Saltar al contenido

Regulation and sustainability

When the document you ask for carries personal data

You ask a company for a certificate and it arrives with names, ID numbers and payslips inside. From then on, that is yours to look after.

Updated on 13/08/2026

You ask for «the subcontractor's paperwork» and a folder arrives with the worker list, their ID numbers, their contracts and sometimes their payslips. Nobody asked for it that way, but it is now inside. And what is inside is data about people who do not work for you and whom you have never asked anything.

The three questions to ask before requesting

QuestionIf the answer is weak…
What do I need this for?Do not ask for it. This filter avoids the most paper
Would a version with less data do?Ask for that one: it almost always exists
How long do I need it?If you cannot answer, it will stay forever
Who in my company needs to see it?«Everyone» is never the right answer

Important

The practical rule that settles 90 % of cases: **ask for the proof, not the whole document**. To know someone is registered and covered you almost never need their payslip; to know a driver may drive that lorry you do not need their full medical history. Every extra piece of data entering your files is data you must protect, justify and one day delete — and that can be demanded back from you. **The paper you never ask for is the only one that never causes trouble.**

What does need setting up

  1. 1

    State what you need it for, in the request itself

    One line. It is what turns a demand into a justified request.

  2. 2

    Give the document an expiry date

    Keeping things «just in case» is the decision nobody remembers taking.

  3. 3

    Restrict who can open it

    Sensitive material does not live in a folder shared with the whole office.

  4. 4

    And delete when due, recording that you did

    Deleting without a trace leaves you unable to show you complied.

Watch out

The point most often missed: **whoever sends you the document cannot send whatever they like either**. If your request is so open that it nudges them into oversharing, you have created a problem for them and one for yourself. That is why a specific request —«the clearance certificate», not «the employment paperwork»— is not just convenience: it is how both sides end up holding only what is needed. And when too much arrives, the healthy move is to say so and ask for the reduced version, not to file it quietly.

When someone asks for their data back

Worth knowing

What data may be required from a third party, on what basis and for how long it may be kept is data-protection territory and depends on context —a subcontractor on site is not the same as a service provider—. **Your adviser or DPO settles that**; here we cover the part that is genuinely yours: asking for less and knowing what you hold.

Can I ask for my supplier's workers' ID numbers?

It depends what for. Ask first whether a certificate from the supplier would do.

They sent more than I asked for — do I delete it?

Say so, ask for the reduced version and record it. Filing it quietly is the worst option.

Is a shared folder good enough?

Not for personal data. The question is not where it sits, it is who can open it.

A real case

The situation

You ask a subcontractor for «the employment paperwork» and it arrives with twelve people's payslips.

What you do

  1. Replaces the request with the specific certificate needed
  2. Asks for the reduced version and records it

What you get

The file stops holding payslips of people who do not work for you.

The situation

Someone who worked for a subcontractor asks what data you hold about them.

What you do

  1. Searches their name across the files and answers with what is held and why

What you get

The reply goes out in hours because it is on record who sent each document and for what purpose.

The situation

A certificate containing personal data has sat for four years in a folder shared with the whole office.

What you do

  1. Restricts who can open it and sets a deletion date

What you get

Sensitive material stops being within reach of people who do not need it, and now has an expiry.

The situation

A certificate arrives with payslips inside and is filed as-is.

What you do

  1. Checks what it contains before storing it

What you get

You know what you are holding.

The situation

The whole team can open that folder.

What you do

  1. Limits who sees anything containing personal data

What you get

Access stops being general by default.

The situation

It is kept indefinitely just in case.

What you do

  1. Applies a retention period

What you get

What is kept has a reason and a period.

This article answers

  • can i ask for my supplier's workers id
  • subcontractor paperwork with personal data
  • how long do i keep third party data
  • what data can i require from a supplier