UK data protection for employee data is governed by the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. Employers process employee data — names, addresses, salaries, health records, performance reviews, and absence data — on a daily basis. Each processing activity must have a lawful basis, and the data must be kept accurate, secure, and no longer than necessary. The Information Commissioner’s Office (ICO) has enforcement powers including fines of up to £17.5 million or 4% of annual global turnover for serious breaches.

This guide covers the lawful bases for processing employee data, the special category data rules, employee monitoring, and the practical obligations employers face.

Key takeaways

  • Employee data processing is governed by the UK GDPR (retained EU law as amended by the Data Protection Act 2018) and overseen by the Information Commissioner’s Office (ICO).
  • The employer must identify a lawful basis for every processing activity — the most common bases for employee data are legitimate interests and contractual necessity.
  • Special category data (health, trade union membership, biometric data, etc.) requires an additional condition — the most common being employment, social security, and social protection law.
  • Employees have rights of access, rectification, erasure, and objection — but these rights are not absolute in the employment context.
  • The employer must maintain a Record of Processing Activities under Article 30 UK GDPR.

Lawful bases for processing employee data

Under Article 6 UK GDPR, every processing activity must have one of six lawful bases. In the employment context, the most relevant are:

Lawful basis When it applies
Contractual necessity (Art. 6(1)(b)) Processing necessary to perform the employment contract — paying salary, providing benefits, managing leave
Legitimate interests (Art. 6(1)(f)) Processing necessary for the employer’s legitimate interests, where those interests are not overridden by the employee’s rights — performance management, absence tracking, fraud prevention
Legal obligation (Art. 6(1)(c)) Processing required by law — HMRC reporting, pension auto-enrolment, right-to-work checks
Consent (Art. 6(1)(a)) Not generally appropriate in employment due to the power imbalance — consent must be freely given and can be withdrawn at any time

The employer must document the lawful basis for each processing activity in its Record of Processing Activities.

Legitimate interests — the balancing test

Where the employer relies on legitimate interests, it must conduct a legitimate interests assessment (LIA) that balances the employer’s interest against the employee’s rights and freedoms. The assessment considers:

  1. Purpose — what is the legitimate interest being pursued?
  2. Necessity — is the processing necessary to achieve that interest?
  3. Balancing — does the employee’s interest in not having the processing occur override the employer’s interest?

Example: Monitoring employee email to prevent fraud is a legitimate interest, but monitoring every email in real time without informing employees is unlikely to pass the balancing test.

Special category data

Special category data is data revealing racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic data, biometric data, health data, or data concerning sex life or sexual orientation — Article 9 UK GDPR.

Processing special category data requires both a lawful basis under Article 6 and an additional condition under Article 9(2). The most relevant conditions for employers are:

Article 9 condition When it applies
Employment, social security, and social protection law (Art. 9(2)(b)) Processing necessary for the employer’s obligations under employment law — health certificates, pension contributions
Explicit consent (Art. 9(2)(a)) Where the employee has given explicit consent — but the power imbalance makes consent a weak basis
Substantial public interest (Art. 9(2)(g)) Processing necessary for reasons of substantial public interest — rarely applies to routine HR processing

Health data is the most frequently processed special category data in the workplace. An employer can process an employee’s health data where it is necessary to comply with its obligations under employment law (e.g., occupational health assessments, sick pay) or where the employee has given explicit consent.

Employee monitoring

Employee monitoring is lawful only if it complies with UK GDPR principles and, in some cases, the Investigatory Powers Act 2016. The employer must:

  1. Inform employees — tell employees what data is being collected, why, how it is used, and who has access.
  2. Have a lawful basis — monitoring for security purposes may be legitimate interests; monitoring personal communications is harder to justify.
  3. Conduct a DPIA — where monitoring is likely to result in a high risk to the rights and freedoms of individuals, a Data Protection Impact Assessment is required under Article 35 UK GDPR.
  4. Be proportionate — the monitoring must be the least intrusive means of achieving the objective.

Common monitoring activities and their compliance status

Activity Compliance requirement
CCTV in the workplace Inform employees, conduct DPIA, limit to business areas
Email and internet monitoring Inform employees in advance, limit to business use, do not monitor personal correspondence
GPS tracking of vehicles Inform employees, limit to working hours, conduct DPIA
Biometric data (fingerprint access) Explicit consent or employment law basis, DPIA required
Absence data and return-to-work records Contractual necessity or legitimate interests, keep within HR

Subject Access Requests

Employees have the right to request access to their personal data under Article 15 UK GDPR. The employer must respond within one month (extendable by two months for complex requests).

Key points for employee SARs:

  • The employee is entitled to a copy of their personal data, the purposes of processing, and the recipients.
  • The employee is not entitled to information that would reveal the employer’s legal strategy (e.g., legal advice about a potential claim).
  • The employer can apply the management information exemption under DPA 2018 Schedule 2 Part 1 to internal communications about the employee.
  • A SAR that is manifestly unfounded or excessive can be refused or charged a reasonable fee — but the bar for this is high.

Data retention

The UK GDPR’s data minimisation principle means employee data should not be kept longer than necessary. The ICO does not prescribe mandatory retention periods for most employee data, but recommends:

  • Recruitment records — 6 months after the decision (for equality monitoring and potential claims)
  • Payroll records — 6 years (HMRC requirement)
  • Pension records — until pension age plus 6 years
  • Health records — 3 years after employment ends (for potential injury claims)
  • Accident records — 40 years (or 3 years for employees under 18)

The employer should publish a retention schedule and destroy data at the end of the retention period.

Common pitfalls

Consent is rarely a valid basis for employee data processing because of the power imbalance — the employee cannot freely withdraw consent without risking their employment. Use contractual necessity or legitimate interests instead.

2. Not having a Record of Processing Activities

Article 30 UK GDPR requires organisations with 250 or more employees to maintain a Record of Processing Activities. Many smaller employers are also required to maintain one if they process special category data on a large scale or carry out systematic monitoring.

3. Failing to inform employees about monitoring

An employer who monitors emails, CCTV, or internet use without telling employees is breaching the transparency principle. The information must be provided at the point of collection and updated when the processing changes.

4. Retaining data indefinitely

Keeping employee data “just in case” breaches the storage limitation principle. Every piece of personal data should have a defined retention period.

Putting it into practice

Five steps to build data protection into your HR processes:

  1. Map your data flows — know what employee data you collect, where it is stored, who has access, and how long it is kept.
  2. Document your lawful basis — for each processing activity, record the lawful basis and the legitimate interests assessment where applicable.
  3. Publish a privacy notice for employees — tell them what data you collect, why, how long you keep it, and who you share it with.
  4. Build retention into your systems — set automated deletion dates so data is not kept beyond its retention period.
  5. Train your HR team on Subject Access Requests — the one-month deadline is strict, and the exemptions are narrow.
You can take advantage of the free 14 days trial and explore Leave Balance.

A leave management system that stores employee data securely, applies retention schedules automatically, and generates reports on request reduces the compliance burden of UK GDPR.

Sources

This article is general information, not legal advice. Data protection law is complex and evolves rapidly — consult the ICO or a data protection solicitor for specific situations.