Subcontractors · Mandatory · Pre-Construction
GDPR Data Processing Consent
A consent form or privacy notice informing workers how their personal data will be processed, stored, and shared on the project.
Last reviewed: 29 March 2026 — This guide reflects UK law as of this date. UK GDPR / DPA 2018 remains current with no amendments enacted as of 29 March 2026. Next scheduled review: 29 March 2027.
| Legal basis | UK GDPR (retained EU law) + Data Protection Act 2018 |
| What data is collected | Names, contact details, NI numbers, passport/ID, health information, emergency contacts, financial/tax data. |
| Lawful bases | Contract (most onboarding data); legitimate interest (safety); explicit consent (health data). Consent is not always the appropriate basis. |
| Privacy notice | Workers must be provided with a privacy notice at the point of data collection covering who, what, why, retention, sharing, and rights. |
| Data subject rights | Access (SAR, 1 month response); rectification; erasure; restriction; portability; objection. |
1. GDPR in Subcontractor Onboarding — Getting the Basics Right
Subcontractor onboarding involves collecting significant volumes of personal data. UK GDPR requires all of this is processed on a lawful basis, workers are informed, and appropriate security protects the data. The GDPR consent form serves two purposes: captures explicit consent where needed and delivers the privacy notice.
Consent is not always the right lawful basis — using it where another basis applies can create unnecessary obligations
2. GDPR Consent / Privacy Notice — Content
The following table sets out the sections that a well-structured GDPR consent form and privacy notice should include.
| Section | What to include |
|---|---|
| Data controller | Organisation name, registered address, contact details, and Data Protection Officer (DPO) details where applicable. |
| Data collected | List of data categories: identity, contact, financial, health, qualifications, next of kin. |
| Purpose and legal basis | For each data category — why it is collected and which lawful basis applies (contract, legitimate interest, or consent). |
| Retention | How long each data category will be retained. Varies by type — e.g. health records longer than contact details. |
| Sharing | Third parties who may receive data: HSE, HMRC, insurers, emergency services, occupational health providers. |
| Data subject rights | Access, rectification, erasure, restriction, portability, objection, and right to complain to the ICO. |
| Consent for health data | Explicit consent statement for special category health data. Signature and date. |
3. Common Mistakes
Using a generic consent form not tailored to the specific data
The consent form and privacy notice must reflect the actual data being collected and the actual purposes. Generic templates rarely meet the specificity required by UK GDPR.
Not providing a privacy notice before data is collected
The privacy notice must be provided at the point of collection. Collecting data first and issuing the notice later does not comply with the transparency requirements.
Retaining data beyond the stated retention period
Data must be deleted or anonymised when the stated retention period expires. Indefinite retention without justification is a common breach.
Not having a process for Subject Access Requests
Organisations must respond to SARs within one calendar month. Without a defined process, deadlines are easily missed, triggering ICO complaints.
Sharing data with third parties not identified in the privacy notice
Every recipient or category of recipient must be identified in the privacy notice. Sharing data with unlisted parties is a transparency breach.
4. Frequently Asked Questions
What is the ICO and its enforcement powers?▾
The ICO is the UK’s independent data protection regulator. It can investigate complaints, conduct audits, issue enforcement notices, and impose fines up to £17.5m or 4% of global annual turnover, whichever is higher.
Is a Data Protection Officer required?▾
A DPO is required for public authorities, organisations carrying out large-scale monitoring, or large-scale processing of special category data. Most construction SMEs do not legally need one, but appointing a data protection lead is good practice.
Does UK GDPR still apply post-Brexit?▾
Yes — retained as ‘UK GDPR’ through the European Union (Withdrawal) Act 2018. The EU has granted the UK an adequacy decision, enabling continued data flows.
What special rules apply to health data?▾
Health data is special category data requiring both an Article 6 lawful basis AND an Article 9 condition. It must be handled with extra care, restricted access, and typically requires explicit consent.
Generate your GDPR Data Processing Consent on Construction Suite
Construction Suite walks you through every required section with a guided Q&A — built to UK GDPR / DPA 2018 — and generates a professionally formatted document in minutes.
Get started freeThis guide is for general informational purposes only and does not constitute legal advice. While every effort is made to ensure accuracy, regulations change and individual project circumstances vary. Construction Suite is a trading name of Xzist Digital Ltd, registered in England and Wales.
