From evolving data protection laws and increasing numbers of data subject access requests, to new complaints processes and the rapid adoption of AI in the workplace, employers are encountering a growing range of privacy-related challenges.

In our recent employment law lab webinar, we explored some of the top data protection and privacy issues which employers are currently grappling with, and we have summarised these below together with actionable guidance to remain compliant.

The new UK right to complain

The Data (Use and Access) Act 2025 introduced a new right for individuals to complain directly to organisations about how their personal data is being handled. This change came into force on 19 June 2026, and we already see organisations having to respond to and investigate complaints.

Employers should establish clear processes for receiving, investigating and responding to complaints within a reasonable timeframe before matters escalate to the ICO.

IA-generated data subject access requests (DSARs)

Generative AI tools have made it easier than ever for data subjects to submit detailed and wide-ranging DSARs. HR teams should expect an increase in volume and complexity and ensure they have a robust process for identifying, reviewing and producing relevant information while protecting third-party rights and legally privileged material (especially given the risk of DSAR responses being inputted into publicly available AI tools). Employers should also be aware that mishandled DSARs may result in complaints (see point 1 above).

Privacy notices

Privacy notices are mandatory documents which employers must have in place to inform employees about what employee data is collected, why it is processed, who it is shared with, how long it is retained and what rights employees have, including their new right to complain. Privacy notices need to be regularly reviewed and updated to reflect changes in processing activities. Employers should also ensure that they have a privacy notice for job applicants and candidates whose personal data is processed during recruitment processes.

Data protection impact assessments (DPIAs)

A DPIA is required where processing is likely to result in a high risk to individuals, particularly when introducing new technologies. Employers will need to conduct DPIAs before deploying tools that involve profiling, automated decision-making, large-scale processing of sensitive information or significant employee monitoring activities.

Responsible use of AI

Many organisations are adopting AI tools for recruitment, workforce planning, performance management and administrative tasks. Employers should ensure AI is used responsibly, with appropriate human oversight, transparency, fairness testing and governance controls. Employees should understand when AI is being used and how decisions affecting them are made.

Employers should consider whether they could benefit from having a policy in place to ensure that employees have a clear understanding of how they are expected to use AI in the workplace.  Shadow AI (unauthorised use of public tools for employer purposes) is a significant business risk which can be mitigated by a robust policy.

Use of AI will often require a DPIA (see point 4), and may also need to be referenced in Privacy Notices (see point 3) and Data Protection Policies (see point 7).

Employee monitoring

Whether monitoring email usage, communications, productivity, attendance or location data, employers must balance legitimate business interests against employees' privacy expectations. Monitoring should be proportionate, clearly communicated and supported by a documented assessment of risks and safeguards.

Occupational health monitoring may be required for some employers to comply with health and safety obligations. However, such activities still also need to be compliant with data protection laws, and will pose a greater data protection risk due to processing of health data. Employers should ensure that HR and data protection teams work together on assessing the impact of these activities.

Data protection policy

Where employers process special category data or criminal offence data under certain conditions in the Data Protection Act 2018, they need an Appropriate Policy Document. More broadly, every organisation should maintain up-to-date data protection policies that explain how personal data should be handled and how compliance is achieved in practice, so that clear expectations are set for employees.

International transfers

Global HR operations frequently involve sharing employee data across borders. Transfers outside the UK require a valid transfer mechanism unless an adequacy decision applies. Employers should review intra-group data flows and ensure appropriate safeguards are in place, particularly when using global HR systems or cloud services.

Data retention

One of the most common compliance challenges is keeping personal data for longer than necessary. Employers should have a documented retention schedule covering recruitment records, personnel files, disciplinary records, payroll information and other employment-related data. Data that is no longer needed should be securely deleted.

Often, retention periods align with limitation or prescriptive periods for claims; however, this may not be appropriate for all datasets (such as recruitment information if there is no risk of a claim). Embedding automated retention policies within IT systems can be beneficial in meeting this obligation.

Personal data security breaches

Employers should have robust systems in place to help prevent breaches, but they should also be prepared for when a breach occurs. It is worth remembering that not all breaches are malicious cyber attacks, and that the law also applies to accidental or human error breaches. While not every security incident is reportable, every incident should still be logged and assessed to identify if any steps can be taken to prevent a recurrence. HR teams should know how to identify a personal data breach, escalate concerns quickly, maintain breach records and work with legal, IT and security teams to determine whether notification to the ICO or affected individuals is required. 

For employers, data protection is a core part of building employee trust and ensuring the responsible adoption of new technologies. Organisations that proactively engage with their responsibilities and review their processes and procedures will be better placed to manage risk, respond to increasing regulatory scrutiny and harness the benefits of AI responsibly.

If you would like to discuss any of the issues discussed above, do not hesitate to contact our employment team or our GDPR and data protection team.

Written by

Related News, Insights & Events

Error.

No results.

Employment Law Lab

Top 10 tips for managing probationary periods

16/06/2026

In this article, we provide our top tips on probationary periods.

Read more
Getting Your Data Ducks In A Row

Getting your data ducks in a row: putting the Data (Use and Access) Act 2025 into practice for pension schemes

09/06/2026

In this blog, we consider how The Data (Use and Access) Act 2025 (the “DUAA”) raises the bar for how pension trustees’ role as data controllers must be performed.

Read more
OEUK’S NRB Guidelines Why Employers Need A Renewed Focus

OEUK’s guidelines: forthcoming changes to employment law put spotlight on NRB decisions

08/06/2026

The OEUK Guidelines for the Permanent Removal of Offshore Personnel were introduced to tackle one of the offshore industry’s most contentious workforce issues.

Read more

Want to hear more from us?

Subscribe here Subscribe here