Skip to content

UK GDPR and Data Protection Act 2018

Data protection in the United Kingdom is governed by the UK GDPR (the UK’s retained version of the EU General Data Protection Regulation) together with the Data Protection Act 2018 (DPA 2018). They govern how organisations collect, store, use, and share personal data about identifiable individuals. They apply to SteadyOn in two specific contexts:

  1. Incident data — when you record information about an injured person, a witness, or an incident reporter
  2. Health and wellbeing data — when you handle medical information about workers as part of injury management or return to work

The regulator is the Information Commissioner’s Office (ICO).

This page is not legal advice. For specific compliance questions, consult a qualified data-protection or legal advisor.


There is no small-business exemption in UK data-protection law. If you process personal data as an organisation — and almost every employer does — UK GDPR and the DPA 2018 apply to you, regardless of size. (Many organisations also need to pay a data-protection fee to the ICO and register, unless an exemption applies.)

You will usually be the controller of the personal data in your SteadyOn workspace — the organisation that determines why and how it is processed. SteadyOn (as the platform) acts as a processor on your behalf for the data you store in it.


When data-protection obligations apply to your SteadyOn data

Section titled “When data-protection obligations apply to your SteadyOn data”

Not everything in SteadyOn is personal data. Hazard records (a wet floor in a warehouse) and inspection records (a checklist of fire-extinguisher locations) typically do not involve personal data. The obligations become relevant when:

ScenarioWhy data-protection obligations apply
Recording the name of an injured worker in an incident reportPersonal data about an identifiable individual
Recording the nature of an injury (e.g. broken arm, mental-health crisis)Special category data (health data) — extra protection
Recording witness names and statementsPersonal data about a third party
Public incident reports that include names or contact detailsPersonal data collected from non-employees
Investigation notes that identify individualsPersonal data held by the organisation
Training records linked to named workersPersonal data about employees

Special category data — health information (Article 9)

Section titled “Special category data — health information (Article 9)”

Information about a person’s health is special category data under Article 9 of the UK GDPR, and attracts a higher standard of protection. In a safety context this includes:

  • The nature of a worker’s injury (specific diagnosis, body part affected)
  • Medical treatment received
  • Mental-health information
  • Return-to-work restrictions or medical certifications

You may only process special category data where you can rely on both a lawful basis (Article 6) and a separate Article 9 condition. For workplace H&S the most relevant Article 9 condition is usually that processing is necessary for carrying out obligations in the field of employment, social security, and social protection law (which UK GDPR Article 9 read with the DPA 2018 permits), backed by an appropriate policy document as the DPA 2018 requires. Explicit consent is rarely the right basis for employee data because of the imbalance of power.

Practical guidance for SteadyOn:

  • Record only what is necessary for the H&S purpose (e.g. “worker sustained a soft-tissue injury to the lower back” is sufficient for most safety purposes; a full medical diagnosis is not).
  • All members of an organisation can see incident records by default — keep sensitive medical detail out of the description, and use attachments for separately stored medical certificates only when essential.
  • Do not include special category data in exported reports that will be shared broadly.

You must have a lawful basis before you process personal data. For H&S records the basis is usually legal obligation (you are required to keep certain records under HSWA 1974, RIDDOR, and the Management Regulations) or legitimate interests. As above, special category data also needs an Article 9 condition.

Practical guidance: You generally do not need an individual’s consent to record an incident that affects them — you are meeting a legal obligation. Do not ask for consent you do not need, as consent can be withdrawn.


Collect only the personal data that is adequate, relevant, and limited to what is necessary for the purpose — here, managing the safety incident and meeting your obligations under H&S law.

Practical guidance: In an incident report, you need enough information to understand what happened, investigate root causes, and take corrective action. You do not need an injured person’s unrelated personal or medical history.


Individuals have the right to be informed about how their personal data is used. You should have a privacy notice and, when collecting data, tell people who you are, why you are collecting it, what it will be used for, and who else might see it.

Practical guidance: If you collect information from injured workers or public reporters, include a short privacy notice explaining that the information is collected for health and safety purposes, will be held by your organisation, and may be shared with the HSE, your insurer, or the emergency services where required. Consider adding this to your public incident reporting link.


You must process personal data securely, using appropriate technical and organisational measures to protect it against unauthorised access, loss, or damage.

SteadyOn’s role: SteadyOn stores all data in SOC 2 compliant cloud infrastructure. Access is scoped to the organisation — only members of your org can see your data. Within an org, every member can see all hazard, incident, action, and inspection records by default; if you need stricter separation, run multiple organisations.

Your role: Ensure your SteadyOn workspace is properly secured — promptly remove members who have left, review the Members tab regularly, and use the Audit metadata and Log tab to keep a record of access.


Storage limitation (don’t keep it longer than necessary)

Section titled “Storage limitation (don’t keep it longer than necessary)”

Personal data must not be kept for longer than is necessary for the purpose it was collected for.

Balancing act — H&S law vs data protection: H&S law requires you to keep certain records to demonstrate compliance — RIDDOR records must be kept for at least three years, and some health-monitoring and exposure records for much longer (up to 40 years for certain hazardous-substance exposures). These legal retention requirements give you a lawful reason to keep the records while they apply, overriding the general “minimise” principle. Once the retention period has passed, records containing personal data should be reviewed and securely deleted or anonymised if no longer needed.


Individuals have a number of rights under UK GDPR, including the right to access the personal data you hold about them (a “subject access request”), to have inaccurate data rectified, and — in some circumstances — to have data erased or its processing restricted.

Practical guidance: Be prepared to provide a worker with the incident or training records you hold about them, and to correct errors. SteadyOn’s records are easy to locate and export for this purpose. Note that the right to erasure does not override your legal retention obligations.


If you suffer a personal data breach that is likely to result in a risk to people’s rights and freedoms, you must notify the ICO without undue delay and within 72 hours of becoming aware of it. Where the breach is likely to result in a high risk, you must also tell the affected individuals.

A breach could occur if, for example, SteadyOn incident records containing personal or health data were accessed by an unauthorised person, or were mistakenly shared outside the organisation.

Your obligations: Conduct regular user-access reviews in SteadyOn. Remove users who are no longer part of the organisation promptly. Be cautious when exporting or sharing reports that contain personally identifiable information.


Public incident reporting and data protection

Section titled “Public incident reporting and data protection”

The public incident reporting link allows anyone to report an incident without a SteadyOn account. People who use this link may provide personal data (their name, contact details, details of what happened to them or others).

Obligations:

  • Display a privacy notice on the public report form (or in your organisation’s public-facing privacy notice) explaining how reports are handled
  • Use the information only for the purpose of managing the safety event
  • Do not share the reporter’s personal details more widely than necessary

ObligationHow to meet it
Have a lawful basisRely on legal obligation / legitimate interests for H&S records
Special category (health) dataUse the employment Article 9 condition; record the minimum necessary
Collect only what is necessaryLimit incident descriptions to H&S-relevant information
Be transparentInclude a privacy notice in public incident reporting
Secure the dataUse SteadyOn roles to restrict access; remove departed users
Don’t over-shareBe selective with exported reports containing personal data
Honour data-subject rightsLocate and export a person’s records on request; correct errors
Retain appropriatelyFollow RIDDOR / health-monitoring retention rules; delete after they expire
Notify breachesReport qualifying breaches to the ICO within 72 hours