Data protection, surveillance and privacy at work: UK employment law
Explore our legal resource on data protection, surveillance and privacy in the workplace
Introduces the concepts of data protection for employers and what individual rights are to access information
This factsheet explores the key elements of data protection in the UK, the role of the data controller (often assigned to HR), the seven core data protection principles, the key terms and actions for data compliance, plus penalties and risk. It is designed to support people professionals (there is also a guide for managers) to assist in supporting data protection compliance within their organisations.
The legal obligation of data protection is from the UK General Data Protection Regulation (GDPR) and the Data Protection Act 2018 (DPA 2018). Some updating has, and will, take place through the changes brought in by the Data (Use and Access) Act 2025. The detail of these pieces of legislation is covered on the law page.
Affiliate membership offers instant access to CIPD resources without the need for assessments or study, or explore your options to become a professional member of the CIPD to demonstrate your commitment to the world of work.
Already a member? Login here.
Explore our legal resource on data protection, surveillance and privacy in the workplace
Introduces the legal issues in the UK around effective retention and organisation of HR records
Explore the latest people profession data and how your organisation compares
This guide provides managers with an overview and principles to apply when handling GDPR and data protection requirements to ensure they play their part in complying with regulations governing its safe handling.
Find out what's meant by fair pay, what pay information UK employers must disclose by law and the opportunities pay narratives bring.
Outlines the role of occupational health services in an organisation and the role of confidentiality and consent in discussing an employee’s health
Facts on the recruitment and resourcing process; from defining the role to making the appointment
Learn how an understanding of the macro-economic context can inform HR practice