Data protection policy for staff
A data protection policy telling staff how to handle personal data, with a staff privacy notice, part of the £995 handbook and core policies, five working days.
Data protection policy for staff
A data protection policy for staff, drafted for the employer, covering the principles every employee must apply, the staff privacy notice and what the employer tells its own workforce, special category data, criminal records and the conditions, subject access, rectification and the requests staff receive, security, breaches and the seventy-two hours, and retention, references, monitoring and the policies alongside. £995 as part of the handbook and core policies, delivered in five working days.
Buy now, £995Data protection in a business is done by its staff, and the policy is the instruction: the principles they must apply to every customer's, colleague's and supplier's data, the security they must keep, the breaches they must report within hours, and the requests they must recognise and pass on. The employer also owes its own staff a privacy notice explaining what it does with their data, which is the document employees ask for when a dispute starts. I draft both for the employer as part of the handbook and core policies for a fixed fee of £995, delivered in five working days.
Who this is for
Employers in England and Wales of any size, since every employer processes staff data and most process customer data, and employers whose data protection policy is a copy of the privacy notice on their website.
What matters in a data protection policy for staff
The principles every employee must apply
Article 5 of the UK GDPR sets the principles the employer is accountable for and staff apply in practice: personal data processed lawfully, fairly and transparently, for specified purposes, limited to what is necessary, accurate, kept no longer than needed, and secure; the policy should translate each into instructions (use data only for the purpose it was collected, do not collect more than the task needs, correct errors, delete on the retention schedule, keep it secure), should explain who in the business is responsible for data protection and whether a data protection officer is required under Article 37, and should state that the employer is registered with the Information Commissioner's Office under the Data Protection (Charges and Information) Regulations 2018 where the fee applies.
The staff privacy notice and what the employer tells its own workforce
Articles 13 and 14 of the UK GDPR require the employer to tell employees what personal data it holds about them, why, on what lawful basis, who it shares it with, how long it keeps it, whether it transfers it outside the United Kingdom, their rights, and whether it monitors them; the staff privacy notice is that document, separate from the policy and from the customer privacy notice, issued on recruitment and when it changes, and the policy should refer to it; an employee in a dispute will ask for the notice and for everything the employer holds, and the notice should already describe what they will receive.
Special category data, criminal records and the conditions
Health data, trade union membership, ethnicity, religion, sexual orientation and the other special categories under Article 9 of the UK GDPR need a condition under Article 9 and, for employment purposes, the condition in Schedule 1 to the Data Protection Act 2018 for obligations under employment law, with an appropriate policy document in place; criminal records data under Article 10 needs its own conditions, with disclosure checks only where the role permits them; the policy should say which special category data the employer processes about staff (sickness records, occupational health reports, equality monitoring, disclosure checks), the conditions it relies on, the appropriate policy document, and the instructions for staff who handle such data about colleagues, customers or clients.
Subject access, rectification and the requests staff receive
Any individual may ask the employer for a copy of their personal data under Article 15 of the UK GDPR, to be provided within one month (extendable by two months for complex requests) free of charge, and may ask for rectification, erasure, restriction and objection in the circumstances the Regulation sets; the policy should tell staff how to recognise a request (which may arrive by email, verbally or on social media and need not use the words), to pass it immediately to the person responsible, not to delete data after a request is received, and how the employer searches, redacts third-party data and responds, because the month runs from receipt by anyone in the business.
Security, breaches and the seventy-two hours
Article 32 of the UK GDPR requires appropriate security, which staff deliver through the IT policy's rules, and Article 33 requires the employer to notify the Information Commissioner's Office within seventy-two hours of becoming aware of a personal data breach likely to result in a risk to individuals, with Article 34 requiring the individuals to be told where the risk is high; the policy should define a breach in plain terms (a lost laptop, an email to the wrong recipient, a cyber attack, an unauthorised look at a record), require immediate internal reporting to a named person, set the assessment and the decision on notification, and keep a breach log of every incident whether notified or not.
Retention, references, monitoring and the policies alongside
The policy should refer to the retention schedule for staff records (recruitment records, personnel files, payroll, sickness and absence, disciplinary records, right to work evidence, with the periods the employer has set by reference to statutory requirements and limitation periods), the rules on references (factual and consistent, under a policy, with the employee's right of access limited for confidential references), the monitoring the employer operates and its privacy notice, and the related policies (IT, bring your own device, homeworking, CCTV where used); the policy should be trained on induction and at intervals with records kept, because the Information Commissioner's Office asks for the training records when a breach is reported.
What it costs
Staff handbook and core policies, £995. Five working days.
Employment contract, £595. One template you can reuse for a grade of staff. Five working days.
Buying online forms the engagement on payment. The scope is what the employment contracts and handbooks page describes, you accept the Terms of Service at checkout, and I email you within four working hours to get started. If you would rather ask something first, email me.
What you get
- A bespoke contract drafted for how you employ people
- Restrictive covenants drafted at a scope a court will uphold
- Confidentiality and intellectual property provisions that put ownership where it belongs
- The statutory particulars, so the document does the job section 1 of the Employment Rights Act 1996 requires it to do
- Flexibility clauses where you genuinely need them, drafted to survive challenge
- Core policies: disciplinary, grievance, sickness absence, equal opportunities, data protection and, increasingly, AI use
- One round of amendments
What is not included
- Acting for employees
- Employment tribunal representation
- Payroll, pensions auto-enrolment and tax
- Immigration and sponsor licence work
- Day to day HR handling, disciplinaries, grievances and redundancy processes
Questions I am often asked
Is our website privacy notice enough for staff?
It is not. Staff need their own privacy notice explaining what the employer does with their data, and the policy tells staff how to handle everyone else's. The two are different documents.
An employee has asked for everything we hold about them. What now?
Treat it as a subject access request: one month from receipt, free, with third-party data redacted and nothing deleted. The policy sets the process and who runs it.
Do we have to report every data breach to the regulator?
Only breaches likely to result in a risk to individuals, within seventy-two hours of becoming aware. Every incident is logged whether notified or not, and the policy requires staff to report internally at once so that the assessment can be made in time.
Related guidance and services
- Employment contracts and handbooks, £995, the service this page describes
- Consultancy and contractor agreements, £595
- IT, email and social media policy
- Staff handbook for a business with fifty employees
This page is general guidance for businesses in England and Wales, not advice on your own circumstances. Last reviewed: October 2026. Email geoffrey@caesar.co.uk.