Skip to main content
Stage 3 · Your progress

0/4 steps

HR Consultancy Launch Programme · Stage 3 of 10

Protect Your Data

Get the data protection you legally need in place, then take anything specific to your own processing from the ICO.

≈ 1 day hands-on · 4 steps

How long

2–4 days

You’ll have

Registered with the ICO, your special-category data mapped, the basics in place, and your status confirmed per client

Steps

4 steps

Resources

2 resources

  1. 01 Step 01

    Step 01

    Register with the ICO and pay the data protection fee

    Processing personal data for business purposes is a legal duty to register with the ICO and pay the fee, unless you are exempt. An HR consultant handling employee data is not exempt.

    Do it yourself

    • Run the ICO self-assessment to confirm you must pay. You will.
    • Pay the data protection fee. A new solo consultancy is almost always Tier 1, currently £52 (ten or fewer staff, or turnover under £632k), with Tier 2 at £78 and Tier 3 at £3,763. The fee rose on 17 February 2025, so confirm the current figure on ico.org.uk.
    • Diarise the annual renewal so your registration never lapses.
    • Put your ICO registration reference where clients can see it, like your site footer or privacy notice.

    Common mistake · Assuming a sole trader or micro-business is exempt. If you process personal data for business purposes, you are not.

    Time~30–45 minutes Cost£52/yr at Tier 1 (confirm the current fee on ico.org.uk) DifficultyEasy
  2. 02 Step 02

    Step 02

    Map the special-category data you’ll hold and set retention

    HR files routinely contain Article 9 special-category data (health, disability, trade-union membership, ethnicity, religion, sexual orientation) and criminal-offence data (Article 10, DPA 2018 s.10), all of which need extra justification.

    Do it yourself

    • List where special-category data enters your work: sickness and occupational-health records, disability adjustments, disciplinary and grievance files, investigation notes, and DBS or criminal-record data.
    • Note that you and your client need an Article 6 lawful basis and an Article 9 condition, commonly the employment condition. In the UK many conditions require an appropriate policy document under Schedule 1 of the DPA 2018, so confirm which fit your processing with the ICO.
    • Set a retention period per data type and a deletion routine, tied to why you hold the data and any statutory minimum.
    • Apply data minimisation: collect only what the task needs.

    Common mistake · Treating all HR data the same, and holding disciplinary or health files indefinitely with no retention rule.

    Time~3–5 hours CostFree DifficultyHard

    Resource for this step

    PDF

    Special-category data map

    Map the sensitive HR data you hold against its lawful condition, retention and deletion. Seeded with worked examples. A signpost, not advice.

  3. 03 Step 03

    Step 03

    Put your data-protection basics in place

    You need the everyday hygiene UK GDPR expects of anyone holding sensitive data: a notice, security, a breach process, and a way to handle access requests.

    Do it yourself

    • Draft a privacy notice for your own business, covering staff, clients and prospects, and publish it on your website.
    • Set your security basics: encrypted devices, MFA, strong passwords, access control, and secure storage for client files.
    • Write a simple personal-data-breach process: what counts, how you would assess it, and the duty to report a reportable breach to the ICO within 72 hours.
    • Know that a subject access request carries a one-month response duty, and follow the ICO’s guidance for handling one.

    Common mistake · Emailing sensitive HR files as unencrypted attachments over personal webmail.

    Time~3–4 hours CostFree (some tools may add cost in the Tech Stack module) DifficultyMedium

    Resource for this step

    CHECKLIST

    Data protection starter pack

    The everyday hygiene UK GDPR expects: a privacy notice, security basics, a breach process, and subject-access-request readiness. A signpost, not advice.

  4. 04 Step 04

    Step 04

    Confirm controller or processor per client, and put a written data agreement in place

    Your data-protection role changes the contract you need with each client, and getting it wrong leaves both parties non-compliant. This is a legal-status question, so confirm it rather than assign it to yourself.

    Do it yourself

    • Understand the split: the client employer is the controller of its HR data, and when you process it strictly on their documented instructions you are likely a processor, needing an Article 28 written data-processing agreement.
    • Understand the nuance: when you exercise independent professional judgement in the advice you give, you may be a controller in your own right, like a solicitor or accountant. Many HR consultants are a mix across engagements.
    • Put a written data agreement in place with every client, covering security, sub-processing, breach reporting and audit.
    • Confirm the status against the ICO’s controller and processor guidance rather than assuming it, because a mishandling by you can make both you and the client non-compliant.

    Common mistake · Assuming you are “just a processor” for everything (or ignoring the question), and having no written data agreement with clients.

    Time~2–4 hours CostFree DifficultyHard

What you’ll have after this stage

  • Your ICO registration confirmed and the data protection fee paid
  • A map of the special-category data you hold, with retention and deletion rules
  • A privacy notice, security basics, and a personal-data-breach process in place
  • A subject-access-request process you can follow
  • Controller-or-processor status confirmed, and a written data agreement per client

A law-firm website, wireframed

Click through the pages to see the shape a credible firm site takes — structure first, words and design later.

yourfirm.co.uk/

Grey blocks are placeholders — they show where things go, not how they look.