New legislation published implementing aspects of the Good Work Plan



Following the recent publication of its “Good Work Plan”, the government has now laid before Parliament three statutory instruments to implement certain aspects of that Plan.

The Employment Rights (Employment Particulars and Paid Annual Leave) (Amendment) Regulations 2018 and the draft Employment Rights (Miscellaneous Amendments) Regulations 2019 will both come into force for the most part on 6 April 2020. They amend the Employment Rights Act 1996 by extending the right to receive a written statement of employment particulars to workers (this right currently only applies to employees) and providing that the written statement must be given on or before the first day of employment, rather than within two months of employment starting. The regulations also add to the mandatory information that must be given in the written statement.

In addition, the regulations increase the reference period for determining an average week’s pay where the worker receives variable remuneration for the purposes of calculating holiday pay from twelve to 52 weeks (or the number of complete weeks for which the worker has been employed if less), lower the threshold required for a valid request to set up information and consultation arrangements from 10% to 2% of employees and increase the maximum limit of an employment tribunal penalty for an aggravated breach of employment law from £5,000 to £20,000 (this latter provision will come into force on 6 April 2019).

The draft Agency Workers (Amendment) Regulations 2019 are also due to come into force on 6 April 2020 and they will amend the Agency Workers Regulations 2010 to repeal the “Swedish derogation” for agency workers and ban the use of this type of contract to avoid agency workers’ equal pay rights. The Swedish derogation currently allows employment businesses to avoid giving agency workers pay equality with comparable direct recruits if they have an employment contract which gives them a right to pay between assignments.



Security guidance on encryption and passwor



The Information Commissioner’s Office (ICO) has published updated security guidance on encryption and on passwords in online services under the GDPR.

The GDPR requires data controllers to implement appropriate technical and organisational measures to ensure they process personal data securely. Article 32 of the GDPR includes encryption as an example of an appropriate technical measure. The guidance suggests that:

  • Encryption is a widely-available measure with relatively low costs of implementation.
  • Data controllers should have an encryption policy in place that governs how and when they implement encryption, and they should also train their staff in the use and importance of encryption.
  • When storing or transmitting personal data, data controllers should use encryption and ensure that their encryption solution meets current standards.
  • Data controllers should nevertheless be aware of the residual risks of encryption and have steps in place to address these.

The ICO stresses that where unencrypted data is lost or destroyed, it is possible that it will pursue regulatory action.

Although the GDPR does not say anything specific about passwords, data controllers are required to process personal data securely by means of appropriate technical and organisational measures and passwords are a commonly-used means of protecting access to systems that process personal data. The guidance suggests that:

  • Any password setup implemented must be appropriate to the particular circumstances of the processing.
  • Data controllers should consider whether there are any better alternatives to using passwords.
  • Any password system that is deployed must protect against theft of stored passwords and “brute-force” or guessing attacks.
  • There are a number of additional considerations data controllers need to take account of when designing their password system, such as the use of an appropriate hashing algorithm to store the passwords, protecting the means by which users enter their passwords, defending against common attacks and the use of two-factor authentication.
  • Data controllers must not forget about their password system once established; they should carry out periodic reviews.


Autumn Budget 2018 – Minimum wage increases



The Chancellor used his Budget speech to confirm that increased National Minimum Wage (NMW) and National Living Wage (NLW) rates are due to come into effect on 1 April 2019.

The NLW first came into effect on 1 April 2016, and is the minimum hourly rate that must be paid to those aged 25 or over. From 1 April 2019 the National Living Wage will increase by 38p to £8.21. This represents an increase of almost 5%.

The hourly rate of the NMW (for 21-24 year olds) will increase to £7.70 (a rise of 32p). The rates for 18-20 year olds will increase to £6.15 (a rise of 25p) and the rate for workers above the school leaving age but under 18 will increase to £4.35 (a rise of 15p). The NMW rate for apprentices increases by 20p to £3.90.

The new rates mirror the recommendations made by the Low Pay Commission (LPC) which have been accepted in full by the government. The independent Low Pay Commission (LPC) was established following the National Minimum Wage Act 1998 to advise the government on the NMW. It is made up of representatives from all sides of industry. The increases will come into effect from April 2019, subject to Parliamentary approval.



Processing of criminal records data in recruitment



Unlock, a charity that assists people with criminal convictions, has published new guidance to help employers ensure that their policies and practices on collecting criminal records data during recruitment are compliant with the GDPR and the Data Protection Act 2018. The guidance includes contributions from the Information Commissioner’s Office.

The guidance emphasises that collecting criminal records data during the initial job application stage is unlikely to be compliant with data protection laws as it’s unlikely to be necessary; employers must be able to demonstrate that processing criminal records data is necessary at whatever stage they decide to collect it. The guidance also states that employers should have a policy in place on collecting personal data, which includes a section on the processing of criminal records data. That policy should clearly identify the purpose of collecting criminal records data and the lawful basis for collecting it, explain how long this data will be retained and who it will be shared with and set out job applicants’ legal rights in relation to their information.

Finally, Unlock recommends employers follow a three-stage process to determine if, when and how they should ask about criminal records:

  1. Define the purpose of collecting criminal records data.
  2. Identify a lawful basis for processing and meet a condition of processing.
  3. Set out their privacy policy and data subject rights.