the personal data will be needed.

If the due diligence process exposes gaps in consent, it will need to be


reconfirmed where appropriate. This involves writing to each individual and
asking them for permission to hold and process data in the absence of having
any other legal basis.

Confirm with the new company that they have not been subject to any
cyberattacks or information mishandling incidents that could have led to a
data breach.

Worker monitoring

Worker monitoring is any form of monitoring of anyone who carries out work on
behalf of the employer.

It covers systematic monitoring where workers are monitored as a matter of


course. But it also includes occasional monitoring, where an employer monitors as
a short-term response to a specific need.
Monitoring of workers could include the following.

Camera surveillance, including wearable cameras for the purpose of health


and safety.

CCTV.

Technologies for monitoring timekeeping or access control.

Keystroke monitoring to track, capture and log keyboard activity.

Productivity tools which log how workers spend their time.

Tracking internet activity.

Monitoring work vehicles, eg tachographs and vehicle telematics (“black


boxes”).

Data protection legislation does not prohibit the monitoring workers, but it does
place requirements on employers.

If monitoring workers who work remotely, for example, from home, employers
should bear in mind that workers’ expectations of privacy are likely to be higher at
home than in the workplace.

Any monitoring of workers must comply with the Data Protection Act 2018 and the
UK GDPR 2018 because personal data will be processed as a result.

Purpose of monitoring

Employers must be clear about the purpose of why they are processing personal
information obtained from monitoring workers. The data must not be used for any
other reason.

If there is another, less intrusive, means of achieving the purpose for which the
monitoring is in place, then employers should select that option instead.

Employers should not monitor workers “just in case” and employers must not
collect more information than they need to achieve their stated purpose.

Personal data captured via monitoring should not be kept for any longer than is
necessary for a particular purpose.

Preparing to monitor employees

If employers are planning to introduce monitoring, they should seek and document
workers’ views before doing so, unless there is good reason not to do so.

A Data Protection Impact Assessment (DPIA) (see below) must be carried out before
undertaking any processing which is likely to cause high risk to workers’ and other
people’s interests. This can helps to identify and minimise any risks that could arise
from monitoring.

For example, processing biometric data of workers; keystroke monitoring of


workers; or using profiling or special category data to decide on access to services.

If employers have a Data Protection Officer (DPO) they must record their advice on
the DPIA before any final decisions are made.

If, following the DPIA, employers progress with the monitoring, they must provide
information from the DPIA to their workforce subject to monitoring.

However, if the DPIA identifies a high risk that cannot be reduced, employers must
consult with the Information Commissioner’s Office (ICO) before starting to monitor
workers.

Informing workers

Workers have the right to be informed about the processing of their personal data.
Employers must be transparent with them about collecting and processing their
personal data, including when it is obtained through monitoring.

A policy should set out the purpose of the monitoring detailing:

why employers are monitoring them

the personal data that is collected

what employer’s lawful basis is

what employers intend to do with the information collected

how long employers intend to keep it for.

Monitoring must have a lawful basis

To lawfully collect and process personal data received from monitoring workers,
employers must identify a lawful basis from those below:

Consent: this is likely only appropriate if the circumstances mean that workers
have a genuine choice and control over the monitoring.

Contract: where monitoring is necessary for a contract employers have with


the worker. It is likely that this would not be appropriate in the context of
monitoring workers.

Legal obligation: for example, if employers are legally required to use


tachographs in vehicles to record information about driving time, speed, and
distance to ensure the rules on drivers’ working hours are followed.

Vital interests: where processing is necessary to protect someone’s life, for


example, a test pilot is monitored for heart rate, blood pressure, brain activity,
as they may change in the demanding and dangerous job of test flights.

Public task: this may be appropriate if employers are a public authority, or if


the organisation carries out tasks in the public interest; and the employer can
demonstrate that monitoring workers is necessary to perform these tasks set
out in UK law.

Legitimate interests: either the employer’s legitimate interests or those of a


third party unless the risks to the workers’ rights overrides them.

Special category of data

This is personal data which reveals or concerns:

racial or ethnic origin

political opinions
religious or philosophical beliefs

trade union membership

genetic data

biometric data where it is used for identification or authentication purposes

health or disability

sex life

sexual orientation.

If monitoring workers includes any of the above personal data, as well as a lawful
basis, employers must have a special category condition before they start
monitoring.

These are:

explicit consent

the purpose of the monitoring is to comply with employment law, or social


security and social protection law

substantial public interest (with a basis in law).

Ensuring compliance with UK law

Employers are responsible for ensuring that their actions comply with the UK GDPR
and for demonstrating this compliance. This includes when employers collate
personal data via monitoring of workers.

Senior management have overall responsibility for monitoring workers and if there
is a Data Protection Officer (DPO) they must make sure that they are closely
involved in any plans to monitor workers.

Having policies, procedures, and measures in place to demonstrate accountability


will be key.

Accuracy of data

Employers must take all reasonable steps to ensure that the personal data they
obtain through the monitoring of workers is correct and is not misleading as to any
matter of fact.

A computer system, for example, could reset to the wrong time zone, so that it
shows incorrect times of when events took place.

If it is discovered that data is incorrect or misleading, reasonable steps to correct or


erase it as soon as possible must be taken.

Data security

Employers should assess the data security risks of any monitoring and use this to
decide the security measures they need to put in place to protect the personal data
they are processing.

Access to the information should be restricted to only those who need access.
If commercially available monitoring tools are used, or the monitoring
functionalities which are available on communication and collaboration tools,
employers are still responsible for compliance with data protection.

If monitoring activities are outsourced then they could be a “data processor” but
employers, as data controller, are still responsible for compliance with data
protection laws.

Covert monitoring

Covert monitoring means carrying out monitoring in a way which is designed to


ensure workers are unaware that it is taking place.

It is unlikely that this can be justified in most usual circumstances.

But if employers are considering it, there are several factors to be aware of, which
include the following.

A DPIA must be carried out.

It should only be authorised by senior management.

Employers should be satisfied that there are grounds for suspecting criminal
activity or an equivalent, and that informing workers about the monitoring
would prejudice its prevention or detection.

It should be strictly targeted at obtaining evidence in the shortest time


possible, and then stopped once the investigation is complete.

Covert audio or video monitoring should not be used in areas where workers
would reasonably expect to be private, such as toilets or changing rooms.

In most cases, employers should not use covert monitoring to capture


communications that workers would reasonably expect to be private, such as
personal emails.

Biometric data

Biometric data is personal data resulting from specific technical processing relating
to the physical, physiological, or behavioural characteristics, which allow or confirm
the unique identification of that person.

It includes:

fingerprints

iris scanning

retinal analysis

facial recognition templates

voice recognition templates.

The nature of biometric data means that it is more closely identified with a specific
person. The risk of harm, in the event of inaccuracies or a security breach are
therefore greater. A DIPA must be carried out before processing any biometric data.

Biometric data is sometimes used for access control, for example, to certain parts
of a building. It is likely to be hard to justify using biometric data in this scenario
without providing an alternative, such as a swipe card or pin numbers, for those
who wish to opt out.

An example of the ICO’s stance on the monitoring of biometric data is the action
taken against Serco Leisure and other associated community leisure trusts who
have been issued with enforcement notices ordering them to stop using facial
recognition technology and fingerprint scanning to monitor employee attendance.
Serco’s processing of its employees’ biometric data was found to be unlawful after
it failed to show a lawful basis for processing under the GDPR and a separate
condition for processing special category biometric data.

The ICO found that the processing of biometric data was not necessary for the
purpose of fulfilling obligations under employment contracts, such as complying
with the Working Time Regulations 1998 and National Minimum Wage
requirements, as less intrusive methods could be used to monitor attendance.
Serco failed to produce evidence of widespread abuse of alternative ways of
monitoring attendance and to explain why disciplinary action had not been
considered.

Subject access requests and employee monitoring

If a worker who has been subjected to monitoring, including covert monitoring,


makes a subject access request, they could be entitled to a copy of their personal
data obtained through monitoring, unless an exemption applies.

Objections to monitoring

Workers can object to employers collecting and processing their personal


information obtained via monitoring in certain circumstances.

A worker can object where the lawful basis employers are relying on is:

public task (for the performance of a task carried out in the public interest or
for the exercise of official authority vested in employers); or

legitimate interests.

The worker must give specific reasons why they object, based on their individual
situation.

It is possible to refuse to comply with their objection if it is manifestly unfounded,


excessive, or:

it can be demonstrated that there is compelling legitimate interests for


processing, which override the interests, rights, and freedoms of the worker;
or

the processing is for the establishment, exercise, or defence of legal claims.

If an employer is satisfied that they do not need to comply with the request, they
must let the worker know, explain why, and inform them of their right to make a
complaint to the ICO and their right to seek to enforce their rights through a judicial
remedy.

If biometric data is obtained from monitoring workers, and if employers are relying
on public task (for the performance of a task carried out in the public interest);
public task (for the exercise of official authority vested in employers ); or legitimate
interests, as the lawful basis, the worker can object. If relying on consent as the
lawful basis for processing biometric data, the worker can withdraw their consent.
Use of the Data Within Discipline, Grievance and Dismissal
Personal data should only be used during this process when it is compatible with
the purposes for which the data was obtained or proportionate to the seriousness of
the matter under investigation. Records used in the course of these proceedings
must be sufficiently detailed to support any conclusions drawn from them. In
addition, all of these records should be kept secure and must only be available to
staff whose duties require access.

A clear procedure should be in place for handling spent disciplinary warnings,


highlighting if and when they are to be deleted from the record. It is acknowledged
that the data may need to be retained by the organisation for its own protection,
for example in the midst of legal proceedings.

Reporting Breaches

A personal data breach has a wider definition than simply losing personal data. It is
a breach of security leading to the destruction, loss, alteration, unauthorised
disclosure of, or access to, personal data. It may include a hacking attack or human
error eg sending information to the wrong email address.

Reportable breaches must be reported to the relevant supervisory authority without


undue delay and within 72 hours of discovery. Organisations will be permitted to
provide information on the breach in phases where a full investigation is not
possible within that timeframe.

A reportable breach is one which is likely to result in a risk to people’s rights and
freedoms. If this is not a likely consequence, the breach does not need to be
reported.

If there is a high risk to people’s rights and freedoms, the affected individual(s) will
also need to be notified. This may be, for example, where an individual may be
discriminated against, suffer financial loss or detriment to reputation or other social
or economic disadvantage. Where the breach is such that the public need to be
informed, this should be done without delay.

Failure to report can lead to a fine of up to £8.7 million or 2% of the organisation’s


global turnover. As such, the DPA and GDPR are overseen by the Information
Commissioner’s Office, which operates as an independent, supervisory authority
reporting to the UK Parliament. The ICO has powers to:

service “information notes” on organisations, which require them to provide


specified information

submit “assessment notices” to an organisation’s premises and examine


specified documents

serve enforcement notices on organisations were data protection is being


infringed

issue penalty notices to organisations who have failed to comply with an


assessment or enforcement notice.

Where any breach in data storage or security is noted, and the breach is likely to
result in the risk to the rights and freedoms of the individual, the timescale for
reporting the breach to the ICO is 72 hours. Furthermore, the individual must be
notified without undue delay.

An organisation could be liable for up to £17.5 million or 4% of its total annual


turnover in fines if it fails to comply with the provisions of the GDPR. It is therefore
essential that all organisations ensure they are clearly following all the specified
provisions.

Data Protection Officer

A new requirement under the GDPR is that organisations must appoint a Data
Protection Officer (DPO) where certain criteria are met. Whilst all organisations
may choose to have a DPO, it will be a legal requirement in the following
circumstances.

Where the organisation is a public authority or body (except for courts acting
in their judicial capacity).

Where the core activities of the organisation consist of processing operations


which, by virtue of their nature, their scope and/or their purposes, require
regular and systematic monitoring of data subjects on a large scale.

Where the organisation carries out large scale processing of special categories
of data or data relating to criminal convictions and offences.

In order for organisations to determine if they meet the criteria mentioned above,
and therefore have a mandatory requirement to appoint a DPO, they will need to
interpret key terms such as “core activities” and “regular and systematic”.
Similarly, organisations will need to determine if they are responsible for processing
special categories of data and if they could be considered as a public authority or
body.

To assist organisations the following are definitions of the key terms as provided by
both the GDPR and the European advisory body responsible for data protection and
privacy, known as Article 29 Working Party (WP29).

Public authority or body — a public authority or body is considered as one that


is governed by national law. This concept is however not limited to national,
regional and local authorities as under the respective national laws this may
also include a range of other bodies that are governed by public law.

Core activities — these are described as the key operations necessary to


achieve the controllers or processors goals.

Regular and systematic monitoring — regular is defined as: (i) ongoing or


occurring at particular intervals for a particular period, or (ii) recurring or
repeated at fixed times, or (iii) constantly or periodically taking place.

Systematic is defined as: (i) occurring according to a system, or (ii) pre-


arranged, organised or methodical, or (iii) taking place as part of a general
plan for data collection, or (iv) carried out as part of a strategy. Examples of
activities that may constitute regular and systematic monitoring include email
retargeting, data-driven marketing, profiling and scoring for purposes of risk
assessment for detection of money-laundering.

Special categories of data — these consist of personal data which reveal racial
or ethnic origin, political opinions, religious or philosophical beliefs or trade
union membership, and the processing of genetic data, biometric data for the
purpose of uniquely identifying a natural person, data concerning health or
data concerning a natural person’s sex life or sexual orientation.

Organisations that conclude their activities fall outside of the scope for the
appointment of a DPO may still wish to voluntarily appoint a DPO as good practice.
The WP29 encourage all organisations to designate a DPO on a voluntary basis, this
will particularly benefit those who are in doubt of whether a mandatory
appointment should be made in the first place. Appointing a voluntary DPO may be
particularly useful in safeguarding organisations from falling foul of other
obligations under GDPR.

The DPO can be an existing employee (no specific qualifications are required but
the individual should have professional experience and knowledge of data
protection law) and one DPO can act for a group of companies. The role must
report directly to the highest level of management and must be given adequate
resources to carry out the role. They should not be dismissed or penalised for
undertaking the tasks required by the role. The role may also be contracted out.

It will be the role of the DPO to:

inform and advise the organisation and its employees about their obligations
to comply with the GDPR and other data protection laws

monitor compliance with the GDPR and other data protection laws, including
managing internal data protection activities, advise on data protection impact
assessments; train staff and conduct internal audits

be the first point of contact for supervisory authorities and for individuals
whose data is processed (employees, customers etc).

It is important to note that whilst having a DPO in place can facilitate data
compliance, DPOs are not considered personally responsible in the event of non-
compliance with the GDPR. The responsibilities for any breach in GDPR compliance
will always remain with the organisation.

The decision on appointing a DPO should be subject to review on a regular basis,


particularly prior to making any new operational decisions as this may change the
need to appoint a DPO.

Fines

A breach of GDPR carries a maximum fine of £17.5 million or 4% of the


organisation’s global turnover.

The Data Protection Working Party’s guidelines on the application and setting of
administrative fines, adopted on 3 October 2017, sets out the principles for
consistent application of fines for data protection breaches. Specific breaches will
not carry a “price tag”. Instead an assessment will be made on the individual
circumstances of the breach against certain criteria. The following will be assessed.

The nature, gravity and duration of the infringement including the purpose of
the processing, the number of people affected by the breach and the level of
damage to their rights.

The intentional or negligent character of the breach, meaning whether the


controller knew of the breach and acted wilfully, or whether there was no
intention to cause a breach.

Any action taken to mitigate the damage suffered by data subjects.


Organisations should do whatever they can to reduce the consequences of the
breach for those concerned.

The degree of responsibility of the controller or processor taking into account


measures implemented by them, eg has the organisation implemented
measures to follow the principles of design and default?
Relevant previous infringements or whether the data controller is already on
the supervisory authority’s “radar”.

Degree of co-operation with the supervisory authority to remedy the breach.

The type of personal data affected by the breach.

Whether the data controller notified the breach.

The controller’s adherence to codes of practice and approved certification


mechanisms.

Any other aggravating feature of the breach.

The extent to which the data controller notified the supervisory authority of
the breach and its co-operation with that authority subsequent to the breach.

In some cases, organisations may receive a reprimand instead of a fine. This may
be, for example, where the breach does not pose a risk to the rights of data
subjects, eg “a minor infringement” or where the data controller is a natural person
and the imposition of a fine would be a disproportionate burden.

Registration with ICO

Unless exempt, all organisations that process personal data are required to register
with the ICO, for which a fee is payable.

Data Protection Law and Coronavirus Testing

Data protection law when carrying out tests

As employers will process information that relates to an identified or identifiable


individual, they need to ensure compliance with the GDPR and the Data Protection
Act 2018. Any personal data hat relates to health is classed as “special category
data”.

The law does not prevent employers from taking steps to keep both their staff and
public safe. But they still need to be responsible with personal data.

Lawful basis for testing employees

Provided there is a good reason for taking this action, employers are able to
process health data that concerns Covid-19. The lawful basis of “legitimate
interests” is likely to be appropriate but all employers should make their own
assessment for their own company. For more information for determining a lawful
basis for processing HR data, please refer to our how to guide.

As health data has the protected status of “special category data” (see above),
employers must also identify an Article 9 condition for processing it. This condition
covers the majority of what employers need to do in this situation, provided they
are not collecting or sharing any data that is unnecessary.

Ensuring compliance with data protection law

Employers will need to use the accountability principle when processing test data.
In effect, this means they are responsible for GDPR compliance and must be able to
demonstrate their compliance, which can involve additional record keeping
requirements.
One way of demonstrating this accountability is conducting a data protection
impact assessment. This should establish:

activity proposed

data protection risks;

whether the proposed activity is necessary and proportionate

the mitigating actions that can be put in place to counter the risks

a plan or confirmation that mitigation has been effective.

An initial assessment should be regularly reviewed and updated.

Collecting appropriate amounts of data

It is important that employers only collect and retain the minimum amount of
information needed in order to fulfil the purpose. All data collected should be:

enough to fulfil the purpose

has a rational link to that purpose

not be more than needed for that purpose.

For example, employers will only likely require test results, rather than any other
details considering underlying conditions.

It is important to note the date of test results as the health status of individuals
change over time.

Keeping lists of staff who have symptoms, or have been tested as positive

Employers can keep lists of this information, however they need to make sure the
data is necessary and relevant for the stated purpose. Data processing should be
secure and consider any duty of confidentiality owed to their staff.

These lists must not result in any unfair or harmful treatment of employees.
Information on staff who have reported symptoms should not be retained for
purposes that staff would not reasonably expect.

Informing staff of data processing

It is important to be clear open and honest with staff and clearly communicate why
the company wishes to use their personal data. It should also be made clear what
decisions will be made with information on positive test results, or testing for those
with symptoms.

Before any tests are carried out, staff should be informed what personal data is
required, what it will be used for and who it will be shared with. It should also be
made clear how long the data will be kept for. It is advisable to discuss the
collection of this data with employees to provide them the opportunity to bring
forward any concerns they may have.

Disclosing positive test results to third-parties

Staff should be informed of positive test results, however, if possible, employers


should avoid identifying individuals.
Data protection law does not prevent employers from ensuring the health and
safety of its employees and employers should consider routes available to share
data as outlined in the law. It should also be considered that there may be risks to
the wider public by not sharing test information.

Ensuring staff are able to exercise their information rights

In order for staff to exercise their rights, they need to fully understand what
personal data is held by the company and what it is being used for. Employers
should therefore consider if they need to put processes or systems in place.

An example given by the ICO is in relation to the right of access, which is also
known as Subject Access. Employers could consider setting up portals or self-
service systems which allow staff to manage and update their personal data where
appropriate.

If this is not possible, employers should still ensure that basic policies and
procedures are in place to allow employee data to be available when required.

Data protection considerations when staff disclose test results

Employers should have due regard to the security of this data and consider any
duty of confidentiality owed to individuals who voluntarily disclose test results.

Using temperature checks or thermal cameras on site

As taking this action is technically considered using intrusive technologies,


especially for capturing health information, employers must give specific thought
to the purpose and context of its use. All staff monitoring needs to be necessary
and proportionate and it is essential to remain transparent.

It should also be considered whether the same results could still be achieved
through less intrusive needs. If so, the monitoring may not be considered
proportionate.

Legal Reform

The Data Protection and Digital Information (No.2) Bill was presented to parliament
by the Government on 8 March 2023. The Bill has passed its first and second
reading in the House of Commons as well as the Committee stage. It is now at the
Report stage before it will next be debated further by MPs at its third reading. No
date has been set for this and there are many further stages in the parliamentary
process that the Bill needs to pass before it can become law.

The Government says the Bill will save British businesses £4.7 billion over the next
10 years by cutting down pointless paperwork and saving costs under its “new UK
version of GDPR”. Aiming to take advantage of post-Brexit opportunities, the
Government wants to ensure that the new regime is built on the UK’s high
standards for data protection and privacy, and seeks to ensure data adequacy,
while moving away from the “one-size-fits-all” approach of the European Union’s
GDPR. The Government is looking to maintain the UK’s internationally renowned
data protection standards so businesses can continue to trade freely with global
partners, including the EU, but also tailor our data protection regime to the UK’s
needs and customs.

What will the Bill do?

The Government says the improved Bill will:


introduce a simple, clear and business-friendly framework that will not be
difficult or costly to implement — taking the best elements of GDPR and
providing businesses with more flexibility about how they comply with the new
data laws

ensure our new regime maintains data adequacy with the EU, and wider
international confidence in the UK’s comprehensive data protection standards

further reduce the amount of paperwork organisations need to complete to


demonstrate compliance

support even more international trade without creating extra costs for
businesses if they’re already compliant with current data regulation

provide organisations with greater confidence about when they can process
personal data without consent

increase public and business confidence in AI technologies by clarifying the


circumstances when robust safeguards apply to automated decision-making.

The Bill will strengthen the Information Commissioner’s Office (ICO) through reform
via the creation of a statutory board with a chair and chief executive, so it can
remain a world-leading, independent data regulator and better support
organisations to comply with data regulation.

A trust framework

Artificial Intelligence (AI)

It is hoped that the Bill will ensure organisations can use automated decision-
making with more confidence, and that the right safeguards are in place for people
about whom those decisions are taken. This means people will be made aware
when such decisions are made and can challenge and seek human review when
those decisions may be inaccurate or harmful.

The Government has set out new measures to clarify that profiling is subject to the
same set of robust safeguards for automated decision making when a significant
decision is taken about a person with no meaningful human involvement. For
example, if a person is denied a job because an automated decision has been taken
without meaningful human input, they can challenge that decision and request a
human to review the outcome instead.

Data protection issues and resolutions

Some of the biggest data protection issues for HR managers are ensuring that
employees’ personal data is processed lawfully, managing data breaches when
they do happen and responding to subject access requests. If the Bill becomes law,
employers and HR teams will still need to deal with these issues, but it is hoped
that the proposed changes to record-keeping in the Bill, where only organisations
whose processing activities are likely to pose high risks to individual’s rights and
freedoms will need to keep processing records, will make it easier, cheaper and
less time consuming for employers to comply with their data protection obligations.

The Bill is not expected to make it easier for employees to “weaponise” their data
and make demands on employers.

Compliance and penalties


The Bill will increase fines for nuisance calls and texts to be either up to 4% of
global turnover or £17.5 million, whichever is the greater, which will be welcome
news for consumers.

Source URL: [Link]

Copyright © 2026 Croner-i Ltd and/or its affiliates. All rights reserved.

You might also like