Understanding the legal framework for investigation records
Workplace and corporate investigations inevitably involve personal data. Whether you are looking into a grievance, a disciplinary matter, a whistleblowing report or suspected fraud, you will be collecting names, allegations, witness statements, emails, notes and more. All of this is personal data under the UK GDPR and the Data Protection Act 2018. That means you must handle it in line with the seven data protection principles: lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability.
It is not enough to simply say you are conducting an investigation. You need to be able to demonstrate that your processing is compliant. The regulator expects you to have a clear legal basis, to be transparent about what you are doing, and to keep records secure. Getting this right protects the individuals involved, your organisation and the integrity of the investigation itself.
Lawful basis and proportionality: the foundations
Before you collect any personal data for an investigation, you need a lawful basis. For most private-sector employers, the most common basis is legitimate interests. You must carry out a balancing test to show that your interests (or a third party's) are not overridden by the individual's rights and freedoms. In some cases, you may rely on legal obligation if a law or regulation requires you to investigate, or vital interests if someone's life is at risk. Public authorities might use public task.
Special category data needs extra care. This includes information about health, race, ethnic origin, political opinions, religious beliefs, trade union membership, sexual orientation, and criminal allegations or convictions. To process it, you need both a lawful basis and a condition from Article 9 of the UK GDPR, often read with Schedule 1 of the Data Protection Act 2018. Common conditions for investigations include legal claims, preventing or detecting unlawful acts, or employment law obligations.
Proportionality is key. Collect only the data you actually need. Do not cast your net wider than necessary. Consider whether less intrusive methods could achieve the same aim. Document your reasoning as you go, because you may need to justify your decisions later.
Secure storage and access controls
Investigation records are sensitive. They can contain allegations that are unproven, and disclosure can cause serious harm. Store them securely. Physical files belong in locked cabinets, not on an open desk. Electronic files should be encrypted, both at rest and in transit. Use access controls so that only those who genuinely need to see the data can do so.
- Role-based access: limit access to the investigation team, HR and legal advisers.
- Audit trails: keep a log of who accessed what and when, so you can spot unauthorised access.
- Pseudonymisation: where possible, use codes instead of names in working documents, especially when sharing with others.
- Redaction: remove irrelevant personal data before circulating documents internally.
- Separate storage: keep the investigation file separate from the main HR file, and do not store data on personal devices or unsecured shared drives.
Think about confidentiality from the outset. A breach of confidence can damage trust and lead to legal claims. Consider using a dedicated case management system with built-in security features. Train everyone involved on how to handle data safely.
Retention: keeping records only as long as necessary
The storage limitation principle says you must not keep personal data for longer than necessary. For investigation records, there is no single retention period that fits all cases. It depends on the purpose, the legal context and the risk of claims.
As a rule of thumb, many organisations retain investigation records for the duration of employment plus six years, to align with the limitation period for contract claims in England and Wales. But that is not a hard-and-fast rule. Employment tribunal claims for unfair dismissal must usually be brought within three months less one day of dismissal, though discrimination claims can have a longer time limit. If the investigation could lead to a regulatory fine or criminal proceedings, you may need to keep records longer.
What matters is that you have a documented retention schedule and you apply it consistently. Review investigation files regularly. When the retention period ends, securely delete or anonymise the data. Do not keep it "just in case". If you need to keep some information for a longer period, record why and limit access to it.
Handling subject access requests and other individual rights
Individuals have the right to access their personal data. A subject access request (SAR) can arrive at any time, including during an investigation. You must respond within one month, though you can extend by two months for complex requests. In investigations, SARs can be tricky because the file may contain data about other people.
You can redact third-party personal data unless the third party consents or it is reasonable to disclose without consent. You can also apply exemptions, but they are narrow. Relevant exemptions may include legal professional privilege, crime and taxation (preventing or detecting crime), negotiations, confidential references and management planning. Do not use exemptions as a blanket refusal. Apply them case by case and document your reasons.
Other rights also apply. Someone can ask you to rectify inaccurate data, erase data, restrict processing or object to processing. If data is disputed, consider adding a note of dispute rather than deleting it. Train your staff to recognise a request, log it immediately and escalate it to your data protection lead or legal adviser. Having a clear SAR procedure in place will save you time and stress.

Comments