The new date protection regulations which came into force on the 25th May 2018 through the General Data Protection Regulations (GDPR) and implemented in the UK through the new Data Protection Act 2018.
There are new rights for people to access the information companies hold about them, obligations for better data management for businesses, and a new regime of fines which are substantial for breaches. Individuals, organisations, and companies that are either 'controllers' or 'processors' of personal data will be covered.
Both personal data and sensitive personal data are covered. Personal data can be anything that allows a living person to be directly or indirectly identified. This may be a name, an address, or even an IP address. It includes automated personal data and can also encompass “pseudonymised” (eg encrypted data) if a person can be identified from it. Sensitive data includes sexual orientation, political views etc.
The idea is to enable people to have easier access to the data companies hold about them, a new fines regime and a clear responsibility for organisations to obtain the consent of people they collect information about. Applying for data used to cost £10 but is now free.
There's also a requirement for businesses to obtain consent to process data in some situations. When an organisation is relying on consent to lawfully use a person's information they have to clearly explain that consent is being given and there has to be a "positive opt-in". A default consent would not be lawful.
In immigration cases, data is collected for a variety of reasons and at a number of sources. Most of the information is collected in an official capacity and is lawful. However there are particular instances in which employers are required by the Home Office particularly in Tiers 2 and 5 particularly, to retain information in the form of CVs, application forms, references etc., about candidates who apply for positions but who are ultimately not selected.
An employer will need specific consent to pass this information to the Home Office, remembering that consent can be withheld at any time. What if the candidate refuses? Can you legitimately refuse to provide this information to the Home Office? And could the Home Office refuse to accept this ? When I contacted the Home Office about this, they pointed out that they are covered by exemptions and provided a link.
Regulation 23 provides that Member States can introduce exemptions from the GDPR’s transparency obligations and individual rights, but only where the restriction respects the essence of the individual’s fundamental rights and freedoms and is a necessary and proportionate measure in a democratic society to safeguard:
- national security;
- defence;
- public security;
- the prevention, investigation, detection or prosecution of criminal offences;
- other important public interests, in particular economic or financial interests, including budgetary and taxation matters, public health and security;
- the protection of judicial independence and proceedings;
- breaches of ethics in regulated professions;
- monitoring, inspection or regulatory functions connected to the exercise of official authority regarding security, defence, other important public interests or crime/ethics prevention;
- the protection of the individual, or the rights and freedoms of others; or
- the enforcement of civil law matters.
This is a broad sweep of exemptions and the question will be whether it is proportionate to pass on this information to the Home Office. The employer is a collector of data and is ultimately responsible for making the decision about disclosing information and will bear the brunt of any breaches. And, in these circumstances, by requiring this personal information could the Home Office be encouraging unlawful use of data?
These are questions that need to be carefully considered and as part of that the Home Office have to make their position of collecting data very clear.

