Time to look at your HR policies

By Kimberley Barrett-St Vall, employment and HR partner at Napthens Solicitors.

The EU’s General Data Protection Regulations will make changes to the Data Protection Act 1998. Breaching the GDPR can have significant fines of up to €20m euros or 4 per cent of the global turnover.

Businesses will benefit from adopting a holistic approach to GDPR compliance across their entire organisation, factoring in IT systems, cyber security, marketing as well as HR and employment law issues.

In this article I’m taking a closer look at the part HR will have to play in GDPR compliance:

Recruitment

Your business will be under an obligation under the GDPR to provide greater detail to candidates setting out:
  • details of the data controller
  • the category of data being processed
  • the legal basis of processing
  • the recipient
  • the processor’s details
  • if the data is to be transferred outside the EEA
  • the consequences on the employee of not providing the information on the contract
If as part of your recruitment process your business uses any form of profiling, candidates must be made aware of this and its consequences.

Employers should only collect the minimum amount of information for a specific purpose and ensure the data is stored for no longer than necessary. Access should be restricted in consideration of what is necessary.

Processing Employee Data

It is common practice for employers to use the employee’s consent as the basis of processing personal data. Even prior to the GDPR this approach was criticised, as it is questionable whether consent can be given “freely in an informed fashion and specific and explicit”, given it is often conditional on the offer of employment.

Going forward you should rely on the legal basis for processing employee personal data. Businesses must ensure processing is based on one of the following:
  1. for compliance of a legal obligation e.g. payroll processing data to ensure the employee is paid
  2. for the performance of a contract e.g. processing data in the context of healthcare insurance provision
  3. based on a legitimate interest of the employer (or third party processor)
Data Subject Access Request

Post May 2018 there will be no fee to pay if employees make a data subject access request and requests must be dealt with in 30 days (currently 40). There is likely to be an increase in requests and it is important you understand how to handle these requests efficiently. The GDPR is clear - it requires employers to demonstrate compliance. I suggest this involves more than a tickbox exercise and rather a change in culture with a commitment to embrace the GDPR. Given your Data Protection Officer cannot be everywhere at all times, cascading understanding and awareness through new policies and procedures and support through training for your employees will be vital.

Enjoyed this? Read more from Lancashire Business View

Latest news

1

£350m Blackpool Talbot Gateway nears full occupancy with NHS move 300 NHS Staff Have Moved Into No 1 Bickerstaffe Square

£350m Blackpool Talbot Gateway nears full occupancy with NHS move

04 Feb 2026

2

Group of eight community pharmacies sold to Cohens Chemist Smithsons Pharmacy

Group of eight community pharmacies sold to Cohens Chemist

04 Feb 2026

3

Northstone appoints James Hargreaves Plumbing Supplies as nominated supplier across the North West Northstone and James Hargreaves

Northstone appoints James Hargreaves Plumbing Supplies as nominated supplier across the North West

04 Feb 2026

4

The Principal that counts - Lisa O'Loughlin big interview Lisa O'Loughlin

The Principal that counts - Lisa O'Loughlin big interview

03 Feb 2026

5

Guy's Thatched Hamlet shuts after 'difficult decision' Guy's Thatched Hamlet (Pic Guy's Thatched Hamlet)

Guy's Thatched Hamlet shuts after 'difficult decision'

03 Feb 2026

Background image for hub sign up block

LBV Hub

Leverage Lancashire Business View platforms

Post your news
Post your events
Post your offers
Build your network
Improve your SEO
Gain coverage in the magazine
Sign-up
Events
CMI Level 5 Management and Leadership Course
UCLanAerialCampus.jpg.jpg
LBV Hub Seminars
21 Feb 2025 - 21 Feb 2026

CMI Level 5 Management and Leadership Course

Preston Campus, Preston , PR1 2HE

09:00 - 17:00

RISE - Lancashire's unique leadership programme for women
thumbnail_Emma Weston Illustration WENDY BOWERS RISE Illustrstion.jpg.jpg
LBV Hub Seminars
22 Oct 2025 - 18 Mar 2026

RISE - Lancashire's unique leadership programme for women

East Lancashire Chamber of Commerce, Clayton le Moors, BB5 5JR

09:30 - 15:30

E-commerce in 2026: From stores to systems
PTC banner Feb 26.jpg.jpg
LBV Hub Networking
10 Feb 2026 - 10 Feb 2026

E-commerce in 2026: From stores to systems

Society1, Coworking Space, Preston, PR1 3LT

18:00 - 19:30

Degree apprenticeship information sessions for businesses
student centre entrance.jfif.jpg
LBV Hub Webinar
10 Feb 2026 - 13 Feb 2026

Degree apprenticeship information sessions for businesses

University of Lancashire, Virtual event, -

10:00 - 09:30

The Business Network Central and East Lancashire
LBV Header (29).png.png
LBV Hub Networking
11 Feb 2026 - 11 Feb 2026

The Business Network Central and East Lancashire

Mytton Fold, Langho, BB6 8AB

11:30 - 14:15

The Ultimate Network – February
Logo.jpg.jpg
LBV Hub Networking
19 Feb 2026 - 19 Feb 2026

The Ultimate Network – February

Brockholes Nature Reserve, Samlesbury, PR5 0AG

16:00 - 18:00

Future Forward Business and Skills Summit
Future Forward Business & Skills Summit
LBV Hub Networking
20 Feb 2026

Future Forward Business and Skills Summit

Lancashire Energy HQ , Blackpool, FY4 2QS

08:00 - 11:00

Armed Forces Covenant Business Engagement
Logo.jpg.jpg
LBV Hub Seminars
24 Feb 2026 - 24 Feb 2026

Armed Forces Covenant Business Engagement

Morecambe Football Club, Morecambe, LA4 4TB

09:00 - 15:00

Preston Freelancer Meet-Up: February
LBV Hub Networking
26 Feb 2026 - 26 Feb 2026

Preston Freelancer Meet-Up: February

Society1, Coworking Space, Preston, PR1 3LT

10:00 - 12:00

Your marketing measurement is useless
Event header.png.png
LBV Hub Seminars
04 Mar 2026 - 04 Mar 2026

Your marketing measurement is useless

Brockholes Nature Reserve, Preston, PR5 0AG

09:00 - 12:00

Tech without the turmoil: How Finance Leaders can drive smarter digital decisions
MHA-BTI Logo_black (002).jpg.jpg
LBV Hub Networking
05 Mar 2026 - 27 Dec 2025

Tech without the turmoil: How Finance Leaders can drive smarter digital decisions

Farington Lodge Hotel, Stanifield Lane, Farington, Preston, PR25 4QR

08:00 - 10:00

Payroll Update 2026 Samlesbury Hall
payroll.jpg.jpg
LBV Hub Seminars
06 Mar 2026 - 06 Mar 2026

Payroll Update 2026 Samlesbury Hall

Samlesbury Hall, Preston, PR5 0UP

08:00 - 10:00

Advertise with us

Reaching 50,000 members, our print, digital and event platforms offer a fantastic way to raise your business profile and help you grow.

Find out more LBV124 Online Graphic
Subscribe now

Weekly news bulletin