Records and data · 5 min read

Employee data and GDPR: what a small employer has to do

Lawful bases for staff data, the workforce privacy notice, health and other special category data, retention, subject access requests, monitoring and GPS clock-in, breaches, and the ICO fee.

Reviewed September 2026. Guidance, not legal advice: employment law moves, so check the current position before relying on any of it.

Every employer processes personal data about its staff, and most of it (health, absence, disciplinary records, right to work documents, bank details) is the kind the law treats most carefully. UK GDPR does not stop you holding any of it. It asks you to know why you hold it, tell people, keep it only as long as you need it, keep it safe, and hand it over when they ask.

This guide covers the lawful basis for the common types of staff data, the privacy notice, special category data and the extra condition it needs, a retention schedule, subject access requests, workplace monitoring including location data from clock-in apps, breach reporting, and the ICO registration fee.

Lawful basis

You need a lawful basis for each purpose. For staff data the bases are almost always:

  • Contract: data needed to perform the employment contract (name, address, bank details, hours, pay).
  • Legal obligation: data the law requires you to hold or report (right to work copies, PAYE records, SSP records, accident book).
  • Legitimate interests: data you need to run the business proportionately (emergency contacts, performance records, most monitoring), balanced against the employee's interests and documented.
  • Consent: rarely, because an employee cannot freely refuse their employer. Do not rely on consent for anything you would need to process anyway.

The workforce privacy notice

Before or when you collect staff data you must tell people what you collect, why, on what basis, who you share it with (payroll provider, pension scheme, HMRC, software suppliers), how long you keep it, and their rights. A two-page workforce privacy notice, given with the offer and available in the handbook, does it. Recruitment candidates need a shorter version. The free template pack on this site includes one.

Special category data

Health (sickness records, fit notes, occupational health reports), ethnicity, religion, trade union membership, sexual orientation and biometric data (fingerprint clock-ins) are special category data. Processing them needs both a lawful basis and a condition under Article 9, which for employers is usually that the processing is necessary for employment law obligations, together with an appropriate policy document under the Data Protection Act 2018 explaining how you comply. Restrict access to the people who need it, and keep it separately from the general file.

Retention

Keep data only as long as the purpose requires, and write down how long that is for each type. The statutory periods (six years for minimum wage records, three years after the tax year for PAYE and statutory payments, two years after leaving for right to work copies, two years for working time records) set floors; the six-year limitation period for contract claims justifies keeping the personnel file for six years after leaving. Unsuccessful candidates' data goes after six months unless they agree to be kept on file. Then delete on schedule; a retention policy nobody follows is worse than none.

Subject access requests

An employee (or ex-employee) can ask for a copy of the personal data you hold about them, and you must provide it within one month, extendable by two more for complex requests, free of charge. The request can be made in any form, to anyone in the business, and does not have to mention GDPR. Search everywhere: HR system, payroll, email, messages, managers' notes. Third-party data can be redacted; confidential references you gave are exempt; legal advice is privileged. Requests often arrive alongside a grievance or a dismissal; treat them as routine and answer on time.

Monitoring, GPS and clock-in data

You can monitor staff where it is necessary and proportionate and they have been told. GPS clock-in, which Work-Lynx provides, records location at the moment of clocking in and out, to verify attendance at the site; it should not track people between those moments or off shift, and the privacy notice should say exactly what is captured and why. Continuous location tracking, CCTV in welfare areas, reading personal messages and covert monitoring all need a very strong justification and usually a data protection impact assessment. The ICO's employment monitoring guidance is the reference.

Security and breaches

Reasonable security means access controls, passwords, encrypted devices, locked cabinets, and not emailing spreadsheets of payroll to personal accounts. A personal data breach that is likely to result in a risk to people (a lost laptop with staff records, payroll sent to the wrong person) must be reported to the ICO within 72 hours of becoming aware, and to the affected individuals where the risk is high. Keep a breach log even for the ones you do not report.

The ICO fee

Almost every organisation processing personal data must pay an annual data protection fee to the Information Commissioner, in tiers by size and turnover. Failure to pay is a fixed penalty. Check whether you are exempt using the ICO's self-assessment; most employers are not.

The checklist

  1. Workforce privacy notice given to every employee and candidate; kept current.
  2. Lawful basis recorded for each processing purpose; consent not relied on for essentials.
  3. Special category data: Article 9 condition identified; appropriate policy document in place; access restricted.
  4. Retention schedule written and followed; recruitment data purged at six months.
  5. Subject access request procedure: logged, searched, answered within a month.
  6. Monitoring described in the privacy notice; GPS limited to clock events; impact assessment for anything intrusive.
  7. Devices encrypted; breach log kept; 72-hour reporting route known.
  8. ICO data protection fee paid annually.

What the law says

  • UK GDPR Arts.5, 6, 9, 13, 15, 30, 32 to 35: principles, lawful basis, special category data, transparency, access, records, security, breaches, impact assessments.
  • Data Protection Act 2018 Sch.1 Part 1 para.1 and Part 4: the employment condition and the appropriate policy document.
  • Data Protection (Charges and Information) Regulations 2018: the ICO fee.
  • ICO guidance: employment practices and data protection, monitoring workers, subject access requests.

Questions people ask

Do I need consent to hold sickness records?

No, and you should not rely on it. Sickness records are processed under the employment condition (legal obligations under employment and social security law), with an appropriate policy document. Consent an employee cannot refuse is not valid consent.

Can a former employee demand every email that mentions them?

They can ask for their personal data, which includes emails about them where they are the subject. Search proportionately, redact other people's data, and withhold what is exempt. "Every email mentioning their first name" is where you can ask them to narrow the request, but you cannot refuse it outright.

Is a fingerprint clock-in allowed?

Biometric data is special category data. It is allowed where necessary and proportionate with a lawful basis, an Article 9 condition and an impact assessment, and where a non-biometric alternative is offered to anyone who objects. The ICO has challenged employers who imposed it without that. A phone-based GPS clock-in avoids the issue.

The admin this guide describes, done for you

Work-Lynx holds the records, calculates the entitlements, drafts the letters and reminds you of the dates: 49 UK policies, GPS clock-in, rotas, leave, timesheets, payslips and Employ AI for the questions in between. £2.50 a month plus £1 per employee, 14 days free, no card.

Start free trial