GDPR Session 7
Question1: What does ‘accountability’ actually mean?
That the ‘Data Controller’ has:-
- Implemented appropriate processes and measures;
- Is able to demonstrate compliance through policies and processes;
- Has provided awareness and general training;
- Appointed a Data Protection Officer (where required)
Question 2: Do I need to appoint a Data Protection Officer (DPO)?
Some Companies will be required to appoint a DPO, where:-
- The Controller is a public authority;
- The Controllers activities require regular and systematic monitoring of Data Subjects on a large scale;
- Its core activities consist (on a large scale) of processing special categories of personal data or data relating to criminal convictions and offences.
If the Controller matches any of the above criteria, there is a requirement to appoint a DPO to oversee data protection activities, monitor GDPR compliance, maintain a register of data breaches, conduct audits, privacy impact assessments and awareness training.
The DPO can be an existing employee and should report to the highest level of management.
Question 3: What if my employees are not at work at the moment?
In Session 2 we detailed the information that should be contained in these documents and advised that further guidance can be found on the ICO website.
It is also important however, to remember those employees who may not be attending work at the time of your announcement for example:-
- Annual leave / Sabbatical;
- Short / Long-term sickness;
- Absent due to family circumstances e.g. maternity, adoption, paternity, parental/shared parental leave etc..
- Home workers or working in other locations / countries (covered by GDPR).
Consideration should also be given to making suitable alternative arrangements to any employees:-
- Who have a disability;
- Where their first language is not English;
- Who do not have access to all communication channels e.g. no access to the intranet.
Question 4: What is a Subject Access Request (SAR)?
As GDPR places the onus on the Data Controller to ensure that Data Subjects have easy access to their personal data, it is recommended that you review your internal processes to ensure that you have a robust process in place to enable Subject Access Requests to be actioned in a timely and efficient manner.
It is further recommended that you review your current template letters to ensure that they include and reflect the new enhanced rights on; data held, how long it will be stored, the mechanisms in place for regular auditing and destruction audits as this transparency could assist in reducing Subject Access Requests.
It should be further noted that the current process of charging the Data Subject a nominal £10.00 administration charge has been abolished and Data Controllers must now provide this information free of charge.
Data Controllers must respond to all SARs without undue delay and in any event within a new time frame of one month, which is significantly reduced from the current 40 day deadline.
Once the Data Controller has responded to the SAR, should the Data Subject have any concerns they have a number of options available to them:-
- Right for any inaccuracies to be corrected and/or the right for information to be deleted;
- Right to object;
- Right to restrict processing;
- Withdraw consent.
Question 5: What about information obtained over the telephone?
Every data collection point requires action, for example if information is being provided or collected over the telephone, e.g. when speaking to potential candidate(s) over the telephone, or email etc., and personal data is being shared. In these instances the individual should be sign-posted to the Data Controller (Company’s) Privacy Policy which should be clearly published and available to the individual e.g. on the Company’s Website.
Question 6: Sharing data with other Data Controllers and 3rd Party/Sub-Contractors
The Data Controller has ultimate accountability to ensure that the appropriate GDPR compliance and technical measures are in place when sharing or transmitting data to; other departments (within or outside of the organisation), third-party providers, suppliers, service and sub-Contractors that may have access to and/or process data on their Data Subjects on their behalf for example:-
- External Payroll Bureau / Accountants;
- Pension Administrators;
- Employee Benefits e.g. medical cover, life assurance etc.,
- Recruitment Agencies (who will also be responsible for gaining consent from the candidate);
- External HR Consultants;
- Finance Department;
- Marketing Department.In all of the above instances, it is imperative that you have a formal agreement in place with all of your Data Processors, that this is included in your Data Privacy Notice and your Data Privacy Notice is communicated and easily accessible.
Question 7: What about Data Storage, Retention and Destruction?
The key principle here is to collect and retain the minimum amount of data required.
“If you don’t need it – don’t keep it’!”
Having informed your employees (Data Subjects) as to the type of data being held (and sought consent where required), the Data Controller is responsible for ensuring that only the minimum about of data required is retained for the agreed retention period and that it is securely stored.
Below are some examples of areas where it is recommended consideration is given:-
- Implementing a ‘clear desk’ policy;
- Ensure all data covered under GDPR is kept confidential e.g. not left on desks, photocopiers etc.,
- That 3rd parties cannot gain access e.g. out of hours, cleaners, security personnel etc..
- Audit desks, cupboards, filing cabinets (lockable and fire proof where necessary);
- Consider what data is transmitted electronically and where encryption may be required, password protect documents and ‘lock’ PCs/devices when not in use;
- Consider all data forms e.g. electronic, laptops, servers (3rd party?), cloud;
- What data has been disclosed to / being held / used by 3rd parties?
- The security measures that are in place for data that is removed from Company premises?
- What security measures are in place for home/remote workers?
The content of this document refers to GDPR compliance in relation to HR data and employees only. Therefore it is recommended that further guidance is sought for GDPR compliance in other business areas. Unsurprisingly we’ve been unable to cover all HR-related topics in this Blog, please contact us if you would like to receive a copy of the full document by sending an email to: jannine@nullb2phr.co.uk.
We have also compiled an HR GDPR pack (please note these documents only relate to HR-activities) consisting of the following templates:-
- Data Protection Impact Assessment (DPIA) spreadsheet;
- Employee Privacy Notice Template (individual employee notification letters)
- Privacy Notice (General to be issued to employees explaining how HR-related activities will be processed in-line with GDPR)
- Privacy Notice (Candidate version for potential job applicants explaining how HR-related activities will be processed in-line with GDPR)
- Data Protection Policy (template)
We would be very happy to share these with you for a small one-off fee of £150 + VAT (to cover research / development time and costs).

