Employee Data & UK GDPR: Don’t Let HR Records Land You a Fine

Employee data is often the most sensitive data a small business holds—sickness records, payroll details, performance notes, disciplinary files—and it’s also the easiest to mishandle during fast hiring, remote work, or vendor changes. If you employ anyone in the UK, UK GDPR applies to your HR records.
The UK’s ICO reported enforcement action totaling over £5.6 million in the year ending March 2024, a reminder that data protection is not just “big-company compliance”—it’s operational risk you can manage with the right HR practices and documentation (ICO Annual Report 2023–24).
Table of Contents
- What UK GDPR Means for Employee Data
- A Step-By-Step UK GDPR HR Compliance Plan
- Handling Employee Rights and DSARs
- When HR Needs a DPIA
- Managing HR Vendors and Processors
- Common UK GDPR Mistakes in HR (And How to Avoid Them)
- Costs, Timelines, and What “Good” Looks Like
- When to Get Legal Help
- Get HR GDPR Compliance Done With AirCounsel
- Frequently Asked Questions
- Recommended
| Takeaway | Explanation |
|---|---|
| UK GDPR applies to employee records | Payroll, benefits, performance, and monitoring data are all regulated personal data. |
| Consent is usually the wrong HR lawful basis | Employment relationships are rarely “freely given,” so rely more on contract, legal obligation, and legitimate interests. |
| Retention is a top enforcement risk | Keeping HR records “just in case” is a common breach; you need documented retention rules and deletion triggers. |
| DSARs need a repeatable workflow | You typically have 1 month to respond, so you need an intake, search plan, and redaction process. |
| High-risk HR processes may require a DPIA | Biometrics, health data programs, and automated decisions often trigger DPIA obligations. |
| The fastest path is a tailored internal policy | A practical workplace data protection policy ties together notices, retention, access, vendors, and training. |
![Infographic: [Insert Short Description Here]](https://supabasekong-ic4gg804g0c0ks0wckkkwgg4.aircounseladmin.com/storage/v1/object/public/blog-images/srfxjl8u.jpg)
What UK GDPR Means for Employee Data
UK GDPR (read with the Data Protection Act 2018) is the UK’s core framework for how you collect, use, store, share, and delete personal data. In HR, your business is usually the controller (you decide the purposes and means), while many HR tools (payroll providers, time tracking apps) are processors (they act on your instructions).
If you get this right, you reduce risk and save time: fewer HR disputes, faster responses to employee data requests, and fewer “fire drills” when something goes wrong.
What Counts as Employee Personal Data
Employee personal data is any information relating to an identified or identifiable employee, worker, or candidate, including:
- Contact info and emergency contacts
- National Insurance number, payroll info, bank details
- Performance reviews, disciplinary notes, grievance files
- Time and attendance records, scheduling data
- Email/chat logs where people are identifiable
- CCTV footage where people are identifiable
- Recruitment materials (CVs, interview notes, references)
Special Category and Criminal Offense Data in HR
Some HR data is more tightly regulated:
- Special category data: health/sickness records, disability accommodations, biometric identifiers, union membership, ethnicity, religion, sexual orientation.
- Criminal offense data: DBS checks, right-to-work checks that reveal criminal history, allegations or disciplinary findings involving criminal conduct.
These categories typically require extra safeguards and a clearly documented legal route for processing. If your HR team is casually storing health details in shared folders or emailing sensitive information widely, that’s a red flag.
For detailed employer guidance on employment records and good retention practices, the ICO’s employer-facing resources are a helpful benchmark (ICO guidance on keeping employment records).
A Step-By-Step UK GDPR HR Compliance Plan
Use this as an operational checklist for a small business HR setup (even if “HR” is you, your office manager, or your finance lead).
Step 1: Map Your HR Data and Access Points
You can’t protect what you can’t see. Start with a simple “where is HR data stored” map:
- Email (Google Workspace/Microsoft 365)
- HRIS/payroll (e.g., payroll bureau, SaaS tools)
- Cloud storage (Drive/Dropbox/SharePoint)
- Paper files (locked cabinet location, key holders)
- Personal devices (phones/laptops used for HR tasks)
- Messaging tools (Slack/Teams/WhatsApp)
Output you want: a list of systems, who has access, and what categories of HR data sit in each.
Step 2: Pick the Right Lawful Basis and Document It
Under UK GDPR, every HR processing activity needs a lawful basis. For special category data you also need a separate special category condition (and extra controls).
| HR Activity | Usually Appropriate Lawful Basis | Why This Works in Practice |
|---|---|---|
| Paying salary, administering benefits | Contract | You can’t employ/pay someone without processing essentials. |
| Tax, PAYE, statutory leave, right-to-work checks | Legal obligation | UK law requires it; document the relevant obligation. |
| Managing performance, basic HR records | Legitimate interests | Often appropriate with a short balancing assessment. |
| Marketing optional perks (non-essential) | Legitimate interests or consent | Use consent only when truly optional and easy to withdraw. |
| Occupational health, sickness management | Special category route needed | Health data needs stricter handling and access limits. |
Practical tip: write this down in a mini register (or your policy). If you’re ever challenged, your documentation is what turns “we try” into “we comply.”
Step 3: Update Your Employee Privacy Notice
Your privacy notice is the “transparency” piece—what you tell employees about how you use their data.
At minimum, cover:
- What data you collect (and what you don’t)
- Purposes (payroll, performance management, compliance, security)
- Lawful bases (and special category handling where relevant)
- Who receives data (payroll provider, benefits broker, accountants)
- International transfers (if tools store data outside the UK)
- Retention periods (or criteria used to set them)
- Employee rights and how to exercise them (including DSARs)
- Contact point for privacy queries
Make it easy to find and re-issue it when your tools or processes change.
Step 4: Set Retention Rules and Deletion Triggers
Retention is where most small businesses drift into risk: “We keep everything forever” is rarely defensible.
Set retention by category and trigger, such as:
- Candidate data: delete after a set period unless you have permission to keep for future roles
- Payroll/tax records: retain for legally required periods
- Disciplinary/performance: retain based on relevance, limitation periods, and internal policy
- Sickness/medical: retain minimally and restrict access tightly
You should also define deletion triggers:
- Employee leaves (start the leaver checklist)
- Probation ends (archive or delete non-essential notes)
- Matter resolves (close and schedule deletion)
Step 5: Lock Down Access and Security
UK GDPR requires “appropriate” security. For HR data, “appropriate” usually includes:
- Role-based access (HR and leadership only, not “whole company”)
- MFA on email, HR systems, and cloud storage
- Device controls (screen locks, encryption where possible)
- A “no personal email” rule for HR documents
- A clean offboarding process (remove access immediately)
Also decide how HR data can be shared internally (for example, managers get what they need, not full files).
Step 6: Train Staff and Prove Accountability
If more than 1 person touches HR data (founder, finance, line managers), train them on:
- What counts as personal and special category data
- What not to write down (e.g., sensitive speculations in notes)
- Where files must live (single source of truth)
- How to escalate a suspected breach or DSAR
Accountability is also about proof: keep a short log of training dates, policy acknowledgments, and key decisions.
For a faster path to “proof,” many small employers choose a tailored internal policy (rather than trying to piece it together across documents). AirCounsel’s Custom Internal Workplace Data Protection Policy is designed for exactly this.
Handling Employee Rights and DSARs
Employees (and candidates) can exercise rights over their personal data, including access, rectification, erasure (in limited contexts), and objection.
The most operationally demanding is usually the DSAR (data subject access request): “Send me all my personal data.”
DSAR Timelines and DUAA 2025 Clarifications
In most cases, you must respond to a DSAR within 1 month, with limited ability to extend (for example, where requests are complex).
The Data (Use and Access) Act 2025 (DUAA) introduced updates and clarifications that affect how organizations handle requests, including aspects of timelines and request handling mechanics. If you’ve not refreshed your DSAR process recently, it’s worth updating now (UK government guidance on DUAA 2025 data protection changes).
A Practical DSAR Workflow for Small Businesses
Use a repeatable workflow so DSARs don’t hijack your week:
| DSAR Step | Owner | Target Timing |
|---|---|---|
| Confirm receipt, identity checks (if needed), clarify scope | HR/Operations | Days 1–3 |
| Identify systems to search (HRIS, email, shared drives, chat) | HR + IT | Days 3–7 |
| Collect data and deduplicate | HR | Days 7–14 |
| Review and redact third-party data and privileged material | HR + solicitor (as needed) | Days 14–21 |
| Deliver response securely and log what was provided | HR | By day 30 |
Key practical points:
- You can limit searches to what is reasonable and proportionate, but you should be able to explain your approach.
- Watch for third-party data (other employees) embedded in emails, Teams/Slack messages, and investigation notes.
- Keep a DSAR log so you can show process and timing.
When HR Needs a DPIA
A Data Protection Impact Assessment (DPIA) is required when processing is likely to result in high risk to individuals. In HR, DPIAs often arise sooner than expected—especially with modern monitoring and automation tools.
Common HR DPIA Triggers
Common triggers include:
- Biometric access control (fingerprint/face ID time clocks)
- Systematic monitoring (keystroke tracking, always-on screenshots, location tracking)
- Large-scale handling of health data (occupational health programs, absence analytics)
- Automated decision-making that significantly affects staff (automated scoring for discipline or termination decisions)
- Combining datasets in new ways (e.g., productivity + health + attendance)
If you’re implementing any of the above, consider pausing rollout until you’ve documented the DPIA and updated your privacy notice and internal policy.
Managing HR Vendors and Processors
Most small businesses use vendors to process HR data (payroll bureaus, pension providers, benefits platforms). UK GDPR requires you to have appropriate contracts and oversight in place.
The DPA Checklist for Payroll and HR Tech
For any processor handling employee data, ensure you have a compliant Data Processing Agreement (DPA) that covers:
- Your documented instructions to the processor
- Confidentiality commitments
- Security measures
- Sub-processor rules (and approvals)
- Breach notification timing and cooperation
- Audit/inspection rights
- Return or deletion at end of services
- International transfer mechanisms (if applicable)
If you’re onboarding a new payroll provider or HR tool, a tailored DPA can prevent painful renegotiations later. AirCounsel can help with a fixed-fee Custom Data Processing Agreement aligned to Article 28 requirements.
Common UK GDPR Mistakes in HR (And How to Avoid Them)
These are the issues that most often create employee complaints, ICO exposure, or costly internal disruption:
- Relying on consent for core HR processing: Use contract/legal obligation/legitimate interests instead; reserve consent for genuinely optional extras.
- Keeping “shadow HR files”: Move HR notes out of inboxes and personal drives into a controlled system.
- Over-sharing sensitive info: Limit who sees health, grievances, and disciplinary details.
- No retention schedule: Define retention by category and automate deletion where possible.
- No DSAR plan: A DSAR should not be the first time you map your HR systems.
- Missing vendor contracts: If a provider processes employee data, you need the right DPA terms.
A well-written workplace policy is often the difference between “we intended to” and “we can prove we did.”
Costs, Timelines, and What “Good” Looks Like
Typical Time Investment for Small Teams
A realistic timeline for a small business starting from scratch:
- Days 1–3: data mapping + access review
- Days 4–7: lawful basis decisions + update privacy notice
- Days 8–14: retention schedule + DSAR workflow + vendor contract check
- Ongoing: training, audits, and updates when tools/processes change
Budgeting for Legal Documents and Policy Drafting
Here’s a simple way to think about cost:
| Approach | Typical Spend | Tradeoffs |
|---|---|---|
| DIY templates + internal effort | £0–£200 | Fast, but often generic and harder to defend if challenged. |
| Targeted solicitor help for one document | From £300–£700 | Stronger fit and clarity; reduces rework and “policy drift.” |
| Full HR data protection policy + supporting docs | From £500+ | Best for repeatability, DSAR readiness, and audit-proofing. |
For many small employers, the highest ROI document is an internal workplace data protection policy because it ties together retention, access controls, DSAR handling, and accountability in one place.
When to Get Legal Help
Consider getting solicitor support if any of the following are true:
- You process health data routinely (sickness, accommodations, occupational health)
- You use monitoring tools, CCTV, biometrics, or automated scoring
- You’ve received a DSAR, grievance, or dispute and expect escalation
- You have multiple HR vendors (payroll, benefits, recruitment, HRIS)
- Your retention practices are unclear (“we keep everything forever”)
- You operate across the UK and EU (cross-border data transfer complexity)
If you want a quick gut-check before investing in full documentation, AirCounsel’s fixed-fee Ask a UK Solicitor a Question can help you validate your lawful basis, DSAR approach, or retention plan.
Get HR GDPR Compliance Done With AirCounsel

If you want HR data protection that’s practical (not theoretical), AirCounsel helps you put the right documents and processes in place quickly—so you can hire, manage, and offboard confidently with clear rules and a defensible paper trail.
Get transparent, fixed-fee support with a Custom Internal Workplace Data Protection Policy, an HR-ready Custom GDPR Employment Agreement Addendum, and a vendor-facing Custom Data Processing Agreement.
Frequently Asked Questions
What lawful basis can employers rely on to process employee personal data under UK GDPR?
Most employers rely on contract (to run employment), legal obligation (tax, statutory requirements), and legitimate interests (day-to-day HR management). Consent is usually not appropriate for core employment processing because it may not be freely given.
How long can we keep different types of employee records, and how do we justify retention periods?
You should set retention by category (payroll, performance, recruitment, health) and document the reason for each period (legal obligation, limitation periods, operational need). Avoid “keep forever,” and set deletion triggers such as leaving dates and case closure.
When should HR run a DPIA, and what triggers one for employee processing?
Run a DPIA when an HR process is likely to create high risk, such as biometrics, systematic monitoring, large-scale health data, or meaningful automated decisions. DPIAs are also smart when introducing new HR tech that changes how data is collected or used.
How do we handle Subject Access Requests from employees, and what has changed under the Data (Use and Access) Act 2025?
Build a repeatable DSAR workflow: confirm scope, search identified systems, review/redact, respond securely, and log actions. DUAA 2025 introduces updates and clarifications affecting request handling and timing mechanics, so your DSAR playbook should be refreshed against the latest government guidance.
Do we need a Data Protection Officer (DPO) as a small business employer?
Often no. A DPO is typically required only in specific cases (for example, large-scale systematic monitoring or large-scale processing of special category data). Many small businesses instead assign a responsible owner (HR/Operations) and document governance in an internal policy.
What should we do if an HR data breach happens (lost laptop, mis-sent email, hacked inbox)?
Contain it, assess risk, document the incident, and decide whether ICO notification is required (often within 72 hours if the risk threshold is met). Having a clear breach policy and communications plan reduces delays and mistakes under pressure.
Recommended
Need Legal Assistance?
Our expert legal team is ready to help you navigate complex legal matters with confidence.