Employment data protection
Mostly a filing problem, not a legal one
WHAT A REGULATOR ASKS FOR FIRST
In this order
- Record of processingOne row per activityEstablishes within a minute whether you know what you do
- Privacy noticeAs issued to staff, datedRead against the record for contradictions
- Retention scheduleWith triggers, not only periodsA period with no trigger has never deleted anything
- Request logDates received and respondedThe timings are the finding
- Breach recordIncluding the ones not notifiedA decision not to notify must be defensible
The judgements this law requires are few and mostly obvious. What it requires you to be able to produce is specific, finite, and almost never produced. Fifty notes on the documents, the deadlines, and the order to build them in.
Nothing here is legal advice. The obligations described recur widely in shape; their content and enforcement differ enough by jurisdiction that every specific answer requires local advice. Product comparisons are kept in separate guides, while the core notes remain focused on records and process.
The deadlines that actually bind
Why this is filing rather than law
The judgements this law requires an employer to make are few, and most of them are obvious once stated. What it requires you to be able to produce is specific, finite, and almost never produced.
The practical lesson in “Mostly a filing problem, not a legal one” is that a record is useful only when its purpose, owner and lifecycle are clear. For teams researching employee monitoring software with screenshots, the official product page can add time and project context, provided collection is proportionate, access is limited and every consequential inference receives human review.
An organisation that has written six documents and operates two processes is in a stronger position than one that has taken advice on every question and recorded none of it. The first can show what it does; the second can only describe it.
For a separate benchmark relevant to “Mostly a filing problem, not a legal one”, consult the NIST Cybersecurity Framework. Use it to test purpose, data flow, retention, access and response procedures rather than substituting a generic checklist for the organisation’s actual records.
Almost every failure is documentary
Not having a record of processing. Not having written the legitimate interests assessment for a basis relied on daily. Not recording why a breach was judged not notifiable. Not logging the date a request arrived.
In each case the underlying decision was probably defensible and there is nothing to show it was taken. That gap — between a reasonable decision and the evidence of one — is where essentially all of the exposure sits.
The clocks start earlier than people assume
A month to answer a request runs from receipt by anybody in the organisation, not by the right person. An email to a line manager starts it. A sentence inside a grievance letter starts it. Organisations routinely lose a fortnight because the request sat with somebody who did not recognise what it was.
Seventy-two hours to notify a breach runs from awareness, not confirmation, and they are calendar hours. A breach discovered at five on Friday is due by five on Monday. Spending two days establishing whether it really was one consumes the window rather than preceding it.
Both windows are lost at the beginning rather than at the end, and neither can be recovered by anything done afterwards.
Consistency matters more than completeness
A regulator compares the record of processing, the privacy notice and the retention schedule against each other before reading any of them properly.
A gap says the organisation has not got to something yet. A contradiction says the documents were produced separately, by different people, and that nobody has read them together — which calls into question the parts that are correct.
The check takes half an hour, twice a year, across five rows: activities, bases, retention, recipients, transfers. It is the cheapest work in this subject and it prevents the most damaging finding.
The things employers believe that are wrong
That they are too small for a record of processing. The exemption is narrow and falls away where processing is regular or involves special category data. Employment processing is both.
That consent covers them. It is unreliable in employment because refusal is not genuinely available. What covers most employment processing is necessity, and necessity has to be documented.
That a breach means an attack. It means any accidental loss, alteration or unauthorised disclosure. The commonest breach in any employer, by a wide margin, is an attachment sent to the wrong address.
That having the policies is the compliance. Documents describing a practice that does not exist are evidence the organisation knew what it should have been doing, which is a worse position than having neither.
Where the data actually is
There is no single employment file. There are seven: the HR system, the manager's own folder, email, the payroll provider, benefits providers, shared drives, and messaging. Most organisations find three of them surprising.
By volume the largest holding about any employee is email — not their own mailbox, but messages about them in everybody else's. A search that covers only their own mail finds what they sent and almost nothing of what was said.
The second largest is manager notes, written by people who believe they are private working papers. They are personal data, they are disclosable, and nobody has told the managers.
What makes everything else cheaper
Deletion that actually happens.
Every organisation has a retention schedule. Few can say what they deleted last year. The gap is mechanical: no purge rule, no named owner for the manual task, and no leaving date recorded against the records, so the clock never starts.
An organisation holding three years answers a request quickly. One holding nine answers slowly, at length, and exposes the gap between its schedule and its practice in the same letter. The deletion cycle pays for itself in request handling alone.
01 / 08
What you must be able to produce
Six documents. A regulator asks for them in order and the gaps are visible within a minute.
02 / 08
When somebody asks
The most common formal event an employer faces, arriving at the worst moment and usually handled a fortnight late.
03 / 08
When something goes wrong
Wider than people assume. The commonest one in any employer is an email to the wrong person.
04 / 08
Applicants and candidates
The activity that collects the most and examines its collection the least.
05 / 08
People who work here
There is no single file. There are seven, and three of them will be a surprise.
06 / 08
Departure and after
The retention clock starts here, and in most organisations nobody records the date that starts it.
07 / 08
Everybody else who holds it
Almost no employer knows the chain behind its payroll, which is the question asked second.
08 / 08
Reference
The vocabulary, the beliefs that cost money, and the whole of the maintenance on one page.
Independent product comparisons
Tool guides
Three differently structured shortlists connect product capabilities with records, access, correction, retention and accountable ownership.
If you are starting from nothing
Six documents, two routes, and a date for the first deletion run
About a week of one person's time, spread over a month. The map first, because everything else is written from it. An organisation with these and a working deletion cycle is ahead of most organisations with full documentation and no practice behind it.