This guide is maintained as a current resource for September 2026 and covers only the laws of England and Wales. Information is for general guidance, not legal advice. Consult a qualified solicitor for advice specific to your situation.
Understand how UK employers must protect employee data under UK GDPR and the Data Protection Act 2018, including lawful bases for processing, data minimisation, security measures, employee rights, retention policies, and compliance with ICO guidance in England and Wales.

Employers in England and Wales have legal duties to protect the personal data of employees under UK data protection law, primarily the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 (DPA 2018). These laws set out how employee information must be handled, stored, shared and disposed of, while also giving employees rights over their own data. Non‑compliance can lead to regulatory action by the Information Commissioner's Office (ICO), significant fines, and civil claims for compensation where individuals suffer damage. This article explains employers' obligations step by step, practical measures to protect data, and common questions that arise in employment contexts.
What Data Protection Law Covers
Data protection law regulates how organisations collect, use, share and secure personal data, including any information relating to an identifiable individual. Employers are generally data controllers when they determine why and how employee data is processed. As data controllers, employers have strict obligations to ensure personal information is handled lawfully, fairly and transparently.
Employee data may include names, contact details, bank information, employment history, attendance records, disciplinary or grievance records, and special category data such as health or ethnicity information. Some personal data is more sensitive and subject to additional safeguards.
The Legal Framework: UK GDPR and the DPA 2018
Two key sources of UK data protection law apply:
- UK GDPR: Retained and adapted from EU law after Brexit; contains core data protection principles, rights, lawful bases for processing, and responsibilities for data controllers and processors.
- Data Protection Act 2018 (DPA 2018): Supplements UK GDPR with national provisions, including conditions for processing special category data and criminal offence data.
Together, these laws require employers to:
- Process personal data only when there is a lawful basis (such as contractual necessity or legal obligation).
- Collect and handle data fairly, transparently and for explicit purposes.
- Limit collection to what is necessary and proportionate for legitimate purposes.
- Keep data accurate and up to date.
- Retain data no longer than is required.
- Ensure appropriate security measures to protect confidentiality and integrity.
Fundamental Data Protection Principles
The UK GDPR sets out core principles that apply to all processing of personal data:
Lawfulness, Fairness and Transparency
Employers must have a lawful basis for processing and must inform employees about what data is used and why. Processing should not surprise employees or be used in ways that could harm their privacy interests.
Purpose Limitation
Data must be collected for specific, explicit, legitimate purposes and not used in ways incompatible with those purposes.
Data Minimisation
Employers should only collect the personal data they truly need for their stated purposes. Excessive data collection increases legal risk.
Accuracy
Employers must take steps to keep employee data accurate and up to date and correct or erase inaccurate data promptly.
Storage Limitation
Personal data should not be kept in identifiable form for longer than necessary. Employers are expected to define retention periods and delete or anonymise data that is no longer required.
Security (Integrity and Confidentiality)
Appropriate technical and organisational measures must protect personal data from unauthorised access, loss, destruction or damage. This includes digital and physical safeguards.
Lawful Bases for Processing Employee Data
Under UK GDPR, employers must identify at least one lawful basis for processing personal data. In employment contexts, common bases include:
- Contractual necessity – processing is required to perform the employment contract (e.g., payroll, benefits administration).
- Legal obligation – processing required to comply with statutory duties (e.g., tax reporting, right‑to‑work checks).
- Legitimate interests – where processing is necessary for business needs and does not override employee privacy rights (e.g., internal investigations).
Employers rarely rely on consent in the employment context because the imbalance of power can make consent invalid; other lawful bases are generally more appropriate.
Special Category Data
Some employee data is inherently more sensitive, such as health information, racial or ethnic origin, trade union membership, religion, or sexual orientation. Processing this special category data requires both a lawful basis under Article 6 of UK GDPR and an additional condition under Article 9 and the DPA 2018 (e.g., employment law compliance or occupational health assessments).
Transparency and Privacy Notices
Employers must inform employees clearly and in plain language about:
- What personal data they collect.
- Why it is processed (purposes).
- The lawful basis relied upon.
- Who has access to it and whether it will be shared with third parties.
- How long data will be retained.
- Employees' data protection rights, such as access, rectification or erasure.
This information is typically provided via an employee privacy notice as part of onboarding or in a staff handbook. Transparency supports fairness and reduces disputes.
Security Measures Employers Should Implement
Protecting employee data requires effective technical and organisational safeguards, including:
- Access controls to restrict who can view employee data.
- Encryption and secure storage for digital files.
- Strong authentication controls, such as passwords and multi‑factor authentication.
- Physical security for paper records.
- Policies and procedures for secure processing, regular audits and incident response.
- Training for staff to recognise security risks, such as phishing or unauthorised access.
Security measures should be proportionate to the sensitivity of data and the risks associated with its processing.
Data Protection Impact Assessments (DPIAs)
When introducing new systems or processing that are likely to pose high risks to employees' privacy (such as biometric systems, extensive monitoring or large‑scale profiling), employers should carry out a Data Protection Impact Assessment (DPIA). DPIAs help identify and mitigate risks before processing begins and demonstrate accountability under UK GDPR.
Rights of Employees
Employees have a range of rights under data protection law, including:
- Right to be informed about processing activities.
- Right of access to their personal data (Subject Access Request).
- Right to rectification if data is inaccurate or incomplete.
- Right to erasure (“right to be forgotten”) in certain circumstances when data is no longer needed for its original purpose.
Employers must respond to valid requests within prescribed time limits (usually one month for subject access requests) and cannot charge a fee for access.
Sharing Data With Third Parties
Employers often need to share employee data with third parties such as payroll service providers, pension administrators or regulators. Before sharing, they must ensure:
- A lawful basis for the disclosure.
- Appropriate safeguards, such as contracts requiring third parties to protect the data.
- Transparency with employees about the sharing arrangements.
Sharing that is unnecessary or unprotected can breach data protection principles and expose employers to complaints or enforcement action.
Retention and Disposal
Data should not be retained indefinitely. Employers should implement a data retention policy that sets out:
- How long different types of data will be kept.
- When and how data will be securely deleted or anonymised.
- Justification for retention periods, linked to statutory, contractual or business needs.
Holding unnecessary data increases risk and can undermine compliance with storage limitation principles.
Consequences of Non‑Compliance
Failing to protect employee data can result in:
- ICO enforcement action, including fines up to £17.5 million or 4 % of global turnover, whichever is higher.
- Civil compensation claims by employees for distress or damage caused by breaches.
- Regulatory notices requiring corrective actions under UK GDPR.
- Reputational harm and loss of trust.
The ICO publishes guidance and can audit or investigate organisations suspected of breaches.
Common Questions
What counts as personal data for employees?
Any information relating to an identifiable person, including payroll records, contact details, appraisal records, attendance and disciplinary history. Sensitive data such as health information requires extra safeguards.
Can employees withdraw consent for data processing?
Because of the imbalance of power in employment relationships, consent is rarely valid as a lawful basis. Employers should use contractual necessity, legal obligation or legitimate interests instead.
Do data protection duties extend to former employees?
Yes. Employers must continue to protect and lawfully process the personal data of former employees and respond to rights requests unless there is a valid reason not to.
Key Takeaways
Protecting employee data under UK data protection law requires employers to follow comprehensive legal obligations grounded in the UK GDPR and the Data Protection Act 2018. Employers must process data lawfully, transparently and fairly; limit collection to necessary information; keep data accurate and secure; inform employees about data use; and respect employees' rights. Implementing robust policies, security measures, data retention practices, and impact assessments helps demonstrate accountability and reduces the risk of regulatory action, fines and civil claims. Careful data governance not only protects legal compliance but also fosters trust in the employment relationship.