Employment Data Processing Check: UK Compliance Guide
review GDPR & DPA 2018 compliance with our expert gap review—avoid fines and protect employee data.
Every UK employer handles personal data—from payroll records to performance reviews. Get it wrong, and you risk ICO fines, tribunal claims, or reputational damage. Yet many small businesses and HR teams overlook the basics: lawful basis for processing, retention periods, and employee rights under the Data Protection Act 2018 (DPA2018) and Employment Rights Act 1996 (ERA1996).
This guide explains how to audit your employment data processing check document—the internal record that proves you’re compliant. We’ll cover what to look for, common pitfalls, and how VetroCheck’s AI-powered review can help you spot gaps before regulators do.
Why data-protection paperwork matters under UK GDPR
Employment data isn’t just names and addresses. It includes disciplinary notes, sickness records, CCTV footage, and even Slack messages. The ICO has ramped up enforcement, with recent fines for employers who failed to:
- Delete data on time: A recruitment agency was fined £20,000 for keeping CVs of unsuccessful candidates for years.
- Respond to subject access requests (SARs): A care home paid £80,000 after ignoring an employee’s request for their HR file.
- Justify processing: A gym chain was penalised for using biometric fingerprint scanners without a clear lawful basis.
For small businesses, the stakes are higher. You may not have an in-house data protection officer, but the law treats you the same as a multinational. Tribunals also consider data protection failures when ruling on unfair dismissal claims—especially if an employee argues their rights were breached during disciplinary proceedings.
The employment data processing check document is your first line of defence. It’s not just a box-ticking exercise; it’s evidence that you’ve thought about compliance. If the ICO investigates, this document shows you took reasonable steps to follow the law.
Is your document complete and internally consistent?
A strong document does three things:
- Proves lawful basis: Explains why you process each type of data (e.g., "payroll processing under Article 6(1)(b) DPA2018 for contract performance").
- Sets retention rules: Defines how long data is kept and when it’s securely deleted (e.g., "sickness records: 3 years post-employment under ERA1996 s.9").
- Documents employee rights: Shows how you handle SARs, rectification requests, and objections to processing.
If your document lacks detail, cites the wrong legal basis, or ignores retention periods, it’s not fit for purpose.
UK GDPR and the Data Protection Act 2018 — plain English
Data Protection Act 2018 (DPA2018)
The DPA2018 is the UK’s version of GDPR. It applies to all personal data—any information that identifies an employee, like their name, email, or even a work ID number. Key rules:
- Lawful basis: You must have a valid reason to process data. Common ones for employers:
- Contract performance (e.g., paying salaries).
- Legal obligation (e.g., HMRC tax records).
- Legitimate interests (e.g., CCTV for security), but only if it doesn’t override employee rights.
- Retention: You can’t keep data forever. The DPA2018 says you must delete it when it’s no longer needed.
- Employee rights: Workers can ask to see their data (SAR), correct errors, or object to processing (e.g., if you’re using their data for marketing).
Employment Rights Act 1996 (ERA1996)
The ERA1996 sets out employee rights, including how long you must keep certain records:
- Pay and tax records: 6 years (to comply with HMRC rules).
- Sickness and maternity records: 3 years after employment ends.
- Disciplinary and grievance notes: At least 1 year after the issue is resolved.
The ERA1996 also protects employees from unfair dismissal, and tribunals often look at data protection practices when deciding cases. For example, if you fired someone without giving them access to their HR file, the tribunal might rule against you.
Five privacy-document checks organisations miss
1. Lawful basis: Are you processing data for a valid reason?
What to check: Your document should list every type of data you process (e.g., bank details, performance reviews) and explain the lawful basis for each. Common mistakes:
- Using "consent" as a catch-all. Consent is rarely valid for employment data because employees may feel pressured to agree.
- Relying on "legitimate interests" without balancing it against employee rights. For example, monitoring emails for productivity might infringe on privacy.
Practical tip: Use this template for each data type:
"We process [data type] under [Article 6(1)(x) DPA2018] for [purpose]. This is necessary because [reason]."
VetroCheck can help: Our AI flags missing or weak lawful basis statements in your document. Try the Employment Data Processing Check now.
2. Retention periods: Are you keeping data too long (or not long enough)?
What to check: Your document should specify how long each type of data is kept and when it’s deleted. For example:
- Payroll data: 6 years (HMRC requirement).
- Job applications: 6 months (ICO guidance).
- CCTV footage: 30 days (unless needed for an investigation).
Practical tip: Create a retention schedule with these columns:
| Data Type | Retention Period | Legal Basis | Deletion Process |
|---|---|---|---|
| Sickness records | 3 years post-employment | ERA1996 s.9 | Secure digital wipe |
VetroCheck can help: We compare your retention periods against DPA2018 and ERA1996 requirements. Upload your document for review.
3. Employee rights: Can workers access, correct, or object to their data?
What to check: Your document should explain how you handle:
- Subject access requests (SARs): Employees can ask for a copy of their data. You must respond within one month (DPA2018 s.54).
- Rectification requests: If an employee spots an error (e.g., wrong salary in their file), you must correct it.
- Objections to processing: Employees can object if you’re using their data for marketing or profiling.
Practical tip: Include a step-by-step process for SARs, like:
- Employee submits request via email/portal.
- HR verifies identity (e.g., passport copy).
- Data is collated and reviewed for third-party information.
- Response sent within 28 days.
VetroCheck can help: We check if your document covers all employee rights under DPA2018. Get your gaps report today.
4. Special category data: Are you handling sensitive information correctly?
What to check: Special category data includes health records, trade union membership, or biometric data. You need:
- A lawful basis (e.g., "employment law obligations" for health data).
- An additional condition (e.g., "explicit consent" or "occupational health purposes").
Practical tip: If you process health data (e.g., for sick pay), add this to your document:
"We process health data under Article 9(2)(b) DPA2018 for occupational health purposes, with explicit consent from the employee."
VetroCheck can help: Our AI flags missing conditions for special category data. Review your document now.
5. Data sharing: Are you transferring data to third parties?
What to check: If you share data with payroll providers, pension schemes, or external recruiters, your document must explain:
- Who you share data with.
- Why it’s necessary.
- How you protect the data (e.g., encryption, contracts).
Practical tip: List all third parties and their purposes, like:
| Third Party | Data Shared | Purpose | Safeguards |
|---|---|---|---|
| Payroll provider | Bank details, NI numbers | Salary processing | Encrypted transfer, GDPR-compliant contract |
VetroCheck can help: We identify missing data-sharing disclosures in your document. Check your compliance here.
Data-protection mistakes that create complaint risk
1. Using "consent" as the default lawful basis
Mistake: Many employers assume they need consent to process data. But under DPA2018, consent is often invalid in employment because of the power imbalance between employer and employee. Consequence: The ICO can fine you for relying on invalid consent. In 2022, a logistics firm was fined £40,000 for using consent forms that employees felt pressured to sign.
2. Ignoring retention periods for disciplinary records
Mistake: Keeping disciplinary notes "just in case" without a clear deletion policy. Consequence: If an employee brings a tribunal claim, old disciplinary records could be used against you. Tribunals expect you to delete data when it’s no longer needed.
3. Failing to respond to SARs on time
Mistake: Missing the one-month deadline for SARs. Consequence: The ICO can issue enforcement notices or fines. In 2023, a retail chain was fined £60,000 for delaying SAR responses by 6 months.
FAQ
What does the Employment Data Processing Check: compliance and gap review review?
The review is an information-only audit of your employment data processing check document. It focuses on three key areas:
- Lawful basis: Are you processing data for valid reasons under DPA2018?
- Retention: Do you have clear rules for how long data is kept and when it’s deleted?
- Employee rights: Does your document explain how you handle SARs, rectification requests, and objections?
The review highlights gaps and provides citations from your document to support each finding.
Which legal sources are used in the review?
The analysis is based on:
- Data Protection Act 2018 (DPA2018): UK’s data protection law, including GDPR principles.
- Employment Rights Act 1996 (ERA1996): Sets out retention periods for employment records.
- ICO guidance: Best practices for employers.
Which specific points are checked?
The agent checks:
- Lawful basis: Are all data types linked to a valid legal basis (e.g., contract performance, legal obligation)?
- Retention periods: Do you specify how long data is kept, with references to DPA2018 or ERA1996?
- Employee rights: Does your document cover SARs, rectification, and objections?
- Special category data: If you process sensitive data (e.g., health records), do you meet the extra conditions?
- Data sharing: Do you disclose third-party transfers and safeguards?
Each finding is backed by a citation from your document.
Which documents can I upload?
The Employment Data Processing Check accepts PDF files up to 20 MB. Suitable documents include:
- Your employment data processing check document (the internal record of your data practices).
- Privacy notices (if they include processing details).
- Retention policies (if separate from your main document).
How much does the review cost and how long does it take?
The full analysis costs £12.99. Results are usually ready within a few minutes as a PDF download. You’ll receive:
- A summary of gaps.
- Citations from your document.
- Practical tips to fix issues.
Check your privacy paperwork — £12.99
Your compliance checklist
- Gather your document: Locate your employment data processing check document (or create one if it doesn’t exist).
- Check the basics: Ensure it covers lawful basis, retention, and employee rights.
- Upload to VetroCheck: Get an AI-powered gap review in minutes. Start your Employment Data Processing Check now.
- Fix gaps: Use the report to update your document and processes.
- Train your team: Ensure HR and managers understand the rules, especially for SARs and retention.
How VetroCheck helps
VetroCheck is not a law firm and does not provide legal advice. We’re an AI-powered tool that helps you spot compliance gaps in your documents. Our Employment Data Processing Check reviews your document against DPA2018 and ERA1996, highlighting:
- Missing lawful basis statements.
- Incorrect retention periods.
- Gaps in employee rights processes.
**Ready to check? Upload your document for a structured PDF review — £12.99. Check your document now — £12.99
Also see the agent topic page for statute themes and related checks.
Check your document now — £12.99
Upload your PDF for a structured review. One-time analysis from £12.99 — not legal advice.