
Data protection policy
- Quick and easy to complete
- Provides a framework for your data processing
- UK GDPR compliant
A data protection policy is an internal document providing a framework for how your organisation will comply with its data protection obligations when handling personal data. This includes what expectations you have of your staff when they are processing personal data on your behalf and how different legal obligations should be complied with. It might also be referred to as a data security policy, a data protection statement or a staff data protection policy.
Whenever your business processes personal data, you are under strict legal requirements to put in place appropriate measures to ensure that your processing is compliant with data protection law at all times. This template will help you to set out what obligations your staff are under when they are processing any personal data for your business.
This policy could form part of your staff handbook or it could be provided as a standalone policy. If you’re looking to produce an entire staff handbook, use our template staff handbook instead.
Alternatively you can purchase this policy as part of the Data protection policy toolkit or the Remote working and cybersecurity toolkit.
Q&A
When should I use this document?
If your business employs staff, you should use this template to put in place a data protection policy setting out your expectations on them in circumstances where they process any personal data on your behalf. You should make sure this policy is in place before they first process any personal data for you.
Make sure you keep this policy updated if there are any changes to the way in which your business processes personal data.
You should make sure this policy is easily available to your staff. You could include it in your staff handbook if you have one.
What does this document cover?
This template policy provides a framework for staff about how they should ensure that data protection is complied with. This includes:
-
what training will be provided;
-
details about the general data protection principles staff should adhere to;
-
the circumstances in which staff may process personal data and what their responsibilities are when doing so;
-
how staff should deal with subject access requests and personal data breaches; and
-
in what circumstances a DPIA may need to be carried out.
-
Why do I need this document?
Businesses processing personal data are under strict legal requirements to put in place appropriate measures to ensure that data is processed in accordance with data protection law at all times. This includes putting in place appropriate policies, which will help to demonstrate compliance.
This template policy will help you to comply with your data protection obligations by providing a framework under which your staff must operate when they are processing any personal data on your behalf. This includes what duties they are under and what security measures they must adhere to. It will also help them to understand who they should refer to if any issues arise.
Where can I find out more?
For guidance about the data protection obligations your business is under whenever it processes personal data, see our Q&A on data protection obligations.
If you want to find out about other HR policies you should put in place, see HR policies.
If you want to produce an entire staff handbook, which includes a copy of this policy, see our template staff handbook.
If you are looking for a privacy notice to let your staff know how you process their personal data, use our template staff privacy notice instead.
Related Toolkits
Data breach toolkit
Personal data breach policy
Template personal data breach register
Notice of a personal data breach (affected individuals)
- How-to guide: Data breach toolkit
Data protection policy toolkit
- How-to guide: Data protection policy toolkit
Privacy policy
Cookie policy
Data protection policy
Staff privacy notice
Staff recruitment privacy notice
Data subject request policy
Data protection impact assessment policy
Personal data breach policy
Data subject request toolkit
- How-to guide: Data subject request toolkit
Data subject request policy
Subject access request form
Data transfer request form
Request form to correct inaccurate or incomplete data
Request form to delete data
Request form to stop using data
Letter acknowledging receipt of data subject request (and requesting verification of ID)
Letter asking for further information about a data subject request
Letter confirming no data held in response to data subject request
Letter explaining reasons for extension of time to respond to data subject requests
Letter to third party seeking consent to disclosure of information
Subject access request response template
Letter confirming that data processing has ceased
Letter explaining why data processing will continue
Letter confirming that data has been corrected
Letter explaining why data will not be corrected
Letter to party who has been supplied with data to confirm its correction
Letter confirming that data has been deleted
Letter explaining why data will not be deleted
Letter to party who has been supplied data to confirm its deletion
Letter supplying data in response to a portability request
Letter supplying data to a third party in response to a portability request
Small claims toolkit
- How-to guide: Small claims toolkit
Letter before action
Witness statement
Letter of non-attendance for small claims hearing