GDPR and data protection policy
This model policy outlines how the Company will comply with statutory requirements of GDPR and data protection.
5 mins
170
What is a GDPR and data protection policy?
The purpose of this GDPR and data protection policy is to provide you with a flexible and customisable document to serve as a robust and effective starting point for you.
By using our GDPR and data protection policy, you can streamline your process, maintain consistency and accuracy, and save time, and it can be easily adapted to fit your specific scenario.
During onboarding / after changes / planned refresher
Internally issued to appropriate recipients in your Company
Great Britain & NI (United Kingdom)
What legislation and best practice guidelines have been taken into account in the development of this template?
-
Data Protection Act 2018 (DPA): This is the UK's primary data protection legislation that incorporates the GDPR into UK law. It sets out the rules and regulations for the processing of personal data, including employee data, and outlines the rights and responsibilities of data controllers and data processors.
-
General Data Protection Regulation (GDPR): Although this is an EU regulation, it applies to the UK as well. It provides a comprehensive framework for the protection and processing of personal data for individuals within the EU, including employees.
-
Employment Rights Act 1996: This legislation contains provisions related to employee privacy and confidentiality. It establishes the duty of employers to maintain the confidentiality of an employee's personal information and employment records.
-
Human Rights Act 1998: This Act incorporates the European Convention on Human Rights (ECHR) into UK law. It includes the right to respect for private and family life, which has implications for how employers handle employee data and ensure data privacy.
-
Equality Act 2010: While primarily focused on promoting equality and preventing discrimination in the workplace, this Act also contains provisions related to the handling of sensitive personal data, such as information about an employee's health or disability.
-
Computer Misuse Act 1990: This legislation addresses unauthorized access to computer systems, which is relevant for protecting employee data stored electronically.
-
Privacy and Electronic Communications Regulations (PECR): These regulations supplement the DPA and GDPR and provide rules on electronic communications, including email marketing and the use of cookies on websites, which may collect personal data from employees.
-
Employment Practices Code: This code of practice, issued by the Information Commissioner's Office (ICO), provides guidance on data protection in the context of employment, helping employers understand their responsibilities when processing employee data.
-
Trade Union and Labour Relations (Consolidation) Act 1992: This legislation ensures that trade unions have access to certain employee data for collective bargaining purposes while maintaining data protection requirements.
-
Whistleblowing Policy: Although not a specific piece of legislation, implementing a whistleblowing policy is essential to encourage employees to report any data protection breaches or concerns they may have.