The GDPR is set to be the greatest shake-up to data protection laws in 20 years. Elly Earls finds out how it will impact payroll and how businesses can manage their personal information
Bâ¬20m (£17.6m) or 4% of a companyâs global annual turnover, whichever is higher.
One department the General Data Protection Regulation (GDPR) will certainly impact is payroll. And in an industry like hospitality â" where casual staff, shifts, irregular hours and weekly payments are commonplace â" payroll departments will have a particularly momentous task on their hands if they donât have the requisite systems and processes already in place.
So where to start? According to Ian McDonald, regional instructional designer at business software company Sage, who is in charge of running regular GDPR webinars for Sage customers, step one for business owners has got to be learning the basics. While most people who attend Sage webinars know that GDPR is just around the corner, the majority havenât yet grasped what it means for their business or what steps they need to take.
âOne of the things I ask at the start of the webinar is how would people rate their knowledge of the GDPR on a scale of zero to 10. The most common response by quite a margin is zero to three,â he says. âPeople know of it and know itâs coming, but not a lot beyond that. The priority has got to be education before we even start talking about the practicalities. This includes making sure people in the business who deal with personal data on a daily basis know this is coming and what it entails.â
Carrying out a data audit
Next, itâs time to carry out a data audit so each department knows exactly what personal data they hold and where it is. âPersonal data is anything that could identify an individual, so itâs not necessarily just the name; it could be a phone number, an email address, a social media handle or even an internal identity,â says Adam Prince, vice-president of product management at Sage.
For payroll, this will mainly be employee information, and the good news, according to Sage product management lead Ceara Metcalf, a specialist in payroll, is that itâs generally quite defined. âIn order to pay somebody, HMRC requires you to have specific pieces of information about a person: their name, their address, their national insurance number and their date of birth. As thereâs a legal reason to have this information, you donât need to get consent from the employee, so that makes things slightly easier from a payroll point of view.â
That said, HR departments will probably also have pieces of personal data that might not immediately spring to mind, such as next of kin or emergency contact details. And as the GDPR stipulates that you must have a legal basis for holding any personal data, consent may need to be obtained to keep hold of these.
The biggest task will be sifting through the various systems â" both digital and paper â" across which personal data is inevitably scattered, from spreadsheets to payroll software, or from Outlook contact lists to pieces of paper. Email attachments may also have been saved to local computers.
One of the principles of the GDPR is that companies donât hold data on anybody for longer than necessary, so once you know what you have, the next job is working out what you must delete. For example, HMRC requires companies to keep employee information for a minimum of three payroll tax years; after that, there is no longer a legal basis to keep it and it will need to be removed unless there are reasons to retain it (for example, ongoing legal action).
âFor companies in the hospitality industry, where there are a lot of records, there may be a lot of information that needs purging, which could be a big administrative task in itself,â McDonald warns.
If any data is required for statistical analysis â" the solution is simply to anonymise it. âSay you want to know what overtime you paid out in 2009: you donât need to know which employee got that overtime, but you may want to keep some of the records,â Metcalf explains. âYou just have to anonymise the people part of it.â
The best advice Metcalf can offer is to consolidate as much data as possible, ideally into an online system. âIf, from your audit, you know that you hold data in 18 different places and you can get that down to five, that will make things easier,â she says. âOnline portal technology is considered industry best practice when it comes to keeping things safe and secure.â
Updating contracts and processes
Besides the data audit, businesses also need to think about with whom theyâre sharing employee data, both regularly and on an ad hoc basis. âThere are some things you legally have to share â" for example, you have to send information to HMRC every time you do a payroll run,â Metcalf says. âBut if youâre buying the team a new uniform and youâve collected all their T-shirt sizes, you donât need to send their names or any identifying information such as email addresses to the third party.â
Itâs also crucial for operators to review and update the legal T&Cs and privacy notices that go into contracts. âThereâs a lot more information that will need to go into a contract than currently and a lot more information you need to tell people in a privacy notice,â McDonald says. It all boils down to not collecting any information you donât need and being clear about the data that is being collected â" why itâs required and what is going to be done with it.
Under the GDPR, employees will also have the right to data portability, the right to be forgotten and the right to be given access to all the information a company holds about them within 30 days (down from 40 days), free of charge. Itâs here where that earlier consolidation will really start to come into play.
âIf the data is kept in as few areas as possible, it will make it much easier when it comes to a subject access request,â Metcalf says. âThirty days sounds like a long time, but when you start to think about email attachments, deleted items and data being in places you might not think of â" an employee could also be an emergency contact for another employee, for example â" it might not seem like such a long time.â
Accountability: âAssume you will be responsibleâ
The GDPR specifies three main actors â" the data controller, who makes the decision to store personal data; the data processor, a person or organisation, such as a payroll bureau who is following the data controllerâs instructions; and the data subject, the person whose data is collected. A hospitality business is the data controller, which means the primary responsibility for complying with the law and ensuring that any member of staff who deals with personal data understands how to comply with it, is theirs.
âThe Information Commissionerâs Office (ICO) recommends you nominate someone in your company as the go-to person for the GDPR â" theyâre responsible for making sure employees, such as payroll clerks, who are processing personal data, understand the regulations and understand what part they can play in making sure the company is following best practice,â Metcalf explains. âSo, if you do an audit and you find a note in a record four years ago where somethingâs been written about someone, they know the company shouldnât have that.â
Prince emphasises: âThe best advice is to assume you may be responsible unless youâve had legal advice confirming youâre not. Donât assume you can just ignore it.â
Knowing where to start
Itâs only two months until the GDPR comes into force, and the vast majority of UK businesses arenât ready, according to Prince. âOf large businesses, Iâd say 15%-20% have very robust, well-executed plans that are on track, another 10%-20% are working on it, and the remaining 60%+ still havenât got there,â he estimates. Their biggest challenge? According to surveys carried out by Sage, knowing where to begin.
McDonald, Prince and Metcalf recommend reading the â12 steps to take nowâ document on the ICO website, which is designed to help businesses prepare for the new law. Steps include awareness, individualsâ rights, subject access requests and consent. The organisation also offers free templates on how to carry out a data audit and other free resources. Then, if a business canât afford or find legal advice â" according to Prince, many of the quality resources are now fully booked â" dedicated GDPR process software may help and there is an emerging range of products focused in this area.
The Sage marketplace, for example, includes partner products for GDPR that can walk any business, whether they run Sage software or not, through the workflow of what they need to do â" from working out what data they hold to where itâs stored and whoâs got access to it. The government-backed Cyber Essentials scheme, which helps businesses protect themselves from cyber security threats, is another great resource for companies looking for information on how to store their employee data in the most safe and secure way.
For Prince, complying with the GDPR essentially comes down to doing the right thing. âConsider the individual rather than you or the organisation when youâre trying to work out what to do,â he advises. âIf you think about it from the individualâs point of view, they will care about whoâs storing their data and what happens to that data.â
The team must understand the consequences of bad data control
At contract catering company Bartlett Mitchell, which implemented a GDPR-compliant payroll system last year and notified employees of their data privacy rights as if the law had already come into force, the upcoming legislative changes are not set to have a huge impact in the context of payroll.
âAs a business, we have very robust systems and processes in place, so we havenât had to change too much,â says founder and executive chairman Wendy Bartlett. âWe were well-prepared for this.â
The biggest challenge and the most important part of the process was to ensure that the team understood why the GDPR was happening and what the consequences of bad data control could be. âThe regulation is quite complex and full-on, so it is really easy for people to disengage with it if they find it overwhelming. Thatâs why itâs important to put all of this into context and explain how it can impact them directly,â Bartlett says.
As part of this, Bartlett Mitchell has provided its senior team with one-to-one training sessions and will also be rolling out further online training to management and the rest of the business.
Bartlettâs biggest tip for other hospitality businesses is to engage an external advisor to audit their activity. âWhile we were confident in our systems and procedures, it was important to have an independent resource to audit exactly what we did,â she explains. Our advisor was able to sense-check our activity and make any recommendations accordingly. Throughout the process, what has become quite apparent is the fact that a lot of it is based on applying common sense to how you gather, store and manage data.â
Another practical change she advises is ensuring transparency. âEach employee should know they have access to their payroll information and how they can quickly access it, update their file and review the information on file,â she says.
The company has also digitised all payroll documents so team members will eventually have access to all their files via a payroll app. âTechnology can be a good enabler for compliance,â Bartlett concludes.
Sage has over 30 yearsâ experience supporting business with compliance. For more information on the GDPR, please visit Sage's GDPR portal. For more details on Sage Payroll solutions, visit Sage's website