Skip to content
What You Have to Produce

Employment data protection

Mostly a filing problem, not a legal one

WHAT A REGULATOR ASKS FOR FIRST

In this order

  • Record of processing
    One row per activityEstablishes within a minute whether you know what you do
  • Privacy notice
    As issued to staff, datedRead against the record for contradictions
  • Retention schedule
    With triggers, not only periodsA period with no trigger has never deleted anything
  • Request log
    Dates received and respondedThe timings are the finding
  • Breach record
    Including the ones not notifiedA decision not to notify must be defensible

The judgements this law requires are few and mostly obvious. What it requires you to be able to produce is specific, finite, and almost never produced. Fifty notes on the documents, the deadlines, and the order to build them in.

Nothing here is legal advice. The obligations described recur widely in shape; their content and enforcement differ enough by jurisdiction that every specific answer requires local advice. Product comparisons are kept in separate guides, while the core notes remain focused on records and process.

The deadlines that actually bind

72 hoursto notify a breach where the threshold is metFrom awareness, not from confirmation. Calendar hours, including the weekend
1 monthto answer a request for somebody's dataFrom receipt by anybody in the organisation, not by the right person
0 daysof grace for a document you never wroteThere is no deadline, because there is nothing to produce

Why this is filing rather than law

The judgements this law requires an employer to make are few, and most of them are obvious once stated. What it requires you to be able to produce is specific, finite, and almost never produced.

The practical lesson in “Mostly a filing problem, not a legal one” is that a record is useful only when its purpose, owner and lifecycle are clear. For teams researching employee monitoring software with screenshots, the official product page can add time and project context, provided collection is proportionate, access is limited and every consequential inference receives human review.

An organisation that has written six documents and operates two processes is in a stronger position than one that has taken advice on every question and recorded none of it. The first can show what it does; the second can only describe it.

For a separate benchmark relevant to “Mostly a filing problem, not a legal one”, consult the NIST Cybersecurity Framework. Use it to test purpose, data flow, retention, access and response procedures rather than substituting a generic checklist for the organisation’s actual records.

Almost every failure is documentary

Not having a record of processing. Not having written the legitimate interests assessment for a basis relied on daily. Not recording why a breach was judged not notifiable. Not logging the date a request arrived.

In each case the underlying decision was probably defensible and there is nothing to show it was taken. That gap — between a reasonable decision and the evidence of one — is where essentially all of the exposure sits.

The clocks start earlier than people assume

A month to answer a request runs from receipt by anybody in the organisation, not by the right person. An email to a line manager starts it. A sentence inside a grievance letter starts it. Organisations routinely lose a fortnight because the request sat with somebody who did not recognise what it was.

Seventy-two hours to notify a breach runs from awareness, not confirmation, and they are calendar hours. A breach discovered at five on Friday is due by five on Monday. Spending two days establishing whether it really was one consumes the window rather than preceding it.

Both windows are lost at the beginning rather than at the end, and neither can be recovered by anything done afterwards.

Consistency matters more than completeness

A regulator compares the record of processing, the privacy notice and the retention schedule against each other before reading any of them properly.

A gap says the organisation has not got to something yet. A contradiction says the documents were produced separately, by different people, and that nobody has read them together — which calls into question the parts that are correct.

The check takes half an hour, twice a year, across five rows: activities, bases, retention, recipients, transfers. It is the cheapest work in this subject and it prevents the most damaging finding.

The things employers believe that are wrong

That they are too small for a record of processing. The exemption is narrow and falls away where processing is regular or involves special category data. Employment processing is both.

That consent covers them. It is unreliable in employment because refusal is not genuinely available. What covers most employment processing is necessity, and necessity has to be documented.

That a breach means an attack. It means any accidental loss, alteration or unauthorised disclosure. The commonest breach in any employer, by a wide margin, is an attachment sent to the wrong address.

That having the policies is the compliance. Documents describing a practice that does not exist are evidence the organisation knew what it should have been doing, which is a worse position than having neither.

Where the data actually is

There is no single employment file. There are seven: the HR system, the manager's own folder, email, the payroll provider, benefits providers, shared drives, and messaging. Most organisations find three of them surprising.

By volume the largest holding about any employee is email — not their own mailbox, but messages about them in everybody else's. A search that covers only their own mail finds what they sent and almost nothing of what was said.

The second largest is manager notes, written by people who believe they are private working papers. They are personal data, they are disclosable, and nobody has told the managers.

What makes everything else cheaper

Deletion that actually happens.

Every organisation has a retention schedule. Few can say what they deleted last year. The gap is mechanical: no purge rule, no named owner for the manual task, and no leaving date recorded against the records, so the clock never starts.

An organisation holding three years answers a request quickly. One holding nine answers slowly, at length, and exposes the gap between its schedule and its practice in the same letter. The deletion cycle pays for itself in request handling alone.

08 / 08

Reference

The vocabulary, the beliefs that cost money, and the whole of the maintenance on one page.

If you are starting from nothing

Six documents, two routes, and a date for the first deletion run

About a week of one person's time, spread over a month. The map first, because everything else is written from it. An organisation with these and a working deletion cycle is ahead of most organisations with full documentation and no practice behind it.