Knowledge Hub
for Growth


Data protection in HR: key risks and priorities for employers

For HR leaders, people directors, and in-house legal teams, data protection is a core part of managing workforce risk. From job applications and payroll details to sickness records and exit interviews, your HR team handles personal data throughout the employee lifecycle. Some of that information may be special category data or criminal offence data, which are subject to extra rules under the UK General Data Protection Regulation and the Data Protection Act 2018 as amended by the Data (Use and Access) Act 2025.

The day-to-day decisions around data use can feel routine. They rarely are. How workforce information is collected, accessed, shared, monitored, transferred, and eventually deleted can expose your business to staff complaints, regulatory scrutiny, legal claims, and reputational damage. Good data governance also makes HR processes easier to manage, particularly when the business is growing or introducing new technology

Our data protection solicitors can help you identify your priorities, respond to difficult compliance issues, and build a practical framework for handling workforce data in line with your legal responsibilities.

This guide introduces high-level examples of some key HR priorities and legal and best practice guidance for handling these issues, focusing on HR teams that already have existing data protection compliance measures in place. It’s intended for employers acting as data controllers – meaning those businesses that determine the purposes and means of processing (i.e. control) personal data.   

What should HR leaders review first?

Start by working out what staff data you hold and where that information sits, why you use it and how long you keep it, who can access it, which external service providers and other third parties receive it, where your working practices have changed since your policies and privacy notices were last reviewed and where you might have compliance gaps. This will help you identify which gaps you need to fill.

This approach gives HR, legal, and IT a practical basis for prioritising data protection work rather than trying to fix everything at once. Immediate attention may be needed where the business has significantly changed how it uses staff data, is introducing artificial intelligence, monitoring technology or biometric systems, handling significant amounts of health information, changing HR platforms or responding to an employee complaint or data subject access request.

The aim isn’t to produce paperwork for its own sake. It is to understand where something could go wrong in the handling of personal data, who needs to be involved, what controls to implement, and what measures to take to protect personal data and demonstrate your compliance posture so you can defend your approach if challenged.

Your legal responsibilities when handling staff data

Employers must be able to demonstrate that their handling of staff data complies with UK data protection law. It isn’t enough to assume that familiar HR processes are compliant because they have been used for several years.

Your organisation will usually be the controller for its core HR activities because it decides why and how staff data is used. However, your role must still be assessed by looking at how you handle data in practice.

Other businesses you work with might also play a role in data processing. For instance - an external provider may be your processor, an independent controller or, less commonly, a joint controller. In those cases, different legal rules can apply depending on how each party handles the data in practice.   

As an employer, your responsibilities can apply to the information you handle about employees, workers, contractors, consultants, applicants, candidates, former staff, interns, volunteers and other individuals connected with your workforce. You therefore need to understand the complete lifecycle of that information, from its collection and use through to its sharing, retention, archiving, and deletion.

You must also apply data protection by design and by default. This means carefully integrating data protection from the initial design stage and throughout the lifecycle of your HR systems and processes.

In practice, this can include limiting use of personal data to what’s necessary, carrying out Data Protection Impact Assessments (risk assessments) where processing is likely to result in a high risk to individuals’ rights and freedoms and building security into HR systems, and allocating responsibility for data protection throughout its lifecycle.

Some activities that appear routine from an HR perspective can create more complex responsibilities and risks from a data protection perspective. These include using artificial intelligence to rank candidates, making solely automated decisions with a legal or similarly significant effect, and processing criminal offence data during recruitment checks. Take legal advice on your duties if you carry out these activities.  Depending on the relevant activity, you may need to take various extra steps. These could cover completing a Data Protection Impact Assessment, identifying and follow additional legal requirements and conditions, checking a system for accuracy and bias, and giving individuals various rights where a significant decision is based solely on automated processing

Understanding how employee data flows through your business

You must understand how personal data moves through your organisation, its systems, to external third parties like service providers. That includes identifying where information is hosted, who can access it, and whether you are sending personal data, or making it accessible, to a separate organisation outside the UK in circumstances that amount to a restricted transfer.

HR teams routinely share information with payroll providers, cloud-hosting companies, benefits platforms, occupational health services, recruiters, and outsourced IT support. Clear responsibilities and appropriate safeguards are vital where staff information is handled by another organisation.

You will need to decide whether each third-party provider acts as a processor, an independent controller or, in some circumstances, a joint controller. If it is your processor, the contract must contain specific data protection terms required by the UK GDPR and should give you suitable oversight of matters such as security, sub-processing, incident response, deletion, and audit rights.

Where two controllers share staff information, a data-sharing agreement may be advisable to explain their respective processing purposes and responsibilities. It can help the parties agree how to manage issues such as transparency, security, individual rights, and accountability consistently.

If staff information is sent, accessed or stored to an external organisation outside the UK, you should assess if this is a restricted transfer. Depending on the destination and arrangement, you may need to rely on UK adequacy regulations, appropriated safeguards (such as the International Data Transfer Agreement or UK, binding corporate rules) and complete a transfer risk assessment to meet the data protection test, or another applicable exception

Embedding data protection into your contracts and policies

Any data protection wording within your employment contracts and HR policies, including the relevant sections of your staff handbook, should be correct and reflect how your business actually uses personal data. Often, contracts will refer staff to the employer’s staff privacy notice.

Older, templated documents may sometimes rely heavily on employee consent. In practice, consent will rarely be the right lawful basis in an employment relationship because people working for you may not have a genuinely free choice when giving their consent. It can still be used in limited situations where the decision is genuinely optional and refusing or withdrawing consent will have no adverse consequences.

A staff privacy notice should explain your processing transparently and set out your lawful basis for using different types of staff personal information. You must separately identify and document the lawful basis that applies to each purpose.

You should also avoid clauses that suggest an individual has waived their data protection rights. Those rights are set by law and can’t be signed away through an employment contract or staff policy.

Providing transparent and compliant staff privacy notices

Staff need to be told information including what personal data you collect, why you use it, where it comes from, who you share it with, whether you transfer it outside the UK, and how long you expect to keep it. This information should be provided clearly and at the appropriate time and is commonly presented through a specifically tailored staff-facing privacy notice.

The notice should include information such as your data processing, use of any special category or criminal offence data, your lawful bases, retention periods or criteria, data sources, recipients, relevant international transfers, the handling of special category and criminal offence data, individual rights, and how they can raise a complaint. Where relevant, it should also give Information about where you make decisions based on solely automated processing (e.g. profiling), so individuals have meaningful information about the rationale and the consequences.

Your notice should be accessible, accurate and up to date. A polished document that no longer matches the way the business handles personal data in real time can create its own risk.

Review the notice whenever your data practices change and where legal rules changes. Introducing a new HR platform, monitoring tool, artificial intelligence system, payroll provider or employee benefits service which impact personal data may require existing wording to be updated before the new data use begins.

Meeting legal requirements for special category (sensitive) employee data

When handling special category data, such as health information, trade union membership, genetic data or certain biometric data, you must meet stricter requirements.

These issues can arise frequently in HR. You may receive health information when managing sickness absence or reasonable adjustments, for example, or process trade union information when dealing with collective consultation.

You must identify both a lawful basis under Article 6 of the UK GDPR and a separate condition under Article 9 for processing special category data. You must determine these before the processing begins and document them.  You may also need to maintain an appropriate policy document where required by law.

Biometric data becomes special category data when it is processed for the purpose of uniquely identifying a person. That can include using fingerprints, facial recognition or another biometric characteristic to control access or record attendance. Before introducing this type of system, run a Data Protection Impact Assessment and consider whether a less intrusive method would achieve the same result.

Criminal offence data is not special category data, but it is separately protected. Recruitment checks and the use of information about convictions or allegations therefore require with strict legal rules. This includes having a valid lawful basis and either official authority or a a relevant condition, an appropriate policy document where required measures and complying with various other legal requirements

Managing retention and deletion of HR data

You must only keep personal data for as long as it is needed for the purpose for which it was collected.

When you’re deciding how long to keep it, also consider any legal or regulatory rules which apply. This reflects the storage limitation principle and is supported by the requirement to minimise the personal data you hold.

There is no single retention period that works for how long you may hold every category of HR information. You’ll need to be able to justify your retention periods. Payroll records, unsuccessful job applications, disciplinary documents, sickness records, and information connected with potential legal claims may all require different treatment and retention periods. Note some types of employment records may need to be kept for specific time periods under the law (e.g. for tax purposes) and you should take advice on this if you’re unsure about this.  

Retention periods should therefore be set for each type of personal information based on the purpose for why you hold it, documented, and applied consistently. Personal information shouldn’t be retained indefinitely simply because it might become useful one day.

A data-retention policy and schedule can help your organisation explain why it holds different categories of HR information and give your business consistent internal rules to follow in terms of how long data should be kept. You should also have a compliant process for when certain personal information may need to be preserved for a complaint, investigation, regulatory requirement or legal dispute.

Using data protection impact assessments in HR

You must complete a data protection impact assessment (DPIA) before starting processing that is likely to result in a high risk to workers’ rights and freedoms.

Relevant HR examples that may trigger this requirement include using artificial intelligence in recruitment and introducing systematic workplace monitoring. A DPIA is required for large-scale processing of health information and whenever biometric data is processed to uniquely identify workers.

The assessment should take place early on before processing starts and whilst the project can still be changed. Leaving it until a supplier has been selected or the system is ready to launch limits its value and can make any necessary changes considerably more expensive.

A useful DPIA will identify the purpose of the processing, assess whether it is necessary and proportionate, assess the risks to workers, explore less intrusive alternatives, and record the safeguards the business intends to use to mitigate risks. It should be reviewed if the project, technology or level of risk later changes.

Reviewing HR data when changing systems

When moving to a new HR system, you should assess the information you already hold. Transferring inaccurate, duplicated or unnecessary data adds legal and security risk.

Identify what does not need to be migrated and appoint an appropriate person to oversee the transfer in line with your retention schedule and in line with applicable legal rules. HR, IT, information security, procurement, and legal teams may all need to contribute.

If you outsource HR functions, you will typically be the controller, and the relevant supplier will typically be the processor. As a controller, your business has the ultimate responsibility for ensuring personal data is processed in line with data protection law rules. You’ll need to take various steps - including telling staff who their data is shared with, entering a contract with the supplier and checking they use appropriate security measures to secure personal data.

Supplier due diligence should cover how the new system stores and protects information, who can access it, which subcontractors (e.g. sub-processors) are involved, how data security incidents (including personal data breaches) will be reported, how personal data is returned or deleted when the contract ends, and whether the arrangement involves international transfers of personal information.

These issues are easier to resolve before the migration approach and supplier contract are finalised. Once thousands of employee records have moved, your room for manoeuvre becomes much smaller.

Managing workplace monitoring lawfully

You must carefully balance your organisation’s reasons for monitoring staff against their privacy and wider data protection rights.

Proposals involving productivity monitoring, remote-working tools, location tracking, communications monitoring or biometrics require particular care.

Before monitoring begins, you should take steps which include the need to document its purpose and lawful basis, assess whether it is necessary and proportionate, consider less intrusive alternatives, and explain the monitoring clearly to affected workers.

A DPIA is needed where the monitoring is likely to result in a high risk to individuals rights and freedoms. You may also need to have an appropriate policy document in place.

Where monitoring software contributes to decisions about performance, discipline, promotion or termination, don’t treat the system’s output as automatically reliable. Consider how data quality, context, accuracy, and potential bias will be checked, and ensure that appropriate human oversight is available. Strict legal rules apply here and legal advice is recommended.

Biometric monitoring or access control needs additional consideration and steps.  For instance, carrying out a DPIA, informing individuals, considering extra security measures, as well as various other actions.

Responding to subject access and data rights requests

Staff can request access to their personal data by making a subject access request. You must respond without undue delay and within one month.

Where a request is complex or the person has submitted several requests, the response period may (where necessary) be extended by up to a further two months. You must explain the extension and the reasons for it within one month of receipt of the request.

If you reasonably need clarification about the personal information requested, the response clock can pause on the day you request clarification and starts again the day after receipt of it. However, clarification should not be used simply to delay a response or make the individual narrow a request.

The Data (Use and Access) Act 2025 has also clarified that an organisation is required to carry out a reasonable and proportionate search for personal data. What is reasonable will depend on matters such as the circumstances of the request, the volume of the information to search and any difficulties finding it.

Subject access requests can become particularly difficult where they overlap with a grievance, disciplinary process or dispute. The response may contain information about colleagues, legally privileged material, management forecasting or planning information or confidential references, and exemptions may need to be considered carefully on a case-by-case basis.

Staff may also have rights relating to rectification, erasure, restriction of processing, objection, data portability, and automated decision-making. These rights are not all absolute, so each request must be assessed individually against the circumstances and the legal conditions that apply.

Our Ask the Expert article covers some of the common questions that arise when an employer receives a subject access request.

Handling data protection complaints from staff

Your business must give staff a clear and accessible way to raise data protection complaints. Your staff privacy notice must make clear that they can submit a data protection complaint (to your organisation and the ICO) and explain how to submit it.  It’s also advisable to have an internal policy or procedure to explain how your business handles such complaints and who’s responsible for dealing with them.

The Data (Use and Access) Act 2025 introduced a statutory complaints process for controllers. Your organisation must acknowledge a complaint within 30 days, and without undue delay, take appropriate steps to respond and make enquiries, make appropriate enquiries, keep the person informed on progress, and explain the outcome. You should also retain suitable records showing what complaint was raised, how it was investigated, and what action was taken.

A prompt and objective internal response may resolve the concern before it develops into an ICO complaint or leads to a dispute or wider loss of trust. Complaints can also provide useful learning opportunities - helping the organisation identify whether the issue points to a broader problem with a system, process or working practice relating to data protection

Training staff on data protection responsibilities

HR and other relevant staff should receive appropriate training on handling personal data. Training should reflect the risks associated with their roles and the types of personal data they handle, rather than relying on a single generic course for the entire organisation.

Someone tasked with responding to subject access requests may need different practical knowledge and training requirements from a manager recording performance concerns or a recruiter using an artificial intelligence tool.

Training should be included in induction, refreshed regularly, and updated when legal obligations, systems, internal policies or the use of data changes. You should retain suitable training records and make sure staff know how to recognise and report or escalate a personal data breach, complaint or data subject rights request in line with your organisation’s policies and legal rules

When should HR take legal advice on employee data?

Legal input is particularly valuable where proposed data processing is novel, sensitive or likely to attract challenge.

Examples include workplace monitoring, artificial intelligence-assisted recruitment, significant automated decisions, using health or biometric data, criminal offence information, making international transfers, responding to complex subject access requests, employee complaints, and making major changes to HR systems which impact personal data

Early advice can help the business identify its lawful options, assess whether a or other steps are required, involve the right internal stakeholders, negotiate suitable data protection terms where needed, and document the reasoning behind its data decisions.

It can also reduce the cost and disruption of changing an approach after a system has been purchased, data has been migrated or a difficult employee issue has already developed.

Getting HR data protection right

Every employer business faces a different combination of HR data risks. Much depends on the size and structure of the workforce, the personal information being processed and how it’s used in practice, the technology being used, the third parties involved and where the data is sent.

The key is to treat data protection as an ongoing responsibility rather than a one-off compliance project. Policies, privacy notices, retention practices, supplier contracts and data sharing arrangements, data access permissions, and training should be reviewed regularly, particularly when the organisation changes how it recruits, monitors, manages or otherwise changes how it handles the data of its workforce.

A structured approach to compliance can make common challenges easier to handle and reduce the risk of important responsibilities being overlooked. It can also help HR teams respond more confidently when an employee asks a difficult question or a senior leader wants to introduce new technology at speed.

If you are dealing with a complex subject access request, updating your privacy documentation or planning a new HR system, taking advice early can help you make a defensible decision, take the right compliance steps and avoid a larger problem later.

Our data protection solicitors and employment law solicitors work closely with HR teams to help them manage staff personal information correctly, meet their legal responsibilities, and handle difficult compliance issues with confidence.


What next?

Please leave us your details and we’ll contact you to discuss your situation and legal requirements. There’s no charge for your initial consultation, and no obligation to instruct us. We aim to respond to all messages received within 24 hours.


Our offices

A national law firm

A national law firm

Our commercial lawyers are based in or close to major cities across the UK, providing expert legal advice to clients both locally and nationally.

We mainly work remotely, so we can work with you wherever you are. But we can arrange face-to-face meeting at our offices or a location of your choosing.

Head Office

Floor 5, Cavendish House, 39-41 Waterloo Street, Birmingham, B2 5PP
Regional Spaces

Capital Tower Business Centre, 3rd Floor, Capital Tower, Greyfriars Road, Cardiff, CF10 3AG
Stirling House, Cambridge Innovation Park, Denny End Road, Waterbeach, Cambridge, CB25 9QE
13th Floor, Piccadilly Plaza, Manchester, M1 4BT
10 Lower Thames Street, London, EC3R 6AF
Belsyre Court, 57 Woodstock Road, Oxford, OX2 6HJ
1st Floor, Dearing House, 1 Young St, Sheffield, S1 4UP
White Building Studios, 1-4 Cumberland Place, Southampton, SO15 2NP
A national law firm

Like what you’re reading?

Get new articles delivered to your inbox

Join 8,153 entrepreneurs reading our latest news, guides and insights.

Subscribe


Speak to a lawyer

Speak to a lawyer