How to handle employee data under UK GDPR
Build one clear map of why employee information is used, who can see it, where it goes and when it should be reviewed or deleted.

In this guide
What your employee-data map needs to answer
- Map each purpose before collecting another field.
- Choose and record the lawful basis before processing starts.
- Give sensitive records their own condition and access controls.
- Match notices, suppliers and retention to the same map.
- Test the setup against a request, complaint and breach.
Find every place employee data is kept
List every person and system that holds employee information. Include candidates, current workers, contractors, leavers, dependants and anyone else whose information appears in an employment record.
Look beyond the HR system. Payroll, recruitment tools, email, shared drives, messaging, manager notebooks, downloaded reports, paper files and external advisers can all hold copies. Ask managers where they keep working notes and ask each supplier what it stores, exports and deletes.
Record the system or location, information held, people covered, owner and any duplicate. The aim is not to create an impressive spreadsheet. It is to know where a request, correction, retention decision or incident would need to reach.
If the inventory exposes a move away from local files or spreadsheets, plan the migration separately. Cleaning the system of record while leaving exports and manager copies untouched does not solve the original problem.
Decide why you need each type of employee data
Split the map by purpose. Paying somebody, managing sickness, checking right to work, keeping an emergency contact and measuring workforce turnover are different uses even when they touch the same profile.
For each purpose, write down:
- the people and information involved
- where the information came from
- why the use is necessary
- the Article 6 lawful basis
- the owner, systems, recipients and access
- what people are told
- the retention trigger and disposal action
Choose and document the lawful basis before processing starts. Use the current ICO basis guide for the specific purpose rather than assuming that legitimate interests will fit ordinary HR work.
Add extra controls for sensitive records
Special-category data includes health, racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, genetic and biometric identification data, sex life and sexual orientation. Criminal-offence information has a separate regime. Do not merge the two in the map.
Special-category processing needs an Article 6 lawful basis and an Article 9 condition. Some employment uses also need a condition from Schedule 1 of the Data Protection Act and an appropriate policy document. Use the ICO condition guide for the purpose in front of you.
Collect the least detail that still serves the purpose. Restrict access by task, keep free-text manager notes out of general profiles and decide how the information will be corrected, reviewed and deleted.
Before introducing intrusive monitoring, biometric identification, significant automated decisions or another use likely to create high risk, screen it against the ICO DPIA criteria. A data-protection impact assessment is most useful while the design can still change.
Tell people what you collect and control supplier access
Turn the map into privacy information people can understand. Explain the purposes, lawful bases, recipients, transfers, retention approach, rights and complaint route. Use separate candidate and worker notices when the information and purposes differ materially.
Grant access for the work somebody needs to do. A manager may need absence dates and an adjustment, while payroll needs pay and statutory-leave inputs. Neither automatically needs the other's full record. Review access when a role changes or somebody leaves.
For each supplier, record what it processes, where, under whose instructions and how it helps with rights, security, incidents and deletion. The contract needs the required processor terms. A supplier's “GDPR compliant” badge does not decide the employer's purpose, basis or retention period.
An HR system can help restrict access, search records, export information and carry out deletion work. Your organisation still decides why employee data is used, what people are told, how long it stays and how requests, complaints and incidents are handled.
Decide when each record will be reviewed or deleted
UK GDPR does not provide one universal retention period for HR records. Choose the period from the purpose, any other legal requirement, the realistic need to establish or defend a claim and the person's reasonable expectations. “We might need it” is not a retention rule.
Record a trigger, period or review date, owner and disposal action for each purpose. The trigger might be a rejected application, the end of employment, expiry of a document or closure of a case. Some records should be deleted; others may be anonymised so they no longer identify a person.
Use the ICO storage-limitation guidance to test the decision. Apply it to live systems, archives, exports, paper and agreed manager locations rather than deleting only the easiest copy.
Make requests and complaints easy to recognise
A subject access request does not need a form or the words “DSAR”. Give managers one route for forwarding any request for personal information, correction, restriction or deletion. Log when it arrived, clarify the scope where appropriate, search reasonable sources and review third-party information and exemptions case by case.
The normal subject-access response period is one month, subject to the current rules on clarification and extension. The ICO employer questions explain the practical search and disclosure issues.
Organisations must also facilitate data-protection complaints. Acknowledge a complaint within 30 days, investigate it and respond without undue delay. Keep the issue, evidence, decision and information about the ICO route together.
Know what to do when employee data is exposed
Give every employee and manager one immediate route for reporting a lost device, wrong recipient, exposed file, suspicious access or other possible personal-data breach. The first job is to contain the problem and preserve enough facts to assess it.
Record what happened, the information and people affected, likely consequences, containment and the reason for the notification decision. A notifiable breach must reach the ICO without undue delay and, where feasible, within 72 hours of awareness. If it is likely to create a high risk to people, the organisation may also need to tell them directly.
Use the ICO breach guide rather than waiting for certainty. Keep a record even when the conclusion is that notification is not required.
Check the rule at its source
These are the official pages we used. Check them when a decision depends on the latest rule or someone’s circumstances.
- ICO - Data (Use and Access) Act changes for organisationsCurrent amendments to UK GDPR and the Data Protection Act 2018.
- ICO - Keeping employment recordsPurpose, access, accuracy, retention and transparency for worker information.
- ICO - Guide to lawful basisChoosing and documenting an Article 6 basis before processing.
- ICO - Special-category conditionsArticle 9 conditions and additional UK requirements.
- ICO - When consent is appropriateWhy employment power imbalances can make consent unsuitable.
- ICO - Privacy information to providePurposes, bases, recipients, transfers, retention and rights.
- ICO - Contracts with processorsRequired processor terms and practical assistance.
- ICO - Storage limitationPurpose-led periods, review, deletion and anonymisation.
- ICO - Subject access requests for employersRecognising, searching and responding to employee access requests.
- ICO - Handling data-protection complaintsThe complaint route, acknowledgement and response duties.
- ICO - Personal-data breachesAssessment, notification, communication and incident records.
- ICO - When a DPIA is requiredScreening work that is likely to create a high risk to people.
Start free with up to 10 active employees.
Bring your team over from a spreadsheet. There is no card, no sales call and no lock-in. For up to 10 active employees, everyday HR is free.