Privacy notice

Colleague Privacy Notice

Page Content

This privacy notice tells you what to expect when Heathrow as your employer (specifically either LHR Airports Ltd, LHR Business Support Centre Ltd or Heathrow Express Operating Company Ltd) collects personal data from you as an employee.   Heathrow is committed to protecting your personal information. Whenever you provide such information we are legally obliged to use your information in line with all applicable laws concerning the protection of personal data, including the General Data Protection Regulation (GDPR).  

What information will we collect about you? To support your employment with us we may collect the following information about you:

  • Name
  • Contact details e.g. email address, contact numbers, address
  • Family information e.g. next of kin, marital status, emergency contact details
  • Date of birth
  • Diversity information, e.g. ethnicity, gender
  • Financial information e.g. bank details
  • Education and qualifications
  • Medical information e.g. Sickness information, medical fitness including substance testing
  • Performance and training information e.g. performance rating, training records, internal assessment results
  • Investigation, disciplinary and grievance information (if relevant)
  • Employment information e.g. employee number, remuneration, details of benefits for you and dependants/beneficiaries, grade
  • Records of your use of our IT, telephone and other systems 
  • Employment and travel history, where required to complete counter terrorism or criminal record checks
  • Security, Location and Access information captured by our access and security control systems
  • Any other personal information that you chose to include on your C.V
  • Your image, e.g. for the production of mandatory ID pass
  • Service Transaction Details e.g. Car Parking records
  • Lifestyle, social and any other sensitive personal information provided by you in Heathrow systems e.g. when you make posts in Yammer
  • Travel information (where bookings have been made to fulfil employment duties)
  • Incident records e.g. when contacting Helpdesk and providing details to the incident management team

How will Heathrow use the information it collects about me? Heathrow will use your personal data to meet our obligations to you as an employee, to meet legal and statutory requirements, to support your ongoing employment with us, and to meet other occasional legitimate interests.  The specific reasons for collecting and processing your data fall into the following broad categories:

  • General Management through the use of records relating to your career history both with us and with previous employers, including, amongst other reasons,  verifying and providing references, confirming your right to work in the UK,  training records, assessments and other performance measures and, where appropriate, disciplinary and grievance records
  • Internal and external recruitment activity
  • Wellbeing, including absence recording, occupational health booking, support, reasonable adjustments and referral systems
  • Supporting our diversity and other colleague support initiatives.
  • Provision of benefits including, where applicable, pensions, health care, and other employee benefit schemes administered by 3rd parties
  • Statutory and legal requirements, including transfer of data to HMRC, Criminal Record Check, background checks and Counter Terrorism Check certification, court ordered disclosures, dealing with investigations and defence of litigation.
  • Safety and security of our colleagues and customers
  • General administration, including general communication and travel administration
  • Payroll administration, including remuneration, rostering, managing all types of leave, application of allowances and calculation of bonus payments, where applicable
  • Final settlement of outstanding balances for ex-employees
  • Measuring business performance, including employee engagement and satisfaction, and company diversity
  • IT Account generation, maintenance and managemen
  • IT Account Access controls

The legal justifications for collecting and using your personal data are that:

  • It is necessary for the performance of our employment contract with you OR
  • It is necessary for compliance with our legal obligations OR
  • It is necessary for the purposes of occupational medicine OR
  • Where we have a legitimate interest OR
  • You have given consent for a specific usage of your data

Your information may be handled and used by the following recipients in order to meet the above obligations:

  • Your employing entity
  • Other entities in the Heathrow “group”
  • Childcare voucher scheme administrator
  • Company health care providers
  • Occupational health service providers
  • Pension providers
  • Other relevant benefits scheme administrators/providers
  • Relevant courts and court appointed persons/entities
  • United Kingdom Security Vetting
  • CAA
  • Corporate travel agents
  • Relevant government departments including HMRC
  • Trade associations and professional bodies
  • Debt collection agencies
  • Employee Database hosting company
  • Career and development system providers
  • Talent development and assessment providers
  • External employee satisfaction benchmarking providers
  • Brokers and other third-party insurance professionals
  • Corporate clothing providers
  • Corporate paper communication providers
  • Third party IT service suppliers

Please be aware that some of your information will be transferred and processed overseas outside the UK and/or European Economic Area. That processing will only occur if the relevant country to which your personal information is to be transferred to ensures an adequate level of protection for such information, we have put in place appropriate safeguards to protect such information, and the transfer of such information is necessary for one of the relevant reasons set out under the GDPR or you explicitly consent to the transfer of such information.  

How long will Heathrow keep my information? Your information will be retained  whilst you are employed by Heathrow group entities.  If you leave employment, your information will be retained for a limited period in line with statutory requirements. Your information will be retained in a secure environment and access to it will be restricted according to the 'need to know' principle.  

What rights do I have over my personal data? Under the GDPR, you have the right to:

  • Access your personal data by making a subject access request
  • Rectification, erasure or restriction of your information where this is justified
  • Object to or restrict the processing of your information where this is justified
  • Data portability

To exercise your rights please contact the Heathrow Data Protection Officer using the following contact details:

By email to:

privacy@heathrow.com  

By post to: Heathrow Data Protection Officer Heathrow Airport Ltd The Compass Centre Nelson Road Hounslow, Middlesex TW6 2GW  

What if I find your response unsatisfactory?

Should you find our response unsatisfactory, you have the right to lodge a complaint with the supervisory authority – the Independent Commissioner’s Office (ICO). You can find more information on the ICO website at https://ico.org.uk/concerns/ regarding the complaints process.  

Privacy & Cookies 

Cookies are small text files which are stored on your computer when you visit certain web pages. At Heathrow we use cookies to understand how our sites are used which helps us to improve your overall online experience. Some of the cookies we use are necessary for some of our sites to work whilst other cookies are used to provide tailored advertising by trusted third parties. The cookies we and our third parties place on your computer do not collect personally identifiable information like your name, address or payment details. To find out more about cookies, visit www.aboutcookies.org  

The different types of cookies we use

Heathrow use the following categories of cookies on our websites:  

Strictly necessary – These cookies are essential for certain features of our websites to work for example when you make payments for car parking. These cookies do not record identifiable personal information and we do not need your consent to place these cookies on your device. Without these cookies some services you have asked for cannot be provided.  

Performance – These cookies are used to collect anonymous information about how you use our websites. This information is used to help us improve our websites and understand how effective our adverts are. In some case we use trusted third parties to collect this information for us but they only use the information for the purposes explained. By using our websites, you agree that we can place these types of cookies on your device.  

Functionality - These cookies are used to provide services or remember settings to enhance your visit for example text size or other preferences. The information these cookies collect is anonymous and does not enable us to track your browsing activity on other websites. By using our websites, you agree that we can place these types of cookies on your device.  

Targeting and Advertising – These cookies are used by trusted third parties to deliver adverts more relevant to you and your interests. They are also used to limit the number of times you see an advertisement as well as help measure the effectiveness of the advertising campaign. Information contained in these cookies is anonymous and doesn't contain your personal information. To find out more about cookies used for targeting and advertising follow www.youronlinechoices.com and www.networkadvertising.org or contact us at website_feedback@baa.com for further information about the trusted third parties we use.  

Managing cookies If you'd prefer to restrict, block or delete cookies from Heathrow and our third-party advertisers, or any other website, you can use your browser to do this. Each browser is different, so check the 'Help' menu of your particular browser to learn how to change your cookie preferences. If you choose to disable all cookies we cannot guarantee the performance of our websites and some features may not work as expected.  

Changes to this privacy notice We will keep this privacy notice under regular review and we will place any updates here. At the start of this privacy notice we will tell you when it was last updated.