GDPR and data protection policy template

£ 20

This model policy outlines how the Company will comply with statutory requirements of GDPR and data protection.

Reading time
How long to understand and prepare this policy?
5 mins
Get a value bundle that includes our GDPR and data protection policy template

Complete package
618 templates, our full range
£ 125
Handbook library
113 templates, supporting multiple handbook needs
£ 50
Security and information policies
8 policies
£ 35

What is a GDPR and data protection policy?

The purpose of this GDPR and data protection policy template is to provide you with a flexible and customisable document to serve as a robust and effective starting point for you.

By using our GDPR and data protection policy template, you can streamline your process, maintain consistency and accuracy, and save time, and it can be easily adapted to fit your specific scenario.

This is a preview. Viewing the content requires a purchase.

This is a preview. Viewing the content requires a purchase.

Best practice timescale for this to be issued
When should this policy be issued?
During onboarding / after changes / planned refresher
Issued by who, to whom
Who should issue this policy, and to whom?
Internally issued to appropriate recipients in your Company
Applicable legal jurisdictions
In which jurisdictions can this policy be used?
Great Britain & NI (United Kingdom), Worldwide

GDPR and data protection policy template

gdpr and data protection policy template

What legislation or best practices underpin this template / should I be aware of?

United Kingdom
  1. Data Protection Act 2018 (DPA): This is the UK's primary data protection legislation that incorporates the GDPR into UK law. It sets out the rules and regulations for the processing of personal data, including employee data, and outlines the rights and responsibilities of data controllers and data processors.

  2. General Data Protection Regulation (GDPR): Although this is an EU regulation, it applies to the UK as well. It provides a comprehensive framework for the protection and processing of personal data for individuals within the EU, including employees.

  3. Employment Rights Act 1996: This legislation contains provisions related to employee privacy and confidentiality. It establishes the duty of employers to maintain the confidentiality of an employee's personal information and employment records.

  4. Human Rights Act 1998: This Act incorporates the European Convention on Human Rights (ECHR) into UK law. It includes the right to respect for private and family life, which has implications for how employers handle employee data and ensure data privacy.

  5. Equality Act 2010: While primarily focused on promoting equality and preventing discrimination in the workplace, this Act also contains provisions related to the handling of sensitive personal data, such as information about an employee's health or disability.

  6. Computer Misuse Act 1990: This legislation addresses unauthorized access to computer systems, which is relevant for protecting employee data stored electronically.

  7. Privacy and Electronic Communications Regulations (PECR): These regulations supplement the DPA and GDPR and provide rules on electronic communications, including email marketing and the use of cookies on websites, which may collect personal data from employees.

  8. Employment Practices Code: This code of practice, issued by the Information Commissioner's Office (ICO), provides guidance on data protection in the context of employment, helping employers understand their responsibilities when processing employee data.

  9. Trade Union and Labour Relations (Consolidation) Act 1992: This legislation ensures that trade unions have access to certain employee data for collective bargaining purposes while maintaining data protection requirements.

  10. Whistleblowing Policy: Although not a specific piece of legislation, implementing a whistleblowing policy is essential to encourage employees to report any data protection breaches or concerns they may have.

This is a preview. Viewing the content requires a purchase.

This is a preview. Viewing the content requires a purchase.


Other territories

Refer to your local employment legislation / labor laws to support the execution of the template. Review the wording for local accuracy.

GDPR and data protection

Overview

This policy outlines how the Company complies with all statutory requirements of GDPR.

Scope

This policy is applicable to all employees of [company name].

General principles

[Company] will comply with all statutory requirements of the GDPR by registering all personal data held on its computer and/or related electronic equipment and by taking all reasonable steps to ensure the accuracy and confidentiality of such information.

The Data Protection Act protects individual's rights concerning information about them held on computer. Anyone processing personal data must comply with the eight principles of good practice. Data must be:

  1. fairly and lawfully processed
  2. processed for limited purposes
  3. adequate, relevant and not excessive
  4. accurate
  5. not kept longer than necessary
  6. processed in accordance with the data subject’s rights
  7. secure
  8. not transferred to countries without adequate protection

Employees can request access to the information held on them by the Company. All requests by employees to gain access to their personnel records should be made in writing. There is no charge for this service.

This policy [does not] form[s] part of your terms and conditions of employment.

Version: [1.0]

Issue date: [date]

Author: [name, job title]

This is a preview. Viewing the content requires a purchase.

This is a preview. Viewing the content requires a purchase.

Why buy our GDPR and data protection policy template?

  • It's easily editable and implementable, saving you time and money
  • It's designed by CIPD accedited Chartered HR practitioners with operational experience in this area
  • You will maintain compliance with ACAS guidelines, legislation, and industry best practices
What other advantages does buying from hrdocbox.co.uk offer?
  • Email notifications for any updates made to this template or its accompanying materials
  • 12 months of unrestricted access without any additional costs (any update in that period is free to you)
  • A 25% discount on all library, toolkit, and template purchases/renewals

I have just renewed our membership for another year for HRdocbox. It's an extremely useful resource with a wide variety of documents and knowledge...
★★★★★
- Rachel Masing, ETM Group

I have been using the service now for around 6 months and it has been really useful in developing and updating polices and processes.
★★★★★
- Jamie Allan, Armstrong Craven

Excellent library of resources and templates which have made my job in my small business so much easier to manage HR for my employees...
★★★★★
- Emma Hunt

Great value and the site contains an extensive library of essential HR documents. I access the site probably once a week...
★★★★★
- Laura Alliss-Etty

HRDocBox is a great resource. It is incredibly good value, providing a large selection of HR guidance materials as well as...
★★★★★
- Emma Beauchamp

Navigating Holiday Requests - Balancing Employee Needs and Operational Demands
Fri, 19 Apr 24

Navigating Holiday Requests - Balancing Employee Needs and Operational Demands

Managing holiday requests in the workplace can be a complex task, requiring employers to balance the needs of their employees with the operational requirements of the business...