Home โ†’ Guides โ†’ Sharing contractor training certificates with a client
Compliance Document Management Software

Sharing contractor training certificates with a client

A client may need evidence that the people arriving on site are trained for their assigned work. A supplier may have named-worker cards, certificates and training records in its files. Sharing the entire personnel folder is rarely the right answer. The question is which fact the client needs to check, for which work, and what personal information is necessary to prove it.

HSE says a construction contractor that engages workers must make sure they have the appropriate skills, knowledge, experience and training, or are in the process of obtaining them. Its contractor-role guidance does not prescribe a universal upload of every worker's personnel record. The ICO's data minimisation guidance says personal data must be adequate, relevant and limited to what is necessary for the purpose.

Write down the verification purpose first

The client should identify the task and the competence question: for example, whether a named person has a current qualification for a specified activity. The supplier should identify which record answers it. A general site-induction record, professional licence and task-specific training certificate may prove different things. A card's presence does not remove the need to check experience and the work environment; HSE's passport-scheme guidance says a passport is not a substitute for site-specific information.

Keep a request record with the work package, evidence category, legal or contractual reason, named recipients, needed date and expected retention review. If the request says only โ€œsend all training filesโ€, ask for the relevant roles and criteria. The supplier should ensure its worker privacy information covers the intended sharing and that its own processing has an identified lawful basis. Do not assume worker consent is always the appropriate basis merely because a client asks for a certificate; the ICO requires the controller to identify the applicable basis for its circumstances.

Minimise the copy and control access

Share enough to verify the person, awarding body, qualification or card type, scope and validity period. Where the verifier can check an official scheme record directly, consider whether recording the verified result is more proportionate than retaining another full image. Do not remove a field that is essential to a valid check, but do not expose unrelated home addresses, identity numbers or other private details simply because they appear on the same page.

Agree a secure transfer method and limit access to the reviewers who need the evidence. A link to a folder shared with everyone on the project is a poor default. The ICO's contracts and data-sharing toolkit emphasises proportionate due diligence, clear roles and only sharing necessary personal information. Supplier and client should establish their respective controller or processor roles for the actual arrangement; a generic label in a procurement form does not decide them.

Keep the decision, then review retention

Record what was checked, by whom, against which task, on what date, and whether the evidence was accepted or clarification is needed. A check is not permanent: a qualification may expire, a worker may be replaced, or the work may change. Link a later recheck to the same decision instead of silently overwriting the old file.

The ICO's storage limitation guidance says personal data should not be kept longer than necessary, and the period should be justified for the purpose. Do not invent a universal retention period for training records; contract, claims, legal obligations and the type of record may affect it. Use a documented schedule and review it after the project ends. Our record-retention owner guide covers that broader task.

For document management, ask a vendor to demonstrate role-based access, evidence versioning, a recorded acceptance decision and retention controls against a real supplier-to-client scenario. Complys document-management software is the relevant commercial route. This article does not assert that Complys determines your lawful basis, redacts personal data automatically or independently validates qualifications.

Primary sources and integration gate

Before integration: Compare the whole current retention, software-permissions and worker-competence owners. If a current page already serves the supplier-to-client certificate-sharing task, merge there. Recheck ICO guidance after any Data (Use and Access) Act update.

Organise the records this involves

Complys gives you one place to store, track and share the compliance records and evidence described here. Legal and assessment decisions stay with you and the relevant authority.

Explore Compliance Document Management Software โ†’