GDPR challenges payroll professionals

4 Min Read

Payroll offices will need to review and update their data protection policies by May 25, deadline day for GDPR. Any updated GDPR policies should be clearly communicated to all employees.

So check with current software providers, data processors and contractors to see what they are doing to comply with the new legislation. You will likely need to update or amend certain contracts you have with your third-party contractors or vendors.

The GDPR makes every business (payroll client) responsible for any third parties (payroll bureaus) who process personal data on their behalf. Under the terms of GDPR, bureaus will need to manage and store their client’s information in a more secure environment. It will also be important to keep a record of how you are storing this information and for what purpose should you ever be audited or reported.

Contract between payroll bureaus and payroll clients

If a bureau is audited, they may need to provide certain information to prove their GDPR compliance such as:

Agreed Contract: There needs to be a written contract or letter of engagement in place between payroll bureaus and the client that covers GDPR. This contract would outline that employee’s personal data will be provided to the bureau to process the payroll for the business. This does not mean a payroll client can simply hand over their employee’s personal data to a bureau and then cast a blind eye. The payroll client must ensure the bureau is also compliant with the GDPR.

Fulfilling the Contract: To fulfil the contract, payroll bureaus will hold certain business information, such as their employer PAYE reference number and their bank account details, which is all legitimately viable under GDPR. Payroll bureaus need to hold this personal information in order to fulfil the agreed contract of processing the client’s payroll.

Legitimate Reason: Every business needs to provide a legitimate reason as to why they hold an individual’s personal details. Payroll bureaus are deemed as processors as they process their client’s and their employee’s personal data. Payroll bureaus hold client and employee payroll information to complete the payroll, such as employee National Insurance numbers, tax codes, dates of birth, employee salaries and employer national insurance details. Under the GDPR legislation, this is classified as a valid and legitimate reason to hold this kind of personal payroll information.

Payroll data and GDPR free guide

What you need to know about consent, emailing payslips, and your legal obligation

Payroll bureaus are legally obliged to protect payroll information on behalf of their clients. The guide will uncover the ins and outs of the impact of GDPR on your payroll processing, highlighting the biggest areas of concern including emailing payslips, employee consent and your legal obligation.

Download Guide

Free CPD Webinar: GDPR for Payroll Bureaus

Payroll bureaus process large amounts of personal data, not least in relation to their customers, their customers’ employees, and their own employees. Consequently, the GDPR will impact most if not all areas of the business and the impact it will have cannot be overstated. In this CPD accredited webinar, we will peel back the legislation to outline clearly:

Agenda

  • What is GDPR and why is it being implemented?
  • Why employers need to take it seriously
  • How it will impact payroll bureaus
  • How to prepare for GDPR
  • How we are working to help you

Register here

BrightPay will be at Accountex 2018 on May 23-24, stand 430.

 

Share This Article