What Employers Must Include in an Employee Privacy Notice (Worker-Facing Privacy Statement) to Be GDPR Compliant
An employee privacy notice (sometimes called a privacy statement or privacy policy) sets out how an employer collects, uses, stores, and shares personal data about its workforce. Under the UK GDPR, this notice plays a central role in meeting the right to be informed and demonstrating transparency.
A privacy notice is a legal requirement. It also functions as a reputational safeguard: if workers feel blindsided by monitoring, data sharing, or retention practices, trust collapses quickly.
This guide explains what an employer must include in a worker-facing privacy notice to remain GDPR compliant, along with practical drafting tips and common pitfalls.

Visit our GDPR Resource Page for a Wealth of Free Tools and Materials on the GDPR and GDPR Compliance
1. Why an employee privacy notice matters
The UK GDPR requires organisations to provide clear information about personal data processing. Employers must give this information to workers:
- at the point of collection (or as soon as reasonably possible), and
- in an accessible, understandable format.
This requirement supports fairness. Workers need to understand what happens to their data so they can exercise their rights and make informed decisions.
A strong privacy notice also reduces operational risk. It helps employers avoid complaints, grievances, and regulator scrutiny—particularly where monitoring, HR investigations, or health data are involved.
2. When employers must provide the privacy notice
Employers should provide the notice:
- during recruitment (applicant privacy notice), and
- at onboarding / contract issue (employee privacy notice), and
- whenever processing changes materially (for example, introducing a new monitoring tool).
Best practice includes making it continuously available via:
- recruitment packs
- HR portals,
- staff intranet,
- induction packs,
- and links in key policies (IT acceptable use, CCTV, monitoring, disciplinary policies).
3. What employers must include: the mandatory GDPR content
Most employee privacy notices rely on the information requirements in Article 13 (data collected from the worker) and Article 14 (data collected from elsewhere).
Below is the content employers must include to be compliant.
A) Identity and contact details of the employer (data controller)
Workers must know who controls their data.
Include:
- the legal name of the organisation,
- registered address,
- contact email or privacy inbox,
- relevant departments (HR, IT, compliance).
Tip: If the organisation operates under multiple trading names, or is part of a group of companies, clarify which legal entity acts as the employer and controller.
B) Data Protection Officer (DPO) or privacy contact point
If the organisation has a DPO (or equivalent privacy lead), include:
- name or role title,
- contact details,
- how workers can contact them confidentially.
Even if no DPO is legally required, workers still need a clear route to raise privacy questions. In these circumstances you might direct low-level queries to line managers, and more complex queries to the Head of HR or equivalent.
C) What personal data the employer collects (categories of data)
This section must explain the types of data processed. Avoid vague statements like “we may collect personal information about you”.
Common categories include:
Core identity and contact data
- name, address, date of birth, NI number
- emergency contacts
- next of kin details
Employment and HR records
- job title, manager, department
- contract terms, salary, working hours
- performance reviews and probation notes
- training records and qualifications
Recruitment and vetting data
- CVs, interview notes, references
- right to work documentation
- DBS checks (where relevant)
Attendance and conduct
- sickness absence and return-to-work notes
- disciplinary records
- grievance and investigation records
Technical and usage data (often overlooked)
- login records and access logs
- email metadata (and sometimes content, in investigations)
- device identifiers and system audit logs
Monitoring data
- CCTV footage
- building access control logs
- time and attendance systems
Special category data (higher risk)
- occupational health reports
- disability and workplace adjustments
- equality and diversity data (ethnicity, religion, sexual orientation)
- union membership (where processed)
Workers deserve clarity here. This section often becomes the “trust test”.
D) The purposes of processing (why the employer uses the data)
Employers must explain why they process worker data. This must be specific enough to be meaningful.
Typical purposes include:
- recruitment and selection
- issuing contracts and managing employment relationships
- payroll, pension, and benefits administration
- managing working time, leave, and absence
- performance management and professional development
- workforce planning and internal reporting
- security, fraud prevention, and access control
- health and safety compliance
- managing disciplinary matters, grievances, and investigations
- compliance with legal obligations and responding to regulators
- safeguarding (where relevant)
- defending or pursuing legal claims
Good practice: Use a bullet list and group by lifecycle stage (recruitment → employment → exit).
E) Lawful bases for processing (Article 6)
Employers must state the lawful basis for processing employee data. This is frequently mishandled.
Common lawful bases in employment include:
- Contract (necessary to manage employment terms)
- Legal obligation (tax, employment law, health and safety duties)
- Legitimate interests (security, internal admin, fraud prevention)
- Public task (public bodies performing statutory functions)
Avoid over-reliance on consent. Consent rarely counts as “freely given” in an employment relationship because of the power imbalance.
F) Additional lawful basis for special category data (Article 9)
If the employer processes special category data (most do), the notice must explain the Article 9 condition relied upon, such as:
- employment, social security and social protection law obligations
- occupational health and fitness for work
- public health and health and safety
- equality of opportunity monitoring
- establishment, exercise or defence of legal claims
- explicit consent (only in limited, genuinely optional cases)
This section reassures staff that sensitive data has heightened protection.
G) Who the employer shares worker data with (recipients)
Workers must know who receives their data and why.
Include:
- payroll providers
- pension scheme administrators
- benefits platforms
- IT providers (email hosting, HR systems)
- occupational health providers
- legal advisors and insurers
- regulators and public authorities (HMRC, police, safeguarding bodies)
- training providers (where relevant)
- parent companies / group organisations (where applicable)
You can name recipients or describe categories, but clarity matters.
Tip: Call out processors vs independent controllers where you can, especially for outsourced HR or occupational health services.
H) International transfers (if data leaves the UK)
If personal data transfers outside the UK (or UK adequacy framework), the notice must explain:
- where it goes,
- why it transfers,
- what safeguards exist (e.g., adequacy decision, UK IDTA, SCCs).
This often applies when employers use cloud platforms hosted outside the UK.
I) How long the employer keeps the data (retention)
Workers must know how long data will be retained, or the criteria used.
Include:
- retention periods by record type (payroll, recruitment, disciplinary, CCTV)
- rationale (legal limitation periods, regulatory requirements)
- deletion and secure disposal approach
Avoid: “We keep data as long as necessary” without any further detail. That does not meet the transparency requirement.
J) Worker rights under GDPR
The notice must explain the worker’s rights, including the right:
- of access (also known as subject access requests)
- to rectification
- of erasure (limited in employment contexts)
- to restrict processing
- to object (especially where legitimate interests applies)
- of data portability (rare in HR but possible)
- and rights related to automated decision-making (if applicable)
Make it clear how workers can exercise these rights and who to contact.
K) Right to complain to the ICO
Workers must be told they can complain to the regulator.
Include:
- the ICO name,
- the right to lodge a complaint,
- ideally a link or instruction on how to do it.
L) Whether workers must provide data (and consequences if they don’t)
Where processing is required by contract or law, employers must state:
- whether the worker must provide the data,
- what happens if they don’t.
Examples:
- refusal to provide right-to-work documentation may prevent employment.
- failure to provide bank details may delay payment.
M) Where data comes from (if not collected directly)
If the employer collects data from third parties, Article 14 requires transparency about sources, such as:
- references from previous employers
- recruitment agencies
- background screening providers
- professional regulators
- social media or public sources (if used)
Employers should be cautious with “open source” data collection. Workers may find it intrusive if not clearly explained.
N) Automated decision-making and profiling (if used)
If the employer uses automated decisions that significantly affect workers (e.g., automated screening, scoring, scheduling decisions), the notice must include:
- that automation occurs,
- meaningful information about the logic involved,
- the significance and consequences for workers,
- the right to request human review (where applicable).
Even if you only use automation in recruitment filtering, say so.
Sign Up Here:
The following aren’t always mandatory, but they strongly improve compliance and reduce disputes. If the employer monitors workers (CCTV, email, internet usage, tracking tools), include: This is where many employers get complaints. Explain that the employer may process data for: Clarify that the employer will handle information confidentially and share only where necessary. You don’t need to disclose security blueprints, but reassure staff that you use: Give staff a clear route to report: This supports accountability and good culture. Consent is rarely valid in employment. Use contract, legal obligation, legitimate interests, or public task instead. HR almost always processes health or equality data. Article 9 must be addressed. Monitoring without clear notice often feels covert and unfair—even if technically lawful. Workers want to know how long records remain “on file”. Provide meaningful timeframes. New HR systems, new payroll providers, new monitoring tools, and restructures all require review. A worker-facing notice should be easy to scan. A good structure looks like this: A compliant employee privacy notice does more than satisfy GDPR. It reduces suspicion, prevents misunderstanding, and helps staff feel respected. In the workplace, privacy issues quickly become people issues. Clear, truthful communication about employee data processing protects everyone involved—workers, managers, and the organisation itself. If you want to build trust internally, start with transparency. Gain the practical skills you need to identify and manage data protection and GDPR with this five-star rated training course. Available in person, online or in-house the focus on practical skills and unique post-course support you get by learning with us will ensure you and your organisation can tackle this key governance activity with confidence.
4. Additional content employers should include (best practice)
Monitoring and surveillance transparency
Internal investigations and HR casework
Data security measures (high-level)
How to raise concerns
5. Common mistakes employers make (and how to avoid them)
❌ Overusing consent
❌ Forgetting special category processing
❌ Missing monitoring transparency
❌ Retention statements that are too vague
❌ Not updating the notice after organisational change
6. How to structure an employee privacy notice (recommended layout)
7. Final thought: transparency prevents conflict
- September 2026
- August 2026
- July 2026
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- September 2022
- August 2022
- June 2022
- May 2022
- March 2022
- February 2022
- January 2022
- December 2021
CONTACT US
Switchboard: 0330 221 0547
Training enquiries: 0330 221 0552
Email: hello@wudo.solutions
15 Warland Rd, London, SE18 2EX
Open every day 8am to 8pm except bank holidays.
Get the latest news, resources and special offers direct to your inbox: