0/4
HR Consultancy Launch Programme · Stage 3 of 10
Protect Your Data
Get the data protection you legally need in place, then take anything specific to your own processing from the ICO.
How long
2–4 days
You’ll have
Registered with the ICO, your special-category data mapped, the basics in place, and your status confirmed per client
Steps
4 steps
Resources
2 resources
-
01 Step 01
Step 01
Register with the ICO and pay the data protection fee
Processing personal data for business purposes is a legal duty to register with the ICO and pay the fee, unless you are exempt. An HR consultant handling employee data is not exempt.
Do it yourself
- Run the ICO self-assessment to confirm you must pay. You will.
- Pay the data protection fee. A new solo consultancy is almost always Tier 1, currently £52 (ten or fewer staff, or turnover under £632k), with Tier 2 at £78 and Tier 3 at £3,763. The fee rose on 17 February 2025, so confirm the current figure on ico.org.uk.
- Diarise the annual renewal so your registration never lapses.
- Put your ICO registration reference where clients can see it, like your site footer or privacy notice.
Common mistake · Assuming a sole trader or micro-business is exempt. If you process personal data for business purposes, you are not.
Time~30–45 minutes Cost£52/yr at Tier 1 (confirm the current fee on ico.org.uk) DifficultyEasy -
02 Step 02
Step 02
Map the special-category data you’ll hold and set retention
HR files routinely contain Article 9 special-category data (health, disability, trade-union membership, ethnicity, religion, sexual orientation) and criminal-offence data (Article 10, DPA 2018 s.10), all of which need extra justification.
Do it yourself
- List where special-category data enters your work: sickness and occupational-health records, disability adjustments, disciplinary and grievance files, investigation notes, and DBS or criminal-record data.
- Note that you and your client need an Article 6 lawful basis and an Article 9 condition, commonly the employment condition. In the UK many conditions require an appropriate policy document under Schedule 1 of the DPA 2018, so confirm which fit your processing with the ICO.
- Set a retention period per data type and a deletion routine, tied to why you hold the data and any statutory minimum.
- Apply data minimisation: collect only what the task needs.
Common mistake · Treating all HR data the same, and holding disciplinary or health files indefinitely with no retention rule.
Time~3–5 hours CostFree DifficultyHardResource for this step
PDFSpecial-category data map
Map the sensitive HR data you hold against its lawful condition, retention and deletion. Seeded with worked examples. A signpost, not advice.
-
03 Step 03
Step 03
Put your data-protection basics in place
You need the everyday hygiene UK GDPR expects of anyone holding sensitive data: a notice, security, a breach process, and a way to handle access requests.
Do it yourself
- Draft a privacy notice for your own business, covering staff, clients and prospects, and publish it on your website.
- Set your security basics: encrypted devices, MFA, strong passwords, access control, and secure storage for client files.
- Write a simple personal-data-breach process: what counts, how you would assess it, and the duty to report a reportable breach to the ICO within 72 hours.
- Know that a subject access request carries a one-month response duty, and follow the ICO’s guidance for handling one.
Common mistake · Emailing sensitive HR files as unencrypted attachments over personal webmail.
Time~3–4 hours CostFree (some tools may add cost in the Tech Stack module) DifficultyMediumResource for this step
CHECKLISTData protection starter pack
The everyday hygiene UK GDPR expects: a privacy notice, security basics, a breach process, and subject-access-request readiness. A signpost, not advice.
-
04 Step 04
Step 04
Confirm controller or processor per client, and put a written data agreement in place
Your data-protection role changes the contract you need with each client, and getting it wrong leaves both parties non-compliant. This is a legal-status question, so confirm it rather than assign it to yourself.
Do it yourself
- Understand the split: the client employer is the controller of its HR data, and when you process it strictly on their documented instructions you are likely a processor, needing an Article 28 written data-processing agreement.
- Understand the nuance: when you exercise independent professional judgement in the advice you give, you may be a controller in your own right, like a solicitor or accountant. Many HR consultants are a mix across engagements.
- Put a written data agreement in place with every client, covering security, sub-processing, breach reporting and audit.
- Confirm the status against the ICO’s controller and processor guidance rather than assuming it, because a mishandling by you can make both you and the client non-compliant.
Common mistake · Assuming you are “just a processor” for everything (or ignoring the question), and having no written data agreement with clients.
Time~2–4 hours CostFree DifficultyHard
What you’ll have after this stage
- Your ICO registration confirmed and the data protection fee paid
- A map of the special-category data you hold, with retention and deletion rules
- A privacy notice, security basics, and a personal-data-breach process in place
- A subject-access-request process you can follow
- Controller-or-processor status confirmed, and a written data agreement per client