top of page

Keeping staff data separate and secure from everybody else

  • Aug 29
  • 3 min read

Updated: 4 days ago

Introduction


Employee files sit in a folder on the shared drive that everybody can open. Sickness notes, a disciplinary record, bank details and an old grievance are all in there, alongside the holiday spreadsheet everybody uses.

Businesses that are careful with customer data are frequently casual with staff data, which is generally more sensitive and belongs to people who work alongside whoever can see it. It is also the category most likely to be the subject of a request, usually at the point somebody is leaving in difficult circumstances. Which is precisely when the file will be examined most closely.


1. Keeping staff data separate and secure starts with access


The single most important control.

Employee records should be accessible only to those who genuinely need them, which in a small business is usually one or two people. A shared drive everybody can browse fails this immediately. And in a small team the people browsing it work alongside the people in the files.


2. Recognise which parts are sensitive


They attract stricter obligations.

Health information, sickness records, occupational health reports, disability details, and in some cases criminal record checks. Most frameworks treat these as special categories with additional conditions for processing.


3. Separate sickness and health information


A specific and useful practice.

Keeping medical information apart from the general personnel file, accessible to fewer people, is straightforward and reflects the higher sensitivity. Managers usually need to know the effect on work rather than the diagnosis. That distinction is both good practice and considerably easier to defend.


4. Have a lawful basis for each part


Not all the same.

Contract for the employment relationship, legal obligation for payroll and statutory records, and specific conditions for health information. Employee consent is a weak basis here because of the imbalance in the relationship. Somebody who fears refusing has not freely consented.


5. Tell staff what you hold and why


An employee privacy notice.

Most frameworks require this and most small businesses have never issued one. It covers different processing from the customer notice and is expected at the point of recruitment.


6. Deal with recruitment data properly


Frequently retained forever.

Applications from unsuccessful candidates, interview notes and references. Set a short retention period, tell applicants what it is, and delete accordingly rather than accumulating years of files.


7. Be careful with monitoring


Legitimate in principle and constrained in practice.

Email monitoring, location tracking on vehicles, CCTV in the workplace and productivity software all engage obligations around necessity, proportionality and transparency. Covert monitoring is very narrowly permitted.


8. Handle references and exit data carefully


Both directions.

What you keep after somebody leaves, for how long, and what you say in a reference. Departing employees are among the most likely to make a request, and the file will be read closely.


9. Secure the practical storage


Physical and digital.

Locked cabinets for paper, restricted folders and encryption for digital files, and no employee data on personal devices. This is basic and it is where most small businesses actually fail. Not on the principles, but on the cabinet that does not lock.

Review who currently has access, because it is almost always more people than intended. Access granted for one purpose years ago persists, and former managers, departed staff and shared logins frequently still reach files nobody realises are exposed.


Conclusion


Treat employee records as more sensitive than customer data rather than less.

Restrict access to the one or two people who genuinely need it, identify which parts fall into special categories, keep health and sickness information separate from the general file, establish a lawful basis for each type of processing rather than relying on employee consent, issue an employee privacy notice, set short retention periods for recruitment data, apply necessity and transparency tests to any monitoring, handle references and post-employment records carefully, secure both paper and digital storage, and audit who currently has access.


Related reading


 
 
 

Comments


bottom of page