The DPA and the accompanying guidance document, the Employment Practices Data Protection Code, sets out guidelines for employers to follow when conducting employee surveillance.
Although general rules will remain the same in accordance with the DPA and the Employment Code, to comply with the GDPR in the future, there are new concepts that must be considered.
Changes
The first new concept is the Data Protection Impact Assessment (DPIA) under Article 35 of the GDPR. Under the DPA and Employment Code, employers must undertake an impact assessment before undertaking surveillance, which involves, among other things, considering whether the surveillance is necessary and proportionate.
However, in accordance with the GDPR, the DPIA will be required where the data processing is ‘likely to result in a high risk to the rights and freedoms of natural persons’ (Information Commissioner’s Office (ICO)). The criteria to consider when determining whether data processing is ‘high risk’ includes:
If employee monitoring satisfies at least two of the criteria under the Working Party guidelines, a DPIA is required. This is important to follow, as failure to comply can result in an administrative fine of up to £10m, or up to 2% of the annual global turnover of the preceding financial year, whichever is higher.
Another concept that will be bolstered by the GDPR is whether data processing is lawful by reference to conditions set out in Article 6 of the GDPR (previously schedule 2 to the DPA). One such condition is consent (Article 4(11)).
Consent will be more difficult to satisfy, as it will not be freely given if there is an imbalance in the relationship between the individual and the data controller (the employer in most cases).
Therefore, employers need to look for another condition to justify surveillance, such as ‘legitimate interests’ under Article 6(1)(f), which is likely to be a favourite amongst employers since employee surveillance will usually be undertaken to prevent or detect crime, to stop the abuse of the employers’ resources (The Law Society Gazette).
However, the legitimate interests condition will not apply to processing carried out by public authorities. Organisations affected should focus on surveillance carried out in the public interest to meet the conditions of lawfulness (Article 6(1)(e)).
One of the biggest changes that will gain significance when conducting employee surveillance is transparency. While consideration must be given to Article 13 and 14 of the GDPR to ensure employers are as open as possible, regard must also be had to Article 8 of the Human Rights Act 1998, the right to privacy.
Compliance with the DPA and GDPR is evidence that the surveillance has been done in accordance with Article 8, thus protecting employers. It is important to take human rights issues into account when carrying out surveillance since courts have previously criticised employers for failing to do so.
Conclusion
Overall, employers need to adapt to the new regulations that are set to come into force on 25 May 2018, as lack of compliance will potentially result in some significant fines and legal claims.
Expert legal advice on GDPR matters
SO Legal has offices across the South East. Our solicitors in Brighton, Eastbourne, Hastings, London and Uckfield can help you understand GDPR requirements.
Looking for
more information?