Time to look at your HR policies

By Kimberley Barrett-St Vall, employment and HR partner at Napthens Solicitors.

The EU’s General Data Protection Regulations will make changes to the Data Protection Act 1998. Breaching the GDPR can have significant fines of up to €20m euros or 4 per cent of the global turnover.

Businesses will benefit from adopting a holistic approach to GDPR compliance across their entire organisation, factoring in IT systems, cyber security, marketing as well as HR and employment law issues.

In this article I’m taking a closer look at the part HR will have to play in GDPR compliance:

Recruitment

Your business will be under an obligation under the GDPR to provide greater detail to candidates setting out:
  • details of the data controller
  • the category of data being processed
  • the legal basis of processing
  • the recipient
  • the processor’s details
  • if the data is to be transferred outside the EEA
  • the consequences on the employee of not providing the information on the contract
If as part of your recruitment process your business uses any form of profiling, candidates must be made aware of this and its consequences.

Employers should only collect the minimum amount of information for a specific purpose and ensure the data is stored for no longer than necessary. Access should be restricted in consideration of what is necessary.

Processing Employee Data

It is common practice for employers to use the employee’s consent as the basis of processing personal data. Even prior to the GDPR this approach was criticised, as it is questionable whether consent can be given “freely in an informed fashion and specific and explicit”, given it is often conditional on the offer of employment.

Going forward you should rely on the legal basis for processing employee personal data. Businesses must ensure processing is based on one of the following:
  1. for compliance of a legal obligation e.g. payroll processing data to ensure the employee is paid
  2. for the performance of a contract e.g. processing data in the context of healthcare insurance provision
  3. based on a legitimate interest of the employer (or third party processor)
Data Subject Access Request

Post May 2018 there will be no fee to pay if employees make a data subject access request and requests must be dealt with in 30 days (currently 40). There is likely to be an increase in requests and it is important you understand how to handle these requests efficiently. The GDPR is clear - it requires employers to demonstrate compliance. I suggest this involves more than a tickbox exercise and rather a change in culture with a commitment to embrace the GDPR. Given your Data Protection Officer cannot be everywhere at all times, cascading understanding and awareness through new policies and procedures and support through training for your employees will be vital.

Enjoyed this? Read more from Lancashire Business View

Latest news

1

Forbes makes Manchester move Forbes Manchester

Forbes makes Manchester move

15 Apr 2024

2

Blackpool approves plans for pair of apartment complexes New South Promenade Apartments Visuals

Blackpool approves plans for pair of apartment complexes

12 Apr 2024

3

International building supplies firm to open new plant in Preston New Kerakoll Group Premises Visuals

International building supplies firm to open new plant in Preston

11 Apr 2024

4

Distinguished engineer takes senior role at Lancaster University Rebecca Lingwood

Distinguished engineer takes senior role at Lancaster University

11 Apr 2024

5

Get more young people applying for your jobs Paul Hannant Lancashire Apprenticeship Service

Get more young people applying for your jobs

19 Apr 2024

Hwc 2024 Email Signature 980x120
Background image for hub sign up block

LBV Hub

Reach 50,000 members of the Lancashire business community

Post your news
Post your events
Post your offers
Company profile
Social reach
Magazine coverage
Sign-up
Events
Health and Wellbeing Conference 2024
Hwc 2024 Social Media 1200px 1
Networking
23 Apr 2024

Health and Wellbeing Conference 2024

Crow Wood Hotel, Burnley , BB12 0RT

08:30 - 13:00

Help to Grow Management Course
HTG2.png.png
LBV Hub Seminars
15 Apr 2024 - 17 Jul 2024

Help to Grow Management Course

Preston Campus , Preston , PR1 2HE

09:30 - 14:00

Business Networking in Preston- BNI Brunch
EVENT LISTING SIZING Brunch .png.png
LBV Hub Networking
19 Apr 2024

Business Networking in Preston- BNI Brunch

Samlesbury Preston Hotel, Preston New Road, Preston, PR5 0UL

09:30 - 11:00

The Pro Club
Untitled design (6).png.png
LBV Hub Networking
19 Apr 2024

The Pro Club

Fraser House, Lancaster, LA1 4XQ

09:30 - 12:30

Business Networking in Blackburn - BNI Infinity
EVENT LISTING BNI Infinity.png.png
LBV Hub Networking
19 Apr 2024

Business Networking in Blackburn - BNI Infinity

Hampton by Hilton, 2 Frontier Ave, Blackburn, BB1 3AL

06:30 - 08:30

St Catherine’s Corporate Skydive
Corporate SkyDive.jpg.jpg
LBV Hub Fundraisers
21 Apr 2024

St Catherine’s Corporate Skydive

Black Knights Parachute Centre, Lancaster, LA2 0YD

12:00 - 16:30

Emergency First Aid at Work
Chamber Logo1.png.png
LBV Hub Seminars
23 Apr 2024

Emergency First Aid at Work

FGH Training, 3rd Floor, Storey House, White Cross Business Park, Lancaster, LA1 4XQ

09:00 - 16:00

Business Networking in Blackburn - BNI Vista
EVENT LISTING SIZING Vista.png.png
LBV Hub Networking
23 Apr 2024

Business Networking in Blackburn - BNI Vista

Hampton by Hilton, 2 Frontier Ave, Blackburn, BB1 3AL

06:45 - 08:30

HR Complete Training Programme: Equality and Diversity
Picture1.png.png
LBV Hub Webinar
23 Apr 2024

HR Complete Training Programme: Equality and Diversity

Online (Zoom)

09:30 - 11:00

Business Networking in Chorley - BNI Endeavour
EVENT LISTING SIZING Endeavour.png.png
LBV Hub Networking
23 Apr 2024

Business Networking in Chorley - BNI Endeavour

Oak Royal, Bury Lane, Chorley, PR6 8SW

06:30 - 08:30

Your Business Bootcamp Bitesize: "Roger That… The Importance of Asking Twice"
CBP-logo LBV.png.png
LBV Hub Webinar
24 Apr 2024 - 24 Apr 2024

Your Business Bootcamp Bitesize: "Roger That… The Importance of Asking Twice"

Online, Online, Online

08:00 - 09:30

Business Networking in Accrington - BNI Zeus
EVENT LISTING SIZING Zeus.png.png
LBV Hub Networking
24 Apr 2024

Business Networking in Accrington - BNI Zeus

The Mill House, Corn Mill Yard, Accrington, BB5 5HX

06:45 - 08:30

Advertise with us

Reaching 50,000 members, our print, digital and event platforms offer a fantastic way to raise your business profile and help you grow.

Find out more Lbv115 Online Graphic
Subscribe now

Weekly news bulletin