Getting GDPR Right For Statutory Pay Gap Reporting

For some time larger organisations have been required to report data on gender pay gaps. Data must be reported to the UK Government’s gender pay-gap portal and a report must be published on each relevant organisation’s website annually.

From April 2027 organisations will also need to submit data and publish reports on pay gaps broken down by ethnicity and by disability.

They must also publish a plan for how the intend to tackle significant pay gaps.

The Data

The requirement covers the same metrics as gender pay gap reporting:

  • Mean (average) hourly pay difference.
  • Median (middle) hourly pay difference.
  • Pay quarters (percentage of staff in four equally sized pay bands).
  • Mean bonus pay difference.
  • Median bonus pay difference.
  • Percentage of employees receiving bonus pay

The metrics will be broken down by the following categories:

  • Disability: Uses a binary approach (disabled versus non-disabled) based on the definition of disability in the Equality Act 2010
  • Ethnicity: reporting across Office for National Statistics (ONS) groups or a binary white-versus-other breakdown.
  • Declaration Rates: Companies must state the percentage of workers who chose not to share their data

GDPR Requirements

Lawful Basis

The GDPR has a lawful basis for the collection and processing of personal data for a statutory duty – Article 5(1)c: processing is necessary for compliance with a legal obligation to which the controller (employer in this context) is subject.

Because the data collected falls within the definition of sensitive personal data a second lawful basis is needed but fortunately this data processing can be covered by Article 9(2)b – for the purposes of employment.

However, employers must be mindful of the first privacy principle which requires their data processing to be lawful, fair and transparent. Implementing appropriate systems to fulfil this statutory duty must meet all three elements of the principle.

Fairness

Fairness will have both technical and organisational elements (we discuss data security below).

The data collection and reporting requirement recognises that people may choose not to share the relevant data. Organisations must not put undue pressure on individuals to share data about themselves they do not want to, as this could result in enforcement action from the ICO.

There is also a rule in the requirement that is there are less than 10 people in an particular metric then this does not need to be reported or published. This helps ensure data reliability but also helps reduces the chance of individuals being identified from any aggregate data.

When it comes to reporting and action planning you cannot rely on the statutory duty lawful basis to include things like case studies, interviews or personal stories and another lawful basis must be found. Consent is an option but employers must always be careful when considering consent as the imbalance of power between employer and employee makes it hard to be sure consent is freely given, and therefore valid.

Transparency

There are three main elements to being open and transparent.

The first is to ensure that the data collection, processing, reporting, publication and action planning are captured in your Record of Processing Activity (RoPA). A RoPA is a statutory requirement that should set out all your personal data processing, whether of employers, customers, suppliers or others.

Secondly you must update your privacy statement to capture this statutory requirement, what data you seek to collect, and what you will do with it.

The third thing is to produce comms for your employees explaining the new requirement and what it means. For example, we worked with a client to produce a template letter that looks like this:

As part of our ongoing commitment to transparency, inclusion, and workplace equity, we are preparing to launch our annual pay gap analysis. As an organisation with over 250 employees, we participate in mandatory reporting of this data.

This year, we are tracking pay representation across gender, ethnicity, and disability status.

Why are we collecting this data?

Pay gap reporting is not an audit of individual pay, nor does it mean people in identical roles are paid differently. Instead, it measures how representation is spread across all levels of our business. Collecting this information helps us see where structural barriers might exist in recruitment, retention, or career progression, allowing us to take meaningful, targeted action.

How your data is protected:

  • Strict Confidentiality: Your responses are safely stored and processed in accordance with strict data protection guidelines. The data will only be accessed by a restricted team responsible for compliance and analysis.
  • Anonymised Reporting: Final reports look purely at aggregate percentages and broad organisational bands. No individuals will ever be identifiable in the published figures, especially within smaller teams.
  • Your Choice Matters: While high participation gives us the clearest picture of our workforce, every single question includes a ‘Prefer not to say’ option. You can choose exactly how much you wish to share.

How to submit your information:

The collection will be handled entirely through a secure internal online form. We will share the direct link alongside the official submission deadline as soon as they are finalised

 

Data Retention

When people first submit their data it is likely that it will be identifiable data. Although you will not necessarily be collecting names you are likely to require data to help you classify data by the relevant metric such as role title, department or team. If you are using an online form you will need a mechanism to ensure everyone submits data only once, and if using a paper form then people may have easily recognisable handwriting.

Once you have collected the data you must ensure that anything potentially identifiable is destroyed and only aggregate data without direct identifiers is retained. This will help ensure you meet the GDPR’s requirements and help improve people’s confidence in your systems.

The only exception to this is if you can identify a legitimate reason to retain some of the data by exception. If this happens you must be clear what the reason is, ensure you keep only the minimum necessary data, and retain it for no longer than necessary.

 

Anonymisation and Pseudonymisation

To minimise data retention and still comply with reporting requirements organisations should ensure they anonymise or pseudonymise the data they collect.

Anonymisation means removing all identifiers from the data and aggregating for reporting and action planning. You should ensure you do not retain any copies of identifiable data to ensure full anonymisation.

Pseudonymisation is a technique where data is effectively anonymised for a particular purposes by assigning each response a unique code, duplicating the data and removing all identifiable data from the duplicate. The advantage of pseudonymisation is that the data sets can be recombined using the code if necessary. For example, in medical research an anonymous patient may need a medical follow up by exception and pseudonymisation allows the patient to be identified without giving researchers access to personal information.

You can watch a brief explanation of pseudonymisation here:

Data Security

Effective data security will be key to gaining trust, which will in turn improve participation rates. All data security relies on a combination of technical and organisational measures.

Technical measures

Organisations should ensure that reporting can be done securely and the recording and transmission or the data is not open to general access or interception.

Access rights must also be considered. Who should have access to individual and aggregate records? What restrictions should be put in place to prevent unauthorised access?

Organisational measures

People with a role in the collection and analysis of data, whether it is managers encouraging their teams to take part, HR professionals involved in action planning or IT, should understand the limits of their role when it comes to accessing relevant data and the consequences of non-compliance.

 

People’s Rights

People who choose to take part in this data collection will still have rights under the GDPR but how they operate is different to the way they would work if, for example, the lawful basis was consent. Briefly rights apply like this:

  • The right to be informed is complied with via your privacy information and communications about the necessary data collection.
  • The right of access would apply if you retain identifiable data about individuals, so it depends how and when you anonymise data and delete any identifiable responses. If you do retain identifiable data it should be disclosed alongside other identifiable you hold and process.
  • Rights to rectification would only apply if identifiable data were retained and were incomplete or inaccurate. Given the reporting requirements it may be difficult to correct any submissions and it is possible this could be complied with by encouraging people to make a full and accurate submission in future.
  • Rights to erasure are unlikely to apply given the statutory basis for the data collection, and again people could simply refuse to take part in any future data submissions. As with other rights, it would only apply to identifiable data.
  • The right to data portability would not apply for this data processing.
  • Rights to object would again not apply for this data processing.
  • The right to restrict processing may apply in certain limited circumstances. For example, the person whose data you have collected could ask you to keep the identifiable data for a certain period for specific reasons.
  • Rights to automated decision making and profiling are unlikely to apply as you are not making a decision about individuals via automated means. You might need to be careful when it comes to profiling due to the action planning element of the statutory duty. For example you might track the performance data of individuals based on reportable characteristics and make decisions about them based on that tracking. This could impose additional duties on you to ensure you remain GDPR compliant.

 

How to Be GDPR Compliant for Statutory Pay Gap Reporting

One last element to consider when processing sensitive personal data for the first time is a data protection impact assessment, or DPIA. This is a tool that should be used to assess and try to mitigate data processing that poses material risks to data subjects. Strictly speaking, a DPIA should be used to help you decide IF you should proceed with some proposed data processing but for organisations that identify significant risks for this requirement should use a DPIA to

  • rigorously analyse the risks and identify potential mitigations
  • demonstrate accountability by having this risk analysis available in the event of any complaint or challenge

 

Your Checklist

Whether or not you do a DPIA consider the following checklist of activities to help you remain GDPR compliant for this statutory reporting:

  • we understand the data that we need to collect and what to do with it
  • we have updated our Record of Processing Activity
  • we have updated our employee-facing Privacy Statement
  • we have instituted internal comms to help people understand
  • we have briefed managers, HR, IT (etc.) on requirements and their duties
  • we have put in place appropriate systems for data collection, storage and destruction
  • we have considered what particular risks may arise in our context for this kind of data processing

 

Statutory reporting GDPR compliance checklist

Conclusion: Getting Statutory Pay Gap Reporting Right

The first data privacy principle means even when data collection and processing is required by law steps must be taken to remain GDPR compliant. As with all data processing reasonable and proportionate steps to maintain privacy and ensure data security, getting this right will improve engagement and trust from employees with your organisation’s needs and help you be seen in a positive light more generally.