End of Summer Savings · Get 10% off any legal service · Ends 31 August

Claim offer

Privacy · UK business guide

Privacy, Data and Workplace Monitoring

Map personal data, lawful bases, notices, processor contracts, monitoring, retention and incident response around the way the business actually operates.

Jurisdiction: United Kingdom.

At a glance

  1. 01

    Map the processing

    Record what personal data enters the business, why it is used, where it goes, who can access it and when it is deleted.

  2. 02

    Match rules to risk

    Choose a lawful basis and check special-category conditions, transparency, contracts, security, transfers and DPIA requirements.

  3. 03

    Operate the controls

    Train staff and maintain practical workflows for rights requests, complaints, monitoring reviews and personal data breaches.

What this guide covers

Make the legal decisions in the right order

Start by identifying why the business uses personal data and whether it acts as controller, processor or joint controller for each activity. It may be a controller for customer and employee records while acting as a processor for client data. The data map should cover collection, systems, access, sharing, international transfers, retention, deletion, security and higher-risk information. A copied privacy policy cannot replace this picture.

Compliance is an operating system, not a document: lawful bases, transparency, minimisation, processor contracts, impact assessments, monitoring controls, rights requests, complaints and incident response. The Data Protection Act 2018 operates alongside the UK GDPR, as amended by the Data (Use and Access) Act 2025. The ICO confirmed on 19 June 2026 that all the Act's data protection provisions are in force, but check current ICO guidance when a process or technology changes.

Decision path

Work through the issue before committing to a course of action

Start with the first stage, then follow the sections that match the route you identify. Keep a written record of the facts, evidence and decisions.

  1. 01

    Map roles, data and purposes

    Map each processing activity before preparing notices or contracts. The map should describe what your staff and systems actually do.

    • Record the basics. For each activity, record what information enters, where it came from, whose information it is, the purpose, system, access, recipients, retention period and deletion route.
    • Flag higher risk. Mark special category data, criminal offence data, children's information, biometrics and international transfers.
    • Assign roles. A controller decides the purpose and essential means of processing. A processor acts on documented instructions. Organisations deciding purposes together may be joint controllers.
    • Why roles matter. The classification affects which notices, records, contracts and responsibilities apply to each activity.
    • Follow real journeys. Build the inventory around actual business journeys, such as recruitment, customer onboarding, marketing and supplier management.

    Checks to make

    • Build a processing inventory for each customer, worker and supplier journey.
    • Assign controller, joint controller or processor roles for every purpose.
    • Flag higher-risk data, vendors, subprocessors and international transfers.
  2. 02

    Choose a lawful and limited use

    Choose and document a lawful basis before processing begins, then keep the use within what you told people.

    • Seven bases. The UK GDPR now provides seven bases, including recognised legitimate interests for specified pre-approved purposes. Ordinary legitimate interests still requires a purpose, necessity and balancing assessment.
    • Consent limits. Consent is not the default and can be difficult to rely on in employment, where workers may lack genuine choice.
    • Extra conditions. Special category and criminal offence data need an additional condition on top of the lawful basis.
    • Stay limited. Tell people clearly what the business does, collect only what is needed and apply real retention rules. Do not quietly reuse information for an incompatible purpose.

    Reassess the basis, transparency and safeguards when the purpose, data, people affected or technology changes.

    Checks to make

    • Record the lawful basis and necessity for every processing purpose.
    • Document any legitimate interests assessment and additional data condition.
    • Align privacy information, retention and deletion with the actual processing.
  3. 03

    Test monitoring before turning it on

    Worker monitoring is not automatically unlawful, but you need a defined purpose, an appropriate lawful basis and the least intrusive effective method.

    • DPIA first. Screen for a data protection impact assessment before procurement. Complete one where the proposed processing is likely to create high risk.
    • High-risk features. Test home working, personal devices, private communications, health or union information, biometrics, automated decisions and overseas vendor access.
    • Tell workers. Give workers clear information before routine monitoring begins, and restrict access and retention.
    • Covert monitoring. Keep it exceptional, tightly targeted and time-limited, generally where specific criminal activity is suspected and prior notification would prejudice detection.

    A monitoring notice cannot make disproportionate surveillance lawful.

    Checks to make

    • Document the purpose, evidence and less intrusive alternatives.
    • Complete and approve DPIA screening before the tool is enabled.
    • Issue accurate notices and configure access, retention and deletion controls.
  4. 04

    Operate requests, complaints and incidents

    Compliance continues after a system launches. Requests, complaints and breaches each run on their own clock.

    • Processor contracts. Put Article 28 terms, security, audit and incident duties into processor contracts, and map safeguards for international transfers.
    • Access requests. A subject access request is generally due without undue delay and within one month.
    • Complaints. Controllers must facilitate data protection complaints, acknowledge them within 30 days and respond without undue delay. Processors should forward complaints and assist the controller under their contract.
    • Breach log. Record every personal data breach and assess its risk, whether or not it turns out to be reportable.
    • Notification duties. Notify the ICO without undue delay and, where feasible, within 72 hours of becoming aware of a breach likely to create a risk, explaining any later notification. Notify affected people without undue delay where the likely risk is high.

    Keep complaint, subject access, grievance and breach workflows distinct so deadlines are not missed.

    Checks to make

    • Assign trained owners and maintain separate deadline registers.
    • Audit processor, subprocessor and international transfer terms.
    • Rehearse containment, risk assessment, notification and communication steps.

Common situations

Where businesses usually need to slow down and check the detail

The business introduces productivity monitoring

Define the precise problem, compare less intrusive options, complete DPIA screening, configure the tool narrowly and inform workers before routine monitoring begins.

A CRM or AI supplier handles customer data

Establish the parties' roles and review Article 28 terms, security, subprocessors, retention, training use and international transfers before sharing personal data.

A worker sends a subject access request during a grievance

Run both processes separately, preserve relevant information, search proportionately and protect other people's information when preparing the response.

An email reaches the wrong recipient

Contain the incident, start a breach log, assess risk, preserve evidence and decide promptly whether the ICO or affected people must be notified.

Selected reading

Understand the issue before deciding what to do next

Start with these articles for the key rules, then check the official sources before you act.

Data controller duties under UK GDPRClassify controller responsibilities and connect them to practical accountability measures.GDPR compliance documents for SMEsCheck which records, notices and policies should support the business's actual data practices.When a DPIA is requiredScreen a new system or processing activity for high-risk features that may require a DPIA before launch.Monitoring internet history at workReview the necessity, proportionality and transparency issues raised by workplace internet monitoring.Handling subject access requestsFollow a practical workflow for recognising, searching, reviewing and responding to a subject access request.Data breach reportingAssess breach risk, preserve the decision record and identify any notification duties.Data processing agreementsCheck the contractual terms needed when a supplier processes personal data on documented instructions.

Primary sources

Source links checked 2 August 2026. Confirm the current rule before acting.

Questions businesses ask

Quick answers before you take the next step

These answers are general. Check the relevant documents and current official guidance for your particular facts.

Do small businesses have to comply with data protection law?

Usually, yes. An exemption from paying the ICO data protection fee is not a general exemption from the UK GDPR or the Data Protection Act 2018.

Can an employer rely on employee consent?

Sometimes, but genuine choice can be difficult to establish in an employment relationship. The employer should use the lawful basis that properly fits the specific purpose.

Is a DPIA always required for worker monitoring?

No, but the need for one should be screened and documented. A DPIA is required where the proposed processing is likely to create a high risk to people.

Are subject access and complaint deadlines the same?

No. Subject access requests are generally due within one month. Data protection complaints must be acknowledged within 30 days and then handled without undue delay.

Must every personal data breach be reported?

No. Record and assess every breach, but notify the ICO and affected people only when the relevant risk thresholds are met.