Last updated: 5 September 2026
TL;DR: Almost every practice has a client privacy notice on the website and nothing at all for staff. A staff privacy notice tells your team what you hold, why, on what lawful basis, how long you keep it and what rights they have. It is one page, it is required, and the moment you most need it is the week somebody resigns or raises a grievance.

A staff privacy notice is the document that satisfies your transparency obligation to your own employees. Under UK GDPR you have to tell people what personal data you hold about them and why, at the point you start holding it. Your clients get that in the client privacy notice. Your staff need their own.
It is not a policy about how staff should handle client data, which is a different document that most practices do have. It is about the practice as an employer holding data about the people who work for it.
Because nobody asks for a staff privacy notice until somebody does, and by then the request usually arrives attached to something else. A grievance. A resignation. A subject access request from a person who has already instructed a solicitor.
At that point the absence of a staff privacy notice is not the serious problem, but it is the one that signals to everybody involved that the practice has not thought about this at all. It is a small document that does a lot of work for its size.
That is the whole of a staff privacy notice. It fits on one side if you write it plainly.
Downloaded staff privacy notice templates frequently say the practice processes data “with your consent”. In an employment relationship that is usually the wrong basis and it creates a problem rather than solving one.
Consent has to be freely given, and the imbalance of power between an employer and an employee means it rarely is. It can also be withdrawn at any time. A staff privacy notice that relies on consent for payroll is a notice that collapses the first time somebody withdraws it, and you cannot stop paying them.
Use the bases that actually fit:
Reserve consent for the genuinely optional, such as a photograph on your website, where somebody can say no without any consequence at all.

Sickness records, fit notes, occupational health reports and anything relating to a disability are special category data, and a staff privacy notice has to say so, and a veterinary practice holds a lot of it, because pregnancy risk assessments and physical injury are routine in this work.
Three practical rules. Keep it separately from the general personnel file. Restrict who can open it. And share only what the recipient actually needs, which means a rota manager is told what adjustments apply and is not told the diagnosis.
A staff privacy notice that says records are kept as long as necessary and points at nothing is not really telling anybody anything. It needs a schedule behind it, and one line on that schedule is no longer a choice.
Since 6 April 2026 annual leave records must be kept for six years, including how holiday pay was calculated and any payment in lieu on termination, and failing to keep them is a criminal offence. That sits alongside the periods that genuinely are your decision, such as how long a personnel file is kept after somebody leaves, and you should be able to explain why you chose each one.
The second failure is having a schedule and never deleting anything. Keeping everything for ever is not caution, it is a breach of the storage limitation principle. Diarise one pass through leaver files a year.
The work is not the writing, it is the finding out. Do it in this order and a staff privacy notice takes one sitting.
Step one is where practices are surprised, usually by how much sits in email and how much a single manager keeps on their own phone. Gov.uk has a short overview of data protection obligations, and our guide to digital staff records covers where to put things once you know what you have.

A staff privacy notice goes out of date quietly. New software gets adopted, a new provider is appointed, a legal duty changes, and the notice still describes the practice as it was two years ago.
Version it and date it, put a review date on the document itself, and add two triggers to the review: any new system that holds staff data, and any new organisation you start sharing it with. Reissue when it changes materially rather than filing the new version silently.
The 2026 example is a good one. The annual leave record-keeping duty added a six year retention obligation that most notices written before that year do not mention at all.
A staff privacy notice will be wrong if you write it from the personnel file alone, because that is not where most of it is.
Nobody needs to stop using the group chat. Everybody needs to write in it as though it will one day be read out, because the week after a grievance it very often is.

No. A staff privacy notice is information you provide, not an agreement you obtain. Asking for a signature can imply you are relying on consent, which is usually the wrong basis. Record that it was issued and when.
Issue the staff privacy notice with the contract, to every new starter, and once to everybody currently employed. Job applicants should get a short version at the point they apply, because you are holding their data from that moment.
Yes. UK GDPR has no small employer exemption, and the transparency obligation applies from the first employee. The document is short and the work is a single afternoon.
That is a subject access request and you have one calendar month to respond, extendable by up to two further months for a complex request if you tell them within the first month. It does not have to be in writing or use those words.
You can operate CCTV for a stated purpose, and staff must be told about it in the staff privacy notice. Keep footage only as long as that purpose requires, and never use it for covert monitoring of employees without taking advice first.
A staff privacy notice is a one page document that takes an afternoon and quietly improves your position in every difficult conversation you will ever have about records. It is also the cheapest compliance win available to a practice, which is a rare combination.
Our free staff data protection pack has the notice, a personnel file index, a retention schedule and a subject access request procedure. The Information Commissioner’s Office publishes plain English employment guidance if you want to check anything, and our guide to GDPR and staff records covers what to keep and for how long.
Read next: Data Breach in a Veterinary Practice.
Contracts, rotas, holiday, a difficult conversation. Tell us what you are dealing with and we will come back within one working day. Nothing to sign up to.
Got it. We will come back to you within one working day. If you do not see a reply, please check your spam folder.