Time to look at your HR policies

By Kimberley Barrett-St Vall, employment and HR partner at Napthens Solicitors.

The EU’s General Data Protection Regulations will make changes to the Data Protection Act 1998. Breaching the GDPR can have significant fines of up to €20m euros or 4 per cent of the global turnover.

Businesses will benefit from adopting a holistic approach to GDPR compliance across their entire organisation, factoring in IT systems, cyber security, marketing as well as HR and employment law issues.

In this article I’m taking a closer look at the part HR will have to play in GDPR compliance:

Recruitment

Your business will be under an obligation under the GDPR to provide greater detail to candidates setting out:
  • details of the data controller
  • the category of data being processed
  • the legal basis of processing
  • the recipient
  • the processor’s details
  • if the data is to be transferred outside the EEA
  • the consequences on the employee of not providing the information on the contract
If as part of your recruitment process your business uses any form of profiling, candidates must be made aware of this and its consequences.

Employers should only collect the minimum amount of information for a specific purpose and ensure the data is stored for no longer than necessary. Access should be restricted in consideration of what is necessary.

Processing Employee Data

It is common practice for employers to use the employee’s consent as the basis of processing personal data. Even prior to the GDPR this approach was criticised, as it is questionable whether consent can be given “freely in an informed fashion and specific and explicit”, given it is often conditional on the offer of employment.

Going forward you should rely on the legal basis for processing employee personal data. Businesses must ensure processing is based on one of the following:
  1. for compliance of a legal obligation e.g. payroll processing data to ensure the employee is paid
  2. for the performance of a contract e.g. processing data in the context of healthcare insurance provision
  3. based on a legitimate interest of the employer (or third party processor)
Data Subject Access Request

Post May 2018 there will be no fee to pay if employees make a data subject access request and requests must be dealt with in 30 days (currently 40). There is likely to be an increase in requests and it is important you understand how to handle these requests efficiently. The GDPR is clear - it requires employers to demonstrate compliance. I suggest this involves more than a tickbox exercise and rather a change in culture with a commitment to embrace the GDPR. Given your Data Protection Officer cannot be everywhere at all times, cascading understanding and awareness through new policies and procedures and support through training for your employees will be vital.

Enjoyed this? Read more from Lancashire Business View

Latest news

1

Public consultation for proposed merger of Blackpool and The Fylde College and Furness College Blackpool and the Fylde College

Public consultation for proposed merger of Blackpool and The Fylde College and Furness College

26 Mar 2026

2

Preston Council invests £1m in plans NW Mutual Bank NW Mutual Bank

Preston Council invests £1m in plans NW Mutual Bank

26 Mar 2026

3

BAE boost as UK signs Typhoon support contract with Turkey Typhoon aircraft new

BAE boost as UK signs Typhoon support contract with Turkey

26 Mar 2026

4

Burnley gets £4.8m heritage boost for town centre regeneration Burnley secures £4.8 million heritage boost for town centre regeneration

Burnley gets £4.8m heritage boost for town centre regeneration

25 Mar 2026

5

Celebrity chef launches training academy at Blackburn College Lisa Goodwin Allen at the academy at Blackburn College

Celebrity chef launches training academy at Blackburn College

24 Mar 2026

Background image for hub sign up block

LBV Hub

Leverage Lancashire Business View platforms

Post your news
Post your events
Post your offers
Build your network
Improve your SEO
Gain coverage in the magazine
Sign-up
Events
AI & Cybersecurity Summit
AI and Cybersecurity Logo
Summit
28 Apr 2026

AI & Cybersecurity Summit

Dunkenhalgh House , Blackburn Road, Clayton Le Moors, BB5 5JP

08:30 - 11:00

Sub36 Networking - Outdoor Elements
Sub36 Outdoor Elements Logo1920x1008
Networking
29 Apr 2026

Sub36 Networking - Outdoor Elements

Outdoor Elements, Pump House Dean Wood, Trapp Lane, Burnley, BB12 7JD

09:00 - 11:00

LBV Magazine Networking Events - SAVE THE DATES
Jan/ Feb Networking Event - Talking
Networking
14 May 2026

LBV Magazine Networking Events - SAVE THE DATES

Lancashire

08:30 - 10:30

The Employment Rights Act 2025: What you need to know
Logo.jpg.jpg
LBV Hub Seminars
26 Mar 2026 - 26 Mar 2026

The Employment Rights Act 2025: What you need to know

Lancaster & Morecambe College, Lancaster, LA1 1TZ

08:00 - 10:00

Lancashire Business Expo 2026
SE, Lancashire 2025.png.png
LBV Hub Exhibitions
27 Mar 2026 - 27 Mar 2026

Lancashire Business Expo 2026

Sir Tom Finney Sports Centre, Preston, PR1 2HE

09:00 - 15:00

90 Day Business Planning Workshop
LBV Hub Networking
27 Mar 2026 - 27 Mar 2026

90 Day Business Planning Workshop

The Holiday Inn, Bolton, BL1 2EW

09:00 - 16:30

The Ultimate Music Quiz
Logo.jpg.jpg
LBV Hub Fundraisers
27 Mar 2026 - 27 Mar 2026

The Ultimate Music Quiz

Morecambe Football Club, Morecambe, LA4 4TB

19:00 - 22:30

RISE - a tailored 6 month leadership programme for women across the North West
WENDY BOWERS RISE Illustrstion copy.jpg.jpg
LBV Hub Seminars
15 Apr 2026 - 15 Apr 2026

RISE - a tailored 6 month leadership programme for women across the North West

East Lancashire Chamber of Commerce, Clayton le Moors, BB5 5JR

09:00 - 15:30

The Business Network Central and East Lancashire
LBV Header (31).png.png
LBV Hub Networking
16 Apr 2026 - 16 Apr 2026

The Business Network Central and East Lancashire

Mytton Fold, Blackburn, BB6 8AB

11:30 - 14:15

Sickness Absence: key actions for your business
Logo.jpg.jpg
LBV Hub Seminars
22 Apr 2026 - 22 Feb 2026

Sickness Absence: key actions for your business

The Longlands Hotel, Carnforth, LA6 1JH

08:00 - 10:00

Freelancer Meet-Up April
April Freelancer Instagram size.png.png
LBV Hub Networking
23 Apr 2026 - 23 Apr 2026

Freelancer Meet-Up April

Society1 Coworking Space, Preston, PR1 3LT

10:00 - 00:00

Vibe Coding: "Who owns what when no one wrote the code?"
April PTC Banner.png.png
LBV Hub Networking
28 Apr 2026 - 28 Apr 2026

Vibe Coding: "Who owns what when no one wrote the code?"

Society1 Coworking Space, Preston, PR1 3LT

18:00 - 19:30

Advertise with us

Reaching 50,000 members, our print, digital and event platforms offer a fantastic way to raise your business profile and help you grow.

Find out more LBV124 Online Graphic
Subscribe now

Weekly news bulletin