---
title: "Employee Health Data and UK GDPR: Where Do Your People's Health Records Actually Live?"
description: Fit notes, occupational health referrals and wellbeing surveys are special category data. What UK GDPR expects of employers, and how ISO 27701 helps.
---

[Insights | Cybercontrols](https://www.cybercontrols.io/blog)

# [Employee Health Data and UK GDPR: Where Do Your People's Health Records Actually Live?](https://www.cybercontrols.io/blog/employee-health-data-and-uk-gdpr-where-do-your-peoples-health-records-actually-live)

 Written by [Marius van Aswegen](https://www.cybercontrols.io/blog/author/marius-van-aswegen) | Oct 8, 2026, 10:05:36 AM

**In short:** World Mental Health Day falls on 10 October, and many employers will mark it by encouraging people to talk about how they are. That is the right instinct. It also means organisations now hold more information about their people's health, including mental health, than ever before. Under UK GDPR that information is special category data. It needs a clear legal basis, tight access and a retention period you actually apply. ISO 27701 is the management system that turns those duties into everyday practice.

## The question we ask in almost every HR audit

When an audit reaches HR, we ask a simple question: where do your people's health records actually live? Not the policy. The records.

The answer is rarely where the policy says. A fit note scanned into a shared drive that half the office can open. An occupational health referral sitting in a line manager's inbox. A wellbeing survey export in a spreadsheet called "final v3" on someone's desktop. Nobody intended any of it. It is simply what happens when well-meaning people handle sensitive information without a system around them.

## Why health data needs extra care

Health information, physical or mental, is special category data under UK GDPR. The ICO's guidance on workers' health information describes it as some of the most sensitive personal information an employer processes. In practice, that brings four obligations.

### 1. A lawful basis and an Article 9 condition

You need an Article 6 lawful basis and, separately, an Article 9 condition, identified and documented before you collect anything. For employers the most common condition is employment, social security and social protection law, which also needs a matching condition in Schedule 1 of the Data Protection Act 2018. The ICO points out that this condition covers legal obligations, such as statutory sick pay, rather than purely contractual ones, such as an enhanced company sick pay scheme.

Consent is rarely the answer. Because of the imbalance of power between employer and worker, the ICO advises employers to avoid relying on it.

### 2. An appropriate policy document

If you rely on the employment condition, you need an appropriate policy document explaining how you comply with the data protection principles and how long you keep the data. The ICO publishes a template. Many organisations that process health data every week have never written one.

### 3. Need-to-know access

Managers can see what they need to manage attendance and fitness for work. They rarely need the diagnosis. The ICO distinguishes between absence records, which give a reason such as sickness, and sickness records, which reveal the condition, and prefers absence records wherever they will do the job. Its own example is a workstation adjustment: the facilities team learns what needs to change, not why. Keep medical detail separate, restrict who can open it, and do not share it beyond the people who need it for their role.

### 4. Retention you actually apply

Keep health information only as long as you need it, record your retention periods, and then delete or anonymise it. A retention schedule that nobody runs is not a retention schedule.

The ICO also expects a data protection impact assessment before any processing that is likely to result in high risk, and given how sensitive health data is, its guidance says employers should carry one out.

## Wellbeing initiatives deserve the same thought

Wellbeing apps, pulse surveys and employee assistance programmes are good things. But a survey that asks how people are coping, linked to their names, may well reveal health information. Before you launch one, decide whether you really need to know who said what. Anonymous or aggregated results often tell you everything you need at a fraction of the risk. Where a third party runs the programme, check what it collects, where the data is held, and whether anything ever comes back to you in a form that identifies individuals.

## Where ISO 27701 fits

[ISO 27701](https://www.cybercontrols.io/it-compliance/iso-27701) is the international standard for privacy information management. The 2025 edition stands on its own, so it can be certified without ISO 27001, or run alongside [ISO 27001](https://www.cybercontrols.io/it-compliance/iso-27001-certification) as one integrated system. It turns good intentions about health data into a system you can evidence:

- **A record of what you process and why,** including the HR and occupational health processing that often gets left out.
- **Privacy risk assessed as risk to the person,** not only to the business, which is exactly the right lens for health information.
- **Controls chosen and justified** in a Statement of Applicability of their own, covering access, retention and sharing.
- **Internal audit and management review,** so somebody actually checks that the fit notes are no longer in the shared drive.

Our [ISO 27701:2025 transition guide](https://www.cybercontrols.io/blog/iso-27701-2025-transition-guide-what-changed-and-what-to-do-next) explains what changed in the new edition.

## Five checks for this week

1. **Find the records.** Search shared drives and HR mailboxes for fit notes, occupational health reports and sickness forms.
2. **Check the basis.** Is the lawful basis and Article 9 condition for each use written down, and do you have an appropriate policy document?
3. **Test the access.** List everyone who can open sickness records. Does each of them need to?
4. **Separate absence from sickness.** Can your managers do their job with absence information alone?
5. **Apply retention.** Pick one category of health data and confirm when it is deleted, and by whom.

## Frequently asked questions

### Is mental health information treated differently from physical health information?

No. Under UK GDPR, health data covers both physical and mental health, and both are special category data.

### Can we rely on employees' consent to hold their health information?

Usually not. The ICO advises employers to avoid consent because of the power imbalance in employment. The employment condition, the legal claims condition or a substantial public interest condition is more often appropriate.

### Do we need ISO 27701 to comply with UK GDPR?

No. UK GDPR applies whether or not you hold a certificate. ISO 27701 gives you a structured way to meet those obligations, and to show customers, regulators and your own people that you do.

### Is the ICO's guidance changing?

The ICO notes that its employment guidance is under review following the Data (Use and Access) Act 2025, so check the current version before relying on any detail.

Looking after people's wellbeing includes looking after their data. Cybercontrols holds ISO 27001 and ISO 42001 certification ourselves, and we help organisations build privacy management that stands up to scrutiny. [Book a free scoping call](https://www.cybercontrols.io/contact) or email hello@cybercontrols.io.

[View full post](https://www.cybercontrols.io/blog/employee-health-data-and-uk-gdpr-where-do-your-peoples-health-records-actually-live)

```json
{
  "@context" : "http://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Marius van Aswegen"
  },
  "dateModified" : "2026-10-08T10:10:39.767Z",
  "datePublished" : "2026-10-08T10:05:36Z",
  "headline" : "Employee Health Data and UK GDPR: Where Do Your People's Health Records Actually Live?",
  "image" : {
    "@type" : "ImageObject",
    "height" : 800,
    "url" : "https://144611087.fs1.hubspotusercontent-eu1.net/hubfs/144611087/Cybercontrols%20blog%20-%20Employee%20health%20data%20-%20header%201600x800.png",
    "width" : 1600
  },
  "mainEntityOfPage" : "https://www.cybercontrols.io/blog/employee-health-data-and-uk-gdpr-where-do-your-peoples-health-records-actually-live",
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "height" : 60,
      "url" : "/hs/hsstatic/content_shared_assets/static-1.4092/img/default-amp-logo.png",
      "width" : 60
    },
    "name" : "Insights"
  }
}
```