
Accident books contain some of the most sensitive information an employer holds. Names, job roles, injuries, medical details, and sometimes witness accounts all sit in one place. That makes accident records a data protection issue, not just a health and safety one.
Many UK employers fall into GDPR problems without realising it. Not because they are reckless, but because accident books have historically been treated as harmless paperwork.
They aren’t.
This guide explains how GDPR applies to accident books, what employers are expected to do in practice, and where most organisations expose themselves unnecessarily.
Why Accident Books Fall Under GDPR
Accident book entries contain personal data and often special category data relating to health. That means they fall squarely within the scope of UK GDPR and the Data Protection Act.
Once an employer records:
who was injured
what injury occurred
when and where it happened
they are processing personal data. The moment health information is included, the bar is higher.
This applies whether records are kept on paper or digitally.
Lawful Basis for Recording Accident Data
Employers do not need employee consent to keep an accident book, but they do need a lawful basis.
In most cases, accident records are processed because they are:
necessary to meet legal obligations under health and safety law
required to protect the health and safety of employees and others
needed for legitimate interests such as incident management and risk control
Health-related information is usually processed because it is necessary for employment and workplace safety obligations.
The mistake many employers make is assuming GDPR somehow prevents them from keeping records. In reality, GDPR allows accident recording. It simply requires it to be done properly.
Access Control Is the Biggest Risk Area
The most common GDPR failure with accident books is who can see them.
Traditional paper accident books are often:
left in open areas
accessible to any employee who asks
visible to visitors or contractors
handled casually by multiple people
This creates unnecessary exposure of personal and health data.
Under GDPR, employers are expected to restrict access to accident records to those who genuinely need it, such as managers, HR, or health and safety leads. Curiosity is not a lawful reason for access.
If you cannot confidently explain who can access your accident records and why, you likely have a problem.
Data Minimisation and Over-Recording
Another common mistake is recording more information than necessary.
Accident books should record:
factual details of the incident
visible injuries or reported symptoms
immediate actions taken
They should not include:
speculation about medical conditions
irrelevant personal information
opinions about behaviour or fault
Recording excessive detail increases risk without improving compliance. GDPR expects employers to collect only what is necessary for the purpose at hand.
Retention: Keeping Records Too Long
GDPR requires personal data to be kept no longer than necessary.
Many employers either:
keep accident records indefinitely “just in case”, or
have no clear retention policy at all
Neither approach is defensible.
Accident records are often kept for several years to cover potential claims, but there should be a clear, documented retention period and a process for secure disposal when that period ends.
Keeping records forever is not safer. It is riskier.
Employee Rights and Transparency
Employees have rights over their personal data, including accident records.
They are entitled to:
know that accident data is being recorded
understand how it is used
request access to records relating to them
What they are not entitled to is unrestricted access to the entire accident book. That distinction is frequently misunderstood and leads to over-sharing.
Employers should be able to provide copies of relevant entries without exposing third-party information.
Digital vs Paper Accident Books Under GDPR
GDPR does not favour digital systems automatically, but digital accident books often make compliance easier.
They typically allow:
controlled access
audit trails
consistent retention rules
better separation of records
reduced casual visibility
Paper systems rely heavily on discipline and procedure. In practice, they are harder to control and easier to misuse, particularly in busy or multi-site environments.
From a GDPR perspective, the issue is not format. It is control.
What the Regulator Expects
Guidance from the Information Commissioner's Office is clear that employers must take appropriate steps to protect personal and health data.
In the event of a complaint or investigation, regulators will look at:
who could access the records
how they were stored
how long they were kept
whether unnecessary data was recorded
Poor accident book practices can quickly become data protection issues.
Why This Matters More Than Employers Realise
GDPR problems with accident books rarely surface immediately. They surface when:
an employee raises a complaint
a dispute escalates
an inspection takes place
records are requested years later
At that point, informal practices are exposed. What once felt routine starts to look careless.
Key Takeaway
GDPR does not prevent employers from keeping accident books. It requires them to do so responsibly.
Accident records should be accurate, limited, securely stored, and accessible only to those with a genuine need. Anything else creates unnecessary exposure.
For many employers, accident books are not just a health and safety issue. They are a quiet data protection risk.