People Group Services
CIS
POLICY DOCUMENT LIBRARY
Company Policy Documents
People Group Services Limited
Company Number: 11570329

GDPR Statement

Introduction

People Group Services Limited (“People Group”, “we”, “our”, or “us”) is committed to the highest standards of data protection, privacy, and information governance in accordance with:

  • UK General Data Protection Regulation (UK GDPR)
  • Data Protection Act 2018
  • PECR (Privacy and Electronic Communications Regulations)
  • Relevant HMRC payroll and employment reporting regulations

People Group operates a compliance-driven payroll and workforce services ecosystem, providing services including:

  • Professional Employment Organisation (PEO)
  • Umbrella employment services
  • PAYE payroll administration
  • Agency and MSP payroll reporting platforms
  • Compliance and workforce audit technology

The processing of personal data is fundamental to the delivery of these services. We therefore operate a privacy-by-design and compliance-by-default approach across all platforms, processes and systems.

Data Controller

The Data Controller responsible for the processing of personal data is:

People Group Services Limited
Registered in England & Wales

For data protection enquiries please contact:

Data Protection Officer / Compliance Team
Email: compliance@peoplegroupservices.com

Scope of Data Processing

People Group processes personal data relating to:

  • Workers and contractors
  • Agency employees
  • Recruitment consultants
  • MSP administrators
  • End-client representatives
  • Platform users
  • Referees and compliance validators

The types of personal data processed may include:

Identity Data

Name, date of birth, national insurance number, passport or identity documents.

Contact Data

Residential address, email address, telephone numbers.

Financial Data

Bank account details, payroll records, tax codes, statutory deductions.

Employment Data

Assignment information, agency details, contracts, working hours, payslips.

Compliance Data

Right-to-work verification, DBS information where applicable, professional qualifications.

Digital & Platform Data

IP addresses, system access logs, audit trails, portal activity.

Lawful Basis for Processing

People Group processes personal data under the following lawful bases defined in UK GDPR Article 6:

Contractual Necessity

Processing required to fulfil payroll, employment or service obligations.

Legal Obligation

Processing required to comply with statutory duties including:

  • HMRC Real Time Information (RTI)
  • PAYE tax reporting
  • National Insurance contributions
  • Employment law obligations
  • Anti-fraud and financial compliance requirements

Legitimate Interests

Processing required for:

  • Platform security
  • Fraud prevention
  • Compliance monitoring
  • Supply chain risk management

Consent

Where applicable for optional services such as referrals or marketing communications.

Data Sharing within the People Group Ecosystem

To operate a compliant workforce supply chain, personal data may be shared with:

  • Recruitment agencies
  • Managed Service Providers (MSPs)
  • End-clients (limited assignment data only)
  • HM Revenue & Customs
  • Pension providers
  • Insurance providers
  • Professional compliance auditors
  • Banking partners
  • Technology infrastructure providers

All third parties are subject to strict contractual data protection obligations.

Payroll Transparency & Compliance Monitoring

People Group operates a compliance-first payroll infrastructure which may include:

  • HMRC RTI reporting
  • Payroll verification technologies
  • Payslip validation tools
  • Supply chain compliance auditing
  • Joint and several liability mitigation reporting
  • Secure audit logs and reporting dashboards

These systems may process worker payroll data for the purpose of:

  • Tax compliance verification
  • Payroll accuracy validation
  • Risk monitoring across the supply chain
  • Regulatory compliance assurance

Such processing is undertaken strictly within legal and compliance frameworks.

Data Security & Safeguards

People Group applies a multi-layered security framework designed to protect personal data from unauthorised access, loss, or misuse.

Security measures include:

  • Encrypted data transmission
  • Secure cloud infrastructure
  • Role-based access controls
  • Audit logging of system access
  • Secure payroll system integrations
  • Continuous security monitoring
  • Restricted access to sensitive payroll data

All staff undergo data protection and confidentiality training.

Data Retention

Personal data is retained only for the period necessary to fulfil legal and contractual obligations.

Typical retention periods include:

Data Type

Retention Period

Payroll & tax records

Minimum 6 years

Employment records

Up to 6 years post-engagement

Compliance documentation

Up to 6 years

Platform logs

Security-based retention periods

Retention periods may be extended where required by legal claims, HMRC investigation, or regulatory requirements.

International Data Transfers

Where data is transferred outside the United Kingdom or EEA, People Group ensures appropriate safeguards are implemented including:

  • Standard Contractual Clauses (SCCs)
  • Approved adequacy mechanisms
  • Secure hosting providers with recognised compliance certification

Individual Rights

Under UK GDPR, individuals have the right to:

  • Access their personal data
  • Rectify inaccurate information
  • Request erasure where applicable
  • Restrict processing
  • Object to processing under legitimate interest
  • Data portability
  • Lodge a complaint with the Information Commissioner’s Office (ICO)

Requests should be submitted to:

compliance@peoplegroupservices.com

People Group will respond within one month in accordance with GDPR requirements.

Data Protection Governance

People Group maintains a formal data governance framework including:

  • Internal data protection policies
  • Data Protection Impact Assessments (DPIAs)
  • Vendor security assessments
  • Incident response procedures
  • Continuous compliance monitoring
  • Board-level compliance oversight

Data protection forms a core component of our Compliance Without Compromise philosophy.

Data Breach Management

Any suspected personal data breach is handled in accordance with our Data Incident Response Policy, including:

  • Immediate containment
  • Risk assessment
  • Regulatory reporting where required
  • Notification to affected parties where necessary

Cookies & Digital Tracking

People Group digital platforms may utilise cookies and tracking technologies to:

  • Improve platform functionality
  • Maintain user sessions
  • Protect against fraud and cyber threats

Further details are provided within our Cookie Policy.

Updates to this Statement

This statement may be updated periodically to reflect:

  • Changes in law
  • Platform development
  • Compliance improvements

The latest version will always be available on our website.

Contact Information

For any questions regarding this statement or data protection practices:

People Group Services Limited
Compliance & Data Protection Team

Email: compliance@peoplegroupservices.com

Compliance Commitment

People Group Services Limited operates under a compliance-first operating model, ensuring that personal data is processed responsibly, transparently, and securely across the entire workforce supply chain.

Declaration

This Policy is approved by the Board of Directors of: People Group Services Limited Company Number: 11570329

Last updated: 5th March 2026