Archive RSS
17
Sep 18

Posted by
Jennie Hussey

Data Protection complaints increase since introduction of GDPR

Nearly 4 months since the General data Protection Regulation (GDPR) was introduced across all of Europe, complaints around Data Protection have nearly doubled in the UK and are up by nearly 2 thirds in Ireland.


GDPR was designed to give Data Subjects more control over their personal data, with more transparency and the threat of larger fines to those in breach of the new rules. The GDPR requires any company that suffers a data breach to notify its users/data subjects within 72 hours of the breach being discovered.


• Ireland’s Data Protection Commission (DPC), head of communications - Graham Doyle has said that ‘there has been a significant increase in the volumes of both breaches and complaints to the DPC since May 25th.’ Since GDPR enforcement began the DPC has seen monthly data breach reports double, while data protection complaints increased by 65%.

• Data protection complaints to the UK’s Information Commissioners Office (ICO) rose to 4214 in July compared to just 2310 complaints received in May before the GDPR came into force. A spokes person for the ICO said the increase was expected, as more users became aware of data protection because of publicity around the new rules and following a series of high-profile data scandals involving big technology firms.


Experts note, however that the increase does not mean that the number of data breaches has suddenly gone up, but rather reflects the full scale of the data breach problem becoming better known.
Organisations that fail to comply with GDPR can face fines of up to 4% of annual global revenue or €20 million, whichever is greater. So far none of the EU’s Data Protection Agency’s has issued any fines. Graham Doyle at the DPC said ‘It is too soon to expect to see any fines levied against organizations that have violated GDPR – given its only 3 months after it went into full effect.’

 

We will be hosting a free online webinar - ‘GDPR 3 Months On’ on Thursday September 20th at 11am, where Graham Doyle will joining us as a guest speaker.


To register for this webinar please click here.

Posted in Company handbook, Employee Contracts, Employee Self Service, Employment Update, Events, GDPR, General Data Protection Regulation

8
Aug 18

Posted by
Jennie Hussey

Back to Basics - Disciplinary Steps and Sanctions

Another question that comes up from time to time is how and when to initiate the disciplinary procedures - How many warnings can an employee receive before being dismissed? When do I give a final warning? Can I fire my employee for committing an offence of gross misconduct?

The first step is always to inform the employee of issues that you may have, even minor issues; whether it is with their job performance, their time keeping, or even a breach of company rules, by means of informal counselling. The employee must be given the appropriate time/measures to defend themselves or at least be given the chance to rectify the problem. Prior to taking the decision to invoke the disciplinary procedure, the employer must ensure that the situation has been thoroughly investigated.

The following disciplinary procedures should apply in matters of discipline; constant repetition of minor offences, willful negligence or unsatisfactory performance or complaints, that are found to be proven against the employees.

The stages in the procedure are as follows:

• Stage 1 - Verbal Warning
• Stage 2 - First Written Warning
• Stage 3 - Final Written Warning                                                                                                                      The final written warning will state clearly that the next stage may be termination of employment if conduct and/or performance does not improve.
• Stage 4: Action Short of Dismissal
In exceptional circumstances, and depending on the individual case, The Company may exercise its discretion to suspend with or without pay. Demotion to a lower position or rate of pay and transfer to another position may also be considered. This is action short of dismissal.
• Stage 5: Dismissal
In an instance of gross misconduct, a full investigation will be conducted and a disciplinary meeting will be held. This will follow the normal procedures outlined above, but the outcome, if found to be gross misconduct, will almost certainly result in dismissal due to the serious nature of the situation.

At each stage in the procedure a disciplinary meeting should be held, where all the facts will be considered and any mitigating circumstances discussed, as well as timelines imposed for improvements, etc. Where a warning is issued, a copy will be placed on the employees personnel file for a defined period. All warnings issued under this procedure will state clearly that the employee will be liable for further disciplinary action should their performance not improve or should there be a further breach of company rules or procedures. In the event of no further transgression occurring and the performance improving, the warning will be removed after a period of no more than 12 months and the employee’s file will be clear. The employee will also be advised of his/her right to appeal against disciplinary action taken.

This is an area where employer’s need to tread carefully, at all times fair procedures must be applied and the company’s’ policy regarding disciplinary steps and sanctions should be adhered to. Once these steps are followed there is no reason why an employer cannot dismiss an employee without repercussions. Most employers tend to fall down and lose Unfair Dismissal cases brought against them, not because they didn’t have disciplinary procedures in place, but because they did and they failed to actually follow them.

Bright Contracts has a very robust Discipline and Grievance Policy set out in its Handbook with all the relevant procedures that an employer needs. To download a free trial of Bright Contracts click here. To request an online demo of Bright Contracts, click here.

 

Bright Contracts | Thesaurus Payroll Software | BrightPay Payroll Software

Posted in Dismissals

24
Jul 18

Posted by
Jennie Hussey

Back to Basics - New Employees

We often get calls into the helpline requesting basic information on HR/Employment Law queries like how to deal with new starters or when should an employer invoke the disciplinary procedures, so we will look at some basic HR topics in a series of blogs starting today with new employees.


New Employees
• A new employee is required by law, under the Unfair Dismissal Act, to receive a copy of the company’s ‘Dismissal Procedures’, which are usually contained in the ‘Disciplinary/Grievance Procedures’ of the Staff or Company Handbook, within 28 days of starting work with the company.
• Under the Terms of Employment (Information) Act 1994 the employer is obliged to furnish new employees within 2 months of starting, with a ‘Written Statement of ‘certain’ terms and conditions’ of their employment, also known as an ‘Employment Contract’.
• The new GDPR regulations specify that employers must provide their employees with information about what personal data they hold on them, for what purpose and how it was collected, who it may be shared with, what security measures are in place to keep it safe and what the employee’s rights are as well as other specific requirements. This is called an ‘Employee Privacy Policy’ or ‘Employee Privacy Notice’ and should be given to the employee as an addendum to their Employment Contract.

Based on these 3 pieces of legislation it would be best practice to provide your new starter with their Employment Contract, Privacy Policy and Staff/Company Handbook on their first day of work, if not before it. An employer can be fined up to 4 weeks pay for not providing the employee with their ‘Written Statement of Terms and Conditions of Employment’ within the 2 month timeframe, so it is best to get into the habit of furnishing the documents as soon as possible.

There is no requirement for a signature from the employee on any of these documents; however it would be prudent of an employer to request a signature from the employee or at least some form of acknowledgement or proof of the employee receiving the documents.

The new Employment Bill 2017, yet to be introduced, stipulates that a new employee should receive some details of their terms of employment within 5 days of starting with a company but it is yet to be seen whether this aspect of the Bill will get the go ahead.

Bright Contracts offers employers a simple and user-friendly system which enables them to easily create and customize all of these documents and keep an electronic record on file. To download a Free Trial click here or book an online Demo of the Bright Contracts software.

 

Bright Contracts | Thesaurus Payroll Software | BrightPay Payroll Software

Posted in Company handbook, Contract of employment, Dismissals, Employee Contracts, Employee Handbook, Employee Records, Employment Contract, GDPR, Staff Handbook

11
Jul 18

Posted by
Jennie Hussey

GDPR deadline gone - So what now?

If you haven’t already updated existing policies for GDPR or if you haven’t started to look at the implication of the new regulations within your organization, you still have time. GDPR compliance will be an on-going process and therefore will need to be monitored and updated on a regular basis – it will not be just a one-off exercise, so it’s certainly not too late to make a start on those updates to get you on the road towards compliance.
The first thing you should consider is to create an inventory of all the personal data you currently store and/or process, whether that be data belonging to employees, customers or suppliers. This inventory will go a long way in helping you, as you will be able to garner from it any areas that need updating or creation of new procedures to help with meeting the GDPR requirements.


• Employee Privacy Policy - If you have employee’s, does the existing contract detail what data you process on them, with whom and what they’re rights are in relation to that data? If not then you would need to create an Employee Privacy Policy.
• Clean Desk Policy – Do you operate a Clean desk Policy? Whereby data belonging to customers or suppliers is not left out on desks overnight where cleaners/security staff may have access to them.
• Data Processor Agreement - Do you share any employee information with your accountant or pension provider? If so do you have a valid or up to date contract or letter of engagement covering the new GDPR stipulations between data controllers and data processor’s?


Realistically it will be difficult for any organization to ever be fully compliant with GDPR; however once you are not ignoring your obligations under the new rules and have or are in the process of taking steps towards demonstrating compliance this should be sufficient if you ever face a Data Protection inspection.


If you require further guidance on GDPR please see our dedicated support section on our website where you can find on-demand GDPR webinars, FAQ’s and template documents like a Data Processor Agreement.
Bright Contracts has also recently been upgraded to include a new Employee Privacy Policy feature whereby you can tick off another box to prove compliance under the new GDPR regulations. Download a free trial of Bright Contracts here. Book a free online Demo of the software.

 

Bright Contracts | Thesaurus Payroll Software | BrightPay Payroll Software

Posted in Employee Contracts, General Data Protection Regulation

22
Jun 18

Posted by
Jennie Hussey

Privacy Policies - a GDPR requirement

One of the main principles of GDPR is that Data shall be processed lawfully, fairly and in a transparent manner, these three elements overlap and all three must be satisfied in order to demonstrate compliance.
Employers, as both Data Controllers and Processors, must be able to show how they comply with the new data protection principles and be clear and open with their employees about the processing of data and their rights. The GDPR stipulates that anywhere personal data is being collected, either directly or indirectly, Privacy Notices should be in place, these policies are critical to complying with the transparency obligations in the GDPR. So the introduction of an Employee Privacy Policy will cover the required elements and ensure demonstratable compliance in this regard.


The Privacy Policy should be written in a clear and easily-understandable format and must include;


• What data is processed – name, address, PPS no., bank details, etc.
• How it was obtained – employee detail request form, CV, ROS, etc.
• The ‘legal basis’ for processing the data – contractual necessity, legal obligation, etc.
• Who has access to it and any third parties– HR dept., payroll clerk, pension company
• How it is stored and security – HR system, Thesaurus software, encryptions, etc.
• How long it is kept for –set in company policies or statutory requirements
• The rights of the employee – right to access, rectification, erasure, etc.
• If data is transferred outside the EEA
• Contact details of Data Controller


We have recently upgraded our Bright Contracts software to include a new Employee Privacy Policy feature, so now employers can facilitate the main GDPR principle of lawful, fair and transparent processing of the employee data. We have also updated the Data Protection Policy within the Handbook and the Data Protection Clause within the contracts.


To download a free trial of Bright Contracts, click here.
To request a free online Demo of Bright Contracts, click here.

 

Bright Contracts | Thesaurus Payroll Software | BrightPay Payroll Software

Posted in Bright Contracts News, Contract of employment, Employee Contracts, Employee Records, GDPR, General Data Protection Regulation, New Features, Software Upgrade

13
Jun 18

Posted by
Jennie Hussey

Why am I getting all these emails about privacy?

Lately you may have noticed your inbox bulging each morning with lots of emails with similar subject lines to these;


“Your privacy = our priority”                   “GDPR Data Protection – Your Data is Safe with us”
“Big Changes are coming”                        “Opt-In to continue receiving our great updates”
“GDPR update – please don’t leave us!”  “We’re keeping your details safe”


New, tougher European regulations around privacy and the use of personal data have now come into force and could see companies hit with huge fines if found to be in breach of the new laws.
In order for personal data to be processed lawfully, the processor must be able to rely on the reasoning being at least one of 6 categories, the main one being Consent. So if you were previously signed up with a company to receive newsletters or emails about special offers, they can no longer continue to send you these without your explicit consent.
Previous Data Protection Legislation allowed for an option to ‘Opt-Out’ as being sufficient means to mark having your consent, however with the new GDPR this is no longer the case. Consent must be ‘freely given’ unambiguous’ and for a ‘specific purpose’. Consent must be easily read and clearly distinguishable from other text and evidence must be collected as to how consent was obtained.
Consent can no longer be assumed and the likes of pre-ticked boxes that would have needed to be unticked if you didn’t want to register are now banned. Also the facility to Unsubscribe must be clear and an easy procedure to follow.


So all the emails you have been receiving, like those listed above, are those companies that you may previously have signed up with, scrambling to cover themselves for GDPR and not wanting to lose you as a possible customer or sale.


For more information on GDPR and how it may affect your organization, please see our dedicated online support documentation here.

 

Bright Contracts | Thesaurus Payroll Software | BrightPay Payroll Software

Posted in Bright Contracts News, Company handbook, Contract of employment, Employee Contracts, Employee Handbook, Employment Contract

30
May 18

Posted by
Jennie Hussey

GDPR Frequently Asked Questions - Answered!

Is the emailing of payslips permissible under GDPR?
There is nothing in the GDPR that states it is no longer permissible to email payslips, this practice is still very much acceptable. The thing to keep in mind in relation to emailing payslips is to ensure that all appropriate security measures are in place. The payslips that are emailed from both Thesaurus and BrightPay are encrypted and deleted from our servers once sent, however it may also be prudent of a processor of the payroll to password protect the payslips also. It will be the responsibility of the Data controllers (employers) to be vigilant that correct email addresses are inputted.

Can I still use my hard-earned mailing lists after May 25th?
Not automatically - the GDPR states that to be able to ‘Lawfully Process’ personal data you must be able to fall into at least 1 of the 6 processing classifications, the first one being Consent. Consent must be:
• Specific, informed, unambiguous, and freely given – there must be evidence that clear affirmative action has been given.
• Must be for a specified purpose
• Where consent is obtained as part of a larger document covering other things, consent text must be clearly distinguished from everything else
• Evidence needs to be retained as to how the consent was obtained. For example; forms, brochures signage, website screenshots.
• Language must be accessible and easily understood.
• Have a clear and seamless opt-Out process in place.
If you have mailing lists that you’ve used pre GDPR you will not be able to continue using them if you haven’t got specific approval or consent from the individuals.

Do we need to ask for consent from our employees to process their data?

No, as the reliance for processing and retaining their data will be down to lawful processing because of the employer’s legal obligation to deduct taxes etc. and also down to the contractual agreement in place to pay them and pay forward the taxes owed on their behalf. And also to the nature of the relationship between the employer and the employee, the status quo is in the employer’s favour so consent would not be unambiguous or freely given.

More information can be found in the GDPR section of our online support documentation on our website - Bright Contracts IRL - GDPR

To book a free online demo of Bright Contracts click here.
To download your free trial of Bright Contracts click here.

BrightPay - Payroll Software | Thesaurus Payroll Software
Bright Contracts - Employment Contracts and Handbooks

22
May 18

Posted by
Laura Murphy

Do employers need to amend employees' contracts to comply with the GDPR?

No, it is not necessary for employers to amend the contracts of existing employees to comply with the General Data Protection Regulation (GDPR). However if your employment contract includes a data protection clause it will need to be revised for any new contracts created. 

For existing employees, employers should issue a new privacy notice to, providing information on the processing of their personal data, which would override any invalid data protection clauses in the contract. The GDPR specifies the information that the employer must provide in the employee privacy policy. The information includes the purposes for which the employer will process the employee's personal data, the legal bases for the processing, information about the retention period and information about the employee's rights as a data subject.

What has Bright Contracts done?

  • Updated employment contract: whilst not necessary to update existing employees’ contracts, we have updated the Data Protection contract clause for all new contracts created in Bright Contract.
  • Employee Privacy Policy: a new Employee Privacy Policy will be made available to all Bright Contracts customers. The new policy contains all the specific information required under GDPR.
  • Data Protection Policy: the handbook Data Protection Policy has been updated and should also be communicated to employees.

 

17
May 18

Posted by
Jennie Hussey

WRC Annual Report 2017 – The Facts and Figures

The Work Place Relations Commission have published their third annual report, outlining the key performance metrics relating to complaints filed and decisions made across the employment realms.

One of the bigger achievements made by the WRC is a dramatic reduction in the length of time it takes to get a case to resolution. When the WRC was established in October 2015 it could take a case up to 2 years to secure an outcome whereas now, once submissions are received, it is taking less than 6 months.

Other Key Facts

• €1.8 million was recovered in unpaid wages; up €300,000 on the previous year
• 4750 workplace inspections were carried out, either announced or unannounced with over 99,000 employees covered by these inspections
• 14,001 complaints were received by WRC relating to:

  • Pay – 27%
  • Unfair Dismissal - 14% 
  • Discrimination and Equality - 11% 
  • Terms and Conditions of Employment – 8%

• Over 52,000 calls were received on the WRC information hotline, with just under half of these relating to employment permit queries.
• There were 4,370 adjudication hearing’s; up 24% on 2016

It is now almost three years since the formation of the WRC, and from the above figures it is clear that they are well into their stride and making significant inroads in terms of their objective of promoting the improvement of workplace relations, encouraging compliance with relevant employment and equality legislation. As such it is imperative that employer’s have the proper records in place in case of an inspection.

Solution

Bright Contracts allows the user to create and customise contracts of employment and company handbooks, this covers part of your obligation as an employer under current Employment Legislation.

To book a free online demo of Bright Contracts click here.
To download your free trial of Bright Contracts click here.

Posted in Company handbook, Contract of employment, Discrimination, Dismissals, Employment Tribunals, Wages, Workplace Relations Commission, WRC

12
Apr 18

Posted by
Laura Murphy

How GDPR will affect your employee processing

The General Data Protection Regulation (GDPR) will come into force on 25th May 2018 changing the way we process data forever. The aim of the GDPR is to put greater protection on the way personal data is being processed for all EU citizens. Personal data can be anything from a name, an email address, PPS number, bank details etc so as you can imagine employers process a huge amount of personal data on a daily basis. So how will the GDPR affect employers in terms of processing employee data?

Consent

Data in the employment context, will include information obtained from an employee during the recruitment process (regardless of whether or not they eventually got the job), it will also include the information you hold on current employees and previous employees. All this information may be saved in hard copy personnel files, held on HR systems or it could be information contained in emails or information obtained through employee monitoring.

Under GDPR your employee’s will have increased rights around their data.

These rights will include:

  • The Right to Access. It’s not a new concept that employees will be able to request access to the data you hold on them. However, there is a new recommendation that where possible employers should provide their employees with access to a secure self-service login where they can view data stored on them. This backs-up the whole concept of transparency and ease of access to data, which underpins the new Regulations.
  • The Right to Rectification. Individuals are entitled to have personal data rectified if it is inaccurate or incomplete. This is an existing right and the onus is on the employer to ensure that your employee records are kept up-to-date. To help ensure you maintain up-to-date records, employers should make it easier for employees to update their data.
  • The Right to be informed. Employers must be very transparent with employees about what data you hold, why and how long it is held for. Up until now it has been the common practice for many employers to include a standard clause in the employment contract regarding the processing of HR Data, under GDPR that will no longer be sufficient. Employers need to be reviewing their Employee Data Protection Policies and possibly writing new Employee Privacy Policies that go into detail on the processing of employee data.

Employee self service

Under the GDPR legislation, where possible employers should be able to provide self-service remote access to a secure system which would allow employees view and manage their personal data online 24/7. Furthermore, the cloud functionality will improve your payroll processing with simple email distribution, safe document upload, easy leave management and improved communication with your employees. By introducing a self-service option, you will be taking steps to be GDPR ready.

 

For information on how long to keep on employee files please see our blog: How long should you retain employee records under GDPR?

To book a free online demo of Bright Contracts click here.
To download your free trial of Bright Contracts click here.

Posted in Bright Contracts News, Contract of employment, Employee Handbook, Employee Records, Employee Self Service, GDPR, General Data Protection Regulation

Older Articles >