Skip to content Skip to footer
Enquiries Call 0345 209 1000

Data protection law may not always grab headlines in the way employment law reforms do, but recent changes are significant and will affect every employer that processes personal data about employees, workers, applicants and customers. With growing awareness of data rights, rising Subject Access Requests and increasing use of AI in the workplace, compliance has never been more important.

The UK’s new Data (Use and Access) Act 2025 updates existing data protection legislation, including the UK GDPR and the Data Protection Act 2018. Rather than replacing the current framework, it amends and modernises it, with many of the changes being brought into force throughout 2026.

The reforms come at a time when data protection remains firmly on the regulator’s agenda. The Information Commissioner’s Office (ICO) receives tens of thousands of data protection complaints each year, highlighting the growing awareness individuals have of their data rights and the importance of employers getting compliance right.

We see subject access requests being used as a strategic tool in workplace disputes, particularly where employees are seeking information ahead of potential grievances, disciplinary processes or Employment Tribunal claims. As a result, employers should ensure that their data protection policies, procedures and training remain up to date and capable of withstanding increased scrutiny.

A new duty to handle data protection complaints

Perhaps the most important practical change for employers is the introduction of a formal requirement to have a process for handling data protection complaints.

Individuals must now be able to raise concerns directly with the organisation about how their personal data has been processed. Employers are expected to facilitate complaints, investigate them and provide an outcome within a reasonable timeframe.

Many employers already have grievance procedures that touch upon data protection issues, but these may not be sufficient. Organisations should review their privacy notices, policies and internal procedures to ensure there is a clear route for individuals to make a data protection complaint.

So, if your employee privacy notice, data protection policy or retention schedule has been sitting untouched since GDPR was introduced in 2018, now would be a sensible time to dust it off and ensure it remains fit for purpose.

Changes to Subject Access Requests

Subject Access Requests (DSARs) continue to be one of the most time-consuming and resource-intensive obligations facing employers.

The new legislation clarifies that organisations are only required to carry out “reasonable and proportionate” searches when responding to a request. It also introduces a “stop the clock” mechanism, allowing employers to pause the response period where additional information is needed from the individual making the request.

While these changes offer some welcome flexibility, employers should not underestimate the importance of handling DSARs properly. Increasingly, employees and former employees are using DSARs as a strategic step before raising grievances, making whistleblowing allegations or commencing Employment Tribunal proceedings. A poorly handled response can therefore create significant legal and employee relations risks.

Having a clear process, identifying relevant data sources early and understanding what information can lawfully be withheld remain essential.

Increased use of automated decision-making and AI

As employers increasingly use technology in recruitment, performance management and workforce planning, the rules around automated decision-making have become increasingly important.

The new framework permits wider use of automated decision-making, including AI-driven systems, provided appropriate safeguards are in place. Individuals must generally be informed when significant decisions are made using automated processes and must be given opportunities to challenge decisions and obtain meaningful human review.

Employers using AI tools to screen CVs, assess candidates, monitor performance or make workforce decisions should carefully review their systems to ensure adequate human oversight remains in place.

Legitimate interests become easier in some circumstances

The legislation introduces a new concept of “recognised legitimate interests”.

In certain prescribed situations, organisations may be able to rely on a legitimate interest basis for processing personal data without undertaking the full balancing exercise traditionally required under UK GDPR. Examples include activities linked to crime prevention, safeguarding and responding to emergencies.

For most routine HR processing, employers are likely to continue relying on existing lawful bases, but the changes may simplify compliance in some limited circumstances.

What should employers do now?

Employers should consider:

  • Reviewing privacy notices and employee data protection policies.
  • Ensuring there is a documented procedure for handling data protection complaints.
  • Reviewing Subject Access Request procedures and template responses.
  • Auditing any AI or automated decision-making systems used in recruitment or employment management.
  • Providing refresher training to HR teams and managers on data protection obligations.
  • Monitoring further guidance from the ICO as additional provisions come into force.

Looking ahead

Data protection compliance is no longer simply about avoiding regulatory action. It increasingly sits at the heart of employee relations, workplace disputes and organisational reputation. Whether responding to a Subject Access Request, dealing with an employee complaint about the use of their personal data or implementing new AI-driven workplace tools, employers are facing greater scrutiny than ever before.

The recent reforms provide some welcome clarification and flexibility in areas such as DSARs, but they also introduce new obligations and reinforce the need for robust policies, procedures and training. Employers that review their documentation, refresh staff training and take a proactive approach to compliance will be best placed to manage risk and avoid costly disputes in the future.

How we can help

Responding to a Data Subject Access Request can be complex, especially during workplace disputes or potential employment tribunal claim. Our employment team advises employers on searches, exemptions, redactions and disclosure obligations, as well as reviewing policies to ensure compliance.

If you would like advice on updating your data protection practices, responding to a DSAR, implementing AI systems or handling a data protection complaint, please send an enquiry or call 0345 209 1000 to speak with a member of our employment team.

Posted:

Your key contact

More on this topic

Employment

Settlement agreements: employer vs employee perspectives

Paula Squire, Partner at Clarke Willmott LLP, explores settlement agreements from both the employer and employee perspective, highlighting how differing objectives and expectations can shape negotiations and outcomes.
Read more on Settlement agreements: employer vs employee perspectives

Looking for legal advice?