![]() |
People Group Services Limited Company Number: 11570329 |
MSP Visibility & Data Access Policy
Policy Statement
People Group Services Ltd (“PGS”) is committed to delivering full transparency, controlled visibility, and secure access to payroll and engagement data across Managed Service Provider (“MSP”) supply chains.
This policy establishes how data is shared, accessed, controlled, and protected within the PGS ecosystem to:
- Support compliance with Finance Act 2025 (Joint and Several Liability – “JSL”)
- Enable MSPs and agencies to verify payroll accuracy and HMRC payments
- Maintain strict adherence to **UK GDPR and the Data Protection Act 2018
- Protect worker confidentiality while ensuring necessary transparency across the supply chain
Scope
This policy applies to:
- Managed Service Providers (MSPs)
- Recruitment Agencies (including supplying agencies)
- End Clients (where applicable)
- Workers/Employees engaged via PGS group entities (including People Pay Limited and People Umbrella Limited)
- Internal PGS staff with authorised system access
Policy Objectives
The objectives of this policy are to:
- Provide controlled visibility of payroll and engagement data across the supply chain
- Enable MSPs to assess and mitigate financial exposure under JSL legislation
- Ensure data minimisation and role-based access controls
- Deliver real-time transparency using PGS portal technology
- Protect personal data through secure access, redaction, and audit controls
Data Visibility Principles
PGS operates under the following core principles:
Necessity-Based Access
Access is granted only where data is:
- Required for compliance
- Necessary for payment validation
- Relevant to supply chain assurance
Role-Based Access Control (RBAC)
Access is determined by role:
| Role | Access Level |
|---|---|
| MSP | Aggregated + worker-level (where required) |
| Agency | Own workers and assignments |
| End Client | Limited, anonymised or summary data |
| Worker | Personal data only |
| PGS Internal | Full access (restricted by function) |
Transparency with Control
- Data is visible on-demand via the portal
- Sensitive information is redacted where not required
- Full audit logs are maintained
Data Categories & Access Levels
Payroll Data
Accessible to MSPs and agencies (as appropriate):
- Gross pay (period and cumulative)
- PAYE tax deductions
- Employee National Insurance
- Employer National Insurance
- Net pay
- Apprenticeship Levy (where applicable)
HMRC Verification Data
PGS provides:
- Real-time validation via HMRC-aligned systems
- Payment confirmation via PGS PAYE Account Checker
- RTI submission visibility:
- Worker level
- Agency level
- Company level
Worker Documentation
Accessible subject to role and necessity:
- Payslips (with corresponding KIDs)
- Key Information Documents (KIDs)
- Contracts of employment / engagement
- Assignment details
Assignment & Supply Chain Data
Includes:
- Worker-to-agency-to-MSP mapping
- Assignment schedules
- Payroll provider identification (in-house or outsourced)
MSP-Specific Access Rights
MSPs are granted access to:
- Workers supplied under their contractual chain
- Associated payroll data and calculations
- Corresponding KIDs and assignment schedules
- HMRC payment validation evidence
This enables:
- Financial exposure assessment under JSL
- Validation of compliance across the supply chain
- Assurance that payroll obligations have been met
Data Redaction & Minimisation
Where full data visibility is not required:
- Personal identifiers may be partially masked
- Non-essential financial or contractual data is removed
- Reports may be provided in aggregated or anonymised format
PGS ensures compliance with:
- Data minimisation principles under UK GDPR
- Purpose limitation requirements
Worker Consent & Transparency
All workers engaged via PGS:
- Are informed that their data may be shared within the supply chain
- Provide explicit consent via contractual agreements and portal access
- Understand that data sharing is necessary for:
- Payroll processing
- Compliance validation
- JSL risk mitigation
Portal Access & Security Controls
Access to data is provided via the PGS portal, which includes:
Authentication
- Secure login credentials
- Multi-factor authentication (where enabled)
Access Controls
- Role-based permissions
- Organisation-level restrictions
- Controlled invitation system for MSPs and agencies
Audit Logging
All actions are recorded, including:
- Data access
- File uploads
- Data downloads
- User activity timestamps
Data Accuracy & Integrity
PGS ensures:
- All payroll calculations are validated against HMRC tools
- Data is processed in real time or near real time
- Errors are identified and corrected through automated checks
Data Retention
Data is retained in accordance with:
- Statutory payroll requirements (minimum 6 years)
- HMRC compliance obligations
- PGS Data Retention Policy
Data Sharing Restrictions
Data accessed under this policy:
- Must not be shared outside the authorised supply chain
- Must not be used for purposes beyond compliance and validation
- Must be handled in accordance with confidentiality obligations
Any misuse may result in:
- Access revocation
- Contractual breach action
- Regulatory reporting (where required)
Compliance & Governance
This policy aligns with:
- Finance Act 2025 (Chapter 11 ITEPA – Joint and Several Liability)
- UK GDPR
- Data Protection Act 2018
- HMRC Real Time Information (RTI) requirements
Breach & Incident Management
Any breach of this policy will be handled under the PGS Data Incident Response Policy and may include:
- Immediate suspension of access
- Investigation and audit
- Notification to affected parties
- Reporting to the Information Commissioner’s Office (ICO), where required
Review & Updates
This policy will be reviewed:
- Annually
- Following legislative or regulatory changes
- Following system or operational updates
Declaration
This Policy is approved by the Board of Directors of: People Group Services Limited Company Number: 11570329
Last updated: 31st March 2026

