The ICO exists to empower you through information.

Organisation Name privacy notice

This privacy notice tells you what to expect us to do with your personal information when you work for us.

Contact details

Organisation address

Organisation phone number

Organisation email address

What information we collect and use, and why

Staff administration

We process the following types of data to manage our staff:

  • Contact details (eg name, address, telephone number or personal email address)
  • Date of birth
  • National Insurance number
  • Gender
  • Photographs (eg staff ID card)

We rely on the following lawful bases for collecting and using your personal data under the UK GDPR:

  • Consent
  • Legitimate interest
    • (Legitimate interest reason)
  • Contract

The lawful basis we rely on depends on the reason we collect and use your information.

Salaries and pensions

We process the following types of data to manage salaries and payments:

  • Job role and employment contract (eg start and leave dates, salary, changes to employment contract or working patterns)
  • Time spent working (eg timesheets or clocking in and out)
  • Expense, overtime or other payments claimed
  • Leave (eg sick leave, holidays or special leave)
  • Maternity, paternity, shared parental and adoption leave and pay

We rely on the following lawful bases for collecting and using your personal data under the UK GDPR:

  • Consent
  • Legitimate interest
    • (Legitimate interest reason)
  • Contract

The lawful basis we rely on depends on the reason we collect and use your information.

Health and wellbeing

We process the following types of data to manage staff health and wellbeing:

  • Occupational health referrals and reports
  • Sick leave forms or fit notes (eg Statement of Fitness for Work from a GP or hospital)
  • Accident at work records

We rely on the following lawful bases for collecting and using your personal data under the UK GDPR:

  • Consent
  • Legitimate interest
    • (Legitimate interest reason)
  • Contract

The lawful basis we rely on depends on the reason we collect and use your information.

How we collect your information

We collect your information from one of the following places:

  • Directly from you
  • Employment agency
  • Schools, colleges, universities or other education organisations
  • Referees (external or internal)
  • Security clearance providers

[You said you collect information from other places. Please add them in yourself here.]

How long we keep your information

For more information about how long we keep your information, look at our retention information.

Who we share personal information with

In some circumstances, we may share information with the following organisations:

  • Training suppliers
  • HMRC
  • Employee benefit schemes

[You said you share information with other organisations. Please add them in here.]

Data processors

We use the following data processors for the following reasons:

  • Data processor name

    • Data processor reason

Sharing information outside the UK

Where necessary, we may transfer staff information outside of the UK. When doing so, we comply with the UK GDPR, making sure appropriate safeguards are in place. Please contact us for more information.

Last updated:

4 August 2023

How long we keep information

For more information about how long we keep your information, take a look at our retention schedule: https://www.organisationwebsite.co.uk/retention-schedule.

or

[Copy and paste the information from your retention schedule here or provide a link. You must do this before you publish the privacy notice. ]

or

Date of birth is kept for:

4 years.

National insurance is kept for:

4 years after you leave.

or 

[You said you wanted to complete you retention schedule at a later date. Once you have downloaded this privacy notice, you can fill the information in below. You must not publish the privacy notice without it.]

 

Date of birth is held for:

[To be added]

National insurance is held for:

[To be added]