GDPR Session 1: So what is GDPR?
Having received a number of requests for HR guidance in relation to GDPR we have pulled together some highlights to share with you and some guidance on the things you should be putting in place.
So let’s start at the beginning……
So what is GDPR?
The General Data Protection Regulations (GDPR) is the new governing legislation for collecting and storing personal data and is applicable to all European member states.
Irrespective of the UK’s decision to leave the EU, GDPR came into force on the 25th May 2018 and applies to all businesses ;established’ in the UK, irrespective of size or number of employees and places obligations on businesses to maintain data processing records in-line with strict principles.
Failure to comply with, or found to be in breach of, these Regulations could lead to financial penalties being imposed of up to 4% of annual global turnover or €20m (whichever is higher).
GDPR requires the Data Controller (the organisation in control of processing data) to make information available to the Data Subjects (the individuals whom the data refers to) about what information is being held, the purpose for which this information is being held and how it will be processed.
GDPR is a major overhaul of current law, with one of the fundamental new principles being to place greater ‘accountability’ on companies (the Data Controller) to ensure that stringent data governance is in place and that the processing of all personal data is undertaken; fairly, lawfully and transparently.
The content of this document refers to GDPR compliance in relation to HR data and employees only. Therefore it is recommended that further guidance is sought for GDPR compliance in other business areas. Unsurprisingly we’ve been unable to cover all HR-related topics in this Blog, please contact us if you would like to receive a copy of the full document by sending an email to: jannine@nullb2phr.co.uk .
We have also compiled an HR GDPR pack (please note these documents only relate to HR-activities) consisting of the following templates:-
- Data Protection Impact Assessment (DPIA) spreadsheet;
- Employee Privacy Notice Template (individual employee notification letters);
- Privacy Notice (General to be issued to employees explaining how HR-related activities will be processed in-line with GDPR);
- Privacy Notice (Candidate version for potential job applicants explaining how HR-related activities will be processed in-line with GDPR);
- Data Protection Policy (template).
We would be very happy to share these with you for a small one-off fee of £150 + VAT (to cover research / development time and costs).

