Diverse team engaging in a collaborative office meeting with laptops and presentations.
|

The data you hold about your own people is the data you look after worst

When a small or growing business takes on its first member of staff, the types of personal data it holds can change overnight. Here’s what changes from a data and privacy perspective, and what can wait.

Many growing businesses are careful with customer data and careless with data of their own employees. The reason is that customer data feels like somebody else’s and employee data feels like the company’s own.

It isn’t. The person whose salary, sick notes, bank details, emergency contact and appraisal notes you hold has the same rights over that information as your customers have over theirs. They also know where their data is kept, and are often the ones most likely to ask for it.

What changes with your first employee

Three things change on the day you take on your first member of staff:

  • You start holding sensitive information such as right to work documentation, bank details for payroll, next of kin. This often includes health data as well: a sick note, an adjustment request, or a condition somebody disclosed in confidence. Health data is special category data under the UK GDPR, which means processing it lawfully requires particularly careful thought.
  • You acquire an obligation to explain yourself. Employees are entitled to be told what you hold and why, in the same way customers are. That’s a short employee privacy notice, and it’s the document most often missing when I first look at a small business.
  • You become a target for requests. Not maliciously. But the point at which somebody is leaving, or unhappy, or in a dispute is exactly the point they ask what’s in their file. That’s the worst possible moment to find out the answer is spread across four systems and a manager’s inbox.

Access is the thing worth getting right

Not everybody working on HR needs access to all HR data on every employee. In most organisations I go into, everybody has it anyway. You never made a conscious decision to do it that way. It’s because systems and access permissions were set when the system went in, and nobody has looked at them since.

Reconfiguring that so that two people hold detailed access rather than a hundred is the smallest change with the largest effect I can ask a business to make. The same principle applies to finance and payroll.

What you need to do to process employee data lawfully:

Roughly in the order of how much trouble each one saves.

  • An employee privacy notice. What data you hold, why, how long, who you share it with, what rights they have. Generally speaking, you should issue an employee privacy notice when a new employee joins.
  • Clear systems of storage and access. The most common problems aren’t policy-related. HR information can end up in someone’s personal email, in a shared drive the whole company can read, or in a manager’s notebook. Ensure there is one defined location with defined access to prevent these  problems arising..
  • Retention periods. Several of these are matters of employment law, not data protection. Payroll records, working time records, right to work documentation and accident records each carry their own required period, and those come from tax and employment law. For PAYE, it’s the current tax year plus the three preceding years.
  • A lawful basis that isn’t consent. Consent works badly in employment because the relationship isn’t equal and an employee can’t freely refuse. Most employee data is based on contract, legal obligation or legitimate interests instead. Remember – if you’re relying on legitimate interests you need to have assessed it rather than asserted it.
  • A decision about recruitment data. Unsuccessful candidates’ CVs are the classic just-in-case file. Keeping them needs a reason and a retention period which – given CVs quickly go out of date – is likely to be a short one.

Where it goes wrong

It’s perfectly possible to deploy technology to track and monitor employee productivity in a lawful way. But doing so without proper thought or sufficient transparency can create huge risks – not just in terms of data protection law, but also for your relationship with your employees. A helpful offer from IT to install new tracking software can mean that monitoring gets introduced without anybody assessing it. Software that tracks activity, logs keystrokes or records calls – nearly all of it needs an assessment and an honest explanation before it begins, rather than after an employee finds out.

Things like handwritten notes by a manager made during an appraisal are disclosable, and can often be the thing that can cause the most damage in a subject access request. That’s not because anything unlawful happened, but because of how people write when they assume nobody will ever read it.

Health information gets handled casually: a sick note forwarded to a team channel or a condition mentioned to a colleague without them understanding that they are disclosing special category data. This is nearly always done with good intentions, which is what makes it hard to control.

What can wait

Most advice in this area is written for organisations that have an HR department, which can leave smaller businesses either overwhelmed, or concluding that it doesn’t apply to them.

At five employees, a little planning and some common-sense controls go a long way. You don’t need a data protection officer. You don’t need a training programme, a governance committee or a lengthy list of policies. As a small business, the priority is having oversight of what you hold, where it is kept, who can see it and how long you’re keeping it.

A client once asked me for a risk assessment across every system in the organisation. We narrowed it to the processes that actually handle personal data, which took out a sizable tranche of the work and a matching amount of the cost.

Doing the small things properly at five people means that at fifty, you’re extending something that works, instead of undoing four years of bad habits.

Related