This guide is maintained as a current resource for September 2026 and covers only the laws of England and Wales. Information is for general guidance, not legal advice. Consult a qualified solicitor for advice specific to your situation.
Learn what legal obligations UK employers have to protect employee privacy at work, including data protection principles, lawful monitoring, privacy notices, handling special category information, and balancing surveillance with workers' rights under UK GDPR and employment law.

Employers in England and Wales have a range of legal duties when it comes to employee privacy at work. These duties arise under data protection law, human rights principles, confidentiality obligations and employment practices. Employers must balance legitimate business interests with respect for workers' privacy rights, especially when processing personal data or undertaking monitoring or surveillance. Failure to protect privacy can lead to enforcement action by the Information Commissioner's Office (ICO), employment tribunal claims, compensation orders and reputational damage. This article explains the legal framework, key privacy rights, employer obligations, lawful monitoring practices, and common questions employers and employees face.
Why Employee Privacy Matters
Employee privacy covers the protection of personal and sensitive information about workers and the limits on how employers can collect, use and monitor that data. Privacy is not absolute, but employers must take reasonable steps to handle personal information fairly, lawfully and transparently - whether it involves personnel records, health details, communications, CCTV footage, biometric information or activity monitoring. Laws such as the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 (DPA 2018), and human rights principles influence how privacy rights are safeguarded.
Employer obligations in this area also support trust, compliance with statutory rights, and avoidance of claims for misuse of personal data or breach of confidence.
Legal Framework: Data Protection and Privacy Rights
UK GDPR and Data Protection Act 2018
The core legal framework governing privacy and data protection at work is the UK GDPR, retained from EU law with modifications post‑Brexit, and the DPA 2018. These set out principles and responsibilities for processing personal data, which includes any information that can identify a living individual. Employers are usually data controllers when they decide how and why employee data is processed. They must ensure all processing complies with the data protection principles.
These principles require that personal data must be:
- processed lawfully, fairly and transparently;
- collected for specified, explicit and legitimate purposes;
- adequate, relevant and limited to what is necessary;
- accurate and kept up to date;
- stored no longer than necessary; and
- secure against unauthorised or unlawful processing.
Employers must plan and document how they meet these requirements and be able to justify their processing activities.
Human Rights Act 1998
Although the Human Rights Act does not create standalone privacy claims in most employment scenarios, Article 8 - the right to respect for private and family life - informs how personal information should be treated, particularly in contexts like homeworking or intrusive monitoring where privacy expectations are greater. Employers should balance business interests against individual privacy rights.
Personal Data at Work: What Employers Can and Cannot Do
Lawful Bases for Processing Data
Under the UK GDPR, employers must identify a lawful basis for processing personal data. In employment contexts, common bases include:
- Contractual necessity, where processing is required to perform the employment contract (e.g., payroll, leave records).
- Legal obligation, where legislation requires processing (e.g., right‑to‑work checks, tax reporting).
- Legitimate interests, where the employer's business needs do not override the privacy rights of the employee - but employers must conduct a balancing test and document the justification.
Employers should generally avoid relying on consent as a lawful basis within employment contexts because of the imbalance of power between employer and employee. Instead, contractual necessity or legal obligation are more appropriate where the processing supports the employment relationship.
Special Category Data
Certain data is considered special category (e.g., health information) and carries additional protections. Processing such data requires both a lawful basis under Article 6 of UK GDPR and an additional condition under Article 9 and the DPA 2018. For example, processing health details to manage sickness absence or make reasonable adjustments must be justified and proportionate. Employers must also inform employees how their special category data is used and ensure it is subject to enhanced security controls.
Transparency: Privacy Notices
Employers must be transparent about how they collect and use personal data. This includes providing employees with a privacy notice that explains:
- The types of data collected;
- The legal basis for processing;
- The purposes of processing;
- How long data will be retained;
- Who will have access to it; and
- The employee's rights under data protection law.
Transparency helps meet legal obligations and reduces the risk of disputes.
Monitoring, Surveillance and Workplace Privacy
Principles for Lawful Monitoring
Monitoring employee communications or activities (such as email, internet use, phone calls, CCTV, or software tracking) can be lawful under data protection law, but only if:
- There is a clear lawful basis for processing the data;
- The monitoring is necessary and proportionate to the purpose (e.g., security, health and safety);
- Employees are informed in advance about the nature, extent and reasons for monitoring;
- Monitoring policies are clearly documented and accessible; and
- Any data collected is secured and only retained as long as necessary.
The ICO emphasises that monitoring must not be excessive or unduly intrusive, and employers should consider reasonable alternatives or less intrusive measures. Employers who monitor without informing workers or who collect unnecessary data may breach UK GDPR and their obligations under DPA 2018.
Data Protection Impact Assessments (DPIAs)
For any monitoring activity that is likely to pose a high risk to employees' privacy rights - such as biometric tracking, keystroke logging, or pervasive surveillance - employers should complete a Data Protection Impact Assessment (DPIA) before implementation. DPIAs help identify and mitigate privacy risks and demonstrate accountability.
Expectations of Privacy
Employees' expectations of privacy vary with context. For example, expectations are typically lower with employer‑owned devices and systems but higher where the monitoring captures information about personal communications or private life, especially for homeworkers. Employers should avoid intrusive practices such as covert audio surveillance or unconsented biometric tracking where the intrusion cannot be justified by a compelling purpose and lawful basis.
Responding to Subject Access Requests and Rights
Employees have specific rights under data protection law, including the right to access personal data held about them (a Subject Access Request). Employers must respond to valid requests within statutory time limits and provide information about the processing and individuals with access. Other rights include correction of inaccurate data, erasure in certain circumstances, and restrictions on processing. Employers should have processes to manage these rights effectively and maintain records of responses.
Record‑Keeping and Security
Employers must apply appropriate technical and organisational measures to protect personal data from loss, unauthorised access or misuse. This includes:
- Restricting access to sensitive information;
- Using encryption and strong authentication controls for electronic records;
- Securing physical files; and
- Training staff on data protection and privacy protocols.
Regular audits, clear retention policies and breach response plans help maintain compliance and support lawful practices.
Risks and Enforcement
Failure to uphold privacy obligations can result in:
- ICO enforcement action, including fines and corrective notices;
- Compensation claims by employees for damage or distress caused by unlawful processing;
- Public and reputational harm.
The ICO monitors employer practices and can intervene when there is evidence of systemic privacy violations. Enforcement actions, such as those used to stop unlawful biometric monitoring, serve as reminders that employers must justify and document their practices, especially when using novel technologies.
Common Questions
Can employers monitor employee emails or internet use?
Yes, but only if there is a lawful basis, the purpose is legitimate, and employees are informed about the monitoring in advance. Unannounced or overly intrusive monitoring may breach UK GDPR.
Does employer privacy duty apply to remote work?
Yes. Monitoring remote workers can have greater privacy implications, and employers must consider how their practices affect employees' rights, especially when private life and work overlap. Transparency and proportionate measures are crucial.
What if employees share sensitive personal data at work?
Sensitive data such as health details should be processed with strict safeguards and lawful bases, and employees should be informed about how their information will be used, stored and protected.
Key Takeaways
Employers in England and Wales must respect and protect employee privacy at work by complying with data protection law, human rights principles and best practices. This includes processing personal and sensitive data lawfully and transparently, informing employees about monitoring, conducting risk assessments, securing data, and responding to privacy rights requests. Prioritising privacy supports lawful employment practices, reduces risks of enforcement or compensation claims, and fosters trust in the workplace.