Please note that we are unable to offer free legal advice.  Our consultation team are here to take your case details and explain any costs involved.

hello@kilgannonlaw.co.uk

Our team is ready to answer any questions

0800 915 7777

Book your consultation today

Take action HR – what are the new data protection rules?

The General Data Protection Regulations are due to come into force on 25 May 2018 and will reform data protection laws within the European Union. The UK will sign up, despite Brexit, and businesses need to start preparing now.

The obligations will apply to all data processors as well as controllers (currently only data controllers are in scope) and are significantly more comprehensive than current rules, introducing tough new privacy requirements in EU Member States.

Sanctions for non-compliance will be severe and include administrative fines of up to Eur.20 million or 4% of an organisation’s annual worldwide turnover.

We have summarised some of the key changes and set out steps your organisation can take to prepare for the changes, and will continue to keep you informed with analysis and updates.

Wider definition of ‘personal data’

Due to the fast pace of technological developments, the definition of ‘personal data’ under the GDPR is wider and now includes any data that can be used to identify an individual, including location data, genetic data and biometric data such as facial recognition and fingerprinting.

From an HR, personnel files and other information, point of view, the new definition could now include electronic data and searchable manual filing systems containing personal data that are not necessarily searchable by name but are searchable, for instance, chronologically or by other criteria (such as characteristics).

Consent and lawful processing

For consent to data processing to be valid, organisations will need to be transparent and notify individuals in clear and plain language the purposes for which their data is being collected before consent is given. Consent can be withdrawn at any time, on a purpose by purpose basis if the individual so wishes, and will not be taken to have reached the required level of validity if there is an imbalance of bargaining power.

We would suggest that the employment relationship represents such an imbalance and that employers who wish to play it safe, at least to begin with, should not rely on consent, but other grounds for lawful processing, such as performance of the employment contract or compliance with a legal obligation. Employers will need to have a good look at what they do with their data to make sure it is processed under one of these headings.

Where ‘sensitive’ personal data is involved (there is a broad definition of this, covering trade union membership to sexual orientation, health and biometric data), ‘explicit’ consent is required. It is currently not clear what this means, but we would advise that the form of consent at least specifically cover those special categories of personal data listed in the regulations.

Under the GDPR, consent must be freely given, specific, informed and unambiguous. Consent must be separate from other terms and must be a positive opt-in. Remaining silent on consent or providing a default pre-ticked box will not be sufficient to establish consent. Consent must also be verifiable, and therefore you will need to ensure there is a record of how and when consent was given.

Privacy notices

Data processors and controllers will need to explicitly inform individuals about their rights when obtaining personal data, including those relating to subject access requests, rectification or erasure, data portability, and their right to withdraw consent.

They will also need to make it clear what legal basis processing is taking place on, how long the date will be retained, whether the data will be transferred overseas (and, if not within the EEA, whether or not to a ‘safe harbour’).

The notices must be set out in a manner which individuals will be able to read and understand.

Subject access requests

If an individual makes a subject access request, data processors will have one month to comply, rather than the current 40 days, and in most cases, will not be permitted to charge for this request.

Data must be ‘ported’ to the person making the request electronically, in a structured and commonly used, machine readable, format. This requirement for data portability leaves a question mark over the status of hand written notes that constitute personal data.

Data processors will therefore want to put suitable procedures in place to deal with such requests, provide training to staff, and ensure that data is stored in a suitable format.

Data Protection Officer requirement

Most public authorities and those that process certain data in a large scale, regular and systematic manner as part of their core activities, must appoint a Data Protection Officer (DPO) who will be required to oversee compliance with the GDPR. The DPO must have professional experience and expert knowledge of data protection laws and practices as they will be the first point of contact in respect of data protection matters.

Data breaches

The GDPR now requires all organisations to notify the Data Protection Authority (this will be the ICO) of certain types of personal data breaches within 72 hours of becoming aware of the breach. Such personal data breaches mean a breach of security leading to the destruction, loss, alteration, unaturorised disclosure of, or access to, personal data.

In addition, where the breach is likely to result in high risk to the rights and freedoms of the data subject, processors will also have to notify the individual affected in most cases.

Right to be forgotten

The GDPR gives data subjects the right to request erasure of their personal data without undue delay in certain circumstances including where the personal data is no longer necessary in relation for the purposes which it was originally collected or processed or where an individual has withdrawn consent.

There are several grounds giving processors the right to refuse to comply with a request for erasure, but these are all public interest in nature, and unlikely to apply in most cases.

Companies should ensure procedures are reviewed and amended to reflect the extended rights of individuals under the GDPR and relevant training is provided to staff.

Next steps

To ensure your organisation is compliant with the standards required under the GDPR, it is important to audit your data processing activities, privacy notices and organisational structure to determine what gaps exist within your current state of compliance. You will then have time to put them right before May 2018.

Contact us to find out how we can help to ensure your organisation is prepared for the GDPR.


A black and white photo of the big ben clock tower
By Louise Maynard October 28, 2024
The Labour Party came into power in 2024 with a promise of substantial reforms aimed at enhancing worker’s rights, improving work-life balance, and addressing inequalities in the workplace.
A woman is sitting in a chair talking to a man.
By Yeing-Lang Chong October 10, 2024
Mental health is an increasingly important issue in the workplace, affecting employees’ wellbeing, productivity, and overall satisfaction. As more employees speak up about their struggles, UK employers must ensure they are providing a supportive environment while adhering to legal responsibilities. The legal framework surrounding mental health in the workplace is clear, but understanding how to apply it practically is key to preventing discrimination and promoting a healthy work culture. With World Mental Health Day on 10th October, now is the perfect time for employers to review their obligations and strategies for supporting mental health in the workplace.
An empty office with a desk and chair in front of a window.
By Yeing-Lang Chong October 9, 2024
Handling Mental Health-Related Absences: Best Practices and Legal Obligations Mental health-related absences are a common challenge for employers, as mental health conditions can lead to prolonged or frequent time off work. Understanding how to handle these absences with compassion while fulfilling legal obligations is crucial for maintaining a supportive work environment and avoiding potential legal pitfalls. As we approach World Mental Health Day on 10th October, this article outlines best practices and key legal responsibilities for UK employers when managing mental health-related absences.
A woman is comforting a man who is sitting at a desk with his head in his hands.
By Emily Kidd October 8, 2024
In the UK, mental health discrimination in the workplace is a growing concern as more employees speak up about their struggles with mental health issues. World Mental Health Day, observed on 10th October, provides an opportunity to reflect on the legal protections in place to safeguard employees from discrimination and to promote mental wellbeing in the workplace. This article will explore the legal framework surrounding mental health discrimination, including how the law defines mental health disabilities, employers' responsibilities, and steps businesses can take to prevent discrimination.
A man is sitting in a chair while two women comfort him.
By Marianne Wright October 7, 2024
Supporting employees with mental health conditions is not just an ethical responsibility for UK employers; it’s a legal obligation under the Equality Act 2010. As we approach World Mental Health Day on 10th October, it’s crucial for employers to understand what reasonable adjustments are, how they can be applied to mental health, and the steps they should take to comply with UK law while fostering an inclusive and supportive work environment.
A group of people are sitting around a table with their hands on each other.
By Marianne Wright October 7, 2024
The Equality Act 2010 is a key piece of legislation in the UK that aims to protect employees from discrimination in the workplace. While much of the focus on this Act has been on physical disabilities, mental health conditions are also covered under its provisions. As we approach World Mental Health Day on 10th October, it’s important to understand how the Equality Act protects employees with mental health conditions, and what employers must do to ensure they meet their legal obligations.
A group of people are clapping their hands in an office.
By Marianne Wright October 7, 2024
In the modern workplace, stress is often considered an inevitable part of the job. However, when stress becomes overwhelming, it can lead to significant mental health issues such as anxiety, depression, and burnout. In the UK, employers have a legal responsibility to manage workplace stress and support employee wellbeing. As we approach World Mental Health Day on 10th October, this article explores the legal framework around workplace stress and provides guidance on how employers can take steps to create a healthier, more supportive work environment.
A man in a wheelchair is sitting at a table with other people.
By Springhouse Solicitors October 2, 2024
The British Airways Plc v Rollett & Others ruling underscores the importance of focusing on the actual disadvantages caused by workplace policies. Employers are now obliged to be more vigilant in assessing the broader impacts of their decisions, ensuring equity and fairness for all employees, regardless of whether they possess a protected characteristic under the Equality Act 2010. By proactively addressing these considerations, employers can foster a more inclusive work environment and mitigate the risk of indirect discrimination claims.
A woman is sleeping at a desk in front of a laptop computer.
By Marianne Wright August 11, 2024
Shift work is a necessity in the healthcare sector, ensuring round-the-clock care. However, long hours, night shifts, and irregular schedules can take a significant toll on healthcare workers' physical and mental health, increasing the risk of burnout. This article outlines your legal rights regarding rest breaks, the impact of shift work, and your employer's obligations to minimise the risks.
By Yeing-Lang Chong August 11, 2024
Mental health conditions are becoming increasingly prevalent in UK workplaces, with far-reaching consequences for employees, businesses, and society as a whole. Employers have a duty of care towards their employees' mental wellbeing, and certain mental health conditions may also be recognised as disabilities under the Equality Act 2010.
More Posts
Share by: