Why GDPR Matters for Security Companies
The General Data Protection Regulation (GDPR), as retained in UK law following Brexit as the UK GDPR, places significant obligations on any organisation that collects, stores, or processes personal data. For security companies, this is not a peripheral concern — it sits at the heart of your operations. Vetting records, DBS check results, employment histories, biometric data, CCTV footage, and incident reports all constitute personal data under the UK GDPR, and all must be handled in accordance with the regulation's requirements.
The consequences of non-compliance are serious. The Information Commissioner's Office (ICO) has the power to issue fines of up to £17.5 million or 4% of global annual turnover — whichever is higher — for the most serious breaches. Beyond financial penalties, a data breach can cause significant reputational damage and erode the trust of clients and employees alike.
The Six Lawful Bases for Processing
Under the UK GDPR, every instance of personal data processing must have a lawful basis. For security companies, the most relevant lawful bases are as follows.
Legal Obligation
Many of the data processing activities carried out by security companies are required by law. Conducting right to work checks, maintaining payroll records, and carrying out DBS checks are all legal requirements. Processing personal data for these purposes is lawful under the legal obligation basis.
Legitimate Interests
The legitimate interests basis allows organisations to process personal data where it is necessary for a legitimate business purpose and where that purpose is not overridden by the individual's rights and interests. For security companies, this basis may apply to activities such as monitoring employee performance, conducting background checks beyond the minimum legal requirements, and maintaining records for business continuity purposes.
Consent
Consent is a valid lawful basis, but it is important to understand that consent under the UK GDPR must be freely given, specific, informed, and unambiguous. In an employment context, consent is generally not the appropriate basis for processing employee data, because the power imbalance between employer and employee means that consent cannot truly be freely given. Consent is more appropriate for optional activities, such as sending marketing communications.
Special Category Data in Security Operations
The UK GDPR places additional restrictions on the processing of "special category" data — a defined list of particularly sensitive personal information. For security companies, the most relevant categories are criminal conviction data (including DBS check results), biometric data (such as fingerprints used for access control), and health data (such as medical information relevant to fitness for duty).
Processing special category data requires both a lawful basis under Article 6 of the UK GDPR and an additional condition under Article 9. For employment-related processing, the most relevant condition is that the processing is necessary for the purposes of carrying out obligations in the field of employment law.
Data Retention
One of the most common GDPR compliance failures in the security industry is retaining personal data for longer than necessary. The UK GDPR requires that personal data is kept only for as long as it is needed for the purpose for which it was collected. Security companies should have a documented data retention policy that specifies how long different categories of data are retained and the process for securely deleting data when the retention period expires.
As a general guide, employment records should be retained for six years after the end of employment (to cover potential employment tribunal claims), DBS check results should be retained for the duration of employment plus a reasonable period thereafter, and CCTV footage should be retained for no longer than 31 days unless it is needed for an ongoing investigation.
Data Subject Rights
Employees and former employees have a range of rights under the UK GDPR, including the right to access their personal data (a Subject Access Request), the right to have inaccurate data corrected, and the right to have data deleted in certain circumstances. Security companies must have processes in place to respond to these requests within the statutory timeframe of one month.
How WFC Verify Supports GDPR Compliance
WFC Verify was designed with data protection principles built in from the ground up. All personal data is stored securely with encryption at rest and in transit. Access controls ensure that sensitive data — such as DBS check results and vetting records — is accessible only to authorised personnel. The platform maintains a full audit trail of all data access and modifications, supporting your ability to demonstrate compliance to the ICO.
Automated data retention policies can be configured within the platform, ensuring that data is flagged for deletion when its retention period expires. Subject Access Requests can be fulfilled quickly and completely, because all employee data is held in a single, searchable system rather than scattered across email inboxes and spreadsheets.