Archive RSS
Blog  »  July 2021  »  Your GDPR Questions Have Been Answered! - Blog
1
Jul 21

Posted by
Jennifer Patton

Your GDPR Questions Have Been Answered!

GDPR/ the General Data Protection Regulation has been around since May 2018 but the stipulations surrounding GDPR can still be confusing at times which is why we decided to cover this topic as FAQ's but firstly to explain what GDPR is, it is the toughest privacy and security law in the world. Even though it was drafted and passed by the European Union (EU), it imposes obligations onto organizations anywhere, so long as they target or collect data related to people in the EU. Under GDPR you have a fundamental right of access to your personal data from data controllers.

What is personal data?

Personal data is information that relates to you, or can identify you, either by itself or together with other available information. Personal data can include your name, address, contact details, an identification number, IP address, CCTV footage, access cards, audio-visual or audio recordings of you, and location data.

What personal data can employers lawfully process?
GDPR states that to be able to ‘Lawfully Process’ personal data you must be able to fall into at least 1 of the 6 processing classifications, the first one being Consent. Consent must be:

  • Specific, informed, unambiguous, and freely given – there must be evidence that clear affirmative action has been given.
  • Must be for a specified purpose
  • Where consent is obtained as part of a larger document covering other things, consent text must be clearly distinguished from everything else
  • Evidence needs to be retained as to how the consent was obtained. For example; forms, brochures signage, website screenshots.
  • Language must be accessible and easily understood.
  • Have a clear and seamless opt-Out process in place.
  • If you have mailing lists that you’ve used pre GDPR you will not be able to continue using them if you haven’t got specific approval or consent from the individuals.

Do we need to ask for consent from our employees to process their data?

No, as the reliance for processing and retaining their data will be down to lawful processing because of the employer’s legal obligation to deduct taxes etc. and also down to the contractual agreement in place to pay them and pay forward the taxes owed on their behalf. And also to the nature of the relationship between the employer and the employee, the status quo is in the employer’s favour so consent would not be unambiguous or freely given.

Is the emailing of pay slips permissible under GDPR?
There is nothing in the GDPR that states it is no longer permissible to email payslips, this practice is still very much acceptable. The thing to keep in mind in relation to emailing payslips is to ensure that all appropriate security measures are in place. The payslips that are emailed from BrightPay are encrypted and deleted from our servers once sent, however it may also be prudent of a processor of the payroll to password protect the payslips also. It will be the responsibility of the Data controllers (employers) to be vigilant that correct email addresses are inputted.

Do I need to provide my employees with training about GDPR?

It is advised that employers provide training to all individuals about their data protection responsibilities as part of the induction process. Additional training should be provided at regular intervals thereafter or whenever there is a substantial change in the law or The Company’s policy and procedures.

If data protection is breached, what are the consequences?

It is important that you comply with the GDPR legislation and put adequate policies and procedures in place. Your organisation can be inspected and could face significant penalties if your practices are in breach of GDPR. The GDPR allows the EU's Data Protection Authorities to issue fines of up to €20 million or 4% of annual global turnover (whichever is higher).

Bright Contracts contains a 'Data Protection' section of the Company Handbook which can be viewed under the 'Introduction' tab. Download a trial of our software to see a sample of this content.

 Related Articles:

 - How BrightPay Connect is helping with GDPR

Online Payslips: Their benefits and why you should use them

GDPR and Thesaurus Software

Posted in Company handbook, Contract of employment, Employee Contracts, Employee Handbook, Employee Records, GDPR, General Data Protection Regulation