Employee privacy information should explain the employer's actual uses of staff data. Cover relevant stages from recruitment through employment and departure, distinguishing routine administration from monitoring or sensitive records. Employees should be able to understand who uses their information and where questions or requests go.
Do not assume employee consent is suitable for every activity given the relationship and potential imbalance. Assess the lawful basis and any additional conditions for health or other sensitive information. Review monitoring separately, including its necessity, proportionality and information given to workers.
Explain the employment relationship by activity
Prepare a staff data map covering recruitment, onboarding, payroll, absence, performance, benefits and departure. Each activity has a different audience and sensitivity. A payroll clerk may need payment details while a line manager needs an absence date but not an unrestricted medical history. The notice should explain the organisation's actual uses in a way workers can connect to their experience, including who handles questions and requests.
Distinguish applicants, employees, contractors and former workers where the processing differs. Do not give an unsuccessful applicant an employee handbook as the only explanation of recruitment data use. Identify which entity is the employer in a group and how other group businesses receive information. A familiar group brand can obscure the separate organisations responsible for decisions about staff information.
Assess health information and monitoring separately
The ICO's employment guidance addresses handling workers' health information and monitoring as distinct areas requiring careful assessment. [1] Record the lawful basis and any additional condition for sensitive information. Consent may be unsuitable in an employment relationship where the person does not have a genuinely free choice. An acknowledgement that the handbook was received does not itself resolve the legal basis for intrusive monitoring.
For a proposed monitoring tool, ask what it captures, whether it runs outside working hours and who sees the output. Screenshots, location histories and productivity scores may reveal information unrelated to performance. Consider less intrusive ways to achieve the objective. Explain any monitoring accurately before deployment and assess whether a DPIA is required. Do not describe a system as attendance tracking if it also analyses communications or records screens continuously.
Give staff meaningful information at the right time
Use a layered approach: a clear core staff notice, with specific explanations for sensitive or unusual activities. Make it available to people without regular access to the company intranet. Include a practical route for questions that does not require the employee to disclose a sensitive concern to their immediate manager. Keep versions so the organisation can establish what information accompanied a particular system rollout.
Check notices against provider contracts and account settings. A benefits platform may permit independent marketing, while a payroll provider may process data on instructions. Explain relevant sharing without suggesting that every external recipient has the same role. The guide to Data processing contracts with suppliers helps with supplier processing arrangements, and When to consider a data protection impact assessment supports assessing new activities before their design becomes fixed.
Limit access and manage the employee lifecycle
Separate confidential health and disciplinary records from broadly accessible personnel folders. Define who can approve access changes when a manager moves teams or leaves. Employee requests may involve emails, messages and historic files, so keep records organised without creating excessive informal dossiers. Record corrections fairly and avoid allowing subjective comments to circulate without context or a clear business purpose.
At departure, distinguish information that must remain for a continuing obligation from accounts and permissions that should close promptly. Explain the retention approach and check personal devices, shared folders and supplier portals. Do not keep a former employee's account active merely to preserve documents if ownership can be transferred through a controlled process. Preserve relevant evidence where a properly scoped dispute hold applies.
For Business privacy notice review, bring the staff notice, recruitment forms, monitoring proposals and a list of external providers. Identify any activity where the actual settings differ from the written explanation. The review should lead to a usable notice and concrete access or collection changes. Ask HR and IT to confirm implementation together; neither team alone may see the complete path of sensitive employment information.
Check information supplied by recruitment partners
Ask a recruiter which candidate details reach hiring managers and what explanation candidates receive about the employer's use. A full CV may contain personal information that an interview scheduler does not need. Decide who can see references, adjustment requests and interview notes, rather than placing every recruitment document in a shared team folder.
When a candidate becomes an employee, identify which records should move into the personnel file and which remain subject to a separate recruitment retention decision. Give the individual the relevant employee information at the appropriate stage. This avoids carrying an entire recruitment archive into long-term employment records merely because an onboarding tool offers a convenient bulk import function.
Illustrative scenario
An employer introduces time-tracking software that also captures screenshots. The privacy review identifies the additional monitoring and sensitive material that screenshots might reveal. The employer assesses the proposed activity and settings before rollout, rather than treating an updated staff notice as sufficient justification.
Preparation checklist
- List recruitment, payroll, benefits and monitoring uses.
- Identify sensitive information and access restrictions.
- Check suppliers and overseas access.
- Explain retention, rights and the internal contact route.
Frequently asked questions
Can employees consent to all monitoring in their contract?
A broad contract clause does not establish that every activity is lawful or proportionate. Assess the specific monitoring, suitable basis, safeguards and information given to workers.
Should managers see full medical records?
Access should follow a justified role and purpose. Often a manager needs practical workplace information rather than unrestricted clinical details; assess the particular circumstances and confidentiality requirements.
Does the employee notice cover applicants automatically?
Not necessarily. Recruitment has its own activities, recipients and retention decisions. Give candidates information appropriate to that stage instead of relying solely on an internal staff handbook.
Who should check a new HR software notice?
HR should confirm the purpose and users, IT the settings and access, and the appropriate adviser the legal issues. Review the supplier's actual data use before finalising the explanation.
Official sources
Sources checked: 8 September 2026. Check the linked guidance for subsequent changes.
General information only. The appropriate action depends on your circumstances and the applicable jurisdiction.
Report a correction