-

The General Data Protection Regulation (GDPR) represents a series of extensive and (in part) complex changes that businesses will need to incorporate and keep under review from 25 May 2018. Implementation will require several parts of the business working together to ensure that all aspects of data storage and processing within the business is GDPR ready.

Failures could now result in significant financial penalties.

Given the scope of GDPR, businesses should be undertaking an impact assessment and drawing up a project plan which will require working groups that are cross departmental to address each aspect of data processing (i.e. IT, HR, Finance, Sales, Marketing).From a HR and employee data perspective the issues that HR professionals will need to consider as part of the overall project plan will include:

Get our essential weekday HR news and updates.

This field is for validation purposes and should be left unchanged.
Keep up with the latest in HR...
This field is hidden when viewing the form
This field is hidden when viewing the form
Optin_date
This field is hidden when viewing the form

 

1. Employee Consent

Employers should no longer rely on the type of passive consent that is currently common in standard employment contracts and so should update new employment contract templates.

To process employee data, the employer should not rely on an employee’s blanket consent requirements, and instead rely on one of the other ‘other conditions for processing data’ such as ‘performance of a contract’, ‘legal obligation’ or ‘legitimate interests’.

Informed and proactive consent might be needed if the processing of employee data is required for a specific purpose other than the purpose of general employment.

2. Update Policies and Procedures

Employer’s will need to review their Data Protection Policy (which will require important amendments) as well as wider policies that connect to the various aspects of data compliance including the Whistleblowing Policy, Code of Conduct, Electronic Communications Policy, IT Policy and Home Working Policy.

3. Training Programme

Employees will need to understand GDPR and how it applies to them in practice. Delivery of the implementation will need to be supported by a comprehensive training programme that is ongoing, regularly updated and regularly attended by relevant staff.

4. Breach Response

HR ought to contribute and be a part of the business’s breach response plan. Many data issues – such as data leaks – will commonly come to HR first as they are almost always related to employees in some way.

5. Subject Access Requests

The rules on responding to subject access have changed and so HR need to familiarise themselves with the new regime in anticipation of receiving a request post May 2018.

6. Impact assessment and Project Plan

HR should be represented on the working groups tasked with identifying risk factors, impact and finalising the project plan.

Chris is a Senior Associate in the Commercial Team and Head of Data Protection and Privacy. Chris specialises in data protection and privacy, regularly advising clients on national and international data protection matters.

Latest news

Personalising the Benefits Experience: Why Employees Need More Than Just Information

This article explores how organisations can move beyond passive, one-size-fits-all communication to deliver relevant, timely, and simplified benefits experiences that reflect employee needs and life stages.

Grant Wyatt: When the love dies – when staying is riskier than quitting

When people fall out of love with their employer, or feel their employer has fallen out of love with them, what follows is rarely a clean exit.

£30bn pension savings window opens for employers ahead of 2029 reforms

UK employers could unlock billions in National Insurance savings by expanding pension salary sacrifice schemes before new limits take effect in 2029.

Expat jobs ‘fail early as costs hit $79,000 per worker’

International assignments are ending early due to family strain, isolation and poor preparation, as rising costs increase pressure on employers.
- Advertisement -

The Great Employer Divide: What the evidence shows about employers that back parents and carers — and those that don’t

Understand the growing divide between organisations that effectively support working parents and carers — and those that don’t. This session shows how to turn employee experience data into a clear business case, linking care-related pressures to performance, retention and workforce stability.

Scott Mills exit puts spotlight on risk of ‘news vacuum’ in high-profile dismissals

Sudden departure of a long-serving BBC presenter raises questions about how employers manage high-profile dismissals and limit speculation.

Must read

Howard Grosvenor: Ten innovations show the cutting edge of assessment

Today’s recruiters want their assessments to deliver four objectives: to differentiate their employer brand, to provide an engaging candidate experience, to deliver process efficiency and, most importantly, to provide robust and objective data about which candidates will thrive in the role and fit their culture.

Daniel Wood: How to create a remote working culture in 2022

People work harder when they feel part of something bigger, writes Daniel Wood, and it’s important to maintain that sense of culture while we all work from home.
- Advertisement -

You might also likeRELATED
Recommended to you