Data Protection Depth
Data Protection Depth
uk)
CIPD HR-inform Pro > Business principles (hri) > Data protection: In-depth
In Practice
Purposes of the Data Protection Act 2018
The Data Protection Act 2018 (DPA) represents the UK’s third generation of data
protection law, aiming to modernise all laws surrounding data protection and
ensure their effectiveness in coming years following the UK’s exit from the
European Union in 2019. The DPA extends to England and Wales, Scotland and
Northern Ireland.
The purpose of the Act is to instruct and inform upon appropriate regulatory actions
for the processing of all information relating to individuals. It has also been
introduced to make provision for a direct marketing code of practice and for
connected purposes.
Within the modern workplace, computers and the internet allow organisations to
store vast amounts of data about individual employees. The DPA sets out how
personal information should be processed to protect individual rights and allows
employees to be aware of, and have some control over, the nature of the data held
about them.
The Act updates and replaces existing provisions highlighted within the existing
Data Protection Act 1998. Although it partly transposes provisions highlighted
within the General Data Protection Regulation (GDPR), it also contains additional,
amended content for adoption within the UK national context.
Therefore, whilst organisations should look to the GDPR for most legal obligations,
the regulation provides limited opportunity to modify how a Member State should
apply the law within their country, such as in areas like academic research,
financial services and child protection. As a result, the GDPR and DPA should be
read in conjunction with one another.
The DPA governs general data covered by the GDPR and all other data.
The General Data Protection Regulation (GDPR) provides a framework for data
protection applicable to all EU member states. Enforceable from 25 May 2018, the
UK Government has confirmed that its provisions will continue to apply regardless
of Brexit.
The GDPR applies to controllers and processors of data in the same manner as with
the DPA. As such, personal data that is covered by the DPA is also covered by the
GDPR.
Personal data must be obtained only for specified, explicit and lawful purposes
and must not be processed in any manner incompatible with the purposes for
which it was collected.
Personal data must be adequate, relevant and not excessive in relation to the
original purpose for which it was processed.
Personal data must be accurate, kept up to date and every reasonable step
taken to ensure that any inaccurate data is erased or rectified without delay.
Personal data must not be kept for any longer than is necessary for the
purpose it was collected.
In addition, the data controller must be able to demonstrate that they take
responsibility for what they do with personal data, ie accountability.
computerised data
The term “data processing” relates to all the routine aspects of handling the
information, from the initial collection of the data about the individual through to
the organisation, change, disclosure and its final destruction.
The DPA specifies additional provisions that apply to “special categories of personal
data” alongside data which relates to criminal convictions and offences. Under the
GDPR, employers must restrict the processing of these special categories of data to
what is necessary and adopt an appropriate company policy for this situation. This
data includes:
political opinions
religious or philosophical beliefs
The GDPR and DPA work in conjunction to protect individuals with regard to the
processing of personal data, requiring that:
personal data is processed lawfully and fairly on the basis of the data subject’s
consent
data subject can obtain information about the processing of their personal
data and rectify inaccurate personal data
When carrying out functions under the GDPR and the DPA, the ICO must have
regard to the importance of securing an appropriate level of protection for personal
data, taking account of the interests of data subjects, controllers and other matters
of general public interest.
Consent
Legitimate interests
Performance of a contract
Legal obligation
Vital interests
Public task.
See our How to guide on determining a lawful basis for processing HR data for
more information on each basis.
Consent
Unless another lawful basis applies, organisations generally use that of consent to
process the data of their employees. However, the rules on obtaining consent are
much more stringent under GDPR than they were under previous rules.
Consent must be freely given, informed and unambiguous. It requires positive opt
in meaning that organisations cannot use default methods including pre-checked
boxes. Employees must be given detailed information on what their consent is
being obtained for; the types of processing activity and the name of the controller.
Blanket consent to cover many different aspects of processing will not be sufficient.
Documents used to obtain consent should be separate from other terms and
conditions in order to ensure data subjects are acutely aware of the consequences
of their actions.
Data subjects must be informed of their right to withdraw their consent at any time
and there must be no repercussions from withdrawal.
You may choose to make use of the template consent forms in our model
documents section.
The ICO recognises that the free giving of consent may be compromised by the
employer-employee relationship in that employers are in a position of power over
individuals and so employees may feel they have no choice but to provide consent
in order to gain or continue employment. Because of this, the ICO recommends
organisations avoid relying on consent as a lawful basis unless there is evidence
that it has been freely given.
See our “How to” guide on determining a lawful basis for processing HR data for
more information on how and when to use consent as a lawful basis.
Individual Rights
Data subjects have the following rights regarding their personal data.
Individuals should receive certain information about the processing of their data,
such as the categories of data and the purpose of processing. The information must
be concise, transparent and written in clear and plain language. A fee cannot be
charged for providing this.
Individuals have the right to access their personal data and other supplementary
information. A fee can only be charged in certain circumstances (see Access to
data).
Individuals have the right to restrict or block processing of personal data in specific
circumstances, including where the accuracy of the data is questioned. The
personal data can continue to be stored but no further processing can take place.
The right to data portability
Individuals can obtain their personal data for personal use across different services.
A fee cannot be charged and requests must be responded to without delay and
within one month, or three months, if the request is complex.
Individuals have the right to object to the processing of personal data in specific
circumstances, including for processing on the basis of a legitimate interest or
direct marketing.
Individuals have rights regarding decisions made without human intervention that
have a significant effect on the individual. This right does not apply to all
automated decisions, including where these are authorised by law.
When the data is obtained directly from the data subject, the GDPR requires the
following to be included in a privacy notice.
Identity and contact details of controller and the controller’s Data Protection
Officer.
The source of the personal data and whether it came from a publicly
accessible source.
You may choose to make use of the employee privacy notice and the job applicant
privacy notice in our model documents section.
Employees have the right to access their data under data protection laws and this
is known as a subject access request. Under the DPA 2018 the administrative
system changed.
Whilst organisations have a duty to facilitate the request, they are not required to
do anything which is unreasonable or disproportionate to the importance of
providing access to the information. This has been made clear in the Data (Use and
Access) Act 2025 which provides that organisations only have to make reasonable
and proportionate searches when someone asks for access to their personal
information.
The request must be complied with without delay, and within one month of receipt
at the latest (this can be extended by a further two months where requests are
complex or numerous but this must be explained to the requester).
Organisations are no longer able to charge a standard £10 fee for complying with a
request. A “reasonable fee” can be charged only where a request is “manifestly
unfounded or excessive, particularly if it is repetitive”, or where further copies of
the same information is requested.
The individual clearly has no intention to exercise their right of access — for
example, an individual makes a request, but then offers to withdraw it in
return for some form of benefit from the organisation.
The request is malicious in intent and is being used to harass the organisation
with no real purposes other than to cause disruption — for example, the
individual has explicitly stated, in the request itself or in other
communications, that they intend to cause disruption.
For example, if an individual is of the belief that the information held about them is
inaccurate, despite the fact that a previous investigation conducted by the
organisation found the information to be accurate yet they continue to request its
correction, their latest request may be confused on the grounds that it is
“manifestly unfounded”.
The nature of the data — this could include whether it is particularly sensitive.
The purposes of the processing — these could include whether the processing
is likely to cause detriment (harm) to the requester if disclosed.
If the organisation is able to clearly outline the reason(s) that the request is
“manifestly unfounded or excessive”, the requester must be informed without
undue delay of the refusal to comply, and within one month at the latest. An
organisation’s reasons for refusal must be given, together with information on the
employee’s right to complain to the Information Commissioner or to take legal
proceedings.
A subject access request may be refused if the information requested falls into one
of the exemptions permitted by the legislation.
Confidential references.
Legal privilege.
Courts have the power to make an order for the purposes of securing compliance if
an infringement has occurred.
See our “How to” guide on managing subject access requests for further practical
assistance.
Under the Access to Medical Reports Act 1998, an employer may have access to
reports on an employee that has been provided by a medical practitioner if they
are in connection with their employment. In this situation, an employee must give
their consent for the employer to be given such access. Medical information of this
nature will also amount to “sensitive personal data”.
The employee maintains the right to withhold their consent or to wish to see the
report before it goes to the employer. However, the employer can be denied access
to the report if the medical specialist believes it could cause them harm or would
reveal information about another person.
The provisions of the Act do not cover reports from independent doctors who have
been requested to examine the employee, such as an occupational health
specialist.
Intercepting Telecommunications
Under the DPA, employers must take special care with all information collected
during the recruitment process. Only data which is relevant to the purpose of
recruitment can be collected, with additional sensitive data only permitted if the
additional condition is satisfied (see Processing of personal data above).
Information obtained from social media sites should only be used as part of
the recruitment process when there is a proper reason to do so.
The Rehabilitation of Offenders Act 1974 allows for applicants with spent
convictions to not disclose them when applying for jobs, unless the job is exempt
from the provisions of the act. In 2014, the Act was amended, decreasing the
length of time needed for the disclosure of convictions.
As such, employers are not permitted to force applicants to provide this information
provided the conviction is spent, nor to obtain or provide a copy of their criminal
record. However, in situations where the job is exempt from this, such as
undertaking work with children or vulnerable adults, the applicant should be made
fully aware of the vetting process that is to be undertaken.
GDPR rules for sensitive data does not apply to information about criminal
allegations, proceedings or convictions. Separate safeguards for the processing of
this data are set out in Article 10, which outlines that the data must be processed
in an official capacity. The result is that employers are unable to carry out criminal
records checks as a matter of course, unless they are recruiting for a role where
checks are authorised by law.
However, the DPA does authorise the use of criminal records checks by
organisations other than those with vested authority, if the data is necessary for
performing or exercising employment law obligations or rights. To carry out this
type of data processing, the organisation must have a clear policy in place that
explains all procedures for securing compliance with the GDPR and also for the
erasure and retention of the data. Under this provision, an employer could also
request a criminal records check if the employee has provided their consent.
All employees are fully entitled to access their own sickness records, disciplinary or
training records, appraisal or performance review notes, emails or wood-processed
documents, email logs, audit trails, information held in general personnel files and
interview notes. Employers should ensure that this information is readily available
and should note that employees do not have to provide a reason for the request.
In storing data related to the employee’s health, one of the conditions for
processing sensitive personal data must be satisfied. Any information in regard to
sickness or injury should only be disclosed for legal reasons or following an
employee providing their explicit consent to the disclosure.
Processing of data about the individual’s racial origin may be lawful if it is done for
the purposes for equal opportunity monitoring as between different groups of
people, with the aim of promoting, enabling and maintaining equality in the
workplace. The individual’s consent must be provided and the data must not be
used for anything other than equality monitoring.
When merging with a separate operation, it is a requirement of TUPE for the new
company to provide employee liability information. However, when undertaking
this process, organisations should practice three areas.
Ensuring that all personal information provided from the new company on its
employees has been obtained with full permission from each individual. If not,
another legal basis for processing the personal data will be needed.
Confirm with the new company that they have not been subject to any
cyberattacks or information mishandling incidents that could have led to a
data breach.
Worker monitoring
Worker monitoring is any form of monitoring of anyone who carries out work on
behalf of the employer.
CCTV.
Data protection legislation does not prohibit the monitoring workers, but it does
place requirements on employers.
If monitoring workers who work remotely, for example, from home, employers
should bear in mind that workers’ expectations of privacy are likely to be higher at
home than in the workplace.
Any monitoring of workers must comply with the Data Protection Act 2018 and the
UK GDPR 2018 because personal data will be processed as a result.
Purpose of monitoring
Employers must be clear about the purpose of why they are processing personal
information obtained from monitoring workers. The data must not be used for any
other reason.
If there is another, less intrusive, means of achieving the purpose for which the
monitoring is in place, then employers should select that option instead.
Employers should not monitor workers “just in case” and employers must not
collect more information than they need to achieve their stated purpose.
Personal data captured via monitoring should not be kept for any longer than is
necessary for a particular purpose.
If employers are planning to introduce monitoring, they should seek and document
workers’ views before doing so, unless there is good reason not to do so.
A Data Protection Impact Assessment (DPIA) (see below) must be carried out before
undertaking any processing which is likely to cause high risk to workers’ and other
people’s interests. This can helps to identify and minimise any risks that could arise
from monitoring.
If employers have a Data Protection Officer (DPO) they must record their advice on
the DPIA before any final decisions are made.
If, following the DPIA, employers progress with the monitoring, they must provide
information from the DPIA to their workforce subject to monitoring.
However, if the DPIA identifies a high risk that cannot be reduced, employers must
consult with the Information Commissioner’s Office (ICO) before starting to monitor
workers.
Informing workers
Workers have the right to be informed about the processing of their personal data.
Employers must be transparent with them about collecting and processing their
personal data, including when it is obtained through monitoring.
To lawfully collect and process personal data received from monitoring workers,
employers must identify a lawful basis from those below:
Consent: this is likely only appropriate if the circumstances mean that workers
have a genuine choice and control over the monitoring.
political opinions
religious or philosophical beliefs
genetic data
health or disability
sex life
sexual orientation.
If monitoring workers includes any of the above personal data, as well as a lawful
basis, employers must have a special category condition before they start
monitoring.
These are:
explicit consent
Employers are responsible for ensuring that their actions comply with the UK GDPR
and for demonstrating this compliance. This includes when employers collate
personal data via monitoring of workers.
Senior management have overall responsibility for monitoring workers and if there
is a Data Protection Officer (DPO) they must make sure that they are closely
involved in any plans to monitor workers.
Accuracy of data
Employers must take all reasonable steps to ensure that the personal data they
obtain through the monitoring of workers is correct and is not misleading as to any
matter of fact.
A computer system, for example, could reset to the wrong time zone, so that it
shows incorrect times of when events took place.
Data security
Employers should assess the data security risks of any monitoring and use this to
decide the security measures they need to put in place to protect the personal data
they are processing.
Access to the information should be restricted to only those who need access.
If commercially available monitoring tools are used, or the monitoring
functionalities which are available on communication and collaboration tools,
employers are still responsible for compliance with data protection.
If monitoring activities are outsourced then they could be a “data processor” but
employers, as data controller, are still responsible for compliance with data
protection laws.
Covert monitoring
But if employers are considering it, there are several factors to be aware of, which
include the following.
Employers should be satisfied that there are grounds for suspecting criminal
activity or an equivalent, and that informing workers about the monitoring
would prejudice its prevention or detection.
Covert audio or video monitoring should not be used in areas where workers
would reasonably expect to be private, such as toilets or changing rooms.
Biometric data
Biometric data is personal data resulting from specific technical processing relating
to the physical, physiological, or behavioural characteristics, which allow or confirm
the unique identification of that person.
It includes:
fingerprints
iris scanning
retinal analysis
The nature of biometric data means that it is more closely identified with a specific
person. The risk of harm, in the event of inaccuracies or a security breach are
therefore greater. A DIPA must be carried out before processing any biometric data.
Biometric data is sometimes used for access control, for example, to certain parts
of a building. It is likely to be hard to justify using biometric data in this scenario
without providing an alternative, such as a swipe card or pin numbers, for those
who wish to opt out.
An example of the ICO’s stance on the monitoring of biometric data is the action
taken against Serco Leisure and other associated community leisure trusts who
have been issued with enforcement notices ordering them to stop using facial
recognition technology and fingerprint scanning to monitor employee attendance.
Serco’s processing of its employees’ biometric data was found to be unlawful after
it failed to show a lawful basis for processing under the GDPR and a separate
condition for processing special category biometric data.
The ICO found that the processing of biometric data was not necessary for the
purpose of fulfilling obligations under employment contracts, such as complying
with the Working Time Regulations 1998 and National Minimum Wage
requirements, as less intrusive methods could be used to monitor attendance.
Serco failed to produce evidence of widespread abuse of alternative ways of
monitoring attendance and to explain why disciplinary action had not been
considered.
Objections to monitoring
A worker can object where the lawful basis employers are relying on is:
public task (for the performance of a task carried out in the public interest or
for the exercise of official authority vested in employers); or
legitimate interests.
The worker must give specific reasons why they object, based on their individual
situation.
If an employer is satisfied that they do not need to comply with the request, they
must let the worker know, explain why, and inform them of their right to make a
complaint to the ICO and their right to seek to enforce their rights through a judicial
remedy.
If biometric data is obtained from monitoring workers, and if employers are relying
on public task (for the performance of a task carried out in the public interest);
public task (for the exercise of official authority vested in employers ); or legitimate
interests, as the lawful basis, the worker can object. If relying on consent as the
lawful basis for processing biometric data, the worker can withdraw their consent.
Use of the Data Within Discipline, Grievance and Dismissal
Personal data should only be used during this process when it is compatible with
the purposes for which the data was obtained or proportionate to the seriousness of
the matter under investigation. Records used in the course of these proceedings
must be sufficiently detailed to support any conclusions drawn from them. In
addition, all of these records should be kept secure and must only be available to
staff whose duties require access.
Reporting Breaches
A personal data breach has a wider definition than simply losing personal data. It is
a breach of security leading to the destruction, loss, alteration, unauthorised
disclosure of, or access to, personal data. It may include a hacking attack or human
error eg sending information to the wrong email address.
A reportable breach is one which is likely to result in a risk to people’s rights and
freedoms. If this is not a likely consequence, the breach does not need to be
reported.
If there is a high risk to people’s rights and freedoms, the affected individual(s) will
also need to be notified. This may be, for example, where an individual may be
discriminated against, suffer financial loss or detriment to reputation or other social
or economic disadvantage. Where the breach is such that the public need to be
informed, this should be done without delay.
Where any breach in data storage or security is noted, and the breach is likely to
result in the risk to the rights and freedoms of the individual, the timescale for
reporting the breach to the ICO is 72 hours. Furthermore, the individual must be
notified without undue delay.
A new requirement under the GDPR is that organisations must appoint a Data
Protection Officer (DPO) where certain criteria are met. Whilst all organisations
may choose to have a DPO, it will be a legal requirement in the following
circumstances.
Where the organisation is a public authority or body (except for courts acting
in their judicial capacity).
Where the organisation carries out large scale processing of special categories
of data or data relating to criminal convictions and offences.
In order for organisations to determine if they meet the criteria mentioned above,
and therefore have a mandatory requirement to appoint a DPO, they will need to
interpret key terms such as “core activities” and “regular and systematic”.
Similarly, organisations will need to determine if they are responsible for processing
special categories of data and if they could be considered as a public authority or
body.
To assist organisations the following are definitions of the key terms as provided by
both the GDPR and the European advisory body responsible for data protection and
privacy, known as Article 29 Working Party (WP29).
Special categories of data — these consist of personal data which reveal racial
or ethnic origin, political opinions, religious or philosophical beliefs or trade
union membership, and the processing of genetic data, biometric data for the
purpose of uniquely identifying a natural person, data concerning health or
data concerning a natural person’s sex life or sexual orientation.
Organisations that conclude their activities fall outside of the scope for the
appointment of a DPO may still wish to voluntarily appoint a DPO as good practice.
The WP29 encourage all organisations to designate a DPO on a voluntary basis, this
will particularly benefit those who are in doubt of whether a mandatory
appointment should be made in the first place. Appointing a voluntary DPO may be
particularly useful in safeguarding organisations from falling foul of other
obligations under GDPR.
The DPO can be an existing employee (no specific qualifications are required but
the individual should have professional experience and knowledge of data
protection law) and one DPO can act for a group of companies. The role must
report directly to the highest level of management and must be given adequate
resources to carry out the role. They should not be dismissed or penalised for
undertaking the tasks required by the role. The role may also be contracted out.
inform and advise the organisation and its employees about their obligations
to comply with the GDPR and other data protection laws
monitor compliance with the GDPR and other data protection laws, including
managing internal data protection activities, advise on data protection impact
assessments; train staff and conduct internal audits
be the first point of contact for supervisory authorities and for individuals
whose data is processed (employees, customers etc).
It is important to note that whilst having a DPO in place can facilitate data
compliance, DPOs are not considered personally responsible in the event of non-
compliance with the GDPR. The responsibilities for any breach in GDPR compliance
will always remain with the organisation.
Fines
The Data Protection Working Party’s guidelines on the application and setting of
administrative fines, adopted on 3 October 2017, sets out the principles for
consistent application of fines for data protection breaches. Specific breaches will
not carry a “price tag”. Instead an assessment will be made on the individual
circumstances of the breach against certain criteria. The following will be assessed.
The nature, gravity and duration of the infringement including the purpose of
the processing, the number of people affected by the breach and the level of
damage to their rights.
The extent to which the data controller notified the supervisory authority of
the breach and its co-operation with that authority subsequent to the breach.
In some cases, organisations may receive a reprimand instead of a fine. This may
be, for example, where the breach does not pose a risk to the rights of data
subjects, eg “a minor infringement” or where the data controller is a natural person
and the imposition of a fine would be a disproportionate burden.
Unless exempt, all organisations that process personal data are required to register
with the ICO, for which a fee is payable.
The law does not prevent employers from taking steps to keep both their staff and
public safe. But they still need to be responsible with personal data.
Provided there is a good reason for taking this action, employers are able to
process health data that concerns Covid-19. The lawful basis of “legitimate
interests” is likely to be appropriate but all employers should make their own
assessment for their own company. For more information for determining a lawful
basis for processing HR data, please refer to our how to guide.
As health data has the protected status of “special category data” (see above),
employers must also identify an Article 9 condition for processing it. This condition
covers the majority of what employers need to do in this situation, provided they
are not collecting or sharing any data that is unnecessary.
Employers will need to use the accountability principle when processing test data.
In effect, this means they are responsible for GDPR compliance and must be able to
demonstrate their compliance, which can involve additional record keeping
requirements.
One way of demonstrating this accountability is conducting a data protection
impact assessment. This should establish:
activity proposed
the mitigating actions that can be put in place to counter the risks
It is important that employers only collect and retain the minimum amount of
information needed in order to fulfil the purpose. All data collected should be:
For example, employers will only likely require test results, rather than any other
details considering underlying conditions.
It is important to note the date of test results as the health status of individuals
change over time.
Keeping lists of staff who have symptoms, or have been tested as positive
Employers can keep lists of this information, however they need to make sure the
data is necessary and relevant for the stated purpose. Data processing should be
secure and consider any duty of confidentiality owed to their staff.
These lists must not result in any unfair or harmful treatment of employees.
Information on staff who have reported symptoms should not be retained for
purposes that staff would not reasonably expect.
It is important to be clear open and honest with staff and clearly communicate why
the company wishes to use their personal data. It should also be made clear what
decisions will be made with information on positive test results, or testing for those
with symptoms.
Before any tests are carried out, staff should be informed what personal data is
required, what it will be used for and who it will be shared with. It should also be
made clear how long the data will be kept for. It is advisable to discuss the
collection of this data with employees to provide them the opportunity to bring
forward any concerns they may have.
In order for staff to exercise their rights, they need to fully understand what
personal data is held by the company and what it is being used for. Employers
should therefore consider if they need to put processes or systems in place.
An example given by the ICO is in relation to the right of access, which is also
known as Subject Access. Employers could consider setting up portals or self-
service systems which allow staff to manage and update their personal data where
appropriate.
If this is not possible, employers should still ensure that basic policies and
procedures are in place to allow employee data to be available when required.
Employers should have due regard to the security of this data and consider any
duty of confidentiality owed to individuals who voluntarily disclose test results.
It should also be considered whether the same results could still be achieved
through less intrusive needs. If so, the monitoring may not be considered
proportionate.
Legal Reform
The Data Protection and Digital Information (No.2) Bill was presented to parliament
by the Government on 8 March 2023. The Bill has passed its first and second
reading in the House of Commons as well as the Committee stage. It is now at the
Report stage before it will next be debated further by MPs at its third reading. No
date has been set for this and there are many further stages in the parliamentary
process that the Bill needs to pass before it can become law.
The Government says the Bill will save British businesses £4.7 billion over the next
10 years by cutting down pointless paperwork and saving costs under its “new UK
version of GDPR”. Aiming to take advantage of post-Brexit opportunities, the
Government wants to ensure that the new regime is built on the UK’s high
standards for data protection and privacy, and seeks to ensure data adequacy,
while moving away from the “one-size-fits-all” approach of the European Union’s
GDPR. The Government is looking to maintain the UK’s internationally renowned
data protection standards so businesses can continue to trade freely with global
partners, including the EU, but also tailor our data protection regime to the UK’s
needs and customs.
ensure our new regime maintains data adequacy with the EU, and wider
international confidence in the UK’s comprehensive data protection standards
support even more international trade without creating extra costs for
businesses if they’re already compliant with current data regulation
provide organisations with greater confidence about when they can process
personal data without consent
The Bill will strengthen the Information Commissioner’s Office (ICO) through reform
via the creation of a statutory board with a chair and chief executive, so it can
remain a world-leading, independent data regulator and better support
organisations to comply with data regulation.
A trust framework
It is hoped that the Bill will ensure organisations can use automated decision-
making with more confidence, and that the right safeguards are in place for people
about whom those decisions are taken. This means people will be made aware
when such decisions are made and can challenge and seek human review when
those decisions may be inaccurate or harmful.
The Government has set out new measures to clarify that profiling is subject to the
same set of robust safeguards for automated decision making when a significant
decision is taken about a person with no meaningful human involvement. For
example, if a person is denied a job because an automated decision has been taken
without meaningful human input, they can challenge that decision and request a
human to review the outcome instead.
Some of the biggest data protection issues for HR managers are ensuring that
employees’ personal data is processed lawfully, managing data breaches when
they do happen and responding to subject access requests. If the Bill becomes law,
employers and HR teams will still need to deal with these issues, but it is hoped
that the proposed changes to record-keeping in the Bill, where only organisations
whose processing activities are likely to pose high risks to individual’s rights and
freedoms will need to keep processing records, will make it easier, cheaper and
less time consuming for employers to comply with their data protection obligations.
The Bill is not expected to make it easier for employees to “weaponise” their data
and make demands on employers.
Copyright © 2026 Croner-i Ltd and/or its affiliates. All rights reserved.