To see all content you need to log in or Subscribe now 

Just to let you know... If you are an existing user before 18th September, you may notice the model documents have changed. This is to coincide with our website relaunch: we wanted to refresh the content too. Don't worry, these are not legally required changes so you can continue to use the previous version you have saved or downloaded. (We have kept the previous date as well to make it easy to reference.)

Don't show this again

Form

HR data audit form (GDPR compliant)

HR data audit form (GDPR compliant)

HR Data audit form (GDPR compliant)
Last Modified

You can use this form to complete your HR data audit in preparation for GDPR. It enables you to review the life cycle of data that you process including the types of data, the reason for the processing, and the security measures you take.

HR data record (GDPR compliant)

HR data record (GDPR compliant)

HR data record (GDPR compliant)
Last Modified

You should use this form to keep an ongoing record of the HR data you process and the lawful basis on which it is processed. You should regularly review the information on this record and ensure it is fully up to date.

Medical report consent form (GDPR compliant)

Medical report consent form (GDPR compliant)

Medical report consent form
Last Modified
Previously modified

This model medical report consent form explains rights relating to a request for a medical report from the employee's GP, including the specifics of the request for information, the employee's rights under the Access to Medical Reports Act 1988, the employee's right to see the report, and the interaction with the Data Protection Act 2018.

Employee privacy notice (GDPR compliant)

Employee privacy notice (GDPR compliant)

Employee privacy notice (GDPR compliant)
Last Modified
Previously modified

A privacy notice can be used as part of a data protection compliance system and explains how you use data. This version is to be used for your employees; a separate version exists for job applicants.

Download

Job applicant privacy notice (GDPR compliant)

Job applicant privacy notice (GDPR compliant)

Job applicant privacy notice (GDPR compliant)
Last Modified
Previously modified

A privacy notice can be used as part of a data protection compliance system and explains how you use data. This version is to be used for your job applicants; a separate version exists for employees.

Confidentiality agreement (GDPR compliant)

Confidentiality agreement (GDPR compliant)

This agreement outlines that an employee agrees to keep secret and not at any time either during their employment or after its termination, use, communicate or reveal to any person for the employee’s or any other person’s benefit, any trade secret or confidential information concerning the business, finances or organisation of the Company or any Associated Company, their systems, techniques or know how of their suppliers or customers. The agreement also clarifies the type of information which is considered
Last Modified

This agreement outlines that an employee agrees to keep secret and not at any time either during their employment or after its termination, use, communicate or reveal to any person for the employee’s or any other person’s benefit, any trade secret or confidential information concerning the business, finances or organisation of the Company or any Associated Company, their systems, techniques or know how of their suppliers or customers. The agreement clarifies the type of information which is considered to be secret and confidential. It also requires the individual to familiarise themselves with the provisions of data protection rules under GDPR.

Policy

Data protection policy (GDPR compliant)

Data protection policy (GDPR compliant)

Data protection policy (GDPR compliant)
Last Modified

This policy outlines the Company's approach to protecting data in the workplace in accordance with GDPR, including data protection procedures, access to data,  disclosures and security of data, how the Company will notify a breach, training and the identification of officers responsible for data protection.

 

Monitoring policy (GDPR compliant)

Monitoring policy (GDPR compliant)

Monitoring policy (GDPR compliant)
Last Modified

This policy, containing references to GDPR, outlines the Company's approach to monitoring in the workplace, including CCTV, email, internet, telephone and related data protection issues. The policy outlines the extent of monitoring in the workplace and states that the Company may use information gathered through employee monitoring as the basis for disciplinary action against employees. It also allows for identification of the Company's Data Protection Officer.

Freedom of Information Act compliance policy

Freedom of Information Act compliance policy

Freedom of Information Act compliance policy
Last Modified
Previously modified

The Freedom of Information Act gives a legal right for any person to ask an organisation within the public sector for access to information that it holds. This policy outlines the procedure to be followed when someone asks for information under the Act.

Letter

Letter asking employee to pay a fee relating to subject access request (GDPR compliant)

Letter asking employee to pay a fee relating to subject access request (GDPR compliant)

Letter asking an employee to pay a fee relating to subject access (GDPR compliant)
Last Modified

Use this letter to request the payment of a fee on receipt of a subject access request. Please note under the GDPR a reasonable fee can only be requested where the request is manifestly unfounded, excessive, repetitive or further requests of the same information are made.

 

Letter in response to a subject access request (GDPR compliant)

Letter in response to a subject access request (GDPR compliant)

Letter in response to a subject access request (GDPR compliant)
Last Modified

Use this letter to acknowledge an employee’s request to see a copy of the personal data held by their employer and enclose a copy and description of the data held, for what purposes it has been used, who has seen it, how it was obtained, how long it will be kept for, and the employee's rights in relation to the data. There are also options to explain why data has been withheld.

 

Letter informing of extension of time to comply with subject access request (GDPR compliant)

Letter informing of extension of time to comply with subject access request (GDPR compliant)

Letter informing of extension of time to comply with subject access request (GDPR compliant)
Last Modified

Use this letter to inform the employee of the reason why the time to comply with the subject access request has been extended. Please note under the GDPR the time to comply can only be extended to three months from the date of receipt of the request.

Letter to the doctor of an employee requesting medical report

Letter to the doctor of an employee requesting medical report

Letter to the doctor of an employee requesting medical report
Last Modified
Previously modified

This letter requests a medical report from an employee's doctor or consultant on an employee's current state of health and a prognosis of future health for a specified period. It must be accompanied by a signed medical consent form and by a copy of the employee’s job description.

Contract clauses