GDPR Session 2
In relation to the 6 Principles of GDPR and different ‘levels’ of data, GDPR provides the following definitions:-
- Consent: Personal data (e.g. that can identify a person), Special Categories or Sensitive Personal Data, examples: video’s, pictures, racial/ethnic origin, genetic or biometric data.
- Contractual Obligation: The performance of the employment contract in which the Data Subject is party to, examples: bank details, name, contact details, salary.
- Legal Obligation: Where the Data Controller has to comply with legal obligations, examples: HMRC, Statutory Payments, Tax, Right to Work, Union Membership.
- Public Interest: The exercise of official vested in the Data Controller, example: it may be unlikely that this category would be used in an HR context but would cover (for example) EU or member state law.
- Vital Interest: Where processing is necessary to protect the vital interest of the Data Subject or another person where the data is incapable of giving consent. Only used for situations where another suitable processing condition cannot be relied upon, example: sharing health background with a medical professional if an employee had a serious accident at work.
- Legitimate Interest: Processing is the purpose of legitimate interest by the Data Controller, example: interview documentation, call monitoring, CCTV.
For further information on The 6 Principles of GDPR visit the Information Commissions Office (ICO) website: https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/principles/
The content of this document refers to GDPR compliance in relation to HR data and employees only. Therefore it is recommended that further guidance is sought for GDPR compliance in other business areas. Unsurprisingly we’ve been unable to cover all HR-related topics in this Blog, please contact us if you would like to receive a copy of the full document by sending an email to:jannine@nullb2phr.co.uk.
We have also compiled an HR GDPR pack (please note these documents only relate to HR-activities) consisting of the following templates:-
- Data Protection Impact Assessment (DPIA) spreadsheet;
- Employee Privacy Notice Template (individual employee notification letters)
- Privacy Notice (General to be issued to employees explaining how HR-related activities will be processed in-line with GDPR)
- Privacy Notice (Candidate version for potential job applicants explaining how HR-related activities will be processed in-line with GDPR)
- Data Protection Policy (template)
We would be very happy to share these with you for a small one-off fee of £150 + VAT (to cover research / development time and costs).

