For some time larger organisations have been required to report data on gender pay gaps. Data must be reported to the UK Government’s gender pay-gap portal and a report must be published on each relevant organisation’s website annually.
From April 2027 organisations will also need to submit data and publish reports on pay gaps broken down by ethnicity and by disability.
They must also publish a plan for how the intend to tackle significant pay gaps.
The Data
The requirement covers the same metrics as gender pay gap reporting:
- Mean (average) hourly pay difference.
- Median (middle) hourly pay difference.
- Pay quarters (percentage of staff in four equally sized pay bands).
- Mean bonus pay difference.
- Median bonus pay difference.
- Percentage of employees receiving bonus pay
The metrics will be broken down by the following categories:
- Disability: Uses a binary approach (disabled versus non-disabled) based on the definition of disability in the Equality Act 2010
- Ethnicity: reporting across Office for National Statistics (ONS) groups or a binary white-versus-other breakdown.
- Declaration Rates: Companies must state the percentage of workers who chose not to share their data
GDPR Requirements
Lawful Basis
The GDPR has a lawful basis for the collection and processing of personal data for a statutory duty – Article 5(1)c: processing is necessary for compliance with a legal obligation to which the controller (employer in this context) is subject.
Because the data collected falls within the definition of sensitive personal data a second lawful basis is needed but fortunately this data processing can be covered by Article 9(2)b – for the purposes of employment.
However, employers must be mindful of the first privacy principle which requires their data processing to be lawful, fair and transparent. Implementing appropriate systems to fulfil this statutory duty must meet all three elements of the principle.
Fairness
Fairness will have both technical and organisational elements (we discuss data security below).
The data collection and reporting requirement recognises that people may choose not to share the relevant data. Organisations must not put undue pressure on individuals to share data about themselves they do not want to, as this could result in enforcement action from the ICO.
There is also a rule in the requirement that is there are less than 10 people in an particular metric then this does not need to be reported or published. This helps ensure data reliability but also helps reduces the chance of individuals being identified from any aggregate data.
When it comes to reporting and action planning you cannot rely on the statutory duty lawful basis to include things like case studies, interviews or personal stories and another lawful basis must be found. Consent is an option but employers must always be careful when considering consent as the imbalance of power between employer and employee makes it hard to be sure consent is freely given, and therefore valid.
Transparency
There are three main elements to being open and transparent.
The first is to ensure that the data collection, processing, reporting, publication and action planning are captured in your Record of Processing Activity (RoPA). A RoPA is a statutory requirement that should set out all your personal data processing, whether of employers, customers, suppliers or others.
Secondly you must update your privacy statement to capture this statutory requirement, what data you seek to collect, and what you will do with it.
The third thing is to produce comms for your employees explaining the new requirement and what it means. For example, we worked with a client to produce a template letter that looks like this:
As part of our ongoing commitment to transparency, inclusion, and workplace equity, we are preparing to launch our annual pay gap analysis. As an organisation with over 250 employees, we participate in mandatory reporting of this data.
This year, we are tracking pay representation across gender, ethnicity, and disability status.
Why are we collecting this data?
Pay gap reporting is not an audit of individual pay, nor does it mean people in identical roles are paid differently. Instead, it measures how representation is spread across all levels of our business. Collecting this information helps us see where structural barriers might exist in recruitment, retention, or career progression, allowing us to take meaningful, targeted action.
How your data is protected:
- Strict Confidentiality: Your responses are safely stored and processed in accordance with strict data protection guidelines. The data will only be accessed by a restricted team responsible for compliance and analysis.
- Anonymised Reporting: Final reports look purely at aggregate percentages and broad organisational bands. No individuals will ever be identifiable in the published figures, especially within smaller teams.
- Your Choice Matters: While high participation gives us the clearest picture of our workforce, every single question includes a ‘Prefer not to say’ option. You can choose exactly how much you wish to share.
How to submit your information:
The collection will be handled entirely through a secure internal online form. We will share the direct link alongside the official submission deadline as soon as they are finalised
Data Retention
When people first submit their data it is likely that it will be identifiable data. Although you will not necessarily be collecting names you are likely to require data to help you classify data by the relevant metric such as role title, department or team. If you are using an online form you will need a mechanism to ensure everyone submits data only once, and if using a paper form then people may have easily recognisable handwriting.
Once you have collected the data you must ensure that anything potentially identifiable is destroyed and only aggregate data without direct identifiers is retained. This will help ensure you meet the GDPR’s requirements and help improve people’s confidence in your systems.
The only exception to this is if you can identify a legitimate reason to retain some of the data by exception. If this happens you must be clear what the reason is, ensure you keep only the minimum necessary data, and retain it for no longer than necessary.
Anonymisation and Pseudonymisation
To minimise data retention and still comply with reporting requirements organisations should ensure they anonymise or pseudonymise the data they collect.
Anonymisation means removing all identifiers from the data and aggregating for reporting and action planning. You should ensure you do not retain any copies of identifiable data to ensure full anonymisation.
Pseudonymisation is a technique where data is effectively anonymised for a particular purposes by assigning each response a unique code, duplicating the data and removing all identifiable data from the duplicate. The advantage of pseudonymisation is that the data sets can be recombined using the code if necessary. For example, in medical research an anonymous patient may need a medical follow up by exception and pseudonymisation allows the patient to be identified without giving researchers access to personal information.
You can watch a brief explanation of pseudonymisation here:
Data Security
Effective data security will be key to gaining trust, which will in turn improve participation rates. All data security relies on a combination of technical and organisational measures.
Technical measures
Organisations should ensure that reporting can be done securely and the recording and transmission or the data is not open to general access or interception.
Access rights must also be considered. Who should have access to individual and aggregate records? What restrictions should be put in place to prevent unauthorised access?
Organisational measures
People with a role in the collection and analysis of data, whether it is managers encouraging their teams to take part, HR professionals involved in action planning or IT, should understand the limits of their role when it comes to accessing relevant data and the consequences of non-compliance.
People’s Rights
People who choose to take part in this data collection will still have rights under the GDPR but how they operate is different to the way they would work if, for example, the lawful basis was consent. Briefly rights apply like this:
- The right to be informed is complied with via your privacy information and communications about the necessary data collection.
- The right of access would apply if you retain identifiable data about individuals, so it depends how and when you anonymise data and delete any identifiable responses. If you do retain identifiable data it should be disclosed alongside other identifiable you hold and process.
- Rights to rectification would only apply if identifiable data were retained and were incomplete or inaccurate. Given the reporting requirements it may be difficult to correct any submissions and it is possible this could be complied with by encouraging people to make a full and accurate submission in future.
- Rights to erasure are unlikely to apply given the statutory basis for the data collection, and again people could simply refuse to take part in any future data submissions. As with other rights, it would only apply to identifiable data.
- The right to data portability would not apply for this data processing.
- Rights to object would again not apply for this data processing.
- The right to restrict processing may apply in certain limited circumstances. For example, the person whose data you have collected could ask you to keep the identifiable data for a certain period for specific reasons.
- Rights to automated decision making and profiling are unlikely to apply as you are not making a decision about individuals via automated means. You might need to be careful when it comes to profiling due to the action planning element of the statutory duty. For example you might track the performance data of individuals based on reportable characteristics and make decisions about them based on that tracking. This could impose additional duties on you to ensure you remain GDPR compliant.
How to Be GDPR Compliant for Statutory Pay Gap Reporting
One last element to consider when processing sensitive personal data for the first time is a data protection impact assessment, or DPIA. This is a tool that should be used to assess and try to mitigate data processing that poses material risks to data subjects. Strictly speaking, a DPIA should be used to help you decide IF you should proceed with some proposed data processing but for organisations that identify significant risks for this requirement should use a DPIA to
- rigorously analyse the risks and identify potential mitigations
- demonstrate accountability by having this risk analysis available in the event of any complaint or challenge
Your Checklist
Whether or not you do a DPIA consider the following checklist of activities to help you remain GDPR compliant for this statutory reporting:
- we understand the data that we need to collect and what to do with it
- we have updated our Record of Processing Activity
- we have updated our employee-facing Privacy Statement
- we have instituted internal comms to help people understand
- we have briefed managers, HR, IT (etc.) on requirements and their duties
- we have put in place appropriate systems for data collection, storage and destruction
- we have considered what particular risks may arise in our context for this kind of data processing

Conclusion: Getting Statutory Pay Gap Reporting Right
The first data privacy principle means even when data collection and processing is required by law steps must be taken to remain GDPR compliant. As with all data processing reasonable and proportionate steps to maintain privacy and ensure data security, getting this right will improve engagement and trust from employees with your organisation’s needs and help you be seen in a positive light more generally.
- September 2026
- August 2026
- July 2026
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- September 2022
- August 2022
- June 2022
- May 2022
- March 2022
- February 2022
- January 2022
- December 2021
CONTACT US
Switchboard: 0330 221 0547
Training enquiries: 0330 221 0552
Email: hello@wudo.solutions
15 Warland Rd, London, SE18 2EX
Open every day 8am to 8pm except bank holidays.
Get the latest news, resources and special offers direct to your inbox: