The business introduces productivity monitoring
Define the precise problem, compare less intrusive options, complete DPIA screening, configure the tool narrowly and inform workers before routine monitoring begins.
End of Summer Savings · Get 10% off any legal service · Ends 31 August
Claim offerPrivacy · UK business guide
Map personal data, lawful bases, notices, processor contracts, monitoring, retention and incident response around the way the business actually operates.
Jurisdiction: United Kingdom.
At a glance
Record what personal data enters the business, why it is used, where it goes, who can access it and when it is deleted.
Choose a lawful basis and check special-category conditions, transparency, contracts, security, transfers and DPIA requirements.
Train staff and maintain practical workflows for rights requests, complaints, monitoring reviews and personal data breaches.
What this guide covers
Start by identifying why the business uses personal data and whether it acts as controller, processor or joint controller for each activity. It may be a controller for customer and employee records while acting as a processor for client data. The data map should cover collection, systems, access, sharing, international transfers, retention, deletion, security and higher-risk information. A copied privacy policy cannot replace this picture.
Compliance is an operating system, not a document: lawful bases, transparency, minimisation, processor contracts, impact assessments, monitoring controls, rights requests, complaints and incident response. The Data Protection Act 2018 operates alongside the UK GDPR, as amended by the Data (Use and Access) Act 2025. The ICO confirmed on 19 June 2026 that all the Act's data protection provisions are in force, but check current ICO guidance when a process or technology changes.
Decision path
Start with the first stage, then follow the sections that match the route you identify. Keep a written record of the facts, evidence and decisions.
Map each processing activity before preparing notices or contracts. The map should describe what your staff and systems actually do.
Checks to make
Choose and document a lawful basis before processing begins, then keep the use within what you told people.
Reassess the basis, transparency and safeguards when the purpose, data, people affected or technology changes.
Checks to make
Worker monitoring is not automatically unlawful, but you need a defined purpose, an appropriate lawful basis and the least intrusive effective method.
A monitoring notice cannot make disproportionate surveillance lawful.
Checks to make
Compliance continues after a system launches. Requests, complaints and breaches each run on their own clock.
Keep complaint, subject access, grievance and breach workflows distinct so deadlines are not missed.
Checks to make
Common situations
Define the precise problem, compare less intrusive options, complete DPIA screening, configure the tool narrowly and inform workers before routine monitoring begins.
Establish the parties' roles and review Article 28 terms, security, subprocessors, retention, training use and international transfers before sharing personal data.
Run both processes separately, preserve relevant information, search proportionately and protect other people's information when preparing the response.
Contain the incident, start a breach log, assess risk, preserve evidence and decide promptly whether the ICO or affected people must be notified.
Selected reading
Start with these articles for the key rules, then check the official sources before you act.
Primary sources
Read the UK statutory framework that operates alongside and supplements the UK GDPR.
Check the enacted amendments to data protection law, including complaints and recognised legitimate interests.
ICO guidance verifying the seven-basis framework for selecting, documenting and explaining each processing purpose.
ICO guidance for testing necessity, proportionality, transparency and DPIA requirements in worker monitoring.
Check the timing, search, redaction and response issues that arise when handling subject access requests.
ICO guidance confirming the required complaint route, acknowledgement and investigation process.
Source links checked 2 August 2026. Confirm the current rule before acting.
Questions businesses ask
These answers are general. Check the relevant documents and current official guidance for your particular facts.
Usually, yes. An exemption from paying the ICO data protection fee is not a general exemption from the UK GDPR or the Data Protection Act 2018.
Sometimes, but genuine choice can be difficult to establish in an employment relationship. The employer should use the lawful basis that properly fits the specific purpose.
No, but the need for one should be screened and documented. A DPIA is required where the proposed processing is likely to create a high risk to people.
No. Subject access requests are generally due within one month. Data protection complaints must be acknowledged within 30 days and then handled without undue delay.
No. Record and assess every breach, but notify the ICO and affected people only when the relevant risk thresholds are met.
Need help putting this into practice?
This guide is general information, not legal, tax or financial advice. The right path depends on the entity, documents and commercial facts.
Related guides