Legal
GDPR and data protection
What UK GDPR asks of you as an employer keeping staff records, and how CubeHR helps you meet it.
Last updated . Issued by Cube Systems Limited, trading as CubeHR, of Unit 11, Olney Business Park, Osier Way, Olney, Buckinghamshire, MK46 5FP. Registered in England and Wales, company number 17220899. ICO registration number ZC216972.
1Who this page is for
This page is for employers who use CubeHR, or are thinking about it. It explains what UK GDPR asks of you when you keep staff records, and which parts of CubeHR help. It is general information, not legal advice for your situation.
Our binding commitments to you are in our data processing terms and our terms of service. If anything here seems to differ from them, those documents apply.
2Controller and processor
Your organisation is the controller of the staff data you keep in CubeHR. You decide what is recorded and why, and you are answerable to your staff and to the ICO for it. Cube Systems Limited is your processor: we store and process the data only on your instructions, under Article 28 terms that are part of every subscription.
For our own records, such as your account contacts and invoices, we are the controller, as our privacy policy explains. We are registered with the Information Commissioner’s Office under number ZC216972.
3Your lawful basis for staff records
Every use of staff data needs a lawful basis. For most HR records it is one of these:
- Contract: paying people, managing holiday and working hours, and the other things you need to do under an employment contract.
- Legal obligation: right to work checks, statutory sick pay, working time records, pension auto-enrolment and what HMRC requires.
- Legitimate interests: running reviews, issuing equipment and keeping the organisation secure, where your interest is not outweighed by your staff’s rights.
Consent is rarely the right basis for employees, because the balance of power between employer and employee means it is hard for consent to be freely given. Keep it for things staff can refuse without any consequence, such as a photo on their profile.
4Special category and criminal offence data
Some HR records need more care than the rest:
- health information, in sickness absence, fit notes, occupational health referrals and adjustments;
- equality monitoring data, such as ethnicity or disability, if you choose to collect it; and
- DBS check results, which are criminal offence data.
For these you need a condition under Article 9 or Article 10 of UK GDPR as well as a lawful basis. For most employment purposes that condition is in Schedule 1 of the Data Protection Act 2018, and it usually means keeping an appropriate policy document that says how you handle the data and how long you keep it.
In CubeHR, use permissions so that only HR and the managers who need it can see these records. Document copies and sensitive fields are encrypted at rest, and access to compliance records is recorded in the audit trail.
5Telling your staff
Your staff privacy notice should explain what you record about people, why, who can see it and how long you keep it. If you use CubeHR, it should cover what you record there, including location at clock-in if you turn on geofencing, and say that your HR system is provided by a UK processor. Our sub-processors page lists who else handles the data.
If you plan to use location features or any other monitoring, a data protection impact assessment is a good idea before you start. We will give you the information about CubeHR that it needs.
6Requests from your staff
Staff can ask to see, correct or delete their data, and you normally have one month to answer. Subject access requests are the most common, and the hardest when records are spread across inboxes and spreadsheets.
With everything in one place, CubeHR lets your administrators find, export, correct and delete an individual’s records. Self-service also lets staff see and update much of their own record, which cuts down the requests you receive. If one of your staff contacts us directly, we will pass the request to you and help you answer it.
7How long to keep records
Keep staff data only as long as you need it. Some records have periods set by law or by HMRC, and others depend on your own risk of a claim. Decide your periods, write them down, and apply them to leavers as well as current staff.
CubeHR lets you set retention rules and delete records when they are no longer needed, and you can export everything at any time. When your subscription ends, we delete your data on the timetable in our data processing terms.
8Security and breaches
CubeHR data is held in the United Kingdom, encrypted in transit and, for sensitive fields and documents, at rest. Sign-in supports two-step verification, and changes to personnel records are recorded in the audit trail. The full list of measures is in our data processing terms.
If a personal data breach affects your staff records, we will tell you without undue delay and within 48 hours, with the details you need. As controller, you decide whether to report it to the ICO, which normally has to happen within 72 hours of you becoming aware of it, and whether to tell the people affected.
9Contact
Questions about data protection in CubeHR, security questionnaires and requests for our data processing terms go to hello@cube-hr.co.uk, or by post to Cube Systems Limited, Unit 11, Olney Business Park, Osier Way, Olney, Buckinghamshire, MK46 5FP. We aim to respond within five working days.
Other policies
Questions about any of this? Email hello@cube-hr.co.uk, call 01234 672 617 or write to us at the address above.