{"id":1021,"date":"2022-08-30T11:42:16","date_gmt":"2022-08-30T11:42:16","guid":{"rendered":"https:\/\/sense.hr\/blog\/keeping-your-hr-department-gdpr-compliant\/"},"modified":"2022-08-30T11:42:16","modified_gmt":"2022-08-30T11:42:16","slug":"keeping-your-hr-department-gdpr-compliant","status":"publish","type":"post","link":"https:\/\/sense.hr\/blog\/keeping-your-hr-department-gdpr-compliant\/","title":{"rendered":"Keeping your HR department GDPR compliant"},"content":{"rendered":"<p>\n  Surely, everyone in the UK\u2014probably everyone in the whole world\u2014has watched a lion hunt on the TV? Look! There\u2019s the herd getting on with herd business, like scratching their friend\u2019s neck, eating grass, and swatting flies. There\u2019s the lioness and her prowling pride, slowly closing in. The threat is real. But the herd is lost in the daily grind\u2014too preoccupied to take much notice. And the lioness hasn\u2019t decided exactly what to\u2026. and boom! She bursts forth! The herd explodes! All is chaos and madness and mayhem and speed and drama\u2026&nbsp;&nbsp;\n<\/p>\n<p>\n  Now, instead of a herd of zebra, envisage millions of businesspeople. And instead of a lioness, imagine four little letters\u2014GDPR. Aaaaand that\u2019s a <s>completely<\/s> fairly accurate portrait of the online business world between 2016, when the General Data Protection Regulation was adopted, and 2018, when it came into effect.&nbsp;&nbsp;\n<\/p>\n<p>\n  Of course, there were more laptops and lattes, than Serengeti wildernesses and watering holes. And we got millions of alarming blog posts instead of David Attenborough\u2019s authoritative yet comforting voiceover\u2026 but you get the idea. It was wild!&nbsp;\n<\/p>\n<p>\n  Things have changed a lot since then. For starters, most people have realised that the GDPR is more \u2018good cop\u2019\u2014there to protect and serve\u2014than bloodthirsty lioness\u2014there to eat everyone who can\u2019t keep up. And, of course, by 1<sup>st<\/sup> January 2021 the United Kingdom had formally exited the European Union and no longer had to conform with the GDPR (EU) at all.&nbsp;\n<\/p>\n<p>\n  So, what\u2019s the score with the GDPR in 2022? What are the obligations of organisations under <a href=\"https:\/\/www.gov.uk\/data-protection\" target=\"_blank\" rel=\"noreferrer noopener\">UK GDPR laws<\/a>\u2014aka the Data Protection Act 2018? And how are HR managers supposed to keep on top of it all?&nbsp;\n<\/p>\n<h2 class=\"wp-block-heading\">What the GDPR do we do now?\u00a0<\/h2>\n<p>\n  The good news\u2014or the bad news, depending on your point of view\u2014is that the UK decided to stick with the GDPR, now called the UK GDPR, which is now part of the Data Protection Act 2018 (DPA). As with its EU counterpart the UK GDPR governs data protection in the UK, how organisations gather, store, and use data, and how individuals can exercise their increasing rights of control over their own personal data. And that includes all the people in your organisation.&nbsp;&nbsp;\n<\/p>\n<p>\n  Combining both ethical and legal concerns, data protection laws impact most HR processes, from recruitment, and record keeping, to performance monitoring, and compensation. So, it\u2019s not something that organisations can brush aside or improvise. <a href=\"https:\/\/www.cipd.co.uk\/knowledge\/fundamentals\/emp-law\/data-protection\/factsheet#gref\" target=\"_blank\" rel=\"noreferrer noopener\">Data must be managed responsibly<\/a>, while legal principles and developments must be upheld. And we\u2019re not going to downplay it\u2014developments in data protection can feel overwhelming.&nbsp;&nbsp;\n<\/p>\n<p>\n  But don\u2019t start carving out the \u2018Abandon Hope All Ye Who Enter Here\u2019 signs just yet. We\u2019ve put together a <s>fun<\/s> practical guide for all things GDPR.&nbsp;\n<\/p>\n<h2 class=\"wp-block-heading\">The anatomy of UK data protection\u00a0<\/h2>\n<p>\n  UK data protection laws are made up of several central bodies, terms, regulations, and rights. It\u2019s best that any HR manager has a basic understanding of the main elements, so we\u2019ll take a quick look at them now.&nbsp;&nbsp;&nbsp;\n<\/p>\n<p>\n  <strong>The Information Commissioner\u2019s Office (ICO)&nbsp;<\/strong>\n<\/p>\n<p>\n  The ICO is an independent body charged with the promotion and enforcement of data protection legislation. And that includes issuing fines like the <a href=\"https:\/\/www.itpro.co.uk\/security\/data-breaches\/357452\/british-airways-dodges-ps183-million-data-breach-fine\" target=\"_blank\" rel=\"noreferrer noopener\">\u00a320 million data breach fine<\/a> issued to British Airways (reduced from an original \u00a3183 million), after a cyber-attack compromised the personal and financial data of over 400,000 customers. While the ICOs limits are yet to be tested, you can rest easy that fines are proportionate to turnover and the level of data loss\u2014data-driven business models be warned. So, although not many of us are likely to find a \u00a320 million bill on our doormat, fines can be up to 4% of total annual worldwide turnover for the most serious failures.&nbsp;\n<\/p>\n<p>\n  <strong>The General Data Protection Regulation (GDPR)&nbsp;<\/strong>\n<\/p>\n<p>\n  The GDPR is largely concerned with individuals\u2019 rights to access information about their own data, as well as data management obligations, and fines for misuse.&nbsp;&nbsp;\n<\/p>\n<p>\n  <strong>The Data Protection Act 2018 (DPA)&nbsp;<\/strong>\n<\/p>\n<p>\n  Together, the DPA and GDPR dictate the obligations of <strong>data controllers<\/strong> (those who decide how and why personal data is processed) and the rights of <strong>data subjects<\/strong> (those whose data is held or processed). In the context of HR, the employer would usually be the <strong>data controller<\/strong>, while workers, employees, past employees, and applicants would be <strong>data subjects<\/strong>.&nbsp;&nbsp;\n<\/p>\n<p>\n  According to the principles of the DPA, data controllers must make sure collected and stored information is:&nbsp;&nbsp;\n<\/p>\n<ul class=\"wp-block-list\">\n<li>\n    used fairly, lawfully, and transparently&nbsp;\n  <\/li>\n<\/ul>\n<ul class=\"wp-block-list\">\n<li>\n    used for specified, explicit purposes&nbsp;\n  <\/li>\n<li>\n    used in a way that is adequate, relevant, and limited to only what is necessary&nbsp;\n  <\/li>\n<li>\n    accurate and, where necessary, kept up to date&nbsp;\n  <\/li>\n<li>\n    kept for no longer than is necessary&nbsp;\n  <\/li>\n<li>\n    handled in a way that ensures proper security, including protection against unlawful or unauthorised processing, access, loss, destruction, or damage&nbsp;\n  <\/li>\n<\/ul>\n<p>\n  <strong>Personal versus sensitive data&nbsp;<\/strong>\n<\/p>\n<p>\n  Personal data relates to personally identifiable information like name and location. Almost all HR records including absence records, performance tracking, and recruitment files can be classed as personal data.&nbsp;&nbsp;\n<\/p>\n<p>\n  <a href=\"https:\/\/www.gov.uk\/data-protection\" target=\"_blank\" rel=\"noreferrer noopener\">Sensitive data<\/a> relates to data that could lead to discriminatory behaviours, reveals protected characteristics, or is singularly personally identifiable. This includes information on race, ethnic background, political opinions, religious beliefs, trade union membership, genetics, identifying biometrics, health, sex life or orientation, and criminal records. While there are stronger legal protections for sensitive data, it can be processed if necessary. For example, criminal records must be accessed for work with children or vulnerable adults. Or fits notes can be collected to prove genuine illness. Even diversity information can be collected if it is in the interest of social security and social protection law. However, any reasons must be fair, lawful, transparent, accurate, and properly recorded.&nbsp;\n<\/p>\n<p>\n  <strong>Individual rights<\/strong>\n<\/p>\n<p>\n  All individuals, including employees or anyone who has worked, is working, or has applied to work for an organisation, has the right to find out what information that organisation holds about them.&nbsp;&nbsp;\n<\/p>\n<p>\n  That includes the right to:&nbsp;\n<\/p>\n<ul class=\"wp-block-list\">\n<li>\n    be informed about how their data is being used&nbsp;\n  <\/li>\n<\/ul>\n<ul class=\"wp-block-list\">\n<li>\n    access personal data&nbsp;\n  <\/li>\n<li>\n    have incorrect data updated&nbsp;\n  <\/li>\n<li>\n    have data erased&nbsp;\n  <\/li>\n<li>\n    stop or restrict the processing of their data&nbsp;\n  <\/li>\n<li>\n    data portability (allowing them to get and reuse their data elsewhere)&nbsp;\n  <\/li>\n<\/ul>\n<ul class=\"wp-block-list\">\n<li>\n    object to how their data is processed in certain circumstances&nbsp;\n  <\/li>\n<\/ul>\n<p>\n  These rights extend to data used for:&nbsp;\n<\/p>\n<ul class=\"wp-block-list\">\n<li>\n    automated decision-making processes&nbsp;\n  <\/li>\n<li>\n    profiling (data used to predict behaviours or interests)&nbsp;\n  <\/li>\n<\/ul>\n<p>\n  HR teams are most likely to be impacted by data protection rights in the form of Data Subject Access Requests (DSARs). These can be either oral or written requests and can relate to general (all) or specific data. In increasingly intertwined workplaces, where one employee document can reference other employees, or performance data for one can reveal performance data for another, it is important that DSARs are handled with great care. Getting it wrong can lead to a data breach.&nbsp;&nbsp;\n<\/p>\n<h2 class=\"wp-block-heading\">Data protection in action\u00a0<\/h2>\n<p>\n  Now you have an idea of what data protection laws look like in 2022, you\u2019re probably wondering how they affect you and your organisation. Let\u2019s look at some examples.&nbsp;&nbsp;\n<\/p>\n<h2 class=\"wp-block-heading\">EU\/UK organisations\u00a0<\/h2>\n<p>\n  Thanks to an <a href=\"https:\/\/ec.europa.eu\/commission\/presscorner\/detail\/ro\/ip_21_3183\" target=\"_blank\" rel=\"noreferrer noopener\">adequacy decision<\/a> made by the European Commission in June 2021 relating to the GDPR, \u201cpersonal data can now flow freely from the European Union to the United Kingdom where it benefits from an essentially equivalent level of protection to that guaranteed under EU law\u201d. Although limited by a 4 year \u2018sunset clause\u2019, at which time it will be reviewed, the decision means that organisations that have operations in the EU as well as the UK can breathe a temporary sigh of relief. And we\u2019re not just talking about people or business activities. If a UK based organisation uses a cloud storage provider based in, for example, Germany, then data will need to flow freely between those two points. So, by 2025 we may all have to start thinking about where our cloud providers are based, and not just the security, privacy, and contents of the data.&nbsp;&nbsp;\n<\/p>\n<h2 class=\"wp-block-heading\">Privacy policies\u00a0\u00a0<\/h2>\n<p>\n  Like cookies and Ts&#038;Cs, privacy policies are an ever-present aspect of online life. And they need to be high on every HR professional\u2019s agenda too. Policies must be transparent, comprehensive, easily accessible for employees and other workers, and up to date. And any changes in data management policies must be communicated organisation wide. The best way to do this is by circulating a privacy notice\u2014here\u2019s a <a href=\"https:\/\/assets.publishing.service.gov.uk\/government\/uploads\/system\/uploads\/attachment_data\/file\/822868\/HMCTS_privacy_notice_for_employees_workers_and_contractors.pdf\" target=\"_blank\" rel=\"noreferrer noopener\">handy template<\/a> provided by the Ministry of Justice.&nbsp;&nbsp;\n<\/p>\n<h2 class=\"wp-block-heading\">Internet, social media, communications, and remote working policies\u00a0<\/h2>\n<p>\n  Providing staff with smart phones, laptops, tablets, and flexible working options is increasingly common and even expected. But spreading workforces and company assets beyond the four walls of HQ comes with its own data protection implications. Robust policies should cover cybersecurity, permitted uses for all devices and communication channels, and unobtrusive monitoring measures such as tracking traffic data.&nbsp;\n<\/p>\n<p>\n  Accountability requirements should be met by training, auditing, and comprehensive documenting of data processing activities, while consistently reviewing HR policies. For example, people must be able to recognise and avoid potential attacks like phishing and organisational data should be encrypted.&nbsp;&nbsp;\n<\/p>\n<h2 class=\"wp-block-heading\">Data protection officers (DPOs)\u00a0<\/h2>\n<p>\n  Although a governance update on the 23rd of June 2022 included proposals to replace requirements to appoint a DPO with an obligation to appoint a senior person who is responsible for data privacy management, it\u2019s still important to hire a DPO if your organisation meets certain criteria. For example, if you\u2019re a public authority or body, or work closely with public authorities or bodies, or perform large-scale monitoring or data processing.&nbsp;&nbsp;\n<\/p>\n<h2 class=\"wp-block-heading\">Third-party data transfers\u00a0<\/h2>\n<p>\n  Just because you\u2019re not selling employee data, doesn\u2019t mean that you\u2019re not sharing it. If you send data through third-party software integrations such as payroll software or HR software, or use external organisations like recruitment agencies, solicitors, or accountancy firms, you need to make sure that they\u2019re compliant too.&nbsp;&nbsp;\n<\/p>\n<h2 class=\"wp-block-heading\">Data security\u00a0<\/h2>\n<p>\n  Data security obligations depend on the size of your organisation, the nature of the data being processed, and the potential harm that could result from a data breach. But risk assessments, up-to-date security systems and software, strict access restrictions, training, and security monitoring should be part of every organisation\u2019s data security practices.&nbsp;\n<\/p>\n<h2 class=\"wp-block-heading\">Record keeping and correction\u00a0<\/h2>\n<p>\n  If your organisation has over 250 employees, then clear, accessible records of all data processing activities must be kept. Smaller organisations only need to keep records for data that they process regularly, such as payroll data, as well as sensitive, potentially harmful, or intrusive data.&nbsp;&nbsp;\n<\/p>\n<h2 class=\"wp-block-heading\">A GDPR action plan\u00a0<\/h2>\n<p>\n  The TL;DR action plan is that every organisation\u2014no matter what size\u2014should audit information systems to find out where data is held and why; issue policies and guidelines regulating data management; ensure the security of all stored data; consider and properly manage international data transfer; keep on top of automated decision-making processes; and review and monitor policies, practices, and training on an ongoing and systematic basis.&nbsp;&nbsp;\n<\/p>\n<p>\n  And that\u2019s it. Phew! A comprehensive post-Brexit guide to UK GDPR.&nbsp;&nbsp;\n<\/p>\n<p>\n  But if you\u2019re still feeling a bit like an outlying Zebra with the lions closing in, then all is not lost, there\u2019s a reliable, hassle-free short cut that can save your hide\u2014HR Software.&nbsp;&nbsp;\n<\/p>\n<h2 class=\"wp-block-heading\">HR software and GDPR compliance\u00a0<\/h2>\n<p>\n  <a href=\"https:\/\/www.hrmagazine.co.uk\/content\/news\/hr-bears-brunt-of-gdpr-compliance\" target=\"_blank\" rel=\"noreferrer noopener\">76% of HR professionals<\/a> have admitted that GDPR requirements have added a significant burden to their HR department. And with increasing numbers of DSARs, data-mapping requirements, data deletion and anonymisation requests, post-Brexit and post-pandemic considerations and regulations, and the ever-changing needs of an evolving workforce, the administrative burden is growing. But it doesn\u2019t have to. With the support of a good HR software, effectively managing GDRP compliance can be easy.&nbsp;&nbsp;\n<\/p>\n<p>\n  SenseHR GDPR-compliant software comes with lots of features to help your organisation stay ahead of legislative requirements.&nbsp;&nbsp;\n<\/p>\n<ul class=\"wp-block-list\">\n<li>\n    Secure: Cloud computing, data encryption, IS027001 certification, multifactor authentication, and ongoing penetration testing mean that your data is safe with SenseHR&nbsp;\n  <\/li>\n<\/ul>\n<ul class=\"wp-block-list\">\n<li>\n    Employee access: Secure Self-service means that all your people can check and update their own\u202finformation at any time, as well as access updates and training&nbsp;\n  <\/li>\n<li>\n    Automated data retention and deletion: Configure your system to delete, anonymise, and retain data according to your rules&nbsp;\n  <\/li>\n<li>\n    Portability: Easy data import and export to help with data portability requirements&nbsp;\n  <\/li>\n<li>\n    A single data source: No more searching. Keep all your data, documents, policies, and training materials in one place&nbsp;\n  <\/li>\n<li>\n    Secure third-party integrations: Keep track of all your data transfers&nbsp;\n  <\/li>\n<\/ul>\n<ul class=\"wp-block-list\">\n<li>\n    Unlimited document storage: Never run out of secure storage space for your organisational documents&nbsp;\n  <\/li>\n<li>\n    E-signatures: Inbuilt document generation and real, on-document, e-signatures mean that you can track and secure the most vital business documents, throughout their lifecycle, without ever leaving the safety of your software&nbsp;\n  <\/li>\n<li>\n    GDPR for everyone: SenseHRs <a href=\"\/blog\/power-to-your-people-with-graph-databases\/\" target=\"_blank\" rel=\"noreferrer noopener\">ground-breaking databases<\/a> and innovative workflows mean that your people data is protected no matter where your people are working or how\u00a0\n  <\/li>\n<\/ul>\n<p>\n  When it comes down to it, GDPR is all about empowering and caring for your workforce. And if it\u2019s done right it can help with employee retention and engagement\u2014it\u2019s not just about protecting your organisation from the lions. And the best and easiest way to do it right is with our next generation <a href=\"\/\">HR software<\/a>.\u00a0\u00a0<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Surely, everyone in the UK\u2014probably everyone in the whole world\u2014has watched a lion hunt on the TV?<\/p>\n","protected":false},"author":4,"featured_media":1020,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[5],"tags":[],"class_list":["post-1021","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-gdpr"],"contentshake_article_id":"","yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.2 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Keeping your HR department GDPR compliant - Sense HR<\/title>\n<meta name=\"description\" content=\"Surely, everyone in the UK\u2014probably everyone in the whole world\u2014has watched a lion hunt on the TV?\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/sense.hr\/blog\/keeping-your-hr-department-gdpr-compliant\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Keeping your HR department GDPR compliant - Sense HR\" \/>\n<meta property=\"og:description\" content=\"Surely, everyone in the UK\u2014probably everyone in the whole world\u2014has watched a lion hunt on the TV?\" \/>\n<meta property=\"og:url\" content=\"https:\/\/sense.hr\/blog\/keeping-your-hr-department-gdpr-compliant\/\" \/>\n<meta property=\"og:site_name\" content=\"Sense HR\" \/>\n<meta property=\"article:published_time\" content=\"2022-08-30T11:42:16+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/sense.hr\/blog\/wp-content\/uploads\/2022\/08\/featured.png\" \/>\n\t<meta property=\"og:image:width\" content=\"880\" \/>\n\t<meta property=\"og:image:height\" content=\"400\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Abbi Melville\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Abbi Melville\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"11 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/sense.hr\\\/blog\\\/keeping-your-hr-department-gdpr-compliant\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/sense.hr\\\/blog\\\/keeping-your-hr-department-gdpr-compliant\\\/\"},\"author\":{\"name\":\"Abbi Melville\",\"@id\":\"https:\\\/\\\/sense.hr\\\/blog\\\/#\\\/schema\\\/person\\\/f2558290201076f2c2bfaec41de5d9f4\"},\"headline\":\"Keeping your HR department GDPR compliant\",\"datePublished\":\"2022-08-30T11:42:16+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/sense.hr\\\/blog\\\/keeping-your-hr-department-gdpr-compliant\\\/\"},\"wordCount\":2274,\"image\":{\"@id\":\"https:\\\/\\\/sense.hr\\\/blog\\\/keeping-your-hr-department-gdpr-compliant\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/sense.hr\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/08\\\/featured.png\",\"articleSection\":[\"GDPR\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/sense.hr\\\/blog\\\/keeping-your-hr-department-gdpr-compliant\\\/\",\"url\":\"https:\\\/\\\/sense.hr\\\/blog\\\/keeping-your-hr-department-gdpr-compliant\\\/\",\"name\":\"Keeping your HR department GDPR compliant - Sense HR\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/sense.hr\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/sense.hr\\\/blog\\\/keeping-your-hr-department-gdpr-compliant\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/sense.hr\\\/blog\\\/keeping-your-hr-department-gdpr-compliant\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/sense.hr\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/08\\\/featured.png\",\"datePublished\":\"2022-08-30T11:42:16+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/sense.hr\\\/blog\\\/#\\\/schema\\\/person\\\/f2558290201076f2c2bfaec41de5d9f4\"},\"description\":\"Surely, everyone in the UK\u2014probably everyone in the whole world\u2014has watched a lion hunt on the TV?\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/sense.hr\\\/blog\\\/keeping-your-hr-department-gdpr-compliant\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/sense.hr\\\/blog\\\/keeping-your-hr-department-gdpr-compliant\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/sense.hr\\\/blog\\\/keeping-your-hr-department-gdpr-compliant\\\/#primaryimage\",\"url\":\"https:\\\/\\\/sense.hr\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/08\\\/featured.png\",\"contentUrl\":\"https:\\\/\\\/sense.hr\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/08\\\/featured.png\",\"width\":880,\"height\":400},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/sense.hr\\\/blog\\\/keeping-your-hr-department-gdpr-compliant\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/sense.hr\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Keeping your HR department GDPR compliant\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/sense.hr\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/sense.hr\\\/blog\\\/\",\"name\":\"Sense HR\",\"description\":\"HR insights, guides and news from the Sense HR team.\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/sense.hr\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/sense.hr\\\/blog\\\/#\\\/schema\\\/person\\\/f2558290201076f2c2bfaec41de5d9f4\",\"name\":\"Abbi Melville\",\"url\":\"https:\\\/\\\/sense.hr\\\/blog\\\/author\\\/abbi-melville\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Keeping your HR department GDPR compliant - Sense HR","description":"Surely, everyone in the UK\u2014probably everyone in the whole world\u2014has watched a lion hunt on the TV?","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/sense.hr\/blog\/keeping-your-hr-department-gdpr-compliant\/","og_locale":"en_US","og_type":"article","og_title":"Keeping your HR department GDPR compliant - Sense HR","og_description":"Surely, everyone in the UK\u2014probably everyone in the whole world\u2014has watched a lion hunt on the TV?","og_url":"https:\/\/sense.hr\/blog\/keeping-your-hr-department-gdpr-compliant\/","og_site_name":"Sense HR","article_published_time":"2022-08-30T11:42:16+00:00","og_image":[{"width":880,"height":400,"url":"https:\/\/sense.hr\/blog\/wp-content\/uploads\/2022\/08\/featured.png","type":"image\/png"}],"author":"Abbi Melville","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Abbi Melville","Est. reading time":"11 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/sense.hr\/blog\/keeping-your-hr-department-gdpr-compliant\/#article","isPartOf":{"@id":"https:\/\/sense.hr\/blog\/keeping-your-hr-department-gdpr-compliant\/"},"author":{"name":"Abbi Melville","@id":"https:\/\/sense.hr\/blog\/#\/schema\/person\/f2558290201076f2c2bfaec41de5d9f4"},"headline":"Keeping your HR department GDPR compliant","datePublished":"2022-08-30T11:42:16+00:00","mainEntityOfPage":{"@id":"https:\/\/sense.hr\/blog\/keeping-your-hr-department-gdpr-compliant\/"},"wordCount":2274,"image":{"@id":"https:\/\/sense.hr\/blog\/keeping-your-hr-department-gdpr-compliant\/#primaryimage"},"thumbnailUrl":"https:\/\/sense.hr\/blog\/wp-content\/uploads\/2022\/08\/featured.png","articleSection":["GDPR"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/sense.hr\/blog\/keeping-your-hr-department-gdpr-compliant\/","url":"https:\/\/sense.hr\/blog\/keeping-your-hr-department-gdpr-compliant\/","name":"Keeping your HR department GDPR compliant - Sense HR","isPartOf":{"@id":"https:\/\/sense.hr\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/sense.hr\/blog\/keeping-your-hr-department-gdpr-compliant\/#primaryimage"},"image":{"@id":"https:\/\/sense.hr\/blog\/keeping-your-hr-department-gdpr-compliant\/#primaryimage"},"thumbnailUrl":"https:\/\/sense.hr\/blog\/wp-content\/uploads\/2022\/08\/featured.png","datePublished":"2022-08-30T11:42:16+00:00","author":{"@id":"https:\/\/sense.hr\/blog\/#\/schema\/person\/f2558290201076f2c2bfaec41de5d9f4"},"description":"Surely, everyone in the UK\u2014probably everyone in the whole world\u2014has watched a lion hunt on the TV?","breadcrumb":{"@id":"https:\/\/sense.hr\/blog\/keeping-your-hr-department-gdpr-compliant\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/sense.hr\/blog\/keeping-your-hr-department-gdpr-compliant\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/sense.hr\/blog\/keeping-your-hr-department-gdpr-compliant\/#primaryimage","url":"https:\/\/sense.hr\/blog\/wp-content\/uploads\/2022\/08\/featured.png","contentUrl":"https:\/\/sense.hr\/blog\/wp-content\/uploads\/2022\/08\/featured.png","width":880,"height":400},{"@type":"BreadcrumbList","@id":"https:\/\/sense.hr\/blog\/keeping-your-hr-department-gdpr-compliant\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/sense.hr\/blog\/"},{"@type":"ListItem","position":2,"name":"Keeping your HR department GDPR compliant"}]},{"@type":"WebSite","@id":"https:\/\/sense.hr\/blog\/#website","url":"https:\/\/sense.hr\/blog\/","name":"Sense HR","description":"HR insights, guides and news from the Sense HR team.","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/sense.hr\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/sense.hr\/blog\/#\/schema\/person\/f2558290201076f2c2bfaec41de5d9f4","name":"Abbi Melville","url":"https:\/\/sense.hr\/blog\/author\/abbi-melville\/"}]}},"_links":{"self":[{"href":"https:\/\/sense.hr\/blog\/wp-json\/wp\/v2\/posts\/1021","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/sense.hr\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/sense.hr\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/sense.hr\/blog\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/sense.hr\/blog\/wp-json\/wp\/v2\/comments?post=1021"}],"version-history":[{"count":0,"href":"https:\/\/sense.hr\/blog\/wp-json\/wp\/v2\/posts\/1021\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/sense.hr\/blog\/wp-json\/wp\/v2\/media\/1020"}],"wp:attachment":[{"href":"https:\/\/sense.hr\/blog\/wp-json\/wp\/v2\/media?parent=1021"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/sense.hr\/blog\/wp-json\/wp\/v2\/categories?post=1021"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/sense.hr\/blog\/wp-json\/wp\/v2\/tags?post=1021"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}