Skip to content

HSE inspections up 47% - HSE carried out over 13,200 workplace inspections in 2024/25.

Health and Safety Records and Data Protection: 7 Questions

A
Arinite Health & Safety Consultants
August 16, 2026
8 min read
Health and Safety Records and Data Protection: 7 Questions

Health and safety runs on records. Accident reports, occupational health referrals, display screen assessments, stress assessments, evacuation plans, return-to-work notes, training histories.

Almost all of it is information about identifiable people, and much of it is information about their health, which is the most tightly controlled category there is. Yet in most organisations these records sit outside the data protection regime entirely: held on shared drives, emailed between managers, retained forever because nobody decided otherwise, and never mentioned in a privacy notice.

That is an odd position for a firm that advises clients on data protection, or one whose own regulator expects rigorous information governance. Seven questions resolve it.

1. Is health and safety data special category data?

Much of it is, and that changes what you need before you collect it.

Under the UK GDPR, data concerning health falls within the special categories, which are prohibited from processing unless a specific condition applies in addition to a lawful basis. The ICO's guidance on special category data sets out the conditions.

The routine ones in this context are processing necessary for obligations in the field of employment law, and processing necessary for occupational medicine purposes or assessment of working capacity. Both require an appropriate policy document to be in place under domestic law, which is a specific artefact rather than a general privacy policy.

The practical test is simple. Ask whoever owns data protection in your organisation whether the appropriate policy document exists and whether it covers health and safety processing. In many firms the answer is that it exists and covers HR, and nobody extended it.

The most common error, and it usually comes from good intentions.

Organisations often ask employees to consent to health and safety processing, reasoning that it is respectful. In an employment relationship consent is difficult to rely on because it must be freely given, and an employee who feels unable to refuse has not given it. Worse, consent can be withdrawn, which would leave you unable to hold records you are legally required to keep.

For processing that flows from a statutory duty, the employment law condition is generally the better route. Consent still has a place for genuinely optional things, such as a voluntary wellbeing programme, where refusal has no consequence. The ICO's employment guidance covers the distinction.

3. Who can actually see it?

The question that produces the most immediate findings when anyone looks.

An accident record contains details of an injury to a named person. A display screen assessment may record a health condition. An evacuation plan necessarily records that someone needs assistance. A stress assessment may record a great deal.

The principle is that access should be limited to those who need it for a defined purpose, which is narrower than "the health and safety inbox" and much narrower than a shared drive folder inherited by successive office managers. Two specific patterns are worth checking: whether line managers can see clinical detail when they only need to know the adjustment required, and whether historical records remain visible to people whose role no longer requires them.

This connects directly to how personal emergency evacuation plans are handled. The people who need to act in an evacuation need to know what to do, not why.

4. How long do you keep it, and who decided?

Retention is where health and safety and data protection genuinely pull in opposite directions, and the resolution is not to pick a side.

Some records must be kept for defined periods. Records of reportable incidents must be retained under regulation 12 of the RIDDOR regulations. Health records associated with health surveillance under the COSHH regime are kept for a very long period, reflecting the latency of some occupational disease. Other jurisdictions go further: France requires successive versions of its mandatory risk assessment document to be retained for forty years.

Against that, the storage limitation principle requires that personal data is not kept longer than necessary. The two are reconciled by having a retention schedule that states, for each record type, how long and why. What fails is having no schedule at all, because the default becomes indefinite retention with no justification, which satisfies neither regime.

Forty-year retention also raises a practical problem that most organisations have not thought about: whether the records will still be readable and findable in forty years, which a shared drive that migrates every few years will not deliver.

5. Does your privacy notice mention any of this?

The cheapest gap to close and among the most common.

Employee privacy notices typically describe HR processing thoroughly and health and safety processing not at all. If you collect accident data, occupational health information, workstation assessments or evacuation needs, employees should be told, including who it is shared with and how long it is held.

Where an external provider is involved, and for most organisations one is, the notice should reflect that, and the arrangement needs the appropriate contractual terms behind it.

6. Does monitoring change the analysis?

Yes, and this is where health and safety intentions can create data protection exposure.

Wellbeing platforms, fatigue tools, wearables, sensor-based occupancy monitoring and productivity systems all generate personal data, sometimes health data, usually at scale. Introducing them typically requires an assessment of the data protection impact before deployment, and the fact that the purpose is protective does not remove that requirement.

There is also a consultation dimension that runs in parallel. In several jurisdictions, introducing a system capable of monitoring behaviour or performance engages employee representation rights independently of data protection. A tool intended to protect people can therefore require both a data protection assessment and a consultation process, and organisations that discover this at rollout lose time they did not budget.

7. What happens when the records are in six countries?

The complication for groups, and the reason this is not purely a domestic question.

A single group register holding health data from entities in several countries involves transfers, differing national rules on employee data, and differing retention requirements that will not align. Some jurisdictions impose specific requirements on occupational health records that sit outside the general data protection framework entirely.

The answer is not to abandon the group view, because a group that cannot see its own compliance position has a worse problem. It is to design the register so that what crosses borders is what needs to: status, actions and dates rather than clinical detail. That distinction is what makes health and safety consultants and software work together properly, and it is worth settling before the system is built rather than after.

The seven, summarised

| Question | Weak position | Strong position | |---|---|---| | Special category | Not identified as such | Condition identified, policy document covers it | | Lawful basis | Consent relied on | Employment law condition, consent only where truly optional | | Access | Shared drive, broad inbox | Need-to-know, adjustment not diagnosis | | Retention | Kept indefinitely by default | Schedule stating period and reason per record type | | Transparency | Notice covers HR only | Notice covers safety processing and providers | | Monitoring tools | Deployed as a safety measure | Impact assessed and representatives consulted first | | Multi-country | Everything centralised | Status and actions cross borders, detail stays local |

The pattern is that none of this requires new infrastructure. It requires the health and safety function and the data protection function to have had one conversation, which in most organisations they have never had.

Where Arinite fits

Arinite builds health and safety arrangements that hold up to information governance scrutiny as well as regulatory scrutiny, which matters more in some sectors than others. We support 1,500+ businesses across 50+ countries and protect 100,000+ employees, with 95%+ client retention over 15+ years. Our health and safety consultants work extensively with legal, finance and banking and insurance organisations, where a data protection function already exists and generally has not been shown the safety records.

Where entities sit in several countries, our global health and safety consultants confirm what each jurisdiction requires to be recorded and retained, and our international health and safety consultants keep that current. Periodic health and safety audits then test whether records are complete, current and appropriately held rather than simply present.

If nobody in your organisation could say how long you keep accident records or why, a free gap analysis is the right place to start.

Share this article
A

Written by

Arinite Health & Safety Consultants

Health & Safety Expert at Arinite

Free Resources

Health & Safety Factsheets

Download our comprehensive library of expert guides, checklists, and templates.

Get Professional Help

Need Expert H&S Advice?

Our qualified consultants are ready to support your specific business needs.