Writing Your Employee Privacy Notice

What Employers Must Include in an Employee Privacy Notice (Worker-Facing Privacy Statement) to Be GDPR Compliant

An employee privacy notice (sometimes called a privacy statement or privacy policy) sets out how an employer collects, uses, stores, and shares personal data about its workforce. Under the UK GDPR, this notice plays a central role in meeting the right to be informed and demonstrating transparency.

A privacy notice is a legal requirement. It also functions as a reputational safeguard: if workers feel blindsided by monitoring, data sharing, or retention practices, trust collapses quickly.

This guide explains what an employer must include in a worker-facing privacy notice to remain GDPR compliant, along with practical drafting tips and common pitfalls.

About the Author
Michael has many years’ experience supporting, developing and improving effective data protection and GDPR compliance systems. He has worked in this field in the public, private and charity sectors including at Board level. This experience has made him the ideal lead trainer for WuDo Solutions’ five-star rated GDPR training course.

 

Periodic Table of the GDPR

Visit our GDPR Resource Page for a Wealth of Free Tools and Materials on the GDPR and GDPR Compliance 


1. Why an employee privacy notice matters

The UK GDPR requires organisations to provide clear information about personal data processing. Employers must give this information to workers:

  • at the point of collection (or as soon as reasonably possible), and
  • in an accessible, understandable format.

This requirement supports fairness. Workers need to understand what happens to their data so they can exercise their rights and make informed decisions.

A strong privacy notice also reduces operational risk. It helps employers avoid complaints, grievances, and regulator scrutiny—particularly where monitoring, HR investigations, or health data are involved.


2. When employers must provide the privacy notice

Employers should provide the notice:

  • during recruitment (applicant privacy notice), and
  • at onboarding / contract issue (employee privacy notice), and
  • whenever processing changes materially (for example, introducing a new monitoring tool).

Best practice includes making it continuously available via:

  • recruitment packs
  • HR portals,
  • staff intranet,
  • induction packs,
  • and links in key policies (IT acceptable use, CCTV, monitoring, disciplinary policies).

3. What employers must include: the mandatory GDPR content

Most employee privacy notices rely on the information requirements in Article 13 (data collected from the worker) and Article 14 (data collected from elsewhere).

Below is the content employers must include to be compliant.


A) Identity and contact details of the employer (data controller)

Workers must know who controls their data.

Include:

  • the legal name of the organisation,
  • registered address,
  • contact email or privacy inbox,
  • relevant departments (HR, IT, compliance).

Tip: If the organisation operates under multiple trading names, or is part of a group of companies, clarify which legal entity acts as the employer and controller.


B) Data Protection Officer (DPO) or privacy contact point

If the organisation has a DPO (or equivalent privacy lead), include:

  • name or role title,
  • contact details,
  • how workers can contact them confidentially.

Even if no DPO is legally required, workers still need a clear route to raise privacy questions. In these circumstances you might direct low-level queries to line managers, and more complex queries to the Head of HR or equivalent.


C) What personal data the employer collects (categories of data)

This section must explain the types of data processed. Avoid vague statements like “we may collect personal information about you”.

Common categories include:

Core identity and contact data

  • name, address, date of birth, NI number
  • emergency contacts
  • next of kin details

Employment and HR records

  • job title, manager, department
  • contract terms, salary, working hours
  • performance reviews and probation notes
  • training records and qualifications

Recruitment and vetting data

  • CVs, interview notes, references
  • right to work documentation
  • DBS checks (where relevant)

Attendance and conduct

  • sickness absence and return-to-work notes
  • disciplinary records
  • grievance and investigation records

Technical and usage data (often overlooked)

  • login records and access logs
  • email metadata (and sometimes content, in investigations)
  • device identifiers and system audit logs

Monitoring data

  • CCTV footage
  • building access control logs
  • time and attendance systems

Special category data (higher risk)

  • occupational health reports
  • disability and workplace adjustments
  • equality and diversity data (ethnicity, religion, sexual orientation)
  • union membership (where processed)

Workers deserve clarity here. This section often becomes the “trust test”.


D) The purposes of processing (why the employer uses the data)

Employers must explain why they process worker data. This must be specific enough to be meaningful.

Typical purposes include:

  • recruitment and selection
  • issuing contracts and managing employment relationships
  • payroll, pension, and benefits administration
  • managing working time, leave, and absence
  • performance management and professional development
  • workforce planning and internal reporting
  • security, fraud prevention, and access control
  • health and safety compliance
  • managing disciplinary matters, grievances, and investigations
  • compliance with legal obligations and responding to regulators
  • safeguarding (where relevant)
  • defending or pursuing legal claims

Good practice: Use a bullet list and group by lifecycle stage (recruitment → employment → exit).


E) Lawful bases for processing (Article 6)

Employers must state the lawful basis for processing employee data. This is frequently mishandled.

Common lawful bases in employment include:

  • Contract (necessary to manage employment terms)
  • Legal obligation (tax, employment law, health and safety duties)
  • Legitimate interests (security, internal admin, fraud prevention)
  • Public task (public bodies performing statutory functions)

Avoid over-reliance on consent. Consent rarely counts as “freely given” in an employment relationship because of the power imbalance.


F) Additional lawful basis for special category data (Article 9)

If the employer processes special category data (most do), the notice must explain the Article 9 condition relied upon, such as:

  • employment, social security and social protection law obligations
  • occupational health and fitness for work
  • public health and health and safety
  • equality of opportunity monitoring
  • establishment, exercise or defence of legal claims
  • explicit consent (only in limited, genuinely optional cases)

This section reassures staff that sensitive data has heightened protection.


G) Who the employer shares worker data with (recipients)

Workers must know who receives their data and why.

Include:

  • payroll providers
  • pension scheme administrators
  • benefits platforms
  • IT providers (email hosting, HR systems)
  • occupational health providers
  • legal advisors and insurers
  • regulators and public authorities (HMRC, police, safeguarding bodies)
  • training providers (where relevant)
  • parent companies / group organisations (where applicable)

You can name recipients or describe categories, but clarity matters.

Tip: Call out processors vs independent controllers where you can, especially for outsourced HR or occupational health services.


H) International transfers (if data leaves the UK)

If personal data transfers outside the UK (or UK adequacy framework), the notice must explain:

  • where it goes,
  • why it transfers,
  • what safeguards exist (e.g., adequacy decision, UK IDTA, SCCs).

This often applies when employers use cloud platforms hosted outside the UK.


I) How long the employer keeps the data (retention)

Workers must know how long data will be retained, or the criteria used.

Include:

  • retention periods by record type (payroll, recruitment, disciplinary, CCTV)
  • rationale (legal limitation periods, regulatory requirements)
  • deletion and secure disposal approach

Avoid: “We keep data as long as necessary” without any further detail. That does not meet the transparency requirement.


J) Worker rights under GDPR

The notice must explain the worker’s rights, including the right:

  • of access (also known as subject access requests)
  • to rectification
  • of erasure (limited in employment contexts)
  • to restrict processing
  • to object (especially where legitimate interests applies)
  • of data portability (rare in HR but possible)
  • and rights related to automated decision-making (if applicable)

Make it clear how workers can exercise these rights and who to contact.


K) Right to complain to the ICO

Workers must be told they can complain to the regulator.

Include:

  • the ICO name,
  • the right to lodge a complaint,
  • ideally a link or instruction on how to do it.

L) Whether workers must provide data (and consequences if they don’t)

Where processing is required by contract or law, employers must state:

  • whether the worker must provide the data,
  • what happens if they don’t.

Examples:

  • refusal to provide right-to-work documentation may prevent employment.
  • failure to provide bank details may delay payment.

M) Where data comes from (if not collected directly)

If the employer collects data from third parties, Article 14 requires transparency about sources, such as:

  • references from previous employers
  • recruitment agencies
  • background screening providers
  • professional regulators
  • social media or public sources (if used)

Employers should be cautious with “open source” data collection. Workers may find it intrusive if not clearly explained.


N) Automated decision-making and profiling (if used)

If the employer uses automated decisions that significantly affect workers (e.g., automated screening, scoring, scheduling decisions), the notice must include:

  • that automation occurs,
  • meaningful information about the logic involved,
  • the significance and consequences for workers,
  • the right to request human review (where applicable).

Even if you only use automation in recruitment filtering, say so.

Enjoying this content?
Get articles like this direct to your inbox with our free newsletter. Full of articles, news and resources with all our content accessible in one place. Plus subscribers get exclusive content, priority access to events, and exclusive special offers. You can unsubscribe any time and we won;t use your data for anything else.

Sign Up Here:

 


4. Additional content employers should include (best practice)

The following aren’t always mandatory, but they strongly improve compliance and reduce disputes.

Monitoring and surveillance transparency

If the employer monitors workers (CCTV, email, internet usage, tracking tools), include:

  • what is monitored,
  • why,
  • how often,
  • who can access the information,
  • retention periods,
  • and safeguards.

This is where many employers get complaints.

Internal investigations and HR casework

Explain that the employer may process data for:

  • disciplinary investigations,
  • grievances,
  • safeguarding,
  • whistleblowing.

Clarify that the employer will handle information confidentially and share only where necessary.

Data security measures (high-level)

You don’t need to disclose security blueprints, but reassure staff that you use:

  • access controls,
  • encryption,
  • secure storage,
  • restricted sharing,
  • audit logs.

How to raise concerns

Give staff a clear route to report:

  • suspected misuse of data,
  • confidentiality breaches,
  • security concerns.

This supports accountability and good culture.


5. Common mistakes employers make (and how to avoid them)

❌ Overusing consent

Consent is rarely valid in employment. Use contract, legal obligation, legitimate interests, or public task instead.

❌ Forgetting special category processing

HR almost always processes health or equality data. Article 9 must be addressed.

❌ Missing monitoring transparency

Monitoring without clear notice often feels covert and unfair—even if technically lawful.

❌ Retention statements that are too vague

Workers want to know how long records remain “on file”. Provide meaningful timeframes.

❌ Not updating the notice after organisational change

New HR systems, new payroll providers, new monitoring tools, and restructures all require review.


6. How to structure an employee privacy notice (recommended layout)

A worker-facing notice should be easy to scan. A good structure looks like this:

  1. Who we are (controller details)
  2. What data we collect
  3. Why we use it (purposes)
  4. Lawful bases (Article 6 + Article 9)
  5. Who we share it with
  6. International transfers
  7. Retention periods
  8. Worker rights and how to exercise them
  9. Complaints and contact routes
  10. Updates to this notice

7. Final thought: transparency prevents conflict

A compliant employee privacy notice does more than satisfy GDPR. It reduces suspicion, prevents misunderstanding, and helps staff feel respected.

In the workplace, privacy issues quickly become people issues. Clear, truthful communication about employee data processing protects everyone involved—workers, managers, and the organisation itself.

If you want to build trust internally, start with transparency.

Learn About the GDPR

Gain the practical skills you need to identify and manage data protection and GDPR with this five-star rated training course.

Available in person, online or in-house the focus on practical skills and unique post-course support you get by learning with us will ensure you and your organisation can tackle this key governance activity with confidence.

Five star training testimonial