Skip to main content
    Regulation14 min readPublished April 18, 2026The QHSE Standard

    GDPR & EHS Data: How to Stay Compliant When Logging Incidents in the EU/UK

    Logging an incident captures personal data. In the EU/UK, GDPR applies — and most EHS programs are quietly non-compliant. Here is how to fix it.

    Reviewed by The QHSE Standard editorial team

    Fact-checked against ISO 45001, OSHA, EU OSH Framework Directive, and CCPS guidance. Independent of vendor influence — see our review methodology.

    Every incident report captures personal data: the injured worker's name, role, location, sometimes medical details. In the EU and UK, that data is subject to GDPR (and the UK GDPR for British operations). Most EHS programs handle it informally — and most are quietly non-compliant.

    This guide walks through how GDPR applies to EHS records, where the common gaps are, and how modern EHS platforms handle privacy by design.

    What Personal Data Is in Your EHS System?

    More than you think:

    • Identification: name, employee ID, photo, contact details
    • Employment: job title, department, supervisor, work location
    • Health data (sensitive): injury type, body part, medical treatment, return-to-work status, occupational health screenings
    • Behavioral: observations of "at-risk behavior," near-miss involvement, training scores
    • Location: site, building, sometimes GPS for lone-worker apps
    • Witness statements: statements naming other workers

    Of these, health data is "special category" data under GDPR Article 9 — subject to stricter rules than general personal data.

    Lawful Basis for Processing

    GDPR requires a lawful basis for processing every category of personal data. For EHS, the typical bases are:

    General personal data (incident logging, training records)

    • Article 6(1)(c) — Legal obligation. Most countries legally require employers to record workplace injuries, near misses, and certain training. This is your strongest basis for incident records.
    • Article 6(1)(f) — Legitimate interest. Useful for observations, leading indicators, and analytics — but you must complete a Legitimate Interest Assessment (LIA) and document it.

    Health data (special category)

    • Article 9(2)(b) — Employment law. Permits processing necessary for compliance with employment, social security, and social protection law (which includes occupational health & safety).
    • Article 9(2)(h) — Occupational medicine. Useful for occupational health surveillance under the supervision of a healthcare professional.

    Consent is rarely the right basis for incident records. The power imbalance between employer and worker means consent is usually not freely given. Use legal obligation or employment-law bases instead.

    Common GDPR Gaps in EHS Programs

    1. No documented retention period

    GDPR requires that personal data be kept "no longer than necessary." Most EHS programs retain data indefinitely. Define a retention schedule:

    • Incident records: typically 5-10 years post-incident (varies by jurisdiction; check national OH&S record-keeping requirements)
    • Training records: lifetime of employment + 5-7 years for safety-critical roles
    • Observations: 12-24 months
    • Near misses: 5-7 years
    • Audit findings: 5-7 years post-closure

    Set the schedule in the platform; auto-archive or anonymize at expiry.

    2. Excessive data collection

    GDPR's data minimization principle says: collect only what you need. Common offenders:

    • Capturing date of birth when only "adult/minor" is needed
    • Capturing home addresses on incident forms
    • Free-text witness statements that include irrelevant personal details
    • Photographs of injured workers without operational necessity

    Audit your forms. Remove anything not directly necessary for the safety purpose.

    3. No privacy notice for workers

    Workers have a right under GDPR Articles 13/14 to be told what data you collect, why, on what basis, and for how long. Most EHS programs have no worker-facing privacy notice. Fix:

    • Add a 1-page EHS data privacy notice to your onboarding pack
    • Reference it from the EHS software login screen
    • Provide a translated version for non-native speakers

    4. Cross-border data transfers

    If your EHS platform's servers are in the US (very common), every incident logged in the EU is a transfer of personal data outside the EEA. Post-Schrems II, this requires:

    • A transfer mechanism (Standard Contractual Clauses are most common)
    • A Transfer Impact Assessment (TIA) documented
    • Supplementary measures if required (encryption, pseudonymization)

    Modern EU-headquartered platforms increasingly offer EU data residency as a feature. If you're processing significant volumes of EU worker data, this is worth specifying in your RFP.

    5. No DPIA for high-risk processing

    GDPR Article 35 requires a Data Protection Impact Assessment (DPIA) for processing likely to result in high risk. EHS programs that include any of these likely require a DPIA:

    • Continuous lone-worker GPS tracking
    • Behavioral monitoring at scale
    • Sensitive health data on large worker populations
    • Cross-border transfer of health data

    6. Worker access requests not honored

    Under Article 15, workers can request a copy of all personal data you hold about them. Most EHS platforms can't easily produce a personalized data export. Test this — your DPO will need to respond within 30 days when a request comes in.

    7. Witness statements containing third-party personal data

    A witness statement in an incident report often names other workers. Those named individuals are also data subjects. Their data must be lawful, necessary, and ideally pseudonymized in any document released externally.

    What "GDPR-Friendly" EHS Software Looks Like

    Modern platforms designed with privacy by design (GDPR Article 25) include:

    • Configurable retention rules per record type, with auto-archive
    • Field-level pseudonymization — show "Worker #4521" in analytics dashboards, full name only to authorized roles
    • Granular role-based access — site lead sees only their site, regional lead sees their region
    • Audit log of who viewed which personal data
    • Data export at the individual subject level (for SAR responses)
    • EU data residency option (servers physically in the EEA)
    • DPA (Data Processing Agreement) ready to sign — not "we'll get you one in a few weeks"
    • SCCs included in the standard contract for international transfers

    Ask vendors for their GDPR/UK GDPR compliance brief during evaluation. If they can't produce one in 48 hours, that's a red flag.

    How EU/UK EHS Differs from US EHS

    US-headquartered platforms often lack EU-residency by default and treat data export at the individual level as a custom feature. EU vendors (Quentic, Tekmon, BlueKanGo, EcoOnline) typically have these built in.

    For multi-region operations, the practical pattern is:

    • Deploy EU instance for EU/UK operations
    • US instance for US/Americas
    • Aggregate analytics via the BI layer, with appropriate data minimization

    FAQs

    Does GDPR apply to UK operations after Brexit?

    The UK adopted GDPR into national law as the UK GDPR. The substance is essentially identical to EU GDPR, with minor divergences. Most EHS compliance approaches work for both.

    Can I share incident data with my client (e.g., on a construction site)?

    Sharing requires a lawful basis. Typically: a contractual obligation in your master service agreement, with appropriate data minimization (anonymized statistics, not identified individuals). Get your DPO's sign-off before establishing the data flow.

    Is SafetyCulture / Intelex / VelocityEHS GDPR-compliant?

    All three offer DPAs and SCCs. Data residency varies — Intelex offers EU residency on enterprise tiers; SafetyCulture and VelocityEHS are primarily US-hosted (check current options). Review our SafetyCulture vs Intelex vs VelocityEHS comparison for more.

    How do I handle data when a worker leaves?

    Apply your retention schedule. Most incident and training data is kept (legal obligation) for 5-10 years post-employment. Observations and other lower-risk data is typically deleted or anonymized within 12-24 months.

    Do I need a DPO (Data Protection Officer) for EHS data alone?

    Usually not, unless EHS data processing is the company's core activity. But your existing corporate DPO must be involved in EHS platform selection and configuration.

    What happens if I get a GDPR fine?

    GDPR fines are up to €20M or 4% of global turnover, whichever is higher. EHS-specific fines are rare but rising — common triggers are health-data breaches, cross-border transfer issues, and excessive retention.


    Need a GDPR-aware EHS platform? Take our Get Matched quiz and we'll suggest 3 platforms with EU data residency, configurable retention, and signed DPAs out of the box.

    GDPRprivacyEUUKcompliancedata protection

    Software covered in this category

    Browse all platforms →
    Not sure which fits? Get matched in 60s

    Looking for the Right QHSE Software?

    Take our 60-second quiz and get personalized recommendations.

    Get Matched — Free
    Back to all articles