All sample legal documents

Sample Employee Privacy Notice

A worked UK employee privacy notice explaining the data held by a fictional employer, legal bases, monitoring, sharing, retention, international transfers and employee rights.

Jurisdiction: Illustrative England and Wales and United Kingdom employment privacy notice — UK GDPR, Data Protection Act 2018 and workplace-monitoring rules must be checked

Download Sample

An editable Microsoft Word version is available from the interactive page.

Important: This sample provides general legal information only and is not legal advice. Check the law, prescribed forms and signing requirements that apply to your exact jurisdiction and circumstances before use.

EMPLOYEE PRIVACY NOTICE

Important legal-advice, jurisdiction and formality warning

This fictional notice is a worked example, not legal advice and not a universally compliant privacy notice. It is written for an employer established in England and Wales and assumes processing under the UK GDPR and Data Protection Act 2018. The correct notice must match actual systems, contracts, suppliers, monitoring, transfers, retention and workforce practices. A notice alone does not make processing lawful, obtain consent, authorise covert monitoring or satisfy a consultation duty. The employer must complete appropriate assessments, give any required separate monitoring information, respect employment and equality law, and obtain current advice before issuing or relying on this document. The version date and all named people, addresses and examples are fictional.

1. Controller and scope

This notice applies from 1 November 2026 to Cairnbridge Renewable Services Limited, company number 14197206, whose registered office is at 28 Meridian Wharf, Newcastle upon Tyne NE1 2QH. Cairnbridge designs and maintains onshore wind equipment. It is the controller for the personal data described here. References to “we”, “us” and “our” mean Cairnbridge. This notice applies to employees, workers, secondees, directors, applicants who become employees, and former employees where we retain their information.

The responsible contact is Lydia May Okafor, Head of People and Privacy, at privacy@cairnbridge.example.test, Cairnbridge Renewable Services Limited, 28 Meridian Wharf, Newcastle upon Tyne NE1 2QH. Our independent data protection adviser is Thomas Edwin Bell, who can be contacted through the same address. We will tell people if responsibility or contact details materially change.

2. Information we collect

We hold identity and contact information such as name, preferred name, photograph, date of birth, home address, personal email, telephone number, emergency contact and employee number. We hold recruitment and eligibility information including application history, references, right-to-work evidence, qualifications, professional registrations, driving entitlement and conflict-of-interest declarations.

For employment administration we process contracts, salary, bank details, tax code, National Insurance number, pension choices, benefits, expenses, working hours, holiday, sickness absence, occupational-health recommendations, performance reviews, training records, disciplinary and grievance material, and correspondence about work. Health information is restricted and may include fit notes, workplace adjustments and accident records. We do not routinely collect genetic, biometric or other special-category information unless a specific lawful purpose requires it.

Company systems create security and operational records. These can include door-entry events, vehicle allocation, laptop and application logs, service-desk records, work email and collaboration messages, training attendance, network security alerts, and safety-camera images at the Newcastle depot. We do not use keystroke surveillance or record private calls. Any new monitoring with a material impact will be assessed, explained and introduced with the required formalities.

3. Purposes and legal bases

We use identity, contact, contract, pay, time and absence data to enter into and perform the employment contract, pay people, administer leave and benefits, manage work and communicate safely. We use tax, right-to-work, pension, wage, health and safety and equality information to comply with legal obligations. We use recruitment, training, performance, workforce planning and business continuity information for our legitimate interests in a safe, skilled and effectively managed workforce, after considering the effect on employees.

We use access logs, device security records, fraud checks and depot images for legitimate interests in protecting people, confidential engineering data, premises and equipment, and for investigating incidents. We may process information to establish, exercise or defend legal claims and to meet a court or regulator's requirements. We will not use personal data for a new incompatible purpose without identifying a lawful basis and giving any information the law requires.

Health and other special-category data is used only with an applicable additional condition, such as employment-law obligations, occupational-health assessment, substantial public interest or explicit consent where appropriate. We will not make an employee's consent the only route to a benefit that can reasonably be provided another way. Criminal-offence information is considered only where authorised by law and with suitable safeguards.

4. People and organisations receiving data

Access is limited to people who need it, including line managers, People team staff, payroll and finance colleagues, security personnel and IT administrators. We use named suppliers for payroll, pension administration, occupational health, benefits, recruitment checks, secure hosting, travel booking, legal advice and employee assistance. Each processor receives only necessary information and must follow a written contract. A host customer or project partner may receive a worker's name, role, training or site-access status where needed for a contract or safety purpose.

We may disclose information to HM Revenue and Customs, The Pensions Regulator, the Home Office, insurers, occupational-health professionals, police, courts and other authorities when required or permitted. If the business is reorganised or sold, advisers and a buyer may receive due-diligence information subject to confidentiality and lawful safeguards. We do not sell employee data or use it for unrelated advertising.

Some suppliers may access data from the European Economic Area or another country. Before a restricted transfer, we will rely on an adequacy decision, the UK International Data Transfer Agreement, the UK Addendum to approved standard clauses or another permitted mechanism, and will assess whether supplementary measures are needed. Employees may contact us for a summary of the safeguard used for a particular transfer.

5. Retention and security

We retain the core personnel file for six years after employment ends, unless a longer period is needed for a claim or a shorter period is required by policy. Payroll, tax and accounting records are normally retained for seven years after the relevant financial year. Right-to-work records are retained for two years after employment ends. Recruitment records for unsuccessful internal candidates are retained for twelve months after the process, unless the person agrees to a talent pool for six months.

Routine access and device-security logs are retained for twelve months, depot images for thirty days unless relevant to an incident, and occupational-health recommendations for six years after employment ends. Disciplinary and grievance records are reviewed after twelve months and retained only as long as reasonably needed, normally six years after the matter closes. Legal-hold, accident and pension records may have different periods explained in the relevant record. We securely delete or anonymise information when the period ends.

Security measures include role-based access, multi-factor authentication, encryption in transit and at rest where supported, managed devices, backups, staff confidentiality duties, supplier due diligence and incident response. No system is risk-free. If a personal-data breach creates a reporting duty or material risk, we will assess it promptly, notify the Information Commissioner's Office where required and tell affected people where appropriate.

6. Rights and decisions

Subject to legal limits, an employee may request access, correction, restriction, erasure, portability or information about processing based on legitimate interests, and may object to such processing. Some rights are limited where we must retain information, comply with law, protect confidential references, conduct negotiations or defend a claim. We do not make solely automated decisions that produce legal or similarly significant effects in employment. If any assisted decision tool is introduced, we will explain its role and provide a route to human review.

Send a rights request to privacy@cairnbridge.example.test or to Lydia May Okafor at the postal address above. We may ask proportionate questions to verify identity. We normally respond within one calendar month, with a lawful extension for complex requests. Complaints may be made to the Information Commissioner's Office at ico.org.uk, although we welcome the opportunity to investigate first. A grievance, subject access request and employment claim are separate processes, and one does not automatically extend a limitation period.

This notice was approved on 30 October 2026 by Marcus Julian Reed, Chief Executive Officer, and will be reviewed every year or sooner after a material processing change.

For Cairnbridge Renewable Services Limited:

Marcus Julian Reed, Chief Executive Officer

Signature: ____________________ Date: 30 October 2026

Employee acknowledgement: Nadia Elise Morgan, Field Service Engineer

Signature: ____________________ Date: 1 November 2026

Acknowledgement records that the notice was provided; it does not waive any data-protection or employment right.

Create a version for your situation

Create a tailored Employee Privacy Notice