Last updated: 17 July 2026
TL;DR: UK GDPR lets a veterinary practice keep the staff records it genuinely needs: personnel files, absence records, payroll, training and disciplinary notes. Most processing rests on contract, legal obligation or legitimate interests, not consent. Keep records only as long as needed, answer a staff subject access request within one month, restrict who can open files, and treat health information with extra care. This guide covers each GDPR staff records duty with ICO sources.

Practices are careful with client and patient data and oddly casual with their own team’s files. The same law covers both. This guide sets out what UK GDPR actually asks of you as an employer, calmly and with the ICO source for each point.
UK GDPR does not stop you keeping staff records. It asks you to keep the right ones, for a stated purpose, on a lawful basis, for no longer than needed, securely, and to be open with staff about what you hold. The ICO publishes employment records guidance that sets out each duty in plain terms.
The ICO’s guidance on collecting and keeping employment records lists the kinds of records an employer may need: personnel files, sickness and injury records, disciplinary and grievance records, training records, appraisals, payroll and pension information, interview notes, emails, references and equality information. A normal practice file is entirely lawful.
The same guidance draws one line worth underlining: you must identify the minimum information you need and not hold more, because holding more than you need is likely to breach the data minimisation principle. In other words, GDPR staff records questions start with why, not with what.
Staff must also be told what you hold and why. The ICO requires employers to give workers privacy information covering the purposes, the lawful basis, retention periods and who the information is shared with. A one page privacy notice in the staff handbook usually carries that duty.
Almost all staff records rest on one of three lawful bases: contract for pay and administration, legal obligation for tax, right to work and safety duties, and legitimate interests for routine management records. Consent rarely works, because the ICO says an employer’s position of power stops it being freely given.
The ICO’s guide to lawful basis is clear that no basis is better than another and that the right one depends on your purpose. For a practice: paying wages sits on contract, keeping PAYE and right to work records sits on legal obligation, and appraisal notes or next of kin details usually sit on legitimate interests.
On consent, the ICO’s employment records guidance says it plainly: as an employer you are generally in a position of power over your workers, they may feel they have no choice but to agree, and in those circumstances consent is not freely given. If a member of staff could not realistically say no, do not build the record on consent.
The practical rule is to pick the honest basis, write it down once in your privacy notice, and stop asking staff to sign consent forms for things you would keep anyway. A signature on the wrong basis protects nobody.
Only a few periods are fixed in law. PAYE records must be kept for 3 years from the end of the tax year, and right to work copies for 2 years after someone leaves. For most other records there is no statutory period: the ICO expects you to set, justify and follow your own retention schedule.
The storage limitation principle, in the ICO’s guide to storage limitation, says you must not keep personal data longer than you need it, you must be able to justify how long you keep it, and you need a policy setting standard retention periods wherever possible. It deliberately sets no universal number. Honest answer: for most of the personnel file, the law leaves the period to you.
The two verifiable statutory anchors are worth pinning down. HMRC requires PAYE records to be kept for 3 years from the end of the tax year they relate to, per GOV.UK guidance on PAYE record keeping. Right to work copies must be kept for the employment plus 2 years after the person stops working for you, per GOV.UK guidance on right to work checks.
For the rest, the ICO’s employment records guidance says different categories need different periods, warns against a one size fits all approach, and notes you may be able to delete some information as soon as employment ends. Clean, dated working records help here: a system like our clock in and out keeps hours records tidy, timestamped and easy to review or delete on schedule instead of living in old spreadsheets forever.

Not sure what is sitting in your staff files, or how long it has been there? Our free 30 minute HR health check includes a plain look at your GDPR staff records handling: what you hold, where it lives, who can open it and what should have been deleted. Book a slot and get straight answers.
Respond without delay and within one month of receiving the request, extendable by up to two further months if the request is complex or one of several, per ICO guidance for employers. Staff do not need to use a form or the words subject access. An email to any manager counts.
The ICO’s subject access request questions and answers for employers covers the employment specifics. The person is entitled to a copy of their personal information, where you got it, what you use it for and who you share it with. You can refuse only if a request is manifestly unfounded or manifestly excessive, and you must justify and document any exemption you rely on.
SARs from staff often arrive mid grievance or mid dispute, and the deadline runs regardless. The calm version of compliance is preparation: know where every record about a person lives, keep opinion out of file notes you would not want read aloud, and have one named person who owns the response.
Third party information needs care rather than panic. Where releasing someone’s file would reveal another person’s information, the ICO expects you to weigh whether it is reasonable to disclose without that person’s consent, considering confidentiality, the steps taken to seek consent and any refusal. Redaction, not refusal, is usually the answer.
The security principle requires measures appropriate to the harm a loss would cause. In practice that means staff files only openable by people authorised to see them, extra protection for health information, and records you can restore if they are lost. Role based access and locked storage cover most of it.
The ICO’s guide to data security frames the duty as appropriate technical and organisational measures, chosen against the risk. Its employment records guidance translates that for staff files: access limited to those authorised, managers seeing only what they need, and the ability to recover information that is accidentally lost, altered or destroyed.
Most GDPR staff records failures in small practices are mundane, not dramatic. A personnel folder on a shared drive every login can open. A disciplinary note emailed to the wrong branch. An ex manager whose account still works. Fixing those three patterns removes most of the real world risk.
Write the rules down as a short data protection policy staff actually see. Our hosted policy library keeps it current and records a dated acknowledgement from each person, so the practice can show not just that a policy existed but that the team knew it.
Health information is special category data, so you need a condition for processing on top of a lawful basis, and often an appropriate policy document. Confidential job references are exempt from subject access, whether you gave or received them. Both deserve tighter handling than the rest of the personnel file.
The ICO lists health among the special categories, alongside information such as ethnicity and trade union membership, and says you may only keep such records if you meet additional requirements. For employers the most relevant condition is employment, social security and social protection law, which often also requires an appropriate policy document. The ICO publishes dedicated guidance on information about workers’ health, covering sickness records, occupational health and medical information.
Practically: keep sickness and injury records separate from the general file, restrict them to the few people who genuinely need them, and collect only what the situation requires. A return to work conversation needs fitness for duties, not a diagnosis.
On references, the ICO’s SAR guidance for employers confirms that confidential references given or received for employment purposes are exempt from the right of access. Say in your privacy notice and policies whether the practice treats references as confidential, so nobody is surprised either way.

Yes. A subject access request entitles them to a copy of their personal information, where it came from, what it is used for and who it is shared with. You must respond without delay and within one month, extendable by up to two further months for complex or multiple requests, per the ICO.
Usually not, and consent is usually the wrong basis for employment records anyway. The ICO says consent is unlikely to be freely given where the employer holds a position of power. Contract, legal obligation and legitimate interests cover the normal personnel file, and they do not evaporate if someone changes their mind.
Keep PAYE records for 3 years from the end of the relevant tax year and right to work copies for 2 years after they leave, both per GOV.UK. For the rest there is no fixed statutory period: set periods per category in a retention schedule you can justify, then actually delete on schedule.
Yes. Health information is a special category under UK GDPR, so keeping sickness and injury records needs a condition for processing on top of a lawful basis, and careful security. Keep them separate from the general personnel file and visible only to the people who genuinely need them.
Not from you, if it is confidential. The ICO confirms confidential references given or received for employment purposes are exempt from subject access, and the exemption applies whether you provided the reference or received it. Make clear in your policies whether the practice treats references as confidential.
GDPR staff records are not a trap. Keep what you need and no more, on an honest lawful basis, behind sensible locks, for periods you can justify, and be ready to show a member of staff their file within a month. A practice that manages patient records to a clinical standard already has the habits; it just needs to point them at the staff files too.
If you want the gaps found before someone else finds them, start with our free HR health check, put your data protection rules in an acknowledged policy library, or browse the frequently asked questions practices bring us most often.
The Vet HR Team provides HR consultancy and white-labelled staff systems exclusively to UK veterinary practices.
—Leave your details and we'll get back to you, usually within a few hours.
Thanks! We've got your message and will be in touch shortly.