The impact of GDPR on HR departments

by Startacus Admin
On May 25th 2018, the much anticipated GDPR comes into effect marking a host of changes to how we collect, store, manage, protect and dispose of data.
While there’s been much panicked discussion around crippling fines (up to €20 million or 4% of annual global turnover ) there’s been less about the changes that will incur these fines.
The new regulations place equal liability on the data controller and processor meaning companies could be liable for any data breach caused by third parties. In addition, the definition of personal data has broadened and individuals are now given the right of action against the data controller and processor without having to show financial loss incurred – stress or anxiety are now viable reasons for financial claim.
Aimee O’Mahony, Jobbio HR & Talent Manager talks through the impact of GDPR on HR departments & how to ensure HR departments are compliant.
“HR professionals are generally data protectors by nature and all personal data is stored securely either password protected or under lock and key- so what is new for us under GDPR?
These are a few headlines to consider:
Consent
The conditions for consent have been strengthened. You need the data subject (that’s the employees for us) to give consent for the processing of data and processing is essentially doing anything with the data including storage. You need to have a purpose for the processing so consider this when you seek personal data to begin with. Each time you request information ask yourself why it’s necessary and how you’ll securely store it. Also with GDPR, consent can be withdrawn at any time by the employee so you’ll also require processes around safe data disposal.
Right to Access
An employee can request all personal data held to be furnished to them free of charge within 30 days of the request.
Demonstrate compliance
Under GDPR, you need to show compliance as well as complying. The onus of proof is on you. This means creating policies and processes in line with GDPR. Review your current practices and develop a data protection policy that ensures you’re adhering to the new regulations.
What do you need to do?
Start with data discovery:
What type of data do I collect?
Where do I store it?
How do I delete it?
How long do I retain it?
How do I process it?
Who do I share it with?
If it is not stored correctly already, get your data storage in order and ensure only data with a purpose is kept. Keeping the employee’s right to access in mind at all times, move to processes that make data minimisation your best friend.
Build robust policies that demonstrate you are compliant and then educate the organisation on these policies. On consent, if the contract of employment doesn’t state clearly and unambiguously the reasons for data processing, seek consent again. More information at https://www.eugdpr.org/”
Interested in the impact of GDPR- you might want to read: The impact of GDPR on Marketing, PR and Outreach for Startups or GDPR primer for startups and self-starters.
About Jobbio and Startacus...
Startacus and Jobbio have joined forces to create a destination careers marketplace for the startup community. For 30 days, startup employers (new to Jobbio) will have full access to the entire Jobbio network, including unlimited job posting, for FREE.
Subscribe to our newsletter
If you would like to receive our startup themed newsletter, full of the latest startup opportunities, events, news, stories, tips and advice, then sign up here.
Tech Nation calls for tangible support to secure capital, talent, growth and exits needed to accelerate the growth of UK tech in decade ahead.

Glasgow-based This is Milk seeks investment for Neve Learning, its cloud-based Ed-Tech platform that has inclusivity and accessibility at its core.

With the UK facing a clear digital skills gap, Amy Caton, Digital Talent and Impact Senior Manager at BT Group shares some insights on what businesses should do to close that divide.

The lowdown on Berlin-based Beazy and its innovative solution that helps teams to plan, produce and deliver creative content and helps businesses to connect with talented content creators.

The lowdown on Fluffy, the app offering dog training, 24/7 vet messaging and insurance to give pet owners peace of mind and support them with their pet care responsibilities.

Huckletree's new Web3 HQ aims to put London’s West End at the forefront of Britain’s tech superpower ambitions.

Leading sports marketing platform, OpenSponsorship announces move into music sector, the first new vertical industry for the trans-Atlantic martech business.

Kingussie High School scoops first place for Junior and Senior categories at this year’s Growing Future Assets Competition.

The lowdown on Manchester-based Arctic Shores and its innovative recruitment solution to help candidate potential count as much as skills and experience.

With the demand for tattoo removal now greater than ever, specialist NAAMA Studios makes a bid for a further £11m in funding.
Published on: 27th February 2018
If you would like to enable commenting via your Startacus account, please enable Disqus functionality in your Account Settings.







- Tech Nation report reveals UK Tech could quadruple in value by 2032 with right conditions 23rd Mar 2023 Tech Nation calls for tangible support to secure capital, talent, growth and exits needed to accelerate the growth of UK tech in decade ahead.
- Neurodiverse learning and training platform Neve shares major six-figure investment opportunity 22nd Mar 2023 Glasgow-based This is Milk seeks investment for Neve Learning, its cloud-based Ed-Tech platform that has inclusivity and accessibility at its core.
- Huckletree opens new London hub for tech companies pioneering Web3 solutions 16th Mar 2023 Huckletree's new Web3 HQ aims to put London’s West End at the forefront of Britain’s tech superpower ambitions.
- OpenSponsorship making its move into the music sector 16th Mar 2023 Leading sports marketing platform, OpenSponsorship announces move into music sector, the first new vertical industry for the trans-Atlantic martech business.