Coronavirus and GDPR breaches

During the coronavirus pandemic it’s possible that employers and their employees might inadvertently breach the GDPR. If this happens are you at risk of enforcement action? More...


CCd external recipients in error - must you tell the ICO?

An e-mail has gone out to a list of external recipients. Unfortunately, the employee CCd everyone rather than BCCing them in. All names and e-mail addresses could be seen. Must this data breach be reported to the Information Commissioner’s Office (ICO)? More...


GDPR: €150,000 fine for getting “consent” wrong

PwC has been fined €150,000 after it wrongly used consent as the basis for processing its employees’ personal data. What’s the problem with relying on consent when you’re processing employment-related personal data? More...


GDPR - privacy notices still missing

The GDPR had its first birthday in May 2019. However, many smaller employers still haven’t got their mandatory privacy notices in place. What must you have by law? More...


Q&A - talking about medical conditions


Employee refusing to release a medical report

You’ve recently referred an employee to an occupational health advisor for a report on their fitness to work. However, the employee is now refusing to allow the report to be released to you. Can you proceed and, if so, how? More...

Data protection

Q&A - sending e-mails to personal accounts


Employee photos on websites and the GDPR

You would like to create a “meet the team” section on your website which has photos of all key staff and a description of their job role. Where do you stand on this legally now that the GDPR is in force? More...


The GDPR: personal data breaches

The General Data Protection Regulation (GDPR) potentially makes employers liable for personal data breaches. What are they and how should you respond to them? More...


How long can we hold CVs on file?

You’ve interviewed a candidate who was unsuccessful but they may well be suitable for a future job role. Are you permitted to hold their CV on file or does the General Data Protection Regulation (GDPR) prohibit this? More...
Last updated: 29.05.2020

