A template internal policy for staff, setting out how a company handles personal data in line with the UK GDPR and Data Protection Act 2018, for use in England & Wales.
How to use this template - Replace every
[SQUARE-BRACKET]field before use. - This is an internal policy guiding staff, it is different from your external privacy notice (which tells customers/individuals how you use their data). You need both. - Keep it consistent with your IT/acceptable-use, retention and security policies. It is not part of the contract of employment and may be amended. - Have a solicitor or data protection adviser review before issuing.
---
[COMPANY NAME] Personal Data Protection Policy (Internal)
1. Purpose. This policy explains how everyone at [COMPANY NAME] must handle personal data to comply with the UK GDPR and Data Protection Act 2018, and to protect the privacy of customers, staff and others. It applies to all [employees, workers and contractors].
2. The principles. When handling personal data, you must ensure it is: processed lawfully, fairly and transparently; collected only for specified purposes; minimal (only what is needed); accurate; kept no longer than necessary; and kept secure. The company must be able to demonstrate compliance (accountability).
3. Lawful basis. Only process personal data where there is a valid lawful basis (such as consent, contract or legitimate interests). If you are unsure, ask [DATA PROTECTION LEAD] before processing.
4. Special category data. Take extra care with sensitive data (such as health, ethnicity or religious data) and criminal-offence data, which require additional conditions.
5. Security. Keep personal data secure: use strong passwords and multi-factor authentication, lock devices, encrypt where required, control access on a need-to-know basis, and never share data without authority. Do not use unauthorised apps or personal accounts for company data.
6. Individuals' rights. People have rights over their data (access, correction, erasure, objection). If you receive a request from an individual about their data (a "data subject request"), forward it immediately to [DATA PROTECTION LEAD], there are strict time limits.
7. Sharing and suppliers. Only share personal data where lawful and authorised, and only with suppliers under an approved data processing agreement. Take care with international transfers.
8. Retention. Keep personal data only as long as needed, in line with the company's retention schedule, then delete or anonymise it securely.
9. Data breaches. If you become aware of a possible data breach (lost device, misdirected email, suspected hack), report it to [DATA PROTECTION LEAD] immediately, the company may need to notify the ICO within 72 hours.
10. Your responsibility. Complying with this policy is part of your role. Misuse of personal data may be a disciplinary matter and can expose you and the company to legal liability.
11. Review. This policy is reviewed every [NUMBER] months and may be amended.
--- This template is a starting point and not legal advice. Have a qualified solicitor or data protection adviser review and adapt it before use. Governing law: England & Wales.