This is part 5 of a 7 part series exploring the far-reaching subject of GDPR. If you’ve missed the first part, you can find it here.

GDPR Session 5

The Data Controller (Employer / Company) must provide information to the Data Subject at the point that data is collected, this obligation extends to providing notification to candidates during the recruitment process, current employees, workers and Contractors.

Where the lawful basis for processing falls under the category which requires the Data Subject to ‘consent’, this consent requires a positive opt-in, which means the Data Controller cannot rely on, implied, automatic or blanket consent, use pre-ticked boxes, or any other method of default consent.  Explicit consent requires a very clear and specific statement of consent.

The most secure way to obtain explicit consent is to consider issuing the Data Subject(s) with an Employee Privacy Letter (or Processing Notice).   Further detailed guidance on the content of Privacy Letters (and Data Privacy Notices) can also be found on the ICO website, however the following represents the highlights:-

  • Identity and contact details of the employer as the Data Controller.
  • Data Protection Officer’s (DPO) name and contact details (where required).
  • Confirmation of the Data Protection Principles.
  • How the data will be collected.
  • What ‘legitimate interest’ data will be processed.
  • Identify ‘special categories’ of data where explicit consent is required.
  • The types of data that will be processed and how it will be processed.
  • The sharing of data (including outside of the European Economic Area (EEA).
  • How the data will be protected.
  • Retention statement.
  • Automated decision making.
  • Employee (Data Subject) rights (e.g. right to access, withdrawing consent, right for any inaccuracies to be corrected / deleted, complaints process)

 

You should also ensure that your Data Privacy Notice (in conjunction with your Data Protection Policy if you have one) is updated, GDPR compliant and displayed clearly and prominently.  You may decide to include HR in your overall Privacy Notice or to create a separate HR-specific Privacy Policy.

Finally it is recommended that training is provided to all employees responsible for GDPR to ensure compliance is maintained.  GDPR training should be based on regular and continuous events, e.g. not just one-off training.  Recommendations are made to issue CPD certificates following such events to enable the Data Controller to demonstrate that training has taken place and provide an audit trail in the case of a data breach.
The content of this document refers to GDPR compliance in relation to HR data and employees only.  Therefore it is recommended that further guidance is sought for GDPR compliance in other business areas.  Unsurprisingly we’ve been unable to cover all HR-related topics in this Blog, please contact us if you would like to receive a copy of the full document by sending an email to:jannine@nullb2phr.co.uk. 

We have also compiled an HR GDPR pack (please note these documents only relate to HR-activities) consisting of the following templates:-

  • Data Protection Impact Assessment (DPIA) spreadsheet;
  • Employee Privacy Notice Template (individual employee notification letters)
  • Privacy Notice (General to be issued to employees explaining how HR-related activities will be processed in-line with GDPR)
  • Privacy Notice (Candidate version for potential job applicants explaining how HR-related activities will be processed in-line with GDPR)
  • Data Protection Policy (template)

We would be very happy to share these with you for a small one-off fee of £150 + VAT (to cover research / development time and costs).