Essential points 

  • Data protection is about safeguarding important information and making sure it is used properly and legally.  
  • Employers can keep a range of personal information about their employees without seeking their permission including their name, address, date of birth, sex, National Insurance number, emergency contact details and any disciplinary action taken against them. 
  • Organisations need their employees’ consent to keep sensitive information on them such as their race or ethnicity, religion, trade union membership, health and medical conditions and sexual orientation. 
  • Employers must keep employees’ personal data secure and up to date and have extra security in place to protect their sensitive personal data. 
  • Organisations must notify the ICO of all data breaches without undue delay and, where possible, within 72 hours. 
  • Employees have the right to be told what records are being kept on them, how they are used, and how their confidentiality is preserved.

Members access only

Unlock exclusive, tailored content and resources, just for members.

Sign in to access

Not a member yet? Find out how you can become a member today!

Disclaimer 

Please note: While every care has been taken in compiling this content, CIPD cannot be held responsible for any errors or omissions. These notes are not intended to be a substitute for specific legal advice. 

Employment
law advice

Want more employment law advice? Members can phone the CIPD legal helpline or take out a discounted subscription to HR-inform for additional resources.

Callout Image

Related content on data protection

Factsheet
Retention of HR records

Introduces the legal issues in the UK around effective retention and organisation of HR records

For Members
Factsheet
Data protection and GDPR in the workplace

Introduces data protection law in the UK, covering the obligations of employers and individual rights to accessing information.

For Members
Guide
People manager guide: Managing data protection requirements

This guide provides managers with an overview and principles to apply when handling GDPR and data protection requirements to ensure they play their part in complying with regulations governing its safe handling.

For Members
Topic
Data Protection and GDPR resources

Learn more about data protection and GDPR to ensure your organisation is compliant.

Employment law

Access more employment law resources

Employment law
Timetable of employment law changes UK

Keep up to date with the latest employment law developments and proposed future changes

For Members
Employment law
Tracking law changes

Find out what will change under new legislation like the Employment Rights Bill and how you can prepare

For Members
Employment law
UK employment law and the EU

The UK’s relationship with EU employment law post-Brexit

For Members
Employment law
Terms and conditions of employment: UK employment law

Explore our collection of resources covering terms and conditions of employment, including Q&As and relevant case law

For Members