Personnel Today
  • Home
    • All PT content
  • Email sign-up
  • Topics
    • HR Practice
    • Employee relations
    • Learning & training
    • Pay & benefits
    • Recruitment & retention
    • Wellbeing
    • Occupational Health
    • HR strategy
    • HR Tech
    • The HR profession
    • Global
    • All HR topics
  • Legal
    • Case law
    • Commentary
    • Flexible working
    • Legal timetable
    • Maternity & paternity
    • Shared parental leave
    • Redundancy
    • TUPE
    • Disciplinary and grievances
    • Employer’s guides
  • AWARDS
    • Personnel Today Awards
    • The RAD Awards
  • Jobs
    • Find a job
    • Jobs by email
    • Careers advice
    • Post a job
  • Brightmine
    • Learn more
    • Products
    • Free trial
    • Request a quote
  • Webinars
  • Advertise

Personnel Today

Register
Log in
Personnel Today
  • Home
    • All PT content
  • Email sign-up
  • Topics
    • HR Practice
    • Employee relations
    • Learning & training
    • Pay & benefits
    • Recruitment & retention
    • Wellbeing
    • Occupational Health
    • HR strategy
    • HR Tech
    • The HR profession
    • Global
    • All HR topics
  • Legal
    • Case law
    • Commentary
    • Flexible working
    • Legal timetable
    • Maternity & paternity
    • Shared parental leave
    • Redundancy
    • TUPE
    • Disciplinary and grievances
    • Employer’s guides
  • AWARDS
    • Personnel Today Awards
    • The RAD Awards
  • Jobs
    • Find a job
    • Jobs by email
    • Careers advice
    • Post a job
  • Brightmine
    • Learn more
    • Products
    • Free trial
    • Request a quote
  • Webinars
  • Advertise

General Data Protection RegulationData protection

Data Protection Bill unveiled

by Qian Mou 14 Sep 2017
by Qian Mou 14 Sep 2017

The Government has published the Data Protection Bill, which will supplement the General Data Protection Regulation (GDPR) in the UK.

More data protection resources

How to start preparing for the GDPR

What is the GDPR?

What happens if an employer fails to comply with the GDPR when it comes into effect?

The Bill, which was announced in the Queen’s Speech in June this year, adds detail to the requirements under the GDPR.

It incorporates the highly publicised fine regime, under which organisations can be fined up to €20 million or 4% of total worldwide annual turnover.

However, the Bill makes a number of changes for employers to process special categories of personal data (such as health data and data on ethnic origin, political opinion, religious beliefs, union membership and sexual orientation) and data relating to criminal convictions.

To process special categories of personal data, also known as sensitive personal data, employers have to meet strict conditions under the GDPR, such as obtaining explicit consent.

Under the Bill, employers will be able to process special categories of personal data to fulfil obligations or exercise rights in employment law if it has a policy document in place that meets additional requirements.

Under the GDPR, employers can process data on criminal convictions only if this is specifically permitted by law.

The Bill will allow processing of criminal conviction data if it meets the same requirements as processing special categories of personal data.

This means that employers will be able to process criminal conviction data with consent, or to exercise rights or obligations provided that they have a policy in place that meets the additional requirements.

The Bill also reproduces certain exemptions from the Data Protection Act 1998 relating to subject access requests.

In particular, employers will not have to include information in their privacy notices or disclose information to employees in response to subject access requests for:

  • information that is covered by legal professional privilege;
  • information used for management planning by the employer;
  • information about the employer’s intentions during negotiations with the employee; and
  • confidential references given (but not those received) by the employer.

The Bill also creates a number of new offences, including an offence of altering, destroying or concealing information to be provided to an individual through a subject access request.

Culture secretary, Karen Bradley said: “The Data Protection Bill will give people more control over their data, support businesses in their use of data, and prepare Britain for Brexit.

“In the digital world strong cyber security and data protection go hand in hand. This Bill is a key component of our work to secure personal information online.”

The Bill will repeal the Data Protection Act 1998 when it comes into effect. In addition to implementing the GDPR, the Bill deals with personal data processed by law enforcement and national security.

Sign up to our weekly round-up of HR news and guidance

Receive the Personnel Today Direct e-newsletter every Wednesday

OptOut
This field is for validation purposes and should be left unchanged.

The GDPR will come into effect directly in the EU, including in the UK, on 25 May 2018. When the UK leaves the EU, the GDPR will be incorporated into UK law by the European Union (Withdrawal) Bill.

Qian Mou

Qian Mou is an employment law editor at XpertHR. She is qualified as a lawyer in England and Wales, and Ontario, Canada. Prior to joining XpertHR, Qian worked as a private practice lawyer specialising in employment law and as an HR consultant at a national bank in Toronto.

previous post
Modern slavery statements: September deadline looms
next post
Nursing unions demand 3.9% pay rise and £800

You may also like

FCA issues clarity on workplace savings schemes to...

27 Aug 2025

Security manager at BBC unfairly dismissed after ‘misusing’...

21 Aug 2025

Could equal pay questionnaires be revived?

19 Aug 2025

PwC uses traffic-light monitoring for office attendance

14 Aug 2025

82% of data breaches contain HR information

22 Jul 2025

CIPD Festival of Work: ‘Wellbeing is not an...

11 Jun 2025

Job seekers crave transparency for ADM in recruitment

6 Jun 2025

ICO strategy to examine use of AI in...

5 Jun 2025

‘Polygamous working’ is a minefield for HR

14 May 2025

M&S pauses hiring as it deals with cyber...

2 May 2025

  • Work smart – stay well: Avoid unnecessary pain with centred ergonomics SPONSORED | If you often notice...Read more
  • Elevate your L&D strategy at the World of Learning 2025 SPONSORED | This October...Read more
  • How to employ a global workforce from the UK (webinar) WEBINAR | With an unpredictable...Read more

Personnel Today Jobs
 

Search Jobs

PERSONNEL TODAY

About us
Contact us
Browse all HR topics
Email newsletters
Content feeds
Cookies policy
Privacy policy
Terms and conditions

JOBS

Personnel Today Jobs
Post a job
Why advertise with us?

EVENTS & PRODUCTS

The Personnel Today Awards
The RAD Awards
Employee Benefits
Forum for Expatriate Management
Whatmedia

ADVERTISING & PR

Advertising opportunities
Features list 2025

  • Facebook
  • Twitter
  • Instagram
  • Linkedin


© 2011 - 2025 DVV Media International Ltd

Personnel Today
  • Home
    • All PT content
  • Email sign-up
  • Topics
    • HR Practice
    • Employee relations
    • Learning & training
    • Pay & benefits
    • Recruitment & retention
    • Wellbeing
    • Occupational Health
    • HR strategy
    • HR Tech
    • The HR profession
    • Global
    • All HR topics
  • Legal
    • Case law
    • Commentary
    • Flexible working
    • Legal timetable
    • Maternity & paternity
    • Shared parental leave
    • Redundancy
    • TUPE
    • Disciplinary and grievances
    • Employer’s guides
  • AWARDS
    • Personnel Today Awards
    • The RAD Awards
  • Jobs
    • Find a job
    • Jobs by email
    • Careers advice
    • Post a job
  • Brightmine
    • Learn more
    • Products
    • Free trial
    • Request a quote
  • Webinars
  • Advertise