Privacy Statement for Workers and Employees

A privacy statement is also frequently referred to as a privacy notice or privacy policy. It is a public declaration by an organisation that explains how it collects, uses, stores, shares, and protects the personal data of individuals.

About the Author
Michael has many years’ experience supporting, developing and improving effective data protection and GDPR compliance systems. He has worked in this field in the public, private and charity sectors including at Board level. This experience has made him the ideal lead trainer for WuDo Solutions’ five-star rated GDPR training course.

Why a Privacy Statement is Necessary for GDPR Compliance: The Right to Be Informed

 

A privacy statement is required under the GDPR (General Data Protection Regulation). It is directly mandated by the “right to be informed”, as outlined in Articles 13 and 14 of the regulation. This right ensures that individuals (referred to as ‘data subjects’) are fully aware of how their personal data is being processed.

Here’s why it’s essential for GDPR compliance:

  1. Transparency Principle (Article 5(1)(a)). The GDPR says that personal data must be processed “lawfully, fairly and in a transparent manner”. A privacy statement is the main way organisations demonstrate this transparency. It ensures that individuals understand what is happening with their data.

  2. Fulfils Article 13 Obligations (Data Collected Directly from the Data Subject). When an organisation collects personal data directly from an individual (e.g., via a website form, through a job application, or during customer sign-up), Article 13 of the GDPR requires the organisation to provide specific information at the time the data is obtained. This key information includes:

    • The identity and contact details of the data controller (the organisation).

    • The contact details of the Data Protection Officer (DPO), if applicable.

    • The purposes for which the personal data is being processed.

    • The lawful basis for that processing (e.g., consent, contract, legal obligation, legitimate interests).

    • The legitimate interests pursued by the controller or a third party (if that’s the lawful basis).

    • The recipients or categories of recipients of the personal data.

    • Whether the data will be transferred to a third country (outside the UK/EEA) and the safeguards in place.

    • The data retention period or the criteria used to determine it.

    • The data subject’s rights (access, rectification, erasure, restriction, data portability, objection, withdrawal of consent).

    • The right to lodge a complaint.

    • Whether providing the data is a statutory or contractual requirement, and the consequences of not providing it.

    • The existence of automated decision-making, including profiling, when and if it happens

  3. Fulfils Article 14 Obligations (Data Not Obtained Directly from the Data Subject). If an organisation obtains personal data from a source other than the individual themselves (e.g., from a third-party lead generator, publicly available records, or another organisation), Article 14 of the GDPR imposes similar, though slightly adjusted, information requirements. This information must be provided within a reasonable period. This should be no later than one month after obtaining the data. However is should be the time of first communication with the individual, or when the data is first disclosed to another recipient. Crucially, it must also include the source from which the personal data originates.

  4. Enables Data Subject Rights. By providing clear information about data processing, the privacy statement empowers individuals to exercise their other GDPR rights effectively. For example, knowing who the controller is and what data is held allows them to make a valid Subject Access Request.

  5. Builds Trust and Confidence. Beyond legal compliance, a clear and accessible privacy statement fosters trust between the organisation and its data subjects. It demonstrates a commitment to transparency and responsible data handling, which is increasingly important for customer loyalty and reputation.

GDPR (General Data Protection Regulation), along with the UK’s Data Protection Act 2018, places significant obligations on organisations regarding the personal data of individuals. This includes not just customers, but crucially, also employees, job applicants, and workers (including contractors and temps). While much of GDPR compliance focuses on customer data, privacy information for the workforce is equally, if not more, critical given the volume and sensitivity of the data involved.

Enjoying this content?
Get articles like this direct to your inbox with our free newsletter. Full of articles, news and resources with all our content accessible in one place. Plus subscribers get exclusive content, priority access to events, and exclusive special offers. You can unsubscribe any time and we won;t use your data for anything else.

Sign Up Here:

 

GDPR

 

Why Privacy Information for the Workforce is Often Overlooked

Despite its importance, employee and worker data privacy often gets less attention than customer data for several reasons:

  1. Internal Focus: Organisations tend to prioritise external-facing compliance, as customer relationships are more directly tied to public perception and sales. Employee data is often seen as an internal HR matter rather than a broader data protection concern.

  2. Perceived Consent: There’s a common misconception that because individuals are part of the organisation (as employees or applicants), they implicitly consent to their data processing. However, under GDPR, consent must be freely given, specific, informed, and unambiguous. Due to the inherent power imbalance in the employer-employee relationship, consent is rarely a valid lawful basis for processing most employee data. Organisations typically rely on other lawful bases like “performance of a contract” (employment contract), “legal obligation” (e.g., tax, national insurance), or “legitimate interests.”

  3. Complexity of Data Types: Employee data is incredibly diverse. It ranges from basic contact details to highly sensitive “special category data” (e.g., health, ethnic origin, trade union membership, biometric data). Managing this array of data, each with its own lawful basis and retention requirements, can be complex.

  4. Legacy Systems and Practices: Many HR systems and manual processes pre-date GDPR, making it challenging to retroactively apply transparent data handling practices.

  5. Lack of Awareness: HR professionals, while experts in employment law, may not always have the same level of expertise in data protection law as dedicated DPOs or privacy officers.

Overlooking these obligations can lead to significant fines, reputational damage, and a loss of trust among the workforce, potentially leading to complaints to the ICO (Information Commissioner’s Office) or even legal action.

 

The Privacy Statement for Workers and Employees

 

For employees, job applicants, and workers, the Privacy Notice should include the same content as any other privacy information, as set out above. It should also be provided at the point at which the data are collected or as soon as possible thereafter. This means it should form part of application forms / packs, or be available online, as well as on an internal intranet or similar library of corporate information.

  1. Identity and Contact Details of the Data Controller. This can be the person’s line manager, or the person leading on recruitment.

  2. Purposes of Processing. A clear and specific explanation of why the organisation collects and uses their personal data. This must be detailed for each purpose (e.g., for recruitment, payroll, performance management, training, health and safety, IT system access, equal opportunities monitoring, disciplinary procedures).

  3. Lawful Basis for Processing. For each purpose, the specific legal ground(s) under GDPR that the organisation relies on. As noted above, this will rarely be based on consent. Instead there will be a mixture of statutory duties (right to work checks, tax information etc.), contract related data processing (operational management, training and development), specific lawful bases for special category data (e.g. health information for employment related occupational health) and a range of legitimate interests such as monitoring for counter-fraud purposes.

  4. Categories of Personal Data Collected. A clear list of the types of personal data collected, including both standard data (e.g., name, address, contact details, NI number, bank details, employment history, qualifications) and any “special category data” (e.g., health information, racial/ethnic origin, religious beliefs, trade union membership, biometric data, criminal conviction data where permitted).

  5. Sources of Personal Data. Where the data originates from, if not directly from the individual (e.g., references from previous employers, background check providers, public sources like LinkedIn for applicants).

  6. Recipients or Categories of Recipients of the Personal Data. Who the organisation shares the data with (e.g., payroll providers, pension schemes, HMRC, benefit providers, IT service providers, legal advisors, insurers, recruitment agencies for applicants).

  7. Transfers to Third Countries. If personal data is transferred outside the UK/EEA, details of the countries and the safeguards in place (e.g., adequacy decisions, Standard Contractual Clauses).

  8. Retention Periods. How long different categories of personal data will be kept, or the criteria used to determine retention periods (e.g., “for the duration of employment plus X years,” “as required by tax law”).

  9. Data Subject Rights: A clear explanation of the individual’s rights under GDPR.

  10. Automated Decision-Making and Profiling. If the organisation uses automated decision-making or profiling that has legal or similarly significant effects on the individual (e.g., some recruitment screening tools).

 

Easy Ways in Which it Can Be Done

 

Transparency is key, and the information must be concise, easily accessible, and understandable.

  1. Dedicated Privacy Notices:

    • Employee Privacy Statement. A comprehensive document covering all aspects of employee data processing, given to all new hires and made available to existing employees.

    • Job Applicant Privacy Statement. A specific notice for job candidates, provided at the point of application (e.g., on the careers page, in the application portal, or alongside the application form).

    • Worker/Contractor Privacy Statement. A separate notice for non-employee workers, tailored to their specific data processing.

  2. Company Intranet/Portal: Publish the full Privacy Notices on an easily accessible internal platform. This ensures employees can refer back to them at any time.

  3. Employee Handbook. Include a summary of the Privacy Notice in the employee handbook, with a clear reference and link to the full document on the intranet.

  4. During Onboarding/Induction: Provide physical copies or clear links to the Privacy Notice during the onboarding process for new employees/workers. This can be combined with a short briefing.

  5. Targeted Communications for Specific Processing. For new data collection or significant changes in how data is processed (e.g., introduction of new monitoring systems, new HR software), send specific notifications or updates.

  6. Layered Privacy Notices: For complex situations, consider a “layered” approach:

    • First layer: A short, high-level summary of the most important information.

    • Second layer: A link to the full, detailed Privacy Notice.

  7. Training and Awareness: Integrate data protection awareness into mandatory employee training. This helps employees understand the why behind the policies and their own rights. This also reminds them where to find the Privacy Notices.

  8. Interactive Tools (where feasible). For small (but perfectly formed) organisations like WuDo Solutions a single privacy notice is quite easy to do. For larger organisations, an online portal where employees can view their data categories, processing purposes, and even manage some preferences can enhance transparency and user control.

  9. Clear Signposting: Ensure that links to privacy notices are clear, prominent, and consistently named. Avoid burying them deep within obscure sections of the intranet.

  10. Plain Language: Write privacy notices in clear, concise, and jargon-free language. Avoid overly legalistic terms where simpler alternatives exist. Using headings, bullet points, and tables can improve readability.

 

By implementing these measures, organisations can move beyond mere compliance checklists. Instead they can foster a culture of transparency and trust with their most valuable asset – their people. They can also ensure their privacy statement complies with their statutory duties and avoid the risks of a GDPR breach.

Learn About the GDPR

Gain the practical skills you need to identify and manage data protection and GDPR with this five-star rated training course.

Available in person, online or in-house the focus on practical skills and unique post-course support you get by learning with us will ensure you and your organisation can tackle this key governance activity with confidence.

Five star training testimonial