Employee privacy notice

A privacy notice for employees, workers and contractors, drafted for the employer as the document given on recruitment, for a fixed fee of £595 with the cookie notice and consent guidance, in five working days.

Share

Employee privacy notice

Buy now, £595

An employer holds more personal data about its staff than about anyone else: identity, pay, bank details, health and absence, performance, disciplinary records, monitoring data and the correspondence of years, and the law requires the employer to tell staff what it does with all of it in a notice that is separate from the customer-facing one. The employee privacy notice is also the document an employee's solicitor asks for at the start of a dispute, and the one the regulator checks when a breach involves staff data. The privacy notice and the cookie notice are drafted for the business, with guidance on the consent mechanism, for a fixed £595 and delivery in five working days.

Who this is for

Employers in England and Wales of any size, since every employer processes staff data, including employers whose staff have only ever seen the website privacy notice.

What matters in an employee privacy notice

Why staff need their own notice and when it is given

As controller, the business must under Article 13 of the UK GDPR tell its employees, workers and contractors what personal data it holds about them, why, on what lawful basis, who it shares it with, how long it keeps it and what their rights are, at the point of collection, which for staff is recruitment and the start of employment, with the notice reissued when the processing changes; the customer privacy notice does not do this (it describes different data for different purposes), the handbook's data protection policy tells staff how to handle other people's data rather than what happens to theirs, and the employee notice is the third document, issued with the contract and available in the handbook.

The data an employer holds and the lawful basis for each use

The notice should list the categories (identity and contact details, right to work evidence, bank and tax details, the contract and its terms, pay, benefits and pension, hours and absence, performance and appraisal, training, disciplinary and grievance records, monitoring data, emergency contacts, references, correspondence) and the lawful basis for each: the employment contract under Article 6(1)(b) for pay and the terms, legal obligation under Article 6(1)(c) for tax, right to work checks under the Immigration, Asylum and Nationality Act 2006, pension auto-enrolment under the Pensions Act 2008 and health and safety records, legitimate interests under Article 6(1)(f) for management, security, monitoring and the employer's own administration with the interest stated; consent is used sparingly because an employee cannot freely refuse it, and the notice should say so.

Special category data, the employment condition and the policy document

Sickness records, occupational health reports, disability and adjustments, pregnancy and family leave, trade union membership, equality monitoring data, and (where the role requires) criminal records checks are special category or criminal records data under Articles 9 and 10 of the UK GDPR, processed under the condition in Schedule 1 to the Data Protection Act 2018 for obligations under employment law, with an appropriate policy document the Act requires the employer to have, and under the equality of opportunity condition for monitoring; the notice should state the conditions, the policy document should exist, and the health data should be handled with the restrictions the notice describes (limited access, separate storage, the employee's consent before occupational health reports are shared).

Monitoring, systems and what the employer sees

Where the employer monitors email, internet use, systems activity, devices, vehicles or premises (CCTV), the notice must say what is monitored, why, on what basis and who sees the results, consistently with the Information Commissioner's guidance on monitoring workers (a stated purpose, a lawful basis, an impact assessment for intrusive monitoring, the least intrusive means, workers told in advance) and with the Investigatory Powers (Interception by Businesses etc. for Monitoring and Record-keeping Purposes) Regulations 2018 where communications are intercepted; the notice should describe the monitoring in terms a worker understands and should not describe monitoring the employer does not do, and covert monitoring should be reserved for the narrow circumstances the guidance allows and never described as routine.

Sharing with payroll, pensions, HMRC and the rest

The notice should list the recipients: the payroll provider and the accountants, HMRC, the pension provider, the benefits providers (private medical, life cover, the employee assistance programme), occupational health, the employer's insurers and lawyers, the Disclosure and Barring Service where checks apply, regulators and the authorities where the law requires, the IT and HR systems providers as processors (with international transfers under Article 46 of the UK GDPR where the systems are hosted abroad), and, on a transfer of the business, the buyer under the Transfer of Undertakings (Protection of Employment) Regulations 2006, which require employee liability information to be passed; each recipient's role (controller or processor) should be stated.

Retention, references and the data of people who have left

The notice should state the retention periods for staff records (the personnel file for a stated period after employment ends that limitation periods and the employer's obligations justify, payroll and tax records for the period HMRC requires, right to work evidence for the period the scheme requires after employment ends, accident records for the periods the regulations set, unsuccessful applicants' data under the applicant notice), the position on references (factual, under a policy, with the employee's right of access limited for confidential references), the rights the individual has (to access, correct, erase, restrict, port and object), the way to exercise them, the month the business has to respond, and the route to the Information Commissioner's Office; registration with the Information Commissioner's Office under the Data Protection (Charges and Information) Regulations 2018 is required where the fee applies, and the notice can state it.

What it costs

Website privacy and cookies pack, £595. Privacy notice, cookie notice and consent guidance. Five working days.

DPA and privacy terms, £795. Data processing agreement plus privacy notice. Five working days.

Buying online forms the engagement on payment. The scope is what the data protection agreements and privacy terms page describes, you accept the Terms of Service at checkout, and I email you within four working hours to get started. If you would rather ask something first, email me.

What you get

  • A data processing agreement that meets the statutory requirements and can be used as a schedule to your main contract
  • A privacy notice written for people to read rather than to be scrolled past
  • Clear allocation of controller and processor roles, which is where most confusion starts
  • International transfer provisions where you use overseas suppliers
  • Sub-processor and security provisions proportionate to what you do
  • A note on the operational steps the documents assume you are taking

What is not included

  • Full compliance audits and data mapping exercises
  • ICO registration, which you do yourself
  • Breach response and regulatory correspondence
  • Cyber security certification such as Cyber Essentials
  • Advice on data protection law outside the UK and EU

Questions I am often asked

Our staff have signed the handbook's data protection policy. Is that enough?

It is not. The policy tells them how to handle other people's data; the employee privacy notice tells them what the employer does with theirs, which Article 13 requires. It is issued with the contract and reissued when the processing changes.

Consent is not needed and is the wrong basis: the employment law condition applies, with the policy document the Act requires. The notice states the condition and the restrictions on access.

We monitor work email. Does the notice have to say so?

It does, in terms a worker understands: what is monitored, why, on what basis and who sees it, consistent with the regulator's guidance. Monitoring that staff were not told about is a breach regardless of the reason.


✉️
Not sure which service fits, or want to ask something first? Email me a few lines about your business and what you need. I reply, usually the same working day.

This page is general guidance for businesses in England and Wales, not advice on your own circumstances. Last reviewed: October 2026. Email geoffrey@caesar.co.uk.