Essential points 

  • Data protection is about safeguarding important information and making sure it is used properly and legally.  
  • Employers can keep a range of personal information about their employees without seeking their permission including their name, address, date of birth, sex, National Insurance number, emergency contact details, any disciplinary action taken against them. 

  • Organisations need their employees’ consent to keep sensitive information on them such as their race or ethnicity, religion, trade union membership, health and medical conditions, sexual orientation. 

  • Employers must keep employees’ personal data secure and up to date and have extra security in place to protect their sensitive personal data. 

  • Employees have the right to be told what records are being kept on them, how they are used, and how their confidentiality is preserved.

Members access only

Unlock exclusive, tailored content and resources, just for members.

Sign in to access

Not a member yet? Find out how you can become a member today!

Disclaimer 

Please note: While every care has been taken in compiling this content, CIPD cannot be held responsible for any errors or omissions. These notes are not intended to be a substitute for specific legal advice. 

Employment
law advice

Want more employment law advice? Members can phone the CIPD legal helpline or take out a discounted subscription to HR-inform for additional resources.

Callout Image

Related content on data protection

Factsheet
Data protection and GDPR in the workplace

Introduces data protection law in the UK, covering the obligations of employers and individual rights to accessing information.

For Members
Guide
People manager guide: Managing data protection requirements

This guide provides managers with an overview and principles to apply when handling GDPR and data protection requirements to ensure they play their part in complying with regulations governing its safe handling.

For Members
Factsheet
Retention of HR records

Introduces the legal issues in the UK around effective retention and organisation of HR records

For Members
Topic
Data Protection and GDPR resources

Learn more about data protection and GDPR to ensure your organisation is compliant.

Employment law

Access more employment law resources

Employment law
TUPE: UK employment law

What you need to know about TUPE transfers; including how the UK court see breaches of these notoriously complex regulations.

For Members
Employment law
AI and technology in the workplace: UK employment law

Guidance on the legal considerations on the use of technology and AI in UK workplaces

For Members
Employment law
Maternity, paternity, shared parental and adoption leave and pay: UK employment law

Explore our collection of resources around maternity and parental rights, including Q&As on shared parental leave and adoption law and relevant case law

For Members