Temporary staffing often involves the movement of personal information between several organisations. A worker may submit their details to a recruitment agency, the agency may share relevant information with a prospective hirer, and the hirer may then create records relating to the worker's assignment, attendance, performance, training, health and safety or payroll administration. Although this information sharing can be necessary to organise work effectively, it also creates responsibilities for the organisations involved.
For hirers, the important point is that temporary workers do not lose their data protection rights simply because they are supplied through an agency. Personal information must still be collected, used, shared, stored and deleted in accordance with applicable data protection requirements. The Information Commissioner's Office (ICO) recognises that recruitment and employment processes may involve several organisations, including hirers, recruitment agencies and other service providers. These arrangements require organisations to understand what information they hold, why they need it and how it should be managed.
Temporary Staffing Creates a Shared Information Environment
When a hirer engages temporary workers, it may need access to information such as a worker's name, contact details, work history, qualifications, training records, availability, attendance records and assignment information. Depending on the role, the hirer may also receive information concerning health, disability, criminal convictions or other sensitive matters.
However, the fact that information is available does not mean that everyone within the organisation should have access to it. A site supervisor may need to know a worker's name, shift pattern and relevant training status, but may not need access to their bank details, medical information or recruitment documents. Similarly, a manager may need information about attendance without needing access to detailed sickness records.
The ICO advises organisations to ensure that employment information is accessed only by appropriate people who have a legitimate reason to use it. Sensitive information should receive additional protection, and organisations should avoid collecting or retaining information that is unnecessary for the purpose for which it was obtained.
For hirers, this means that temporary-worker data should be treated as part of the organisation's wider information-governance responsibilities, not as informal paperwork belonging to the staffing agency.
Who Is Responsible for the Information?
The relationship between a staffing agency and a hirer can be complex. Depending on the activity being undertaken, one organisation may act as a data controller, another may act as a processor, or both organisations may process information independently for their own purposes. These roles should not be assumed simply because one organisation supplies workers to the other.
An agency may collect information to register a worker, assess suitability, manage recruitment and administer the employment relationship. The hirer may separately process information to manage access to its premises, organise shifts, provide training, monitor attendance, investigate incidents or manage performance.
Each organisation needs to understand its own responsibilities and the legal basis for the processing it undertakes. The ICO's guidance emphasises the importance of clarity about responsibility when recruitment and employment activities involve several organisations. Employers should therefore avoid relying on vague statements such as "the agency manages the data" without understanding what that means in practice.
A clear staffing agreement should identify what information will be shared, why it is needed, who can access it, how it will be protected and what happens when the assignment ends.
Collect Only What You Need
One of the most practical principles of data protection is data minimisation. A hirer should collect and use only the personal information that is necessary for a specific and legitimate purpose.
For example, if a hirer needs to confirm that a temporary worker has completed site-specific training, it may need a record of the training date and completion status. It may not need access to the worker's entire recruitment file. If a supervisor needs to contact a worker about a shift, they may need an approved contact channel, but not necessarily the worker's personal documents.
Unnecessary data collection increases risk. The more information an organisation holds, the more it must protect, maintain and eventually dispose of. It also creates a greater chance that information may be shared with the wrong person or retained long after it is needed.
Hirers should therefore review the information they request from staffing agencies and ask whether each data item has a clear operational or legal purpose.
Temporary-Worker Information Must Be Kept Secure
Security is another important responsibility. Personal information relating to temporary workers may be held in spreadsheets, email accounts, HR systems, payroll platforms, paper files, access-control systems or timesheet applications. Each of these systems can create risks if access is not properly managed.
Hirers should ensure that records are stored securely, access is restricted to authorised personnel, and staff handling personal information understand their responsibilities. Paper documents should not be left in open areas, and digital records should not be shared casually through unsecured channels. Where third-party platforms are used, employers should understand how the provider processes the information and what contractual safeguards are in place.
The ICO also highlights the importance of keeping employment records accurate and up to date. Incorrect information can affect a worker's pay, assignment, access to the workplace, training status or employment experience. Data protection is therefore not only about preventing leaks; it is also about ensuring that information is reliable and used appropriately.
What Happens When an Assignment Ends?
The end of a temporary assignment should trigger a review of the information held about the worker. Hirers may need to retain certain records for legitimate business, legal or regulatory reasons, but that does not mean every document should be kept indefinitely.
Organisations should understand their retention periods and securely delete or dispose of information when it is no longer required. Access permissions should also be reviewed. A worker who has completed an assignment should not continue to have unnecessary access to workplace systems, internal platforms or confidential records.
Similarly, hirers should consider whether information needs to be returned to the agency, retained by the hirer or securely deleted. These decisions should be guided by the purpose of the information, legal requirements and any relevant contractual arrangements.
A Practical Example
Imagine that a business uses an agency to supply temporary warehouse workers. The agency shares a spreadsheet containing worker names, contact details, assignment dates and other recruitment information. The hirer forwards the spreadsheet to several supervisors, even though most of them only need names and shift details.
One supervisor later sends the spreadsheet to a personal email account to work on it at home. The document is then stored on an unsecured device and remains there after the assignment ends.
The problem in this example is not simply that information was shared. The problem is that the hirer may not have applied appropriate controls over access, sharing, storage, and retention. A more responsible process would limit the information shared with supervisors, use an approved system, restrict access, and establish clear rules for handling and deleting records.
What Employers Should Review
Employers using temporary workers should consider whether they have:
- Clearly defined responsibilities with staffing providers.
- A documented reason for collecting each category of personal information.
- Appropriate access controls for managers and supervisors.
- Secure systems for storing worker records.
- Clear rules for sharing information internally and externally.
- Processes for correcting inaccurate information.
- Retention and deletion procedures.
- A method for removing access when an assignment ends.
- Staff training on confidentiality and data protection.
The Financial Consequences of a Workers' Data Breach
A data breach involving temporary workers is not only a privacy concern; it can also create significant financial exposure for the organisation. Under the UK GDPR and the Data Protection Act 2018, the Information Commissioner's Office (ICO) can impose fines of up to £17.5 million or 4% of an organisation's total worldwide annual turnover, whichever is higher, for serious infringements. Other breaches may attract a standard maximum of £8.7 million or 2% of worldwide annual turnover, whichever is higher. The actual penalty depends on factors such as the seriousness and duration of the breach, the type of personal data involved, whether the failure was deliberate or negligent, and the organisation's response.
The financial impact may extend beyond an ICO penalty. An organisation may also face investigation and remediation costs, legal advice, cybersecurity support, notification expenses, operational disruption, contractual disputes and potential compensation claims from affected individuals. Where a breach involves workers' payroll details, bank information, identity documents, immigration records or other sensitive employment information, the consequences can be particularly serious. In May 2026, the ICO fined South Staffordshire Plc and South Staffordshire Water Plc £963,900 after a cyberattack compromised the personal data of more than 633,000 customers and employees, demonstrating that large-scale data-security failures can result in substantial regulatory costs.
For hirers using recruitment agencies, this makes clear data-sharing arrangements essential. Businesses should establish what information is collected, which organisation is responsible for each processing activity, who can access the records, how information is transferred, how long it is retained and what happens when an assignment ends. They should also ensure that both the agency and the hiring organisation have clear procedures for identifying, containing and reporting breaches. Where a reportable breach occurs, the ICO generally expects notification within 72 hours of the organisation becoming aware of it, where feasible.
The main lesson is simple: temporary workers' information should not be treated as temporary information. Weak controls over agency-worker records can expose an organisation to regulatory penalties, operational disruption, reputational damage and loss of worker confidence. Protecting personal data is therefore not merely an administrative task; it is an important part of responsible workforce management.
Responsible Staffing Includes Responsible Data Management
Temporary staffing depends on information. Hirers need information to organise work, manage safety, confirm training, process timesheets and communicate with workers. However, the need for information must be balanced with the worker's right to privacy and appropriate data protection.
The most effective staffing relationships are those in which hirers and agencies understand what information they need, why they need it and how they will protect it. Data protection should not be treated as an issue that belongs only to HR or the staffing agency. Anyone who collects, accesses, shares or manages temporary-worker information has a role to play.
Temporary workers are part of your workforce. Their personal information deserves the same care as every other business record.
References
- ICO — Recruitment and selection: UK GDPR guidance for employers
- ICO — Employment practices and data protection: keeping employment records
- ICO — The maximum amount of a fine under UK GDPR and DPA 2018
- GOV.UK — Data protection for your business: recruitment and managing staff records
- ICO — Fine issued against South Staffordshire Plc and South Staffordshire Water Plc
