Skip to main content

Insight article

January 24, 2017

What is General Data Protection Regulation?

The aim of the GDPR is to harmonise the current data protection laws across the EU member states.

The General Data Protection Regulation will apply in the UK from 25 May 2018. This is a significant change in data protection law, and businesses will need to invest time in preparing for the changes.

Given Brexit, do you still need to prepare for compliance with the GDPR?

Yes. The government has confirmed that the UK’s decision to leave the EU will not affect the commencement of the General Data Protection Regulation.

To avoid being classified as inadequate in terms of the level of protection given to personal data, the UK must offer data protection standards that comply with EU requirements. A company outside the EU with operations in the EU must also comply.

The short answer is no.

Under the General Data Protection Regulation, consent must be given:

  • freely, i.e. not as part of the employment contract;
  • actively, i.e. not simply ‘by default’; and
  • it must be as easy to withdraw as to give.

As an employee cannot usually reject a clause in their employment contract, it is not (for GDPR purposes) considered to be ‘freely given’. Therefore, silence, pre-ticked boxes or inactivity cannot constitute consent as these do not allow the employee to say no to an aspect of the proposed processing.

However, the General Data Protection Regulation does allow employers to rely on alternative valid bases for processing personal data (other than just employee consent). For example, where an employer needs to process personal data to operate the payroll or the sick pay system. Employers can rely on the justification that such processing must happen for the employer to perform the employment contract.

How will the GDPR change the rules regarding subject access requests?

A subject access request is a written request made by or on an individual’s behalf for the information he or she is entitled to ask for under section 7 of the Data Protection Act 1998.

In standard cases, the current 40-day time limit for responding to subject access requests will be reduced to one month, and the £10 fee will be revoked.

In complex cases, the one-month timeframe can be extended by a further two months, and provision will be made for a fee to be charged if the request is clearly unfounded or excessive.

The General Data Protection Regulation will extend the right of access to personal data. Employees will be entitled to more information about how their data is handled, who has access to it, how long it is held, etc. Therefore, employers should ensure that anyone appointed to handle subject access requests has received up-to-date training.

What steps should employers take to prepare for the GDPR coming into force?

The General Data Protection Regulation affects the whole of the business, but from an HR angle, we would suggest the following steps are taken as part of the overall business preparations:

Audit HR data and data processes

Now is the time to assess what data is held by HR and how it is processed (who it is shared with and why?).

What data protection policies and procedures do you currently have, and are these working?

Are there any risk areas that need attention before the General Data Protection Regulation comes into force?

Audit your third-party processors

The General Data Protection Regulation increases employers’ obligations to ensure that their third-party data processors comply with data protection laws. The obvious ones here include external payroll providers and occupational health assessors.

You need to make sure that your contractual terms require third parties to comply with data protection laws in processing personal data about your workforce.

You should consider what steps you take to vet and check external service providers for compliance both prior to and during their appointment.

Ensure staff are trained appropriately

General data protection training is as important as ever. Those with specific data processing responsibilities should be given additional tailored training.

Move away from relying solely on employee consent to justify business-critical data processing.

Do you need to appoint a data protection officer?

The GDPR requires companies whose core activities consist of processing operations that require regular and systematic monitoring of data subjects on a large scale to appoint a data protection officer. This person must have expert knowledge of data protection law and practices, and their job will be to monitor internal compliance with the GDPR. Businesses that do not fall into this category may still wish to appoint someone to monitor data processing and keep a check on compliance.

If you’re concerned about the General Data Protection Regulation, speak to Karen Cole today.

Note: This article is not legal advice; it provides information of general interest about current legal issues.

Stay in touch

Subscribe to our newsletter

Stay in touch

By completing your details and submitting this form you confirm you are happy for us to send you marketing communications and that you agree to our Website Privacy Policy and Legal Notice and to us using Mailchimp to process your data.


Sending

News/Insight

  • The do’s and don’ts of using AI in your business
    AI can help businesses improve efficiency and make informed decisions, but it also comes with risks. Explore the key do’s and don’ts of using AI responsibly, including data protection, legal considerations and the importance of human oversight.


    Read more
  • Next equal pay appeal: when can market pressures justify different pay
    When can recruitment and retention pressures justify different pay? Karen Cole explores the Next equal pay appeal, explaining why equal pay risks remain and what employers should consider when reviewing pay packages and the evidence supporting their


    Read more
  • Domestic Abuse Protection Orders: where are they available and what other protection can you seek?
    Domestic Abuse Protection Orders can offer tailored protection, but availability is currently limited. Pippa Marshall explains how they work, who can apply and the other protective orders available, including non-molestation and occupation orders.


    Read more
  • Missing beneficiaries and unknown heirs: what should executors do?
    What should an executor do if someone entitled to inherit cannot be found? James McMullan explains how to trace missing beneficiaries, the limits of statutory notices and the options to consider before distributing an estate.


    Read more
  • Pay transparency in recruitment: Is your business ready to disclose salaries?
    Employers may eventually have to provide salary information much earlier in the recruitment process under proposals being considered by the Government.


    Read more

What they say...

  • Bryan E, September 2026
    Absolutely outstanding “This firm is super professional, efficient and friendly at the same time. You could not wish for a better service. I have used them for my Will and a range of other matters over many years. I’ve found all the vario

  • Jan Norris, September 2026
    Excellent Service “Charlotte Barbaroussis has prepared our wills, LPAs and a discretionary trust. She was professional, kind and patient throughout. A very fine person to have looking after us.”

  • Brian Nunan, August 2026
    “I dealt with the group for many years, and no matter which solicitor I used, the results were always the same. Excellent!”

  • Client, July 2026
    Constructive and empathetic “I contacted Pippa Marshall at RIAA Barker Gillette through a recommendation regarding a family law matter. Pippa was always clear, efficient, empathetic and helpful, offering constructive insights on my situation. I

  • Dino, July 2026
    A lucky professional meeting! “We had an excellent professional experience to recommend to all those who need legal help in the UK.”

Read more
Send this to a friend