FLR Staff Privacy Notice and Data Retention Schedule

PRIVACY & DATA PROTECTION

Staff Privacy Notice & Data Retention Schedule

First Line Response Limited · Staff and applicant privacy information · ICO Registration Z9914440

FLR Staff Privacy Notice and Data Retention Schedule

First Line Response Limited
Version 1.3  |  Effective 26 September 2026  |  Owner: Director

Summary

First Line Response Limited (“FLR”) processes staff and applicant information to recruit suitable people, verify identity and professional compliance, manage working relationships, meet legal duties, and provide safe services. We restrict access to people who need the information, retain each category only for its stated period, and delete or anonymise it when the purpose ends.

This notice applies to applicants, employees, workers, contractors, agency personnel and clinical professionals who provide or seek to provide services for FLR. It applies to information collected through the FLR staff portal at flrmedics.co.uk and through related workforce, rostering, accounting and compliance systems.

Who controls your information

First Line Response Limited is the data controller for the personal information covered by this notice. Questions, requests and objections should be sent to Shawn Bullivant at shawn@firstlineresponse.co.uk. FLR is registered with the Information Commissioner’s Office (ICO), registration reference Z9914440.

Information we collect

  • Identity and contact details, including legal name, date of birth, address, email, telephone number, National Insurance number where required, and emergency contact information.
  • Recruitment and engagement information, including CVs, applications, interview notes, references, availability, work history, contracts and declarations.
  • Professional and operational evidence, including qualifications, registrations, PINs, training, competencies, driving entitlement, insurance and company details.
  • Right to work information, including the result and date of a check, share-code information and copies that the Home Office requires FLR to retain.
  • DBS and other vetting information. This is criminal offence data even where a check records no convictions.
  • Health, disability, sickness, occupational health and workplace adjustment information where relevant. Health information is special category data.
  • Pay, tax, pension, expenses, time, attendance, leave and performance information where FLR employs or engages the individual.
  • System records such as submission dates, approvals, verification outcomes, changes, access logs and audit trails.

We normally obtain information from you. We may also receive it from referees, professional regulators, the Disclosure and Barring Service or its registered body, the Home Office, training providers, clients, recruitment providers and public registers.

Why we use it and our lawful bases

Purpose Article 6 basis
Recruit and enter into an engagement Steps requested before a contract and performance of a contract; legitimate interests in fair and effective recruitment.
Verify identity, right to work, pay and employment duties Legal obligation; contract where applicable.
Verify competence, professional registration and suitability Legal obligation where one applies; legitimate interests in safe staffing, clinical governance and service quality.
Administer work, pay, pension, training and performance Contract; legal obligation; legitimate interests in running and protecting the business.
Protect health, safety and people in our care Legal obligation; vital interests where necessary; legitimate interests in safe operations.
Handle complaints, incidents, audits and legal claims Legal obligation; legitimate interests in accountability and establishing, exercising or defending legal claims.

Where we use health or other special category information, we identify an Article 9 condition, normally employment and social protection law, health or social care, occupational health, vital interests, or legal claims. We use the least intrusive condition that fits the purpose and apply additional safeguards.

DBS information requires an Article 6 basis and lawful authority under Article 10 and the Data Protection Act 2018. Before routine criminal-offence-data processing, FLR will record the applicable Schedule 1 condition and maintain an Appropriate Policy Document where required. A form declaration or acknowledgement confirms that this notice was received; it is not, by itself, FLR’s lawful basis for mandatory employment or safeguarding processing.

Vetting and DBS information

FLR requests vetting only where it is necessary and proportionate for the role. Certificate information is used only for the purpose for which it was obtained. Access is limited to authorised compliance decision-makers.

DBS certificate images and related evidence are stored in protected portal storage and are not placed on the general operational staff board or disclosed to a client unless disclosure is lawful and necessary. After the relevant decision and any justified audit period, FLR deletes certificate images and retains only a minimum verification record, such as the subject’s name, certificate issue date, check type, role, certificate reference and decision. Any exception to the standard deletion target must record the reason, legal basis, access restriction and new review date.

Who receives information

We disclose only what is necessary to:

  • clients and service partners that need confirmation of identity, grade, competence or verified compliance status;
  • professional regulators, the DBS or its registered body, the Home Office, HMRC, pension and payroll providers, insurers, auditors, legal advisers, law enforcement or regulators where lawful;
  • technology providers acting under contract. The FLR staff portal is hosted for FLR and used as the source system for staff identity and compliance evidence. monday.com is used for governance, work management and compliance status information rather than as the primary store for sensitive evidence. Approved integrations may use Make. Other workforce or finance systems may include Sling and Xero/Hubdoc where relevant to rostering, payments or accounting.

FLR does not give clients copies of DBS certificates, passports or unrelated personnel documents merely for convenience. Processors may act only on FLR’s documented instructions and must provide appropriate confidentiality, security, deletion and subprocessor commitments.

International transfers

Some providers or their subprocessors may process information outside the UK. Before enabling that processing, FLR will verify the selected hosting region and contractual terms and ensure that an adequacy regulation, the UK International Data Transfer Agreement, the UK Addendum to approved standard contractual clauses, or another lawful safeguard applies.

Security and access

  • Sensitive compliance evidence submitted through flrmedics.co.uk is stored in protected server storage outside the public web root rather than in the normal WordPress media library.
  • Access is role-based. Staff are limited to their own portal information and evidence; compliance reviewers receive only the access required to review relevant staff records.
  • Administrator and compliance-reviewer access is protected by two-factor authentication and unique user accounts.
  • General operational records hold verification outcomes, expiry dates and status information rather than unnecessary duplicate identity or DBS files.
  • Evidence is served through authenticated, authorised controls rather than by public file URLs.
  • FLR reviews privileged access periodically and removes access promptly when duties change.
  • Encryption in transit and at rest, access control, audit history, secure devices, incident response, backup controls and staff confidentiality are used as appropriate to the system.
  • Sensitive evidence files and exports must not be sent through personal email, consumer messaging accounts or unmanaged devices.

How long we keep information

UK GDPR does not set one retention period for all staff information. The schedule below distinguishes fixed legal minimums from FLR policy periods. A legal hold, safeguarding investigation, regulatory requirement or live claim may justify longer retention. FLR records the exception and reviews it at least every six months. Early deletion remains possible when the information is no longer needed.

Record category Legal minimum or rule FLR standard
Unsuccessful application and interview records No universal statutory period 6 months after outcome. Talent-pool copy: 12 months from last meaningful contact where the person has chosen this.
Successful application materials No universal statutory period Move only necessary information to the personnel record; delete duplicates within 6 months of start.
Contract, core personnel, performance and engagement records Varies by record Engagement plus 6 years, then delete or anonymise unless a shorter category below applies.
Right to work check and required copies Employment/engagement plus 2 years where the statutory right-to-work retention rule applies Engagement plus 2 years, then securely delete.
DBS certificate image or certificate contents No universal fixed period; no longer than necessary Delete as soon as the decision and any justified safeguarding audit are complete; target no later than 6 months after the decision unless a documented exception applies.
Minimum DBS verification record No universal fixed period Engagement plus 6 years. Keep only the minimum verification record required for audit and governance.
Qualification, registration, training and competence evidence Varies by role and regulator Keep current evidence while engaged; verification record and material competency evidence for engagement plus 6 years.
Driving licence, emergency-driving qualification and insurance files Varies Keep current evidence while relevant. Delete superseded copies after the next completed verification; retain check outcome for engagement plus 6 years.
PAYE, payroll, leave and statutory payment records Normally at least 3 years from the end of the relevant tax year for specified PAYE records 6 years where the same records evidence minimum wage or contractual payments; otherwise at least the applicable statutory period.
National Minimum Wage records 6 years from the end of the following pay reference period 6 years.
Workplace pension records Usually 6 years; certain opt-out records 4 years Apply the relevant statutory period.
Health, sickness and adjustment information Varies Review annually and at the end of engagement. Delete detailed medical material when no longer needed; retain only a limited decision or statutory-payment record for its applicable legal or claims period.
Complaints, disciplinary matters, incidents and legal claims Varies 6 years after closure or end of engagement, whichever is later; longer only while a live claim, safeguarding matter or regulator requires it.
Form submissions, failed imports and duplicate exports No fixed period Delete duplicates within 30 days after verified transfer. Delete abandoned test submissions within 14 days.
Access and workflow audit logs No fixed period 24 months, unless required for an incident, audit or claim.

Retention procedure

  1. Set the retention review date when evidence is received or verified.
  2. At review, confirm whether the record is still required, replace it with a minimum verification outcome where possible, and securely delete unnecessary files.
  3. Record the deletion date. If retention continues, record the reason, lawful basis, authorised owner and next review date.
  4. Review portal retention items regularly and complete a full schedule review at least annually.

Your rights

Depending on the circumstances, you may ask for access to your information, correction, erasure, restriction, portability or objection to processing based on legitimate interests. You may withdraw consent where FLR genuinely relies on consent. Withdrawal does not affect earlier lawful processing. Some rights are limited where FLR must retain information by law or for legal claims.

Send a request to shawn@firstlineresponse.co.uk. FLR may request proportionate proof of identity and normally responds within one month. You may also complain to the Information Commissioner’s Office.

Automated decisions

FLR does not make recruitment, engagement or compliance decisions solely by automated means that produce legal or similarly significant effects. Automations may create records, issue reminders, validate workflow steps or route items for review, but an authorised person makes the decision.

Changes to this notice

FLR reviews this notice at least annually and when its services, forms, legal duties, processors or retention practices change. Material changes will be brought to affected individuals’ attention.

Governance controls

  • Public staff registration is intentionally enabled for direct FLR applications and is protected by account verification, anti-abuse controls and reviewer approval before operational use.
  • FLR maintains an approved Appropriate Policy Document for special category and criminal-offence/DBS processing and reviews it at least annually and when processing changes.
  • FLR maintains an approved Data Protection Impact Assessment for the staff portal and connected compliance workflow and reviews it when scope, processors, integrations or data flows materially change.
  • Processor contracts, international-transfer safeguards, hosting arrangements, two-factor authentication, file permissions, incident contacts, backup/restore controls and deletion behaviour remain subject to ongoing governance review.
  • Synthetic records are used for testing and are removed when testing is complete. Sensitive evidence must not be copied to general operational boards or connected systems unnecessarily.
  • Live DBS Update Service status checking may be enabled only for individual staff records that meet FLR’s documented legal, governance, identity, certificate-scope and consent prerequisites. The global service and each individual enrolment remain subject to human oversight and can be disabled at any time.

Reference sources

  • ICO storage limitation guidance
  • ICO encryption and security guidance
  • ICO criminal offence data guidance
  • ICO recruitment and selection guidance
  • Home Office right to work checks guidance
  • DBS guidance on handling certificate information
  • HMRC PAYE record-keeping guidance
  • GOV.UK National Minimum Wage employer records
  • The Pensions Regulator record-keeping guidance

Public staff verification

Where First Line Response issues a staff identification card with a verification QR code or verification link, that link may display a limited public verification record so clients, venues and authorised third parties can confirm whether the person is currently recognised by First Line Response.

The public verification page is limited to the staff member's name, profile photograph, FLR Staff ID, role or grade, and whether the FLR verification record is current or not current. It does not display date of birth, contact details, home address, professional registration number, DBS information, training records, uploaded evidence or other compliance information.

The verification page confirms FLR identity and current FLR status only. It is not a substitute for checking a professional regulator's register where an independent professional-registration check is required.

Verification tokens can be revoked or replaced. Staff who are suspended, inactive, no longer approved or no longer eligible are shown as not current. Accesses to the public verifier may be recorded in the FLR audit log for security and governance purposes without storing the verification token or visitor personal data.