Workforce Compliance · From the Auditor's Desk

Right to work, DBS and the £60,000 mistake: the employee checks UK employers keep getting wrong

Employing one person without the right to work can now cost up to £60,000. Starting a carer before their DBS clears is a safeguarding breach. These are not HR admin — they are legal duties, and the price of getting them wrong has risen sharply. Here is what care, construction and security employers must check, and the personnel-data trap sitting behind it.

Jason Misters · IRCA® Registered Principal Auditor · 24 July 2026

There is a kind of compliance that quietly decides whether a business survives an inspection, an audit or a Home Office visit — and it has nothing to do with ISO clauses or cyber controls. It is whether you can prove, for every person on your payroll, that you were legally allowed to employ them and that they were safe to do the job.

For years this was treated as HR paperwork: a passport photocopied into a folder, a DBS certificate filed and forgotten. Two things changed that. The penalties for getting it wrong have risen sharply, and the data those checks produce is now some of the most tightly regulated information a business holds. This is a plain-English guide to what UK employers — especially in care, construction and security — actually have to do.

Right to work: the £45,000–£60,000 check

Every employer must confirm a person has the right to work in the UK before they start. Get it wrong and, since 13 February 2024, the civil penalty is up to £45,000 per worker for a first breach and £60,000 per worker for a repeat breach within three years — roughly triple the previous levels. That is per worker, not per business.

Above the civil penalty sits the criminal offence: knowingly employing someone without the right to work — or having reasonable cause to believe they lack it — carries up to five years' imprisonment and an unlimited fine.

Enforcement is not theoretical. Home Office illegal-working visits rose to roughly 12,800 in 2025, and a single quarter of that year saw 748 penalty cases totalling £41.6 million — concentrated in hospitality, construction, care and small retail.

The good news: doing it right is mostly free. You establish a “statutory excuse” — your defence against a penalty — by one of three routes, completed and recorded before the start date:

1 — Online check via share code

For most people with a digital immigration status (eVisa holders), you enter their share code and date of birth into the free Home Office online service. Instant — and it gives you a statutory excuse.

2 — Manual document check

Check an original acceptable document (usually a passport) in the person's presence — or by video call with the original in hand — then copy, date and keep it.

3 — Digital identity (IDVT)

For British and Irish citizens with a valid passport, a certified Identity Service Provider can verify identity digitally. Use an uncertified provider and you get no statutory excuse — the liability stays with you.

DBS: the right level, and the retention trap

A right-to-work check tells you someone can work; a DBS check helps tell you they are safe to do a particular job. There are three levels, and using the wrong one is its own failure:

LevelWhat it showsTypical roles & fee
BasicUnspent convictions and cautionsAny role; anyone can apply directly via gov.uk (£21.50)
StandardSpent & unspent convictions, cautions, warningsSpecific roles set in law — including every SIA security licence (£21.50)
EnhancedThe above plus police intelligence and, where relevant, the barred list“Regulated activity” — caring for children or vulnerable adults (£49.50)

DBS fees as set on 2 December 2024. Check gov.uk for the current position.

Care. Most hands-on care work is regulated activity, so it needs an Enhanced check with a barred-list check. Starting someone in that role before the check is satisfactory is treated by the CQC as a serious safeguarding breach — the classic finding that turns a routine inspection into enforcement.

Construction & security. Most construction roles need a Basic check at most; security staff need a Standard check as a mandatory part of every SIA licence. Two traps catch people out: Standard and Enhanced checks can only be obtained through a DBS Registered Body or an umbrella body — you cannot apply directly — and the certificate you receive cannot simply be filed forever.

The DBS Code of Practice says certificate information should be kept no longer than reasonably necessary — usually taken to mean no more than about six months — then securely destroyed, with no copies kept. A folder of old DBS certificates isn't diligence; it's a data-protection liability.

The law is moving under your feet

Even employers who had this nailed a year ago need to look again. The last two years have brought real change:

1

Right-to-work penalties tripled — Feb 2024

The jump to £45,000/£60,000 per worker is the single biggest change, and the reason a check you “usually get round to” is now a board-level risk.

2

Duty to prevent sexual harassment — Oct 2024

The Worker Protection Act 2023 created a proactive duty to take reasonable steps to prevent sexual harassment, including by third parties, with tribunal compensation uplifts of up to 25% where you fall short. Induction, policies and training records now have to prove the steps you took.

3

Employment Rights Act 2025

Royal Assent in December 2025. Among the changes expected to phase in through 2027: the unfair-dismissal qualifying period cut from two years to six months, the compensation cap removed, and tighter rules on zero-hours and fire-and-rehire. Clean records and defensible processes matter more, not less. (Most provisions are not yet in force — check the current position.)

4

Data (Use and Access) Act 2025

Commenced February 2026, with the ICO entering the year with sharper enforcement powers — which brings us to the part most employers overlook.

The data trap nobody plans for

The checks above generate exactly the kind of data the law protects most. A DBS result is criminal-offence data under Article 10 of the UK GDPR; health and medical information is special-category data under Article 9. Both demand more than a locked filing cabinet:

  • Consent is not your lawful basis. In an employment relationship a candidate's “consent” to a DBS check isn't freely given, so it fails the UK GDPR consent test. You need a proper condition (typically a Schedule 1 DPA 2018 employment condition) and an appropriate policy document behind it.
  • Data minimisation and retention. You keep the derived result, not a pile of certificates — which is exactly why the DBS six-month destruction rule exists.
  • Accountability (Articles 5, 30, 32). You should be able to show who accessed a sensitive record and when, hold it under access controls and encryption, and record the processing.

This matters because ICO enforcement is intensifying — the regulator collected several times more in fines in 2025 than in 2024, with the average penalty rising into the millions. A spreadsheet of DBS numbers on a shared drive, visible to whoever, is the kind of arrangement that looks fine until the day it very much doesn't.

What good looks like

1

Check before day one — every time, recorded

Right to work established (share code, manual, or certified IDVT), the correct DBS level for the role obtained, references and any role-specific credentials (SIA, CSCS, professional registration, medical) on file. Keep the evidence, not just a tick.

2

Set retention by document type

DBS destroyed at around six months; right-to-work kept for the statutory period; payroll for years. One retention rule for “HR files” is over-retention and under-retention at once.

3

Lock the sensitive stuff down

Restrict who can see criminal-offence and health data to those who genuinely need it, log every access, and encrypt it at rest. If you can't say who looked at a DBS record last month, you can't answer an inspector or the ICO.

4

Have a clean leaver process

When someone leaves, revoke access and let retention rules erase what you're no longer allowed to keep — with an audit record that erasure happened. Right to erasure is a duty, not a favour.

Doing it in PICMS

This is exactly what we built the PICMS People Vault to do — a single, locked-down home for your team's records: right to work, DBS, medicals, competence and registrations, with the compliance built in rather than bolted on.

You can run the free Home Office right-to-work check and a Basic DBS straight from a person's record and file the result as evidence; per-role rules tell you which checks each job needs; and a new starter's onboarding pack tracks what's outstanding. Sensitive data is encrypted at rest and every view is logged; criminal-offence and health data only ever leaves the vault through an explicit, recorded share; and access can be protected with a one-time verification code. When someone leaves, offboarding revokes their shares and retention rules delete each document the day its lawful period ends — the DBS at six months, payroll years later — every deletion recorded.

To be plain about what software does: PICMS does not carry out your checks for you, is not a DBS body, and this article is general guidance, not legal advice — penalty and fee figures change, so check gov.uk at the time of reading. What it does is make the duty visible, the evidence current, and the data defensible, so a check you'd otherwise “get round to” is done, provable and safe.

Jason Misters — IRCA® Registered Principal Auditor

Lead auditor and ISO consultant. Founder of Training Assurance Consultancy and PICMS. Writes from years of hands-on experience implementing and auditing information security management systems in UK businesses. Verifiable on the CQI-IRCA register.

Your people checks, done and provable.

PICMS People Vault is a locked-down home for right to work, DBS, medicals and competence — run the free gov checks from a person's record, log every view, and let retention rules erase what you can't lawfully keep. From £149/mo, on any plan.

Start a Free Trial Explore People Vault