Meeting the requirements of data protection law whilst handling staff data effectively can be challenging. Holding and using staff information carries significant legal responsibilities and risks.
This invaluable one-day session is designed to meet the needs of anyone who has responsibility for the use of employee and other worker data, including Human Resources Officers and Compliance Officers. It is also useful to Data Protection Officers and Employment Lawyers and companies providing outsourced HR functions to other organisations.
Following the latest guidance and requirements set out in the UK GDPR, the Data Protection Act 2018 and the Data (Use and Access) Act 2025, this course uses case studies based on real life scenarios to give delegates a practical understanding of the data protection compliance issues involved in employing and managing staff. The session gives delegates an understanding of the key areas of risk, and includes practical advice on:
- ensuring that the recruitment and selection process meets the legal requirements, including the content of application forms, pre-employment vetting, criminal records, medical checks, the interview process and using new technologies like automation and AI to streamline these processes
- keeping staff records, including ensuring records are retained for appropriate periods of time
- handling sensitive information such as health and sickness records and medical data
- monitoring staff activities and communications, including using line managers, CCTV cameras and new technologies like AI to monitor individuals at work
- outsourcing functions to third party providers, including practical steps to take when buying in new monitoring tools and the importance of adopting a privacy by design approach from the outset
- how to comply with the latest ICO guidance, particularly in relation to information about workers’ health, monitoring workers, keeping employment records, and recruitment and selection
- an introduction to dealing with rights requests from staff (for detailed guidance on subject access requests, delegates should attend the course ‘Handling Subject Access Requests’)
- disclosing staff information to outside third parties, for example, in the case of reference requests – the legal requirements that must be met before staff information can be sent outside the organisation
- how to handle staff complaints and concerns regarding how you’re processing their personal data, including how to mitigate against the risk of potential data protection related claims for compensation from staff
- practical guidance for dealing with data breaches, including the importance of having data protection training and relevant policies in place
- the role of the Information Commissioner and what to if an investigation occurs
Attendance on the Classroom and Virtual(Teams) formats of this course can be used as credit towards gaining the Practitioner Certificate in Data Protection.
Delegates with limited data protection knowledge may find it helpful to attend Data Protection Essential Knowledge Level 1 before attending this training course.
“Interesting course made better by the exercises. It was useful to have these throughout the training as they really helped me understand the material.”