Staff Data Protection and Privacy Templates
These Staff Data Protection and Privacy templates help UK employers manage employee personal data lawfully and transparently under the UK GDPR and Data Protection Act 2018. They are designed for use in staff handbooks and internal HR documentation, giving a clear framework for how staff data is collected, used, stored, shared and protected, and how employees can exercise their data protection rights.
This mini-suite comprises:
Staff Data Protection Policy
This policy template is a comprehensive, detailed staff data protection policy covering principles, lawful bases, staff rights, DPIAs, security, data sharing, international transfers and breach notification.
Typical Use:
Larger or higher-risk organisations or those wanting a full, stand-alone staff data protection policy for the staff handbook.
Short Form Staff Data Protection Policy
This short policy template is a streamlined version focusing on core UK GDPR principles, lawful bases, staff rights, and signposting to other policies (IT security, data retention, etc.).
Typical Use:
SMEs or organisations wanting a concise but robust policy that’s easier for employees to read and for managers to implement.
Staff Subject Access Request Form (SAR Form)
The SAR Form is a practical form for employees to make subject access requests (SARs) under the UK GDPR “right of access” and for HR to capture the information needed to respond.
Typical Use:
Any employer needing a consistent, documented process for handling staff SARs within statutory timescales.
Employers can either adopt the full or the short-form Staff Data Protection Policy (not usually both), and use the Subject Access Request Form alongside the chosen policy to handle employee data subject access requests in a consistent, compliant way.
These templates are also available at Employee Data Protection and the UK GDPR which also includes a Homeworking Data Protection Policy, Additional SAR Form with letter templates, and Privacy Notices.
Please click on the links below for full details of these documents and to download:
Staff Data Protection and Privacy Templates is part of Employment. Just £38.50 + VAT provides unlimited downloads from Employment for 1 year.
Frequently Asked Questions
Does my business need a written staff data protection policy? +
The UK GDPR accountability principle effectively requires a written data protection policy in practice, even though no single statutory provision expressly mandates a standalone one. Employers must demonstrate compliance with data protection principles, and a documented policy is a primary way of doing so. The ICO treats it as a key organisational measure. Choose a comprehensive Staff Data Protection Policy for larger or higher-risk organisations, or a Short-Form Staff Data Protection Policy for SMEs wanting a concise but robust alternative. Adopt one, not both.
What is the difference between the full Staff Data Protection Policy and the Short-Form version, and which one should I use? +
Both templates address UK GDPR compliance for staff data, but they differ in depth and intended audience. The full Staff Data Protection Policy covers lawful bases, data protection impact assessments, security, data sharing, international transfers and breach notification in detail. It suits larger organisations or those handling higher-risk data who want a comprehensive stand-alone handbook policy. The Short-Form version covers the same core principles and staff rights but is more concise, signposting to related policies such as IT security and data retention. It suits SMEs or organisations that want something easier for employees to read and managers to implement. Choose one and use it alongside the Staff Subject Access Request Form.
An employee has asked for a copy of all the personal data we hold about them. What must we do and how quickly? +
Treat this as a subject access request (SAR) under Article 15 UK GDPR: within one calendar month of receiving it, provide a copy of the personal data held plus supplementary information including the purposes of processing, categories of data, recipients and retention periods. Where the request is complex, or the individual has made multiple requests, you may extend by up to two further months, but you must notify the employee within the original month and explain why. Since 5 February 2026 the Data (Use and Access) Act 2025 codifies a stop-the-clock mechanism: if you genuinely need further information to identify the scope, the clock pauses until the employee responds. The Simply-Docs Staff Subject Access Request Form provides a consistent, documented process within statutory timescales.
Can I rely on employee consent as the lawful basis for processing staff data? +
Consent is rarely the right lawful basis in employment: the UK GDPR requires it to be freely given, but the employer-employee power imbalance means it is very likely treated as not freely given. Most employers instead rely on contractual necessity (paying wages or administering benefits), legal obligation (HMRC reporting or right-to-work checks) or legitimate interests. Special category data such as health records or trade union membership needs an additional Article 9 condition, and sometimes an Appropriate Policy Document under the Data Protection Act 2018. A well-drafted staff data protection policy, as provided in the Simply-Docs templates, documents these lawful bases and reduces regulatory exposure.
We process employee health and sickness data. Do we need to do anything extra compared with ordinary staff data? +
Yes, because health data is special category data under Article 9 UK GDPR, so processing needs both an Article 6 lawful basis and a separate Article 9 condition. Employers most often rely on processing necessary for employment law obligations, and where you rely on that Article 9(2)(b) employment condition, or on the Article 9(2)(g) substantial public interest condition, you also need an Appropriate Policy Document under Schedule 1 of the Data Protection Act 2018. Some other Article 9 conditions that can arise with health data do not need a Schedule 1 condition or an Appropriate Policy Document, for example explicit consent, vital interests, data manifestly made public by the individual or processing necessary for legal claims, so check which condition you are relying on. Restrict access to those with a genuine need to know: sharing medical details by general team email would not be compliant. The Simply-Docs Staff Data Protection Policy addresses these requirements.