Time to look at your HR policies

By Kimberley Barrett-St Vall, employment and HR partner at Napthens Solicitors.

The EU’s General Data Protection Regulations will make changes to the Data Protection Act 1998. Breaching the GDPR can have significant fines of up to €20m euros or 4 per cent of the global turnover.

Businesses will benefit from adopting a holistic approach to GDPR compliance across their entire organisation, factoring in IT systems, cyber security, marketing as well as HR and employment law issues.

In this article I’m taking a closer look at the part HR will have to play in GDPR compliance:

Recruitment

Your business will be under an obligation under the GDPR to provide greater detail to candidates setting out:
  • details of the data controller
  • the category of data being processed
  • the legal basis of processing
  • the recipient
  • the processor’s details
  • if the data is to be transferred outside the EEA
  • the consequences on the employee of not providing the information on the contract
If as part of your recruitment process your business uses any form of profiling, candidates must be made aware of this and its consequences.

Employers should only collect the minimum amount of information for a specific purpose and ensure the data is stored for no longer than necessary. Access should be restricted in consideration of what is necessary.

Processing Employee Data

It is common practice for employers to use the employee’s consent as the basis of processing personal data. Even prior to the GDPR this approach was criticised, as it is questionable whether consent can be given “freely in an informed fashion and specific and explicit”, given it is often conditional on the offer of employment.

Going forward you should rely on the legal basis for processing employee personal data. Businesses must ensure processing is based on one of the following:
  1. for compliance of a legal obligation e.g. payroll processing data to ensure the employee is paid
  2. for the performance of a contract e.g. processing data in the context of healthcare insurance provision
  3. based on a legitimate interest of the employer (or third party processor)
Data Subject Access Request

Post May 2018 there will be no fee to pay if employees make a data subject access request and requests must be dealt with in 30 days (currently 40). There is likely to be an increase in requests and it is important you understand how to handle these requests efficiently. The GDPR is clear - it requires employers to demonstrate compliance. I suggest this involves more than a tickbox exercise and rather a change in culture with a commitment to embrace the GDPR. Given your Data Protection Officer cannot be everywhere at all times, cascading understanding and awareness through new policies and procedures and support through training for your employees will be vital.

Enjoyed this? Read more from Lancashire Business View

Latest news

1

£90m-backed regeneration plans submitted for Central Drive Artist's impression of Central Drive

£90m-backed regeneration plans submitted for Central Drive

19 Jun 2026

2

Manufacturers boost growth with digital investment Daleside Fabrication

Manufacturers boost growth with digital investment

19 Jun 2026

3

Planning ahead is key for attracting funding Funding Summit

Planning ahead is key for attracting funding

18 Jun 2026

4

Science in Sport secures £30m-plus backing for growth plans Sir Chris Hoy, chairman of SiS Elite Performance Advisory Panel

Science in Sport secures £30m-plus backing for growth plans

18 Jun 2026

5

BAE Systems commits €50m to European defence start-ups bae-systems-samlesbury.jpg

BAE Systems commits €50m to European defence start-ups

16 Jun 2026

Background image for hub sign up block

LBV Hub

Leverage Lancashire Business View platforms

Post your news
Post your events
Post your offers
Build your network
Improve your SEO
Gain coverage in the magazine
Sign-up
Events
LBV129 July/August Magazine Networking Event
Nov/Dec Networking Event
Networking
16 Jul 2026

LBV129 July/August Magazine Networking Event

Brysdales, Britannia Buildings Drumhead Road, Chorley, PR6 7BX

16:00 - 18:00

LBV130 September/October Magazine Networking Event
Jan/Feb Networking Event - Entrance
Networking
17 Sep 2026

LBV130 September/October Magazine Networking Event

The Beehive Blackburn, Shadsworth Business Park, BB1 2Q

08:30 - 10:30

LBV131 November/December Magazine Networking Event
Jan/ Feb Networking Event - Talking
Networking
19 Nov 2026

LBV131 November/December Magazine Networking Event

Lancashire

08:30 - 10:30

The Bay Business Club
Logo.jpg.jpg
LBV Hub Networking
22 Jun 2026

The Bay Business Club

Morecambe Football Club, Morecambe, LA4 4TB

17:00 - 19:00

Preston Freelancer Meet-Up: June
June Freelancer Square.png.png
LBV Hub Networking
24 Jun 2026

Preston Freelancer Meet-Up: June

Society1 Coworking Space, Preston, PR1 3LT

10:00 - 12:00

How to manage grievances…with confidence
Logo.jpg.jpg
LBV Hub Seminars
24 Jun 2026

How to manage grievances…with confidence

The Longlands Hotel, Carnforth, LA6 1JH

08:00 - 10:00

Cyber Crime Awareness Event
Logo.jpg.jpg
LBV Hub Seminars
24 Jun 2026

Cyber Crime Awareness Event

Morecambe Golf Club, Morecambe, LA4 6AJ

13:00 - 16:00

How can smarter employee benefits reduce costs and improve staff retention?
Screenshot 2026-05-20 100211.png.png
LBV Hub Roundtables
25 Jun 2026

How can smarter employee benefits reduce costs and improve staff retention?

Forbes Solicitors , Preston, PR5 6AW

08:30 - 10:00

NO Rackets Required - The Ultimate Padel Party
Crowdfunder.png.png
LBV Hub Social
26 Jun 2026

NO Rackets Required - The Ultimate Padel Party

Pendle Padel Club, Nelson, BB9 5SR

16:00 - 00:00

How hackers target SMEs - and how to protect your business
Lancashire_gamesdesign_Feb26-2120.jpg.jpg
LBV Hub Seminars
02 Jul 2026

How hackers target SMEs - and how to protect your business

Engineering Innovation Centre, Preston, PR1 2XS

09:30 - 11:30

The AI Lab: Marketing Multiplier
Event post 03.07.png.png
LBV Hub Seminars
03 Jul 2026

The AI Lab: Marketing Multiplier

Door4, Burnley Wharf, Manchester Road, Burnley, BB11 1JG

09:00 - 11:30

Clubhouse Business Network sponsored by Orca Finance - July 2026
padel-networkpng.png.png
LBV Hub Networking
09 Jul 2026 - 09 Jul 2026

Clubhouse Business Network sponsored by Orca Finance - July 2026

Clubhouse, Blackburn, BB1 3NT

14:00 - 16:00

Advertise with us

Reaching 50,000 members, our print, digital and event platforms offer a fantastic way to raise your business profile and help you grow.

Find out more LBV124 Online Graphic
Subscribe now

Weekly news bulletin