People Group Services
CIS
POLICY DOCUMENT LIBRARY
Company Policy Documents
People Group Services Limited
Company Number: 11570329

MSP Visibility & Data Access Policy

Policy Statement

People Group Services Ltd (“PGS”) is committed to delivering full transparency, controlled visibility, and secure access to payroll and engagement data across Managed Service Provider (“MSP”) supply chains.

This policy establishes how data is shared, accessed, controlled, and protected within the PGS ecosystem to:

  • Support compliance with Finance Act 2025 (Joint and Several Liability – “JSL”)
  • Enable MSPs and agencies to verify payroll accuracy and HMRC payments
  • Maintain strict adherence to **UK GDPR and the Data Protection Act 2018
  • Protect worker confidentiality while ensuring necessary transparency across the supply chain

Scope

This policy applies to:

  • Managed Service Providers (MSPs)
  • Recruitment Agencies (including supplying agencies)
  • End Clients (where applicable)
  • Workers/Employees engaged via PGS group entities (including People Pay Limited and People Umbrella Limited)
  • Internal PGS staff with authorised system access

Policy Objectives

The objectives of this policy are to:

  1. Provide controlled visibility of payroll and engagement data across the supply chain
  2. Enable MSPs to assess and mitigate financial exposure under JSL legislation
  3. Ensure data minimisation and role-based access controls
  4. Deliver real-time transparency using PGS portal technology
  5. Protect personal data through secure access, redaction, and audit controls

Data Visibility Principles

PGS operates under the following core principles:

Necessity-Based Access

Access is granted only where data is:

  • Required for compliance
  • Necessary for payment validation
  • Relevant to supply chain assurance

Role-Based Access Control (RBAC)

Access is determined by role:

Role Access Level
MSP Aggregated + worker-level (where required)
Agency Own workers and assignments
End Client Limited, anonymised or summary data
Worker Personal data only
PGS Internal Full access (restricted by function)

Transparency with Control

  • Data is visible on-demand via the portal
  • Sensitive information is redacted where not required
  • Full audit logs are maintained

Data Categories & Access Levels

Payroll Data

Accessible to MSPs and agencies (as appropriate):

  • Gross pay (period and cumulative)
  • PAYE tax deductions
  • Employee National Insurance
  • Employer National Insurance
  • Net pay
  • Apprenticeship Levy (where applicable)

HMRC Verification Data

PGS provides:

  • Real-time validation via HMRC-aligned systems
  • Payment confirmation via PGS PAYE Account Checker
  • RTI submission visibility:
    • Worker level
    • Agency level
    • Company level

Worker Documentation

Accessible subject to role and necessity:

  • Payslips (with corresponding KIDs)
  • Key Information Documents (KIDs)
  • Contracts of employment / engagement
  • Assignment details

Assignment & Supply Chain Data

Includes:

  • Worker-to-agency-to-MSP mapping
  • Assignment schedules
  • Payroll provider identification (in-house or outsourced)

MSP-Specific Access Rights

MSPs are granted access to:

  • Workers supplied under their contractual chain
  • Associated payroll data and calculations
  • Corresponding KIDs and assignment schedules
  • HMRC payment validation evidence

This enables:

  • Financial exposure assessment under JSL
  • Validation of compliance across the supply chain
  • Assurance that payroll obligations have been met

Data Redaction & Minimisation

Where full data visibility is not required:

  • Personal identifiers may be partially masked
  • Non-essential financial or contractual data is removed
  • Reports may be provided in aggregated or anonymised format

PGS ensures compliance with:

  • Data minimisation principles under UK GDPR
  • Purpose limitation requirements

Worker Consent & Transparency

All workers engaged via PGS:

  • Are informed that their data may be shared within the supply chain
  • Provide explicit consent via contractual agreements and portal access
  • Understand that data sharing is necessary for:
    • Payroll processing
    • Compliance validation
    • JSL risk mitigation

Portal Access & Security Controls

Access to data is provided via the PGS portal, which includes:

Authentication

  • Secure login credentials
  • Multi-factor authentication (where enabled)

Access Controls

  • Role-based permissions
  • Organisation-level restrictions
  • Controlled invitation system for MSPs and agencies

Audit Logging

All actions are recorded, including:

  • Data access
  • File uploads
  • Data downloads
  • User activity timestamps

Data Accuracy & Integrity

PGS ensures:

  • All payroll calculations are validated against HMRC tools
  • Data is processed in real time or near real time
  • Errors are identified and corrected through automated checks

Data Retention

Data is retained in accordance with:

  • Statutory payroll requirements (minimum 6 years)
  • HMRC compliance obligations
  • PGS Data Retention Policy

Data Sharing Restrictions

Data accessed under this policy:

  • Must not be shared outside the authorised supply chain
  • Must not be used for purposes beyond compliance and validation
  • Must be handled in accordance with confidentiality obligations

Any misuse may result in:

  • Access revocation
  • Contractual breach action
  • Regulatory reporting (where required)

Compliance & Governance

This policy aligns with:

  • Finance Act 2025 (Chapter 11 ITEPA – Joint and Several Liability)
  • UK GDPR
  • Data Protection Act 2018
  • HMRC Real Time Information (RTI) requirements

Breach & Incident Management

Any breach of this policy will be handled under the PGS Data Incident Response Policy and may include:

  • Immediate suspension of access
  • Investigation and audit
  • Notification to affected parties
  • Reporting to the Information Commissioner’s Office (ICO), where required

Review & Updates

This policy will be reviewed:

  • Annually
  • Following legislative or regulatory changes
  • Following system or operational updates

Declaration

This Policy is approved by the Board of Directors of: People Group Services Limited Company Number: 11570329

Last updated: 31st March 2026