A privacy statement is also frequently referred to as a privacy notice or privacy policy. It is a public declaration by an organisation that explains how it collects, uses, stores, shares, and protects the personal data of individuals.
Why a Privacy Statement is Necessary for GDPR Compliance: The Right to Be Informed
A privacy statement is required under the GDPR (General Data Protection Regulation). It is directly mandated by the “right to be informed”, as outlined in Articles 13 and 14 of the regulation. This right ensures that individuals (referred to as ‘data subjects’) are fully aware of how their personal data is being processed.
Here’s why it’s essential for GDPR compliance:
-
Transparency Principle (Article 5(1)(a)). The GDPR says that personal data must be processed “lawfully, fairly and in a transparent manner”. A privacy statement is the main way organisations demonstrate this transparency. It ensures that individuals understand what is happening with their data.
-
Fulfils Article 13 Obligations (Data Collected Directly from the Data Subject). When an organisation collects personal data directly from an individual (e.g., via a website form, through a job application, or during customer sign-up), Article 13 of the GDPR requires the organisation to provide specific information at the time the data is obtained. This key information includes:
-
The identity and contact details of the data controller (the organisation).
-
The contact details of the Data Protection Officer (DPO), if applicable.
-
The purposes for which the personal data is being processed.
-
The lawful basis for that processing (e.g., consent, contract, legal obligation, legitimate interests).
-
The legitimate interests pursued by the controller or a third party (if that’s the lawful basis).
-
The recipients or categories of recipients of the personal data.
-
Whether the data will be transferred to a third country (outside the UK/EEA) and the safeguards in place.
-
The data retention period or the criteria used to determine it.
-
The data subject’s rights (access, rectification, erasure, restriction, data portability, objection, withdrawal of consent).
-
The right to lodge a complaint.
-
Whether providing the data is a statutory or contractual requirement, and the consequences of not providing it.
-
The existence of automated decision-making, including profiling, when and if it happens
-
-
Fulfils Article 14 Obligations (Data Not Obtained Directly from the Data Subject). If an organisation obtains personal data from a source other than the individual themselves (e.g., from a third-party lead generator, publicly available records, or another organisation), Article 14 of the GDPR imposes similar, though slightly adjusted, information requirements. This information must be provided within a reasonable period. This should be no later than one month after obtaining the data. However is should be the time of first communication with the individual, or when the data is first disclosed to another recipient. Crucially, it must also include the source from which the personal data originates.
-
Enables Data Subject Rights. By providing clear information about data processing, the privacy statement empowers individuals to exercise their other GDPR rights effectively. For example, knowing who the controller is and what data is held allows them to make a valid Subject Access Request.
-
Builds Trust and Confidence. Beyond legal compliance, a clear and accessible privacy statement fosters trust between the organisation and its data subjects. It demonstrates a commitment to transparency and responsible data handling, which is increasingly important for customer loyalty and reputation.
GDPR (General Data Protection Regulation), along with the UK’s Data Protection Act 2018, places significant obligations on organisations regarding the personal data of individuals. This includes not just customers, but crucially, also employees, job applicants, and workers (including contractors and temps). While much of GDPR compliance focuses on customer data, privacy information for the workforce is equally, if not more, critical given the volume and sensitivity of the data involved.
Sign Up Here:
Despite its importance, employee and worker data privacy often gets less attention than customer data for several reasons: Internal Focus: Organisations tend to prioritise external-facing compliance, as customer relationships are more directly tied to public perception and sales. Employee data is often seen as an internal HR matter rather than a broader data protection concern. Perceived Consent: There’s a common misconception that because individuals are part of the organisation (as employees or applicants), they implicitly consent to their data processing. However, under GDPR, consent must be freely given, specific, informed, and unambiguous. Due to the inherent power imbalance in the employer-employee relationship, consent is rarely a valid lawful basis for processing most employee data. Organisations typically rely on other lawful bases like “performance of a contract” (employment contract), “legal obligation” (e.g., tax, national insurance), or “legitimate interests.” Complexity of Data Types: Employee data is incredibly diverse. It ranges from basic contact details to highly sensitive “special category data” (e.g., health, ethnic origin, trade union membership, biometric data). Managing this array of data, each with its own lawful basis and retention requirements, can be complex. Legacy Systems and Practices: Many HR systems and manual processes pre-date GDPR, making it challenging to retroactively apply transparent data handling practices. Lack of Awareness: HR professionals, while experts in employment law, may not always have the same level of expertise in data protection law as dedicated DPOs or privacy officers. Overlooking these obligations can lead to significant fines, reputational damage, and a loss of trust among the workforce, potentially leading to complaints to the ICO (Information Commissioner’s Office) or even legal action. For employees, job applicants, and workers, the Privacy Notice should include the same content as any other privacy information, as set out above. It should also be provided at the point at which the data are collected or as soon as possible thereafter. This means it should form part of application forms / packs, or be available online, as well as on an internal intranet or similar library of corporate information. Identity and Contact Details of the Data Controller. This can be the person’s line manager, or the person leading on recruitment. Purposes of Processing. A clear and specific explanation of why the organisation collects and uses their personal data. This must be detailed for each purpose (e.g., for recruitment, payroll, performance management, training, health and safety, IT system access, equal opportunities monitoring, disciplinary procedures). Lawful Basis for Processing. For each purpose, the specific legal ground(s) under GDPR that the organisation relies on. As noted above, this will rarely be based on consent. Instead there will be a mixture of statutory duties (right to work checks, tax information etc.), contract related data processing (operational management, training and development), specific lawful bases for special category data (e.g. health information for employment related occupational health) and a range of legitimate interests such as monitoring for counter-fraud purposes. Categories of Personal Data Collected. A clear list of the types of personal data collected, including both standard data (e.g., name, address, contact details, NI number, bank details, employment history, qualifications) and any “special category data” (e.g., health information, racial/ethnic origin, religious beliefs, trade union membership, biometric data, criminal conviction data where permitted). Sources of Personal Data. Where the data originates from, if not directly from the individual (e.g., references from previous employers, background check providers, public sources like LinkedIn for applicants). Recipients or Categories of Recipients of the Personal Data. Who the organisation shares the data with (e.g., payroll providers, pension schemes, HMRC, benefit providers, IT service providers, legal advisors, insurers, recruitment agencies for applicants). Transfers to Third Countries. If personal data is transferred outside the UK/EEA, details of the countries and the safeguards in place (e.g., adequacy decisions, Standard Contractual Clauses). Retention Periods. How long different categories of personal data will be kept, or the criteria used to determine retention periods (e.g., “for the duration of employment plus X years,” “as required by tax law”). Data Subject Rights: A clear explanation of the individual’s rights under GDPR. Automated Decision-Making and Profiling. If the organisation uses automated decision-making or profiling that has legal or similarly significant effects on the individual (e.g., some recruitment screening tools). Transparency is key, and the information must be concise, easily accessible, and understandable. Dedicated Privacy Notices: Employee Privacy Statement. A comprehensive document covering all aspects of employee data processing, given to all new hires and made available to existing employees. Job Applicant Privacy Statement. A specific notice for job candidates, provided at the point of application (e.g., on the careers page, in the application portal, or alongside the application form). Worker/Contractor Privacy Statement. A separate notice for non-employee workers, tailored to their specific data processing. Company Intranet/Portal: Publish the full Privacy Notices on an easily accessible internal platform. This ensures employees can refer back to them at any time. Employee Handbook. Include a summary of the Privacy Notice in the employee handbook, with a clear reference and link to the full document on the intranet. During Onboarding/Induction: Provide physical copies or clear links to the Privacy Notice during the onboarding process for new employees/workers. This can be combined with a short briefing. Targeted Communications for Specific Processing. For new data collection or significant changes in how data is processed (e.g., introduction of new monitoring systems, new HR software), send specific notifications or updates. Layered Privacy Notices: For complex situations, consider a “layered” approach: First layer: A short, high-level summary of the most important information. Second layer: A link to the full, detailed Privacy Notice. Training and Awareness: Integrate data protection awareness into mandatory employee training. This helps employees understand the why behind the policies and their own rights. This also reminds them where to find the Privacy Notices. Interactive Tools (where feasible). For small (but perfectly formed) organisations like WuDo Solutions a single privacy notice is quite easy to do. For larger organisations, an online portal where employees can view their data categories, processing purposes, and even manage some preferences can enhance transparency and user control. Clear Signposting: Ensure that links to privacy notices are clear, prominent, and consistently named. Avoid burying them deep within obscure sections of the intranet. Plain Language: Write privacy notices in clear, concise, and jargon-free language. Avoid overly legalistic terms where simpler alternatives exist. Using headings, bullet points, and tables can improve readability. By implementing these measures, organisations can move beyond mere compliance checklists. Instead they can foster a culture of transparency and trust with their most valuable asset – their people. They can also ensure their privacy statement complies with their statutory duties and avoid the risks of a GDPR breach. Gain the practical skills you need to identify and manage data protection and GDPR with this five-star rated training course. Available in person, online or in-house the focus on practical skills and unique post-course support you get by learning with us will ensure you and your organisation can tackle this key governance activity with confidence.

Why Privacy Information for the Workforce is Often Overlooked
The Privacy Statement for Workers and Employees
Easy Ways in Which it Can Be Done
- July 2026
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- October 2022
- September 2022
- August 2022
- June 2022
- May 2022
- March 2022
- February 2022
- January 2022
- December 2021
CONTACT US
Switchboard: 0330 221 0547
Training enquiries: 0330 221 0552
Email: hello@wudo.solutions
15 Warland Rd, London, SE18 2EX
Open every day 8am to 8pm except bank holidays.
Get the latest news, resources and special offers direct to your inbox: