Do employers need to amend employees' contracts to comply with the General Data Protection Regulation (GDPR)?
No, it will not be necessary for employers to amend the contracts of existing employees to comply with the General Data Protection Regulation (GDPR). However, they should issue a new privacy notice to employees, providing information on the processing of their personal data and overriding any invalid data protection clauses in the contract. The GDPR specifies the information that the employer must provide in the privacy notice (also known as an information notice or fair processing notice). The information includes the purposes for which the employer will process the employee's personal data, the legal bases for the processing, information about the retention period and information about the employee's rights as a data subject.
The GDPR will come into effect on 25 May 2018.