Please ensure Javascript is enabled for purposes of website accessibility

People

Big things are happening at Ogier. Change is embedded in everything we do. It is redefining our talent, our ways of working, our platforms of delivery, our culture.

Expertise

Services

We have the expertise to handle the most demanding transactions. Our commercial understanding and experience of working with leading financial institutions, professional advisers and regulatory bodies means we add real value to clients’ businesses.

View all services

Business Services Team

View all Business Services Team

Sectors

Our sector approach relies on smart collaboration between teams who have a deep understanding of related businesses and industry dynamics. The specific combination of our highly informed experts helps our clients to see around corners.

View all sectors

Locations

Ogier provides practical advice on BVI, Cayman Islands, Guernsey, Irish, Jersey and Luxembourg law through our global network of offices across the Asian, Caribbean and European timezones. Ogier is the only firm to advise on this unique combination of laws.

News and insights

Keep up to date with industry insights, analysis and reviews. Find out about the work of our expert teams and subscribe to receive our newsletters straight to your inbox.

Fresh thinking, sharper opinion.

About us

We get straight to the point, managing complexity to get to the essentials. Our global network of offices covers every time zone. 

No Content Set
Exception:
Website.Models.ViewModels.Components.General.Banners.BannerComponentVm

GDPR: what your HR team needs to do now (1)

Insight

17 July 2018

Guernsey, London

ON THIS PAGE
Save as PDF

Having survived the weeks leading up to 25 May and the deluge of emails from firms you've never even heard of about your mailing preferences, you'd be forgiven for thinking that your GDPR troubles are over.

For HR professionals, there are actually far more significant points to consider.

The GDPR – a convenient shorthand for reform of data privacy laws to bring them into the age of the internet - has mostly been presented as a digital exercise about data cleansing, firewalls and obtaining and recording consent.

But it has also changed the balance of power between employees and employers in a pretty fundamental way.

Under the new rules, employers can no longer compel their employees to produce and hand over their health records, no matter what pre-GDPR clauses exist in their contracts. The laws enacted in both Jersey and Guernsey to enable the GDPR specifically say that contractual terms requiring employees to disclose a health record, or even part of any health record, will be void from the point that the GDPR entered into force.

Over and above that, employees now also have a legitimate expectation that they can keep their personal health information private, and that employers will respect their privacy. Where health information is being collected, employees should know what is held, who is holding it, where it is held and the reasons why it is held.

This changes the picture in a number of ways, but most significantly in terms of dismissals on the grounds of ill-health, particularly as the onus is on the employer, not the employee, to obtain evidence to support a decision to dismiss.

In the same way, an employer's right to demand evidence of criminal records has been swept away (except under certain circumstances). Employers are no longer able to demand evidence of criminal records unless the employee (or the position being recruited for) fits a defined list of categories including healthcare, schools, caring for the vulnerable, financial services or jobs working in the legal sector.

A further fresh challenge is in respect of employees' social media accounts – it has been fairly common practice in all kinds of businesses for employees to share, like and comment on their employers' social media content. But monitoring of employees' social media activity will inevitably lead to processing and/or storing personal data about them – and therefore it has to be conducted in accordance with the GDPR, which means that employers will have to demonstrate lawful grounds for processing that data.

GDPR is a game-changer for the employee/employer relationship in many ways, not just those outlined above – and it's about much more than email marketing databases.

If you haven't carried out full GDPR audits and updated existing policies, procedures and employment contracts so that areas of risk can be identified and rectified, then that work needs to start. Above all, employers will need to be able to clearly demonstrate that they are acting in accordance with the new policies.

Rachel DeSanges is Head of Employment in Guernsey. She advises employers and employees on contentious employment matters, and has acted on many high profile cases before the Guernsey Employment Tribunal. Rachel – a former president of the Guernsey International Legal Association and Vice President of the Guernsey Chamber of Commerce – also advises on non-contentious matters including due diligence processes in mergers and acquisitions, immigration and relocation issues, subject access requests and director's duties.

About Ogier

Ogier is a professional services firm with the knowledge and expertise to handle the most demanding and complex transactions and provide expert, efficient and cost-effective services to all our clients. We regularly win awards for the quality of our client service, our work and our people.

Disclaimer

This client briefing has been prepared for clients and professional associates of Ogier. The information and expressions of opinion which it contains are not intended to be a comprehensive study or to provide legal advice and should not be treated as a substitute for specific advice concerning individual situations.

Regulatory information can be found under Legal Notice

No Content Set
Exception:
Website.Models.ViewModels.Blocks.SiteBlocks.CookiePolicySiteBlockVm