Protecting People and Paperwork: The HR Side of Data Protection
Data protection has always been a core part of good HR practice but with new complaint‑handling rules now in force, it’s more important than ever for employers to understand their responsibilities when handling personal data, especially when providing references. Recent updates have put a spotlight on how organisations collect, store, and share information about both current and former employees.
For small businesses, this can feel like yet another layer of complexity. But with a clear understanding of the rules, you can protect your organisation, support your people, and stay confidently compliant.
Why references fall under UK GDPR
When you provide a reference, you’re processing personal data, often detailed information about someone’s performance, conduct, or employment history. Under UK GDPR, that makes you a data controller, responsible for ensuring the information is handled lawfully and fairly.
Before you share any information, you must identify a lawful basis for processing. In most cases, this will be consent from the individual requesting the reference. Although consent is not usually relied upon in employment relationships due to the imbalance of power, it is considered valid for references as long as it is unambiguous and freely given.
Employers have two straightforward options for recording consent:
During an exit interview - ask the departing employee for permission to retain and use their information for future references, and record this clearly.
Via the prospective employer - request evidence (often an email) showing the individual has agreed to the reference being provided.
Whichever route you use, keep a copy of the consent so you can demonstrate your lawful basis if needed. If you’re ever unsure whether consent has been given, you must check with the individual, ideally in writing.
Did you know that references are exempt from subject access requests? This means neither the employer giving the reference nor the employer receiving it can be compelled to disclose it under a data access request. However, this exemption doesn’t remove your duty of care.
You also have a duty of care when writing a reference and it must be accurate, fair and not misleading. Failing to meet this could expose you to civil claims. There is also a risk of discrimination claims if the information you include relates to protected characteristics or is presented in a way that could disadvantage the individual unfairly.
So the majority of employers now prefer to give brief factual references only confirming job title, dates of employment, and sometimes eligibility for rehire.
From 19 June 2026, organisations must follow a new complaint‑handling framework for data protection issues including complaints relating to references.
You must now:
Offer a clear way for individuals to raise data protection complaints
Acknowledge complaints within 30 days
Handle them without undue delay
If you don’t yet have a procedure in place, this is the moment to act.
What this means for small businesses
For many small employers, references are a routine part of recruitment but they’re also a potential risk area if not handled carefully.
Here’s what good practice looks like:
Keep your reference process simple and consistent
Document consent clearly
Stick to factual, fair information
Avoid commentary that could be misinterpreted
Put a complaint‑handling process in place
Train managers on what they can and cannot say
Clear processes protect your business, support fair recruitment, and build trust with both current and former employees.





Comments