---
id: KB-NO-023
url: https://app.codecontract.io/help/regulation/documents-that-carry-personal-data
idioma: en
categoria: normativa
subcategoria: cadena
audiencia: usuario
nivel: intermedio
actualizado: 2026-08-13
tambienEn: [es]
relacionados: [KB-NO-013, KB-TZ-006]
citadoPor: [KB-PR-025, KB-NO-027]
---

# When the document you ask for carries personal data

_You ask a company for a certificate and it arrives with names, ID numbers and payslips inside. From then on, that is yours to look after._

**Responde a:** can i ask for my supplier's workers id · subcontractor paperwork with personal data · how long do i keep third party data · what data can i require from a supplier

You ask for «the subcontractor's paperwork» and a folder arrives with the worker list, their ID numbers, their contracts and sometimes their payslips. Nobody asked for it that way, but it is now inside. And what is inside is data about people who do not work for you and whom you have never asked anything.

## The three questions to ask before requesting

| Question | If the answer is weak… |
| --- | --- |
| What do I need this for? | Do not ask for it. This filter avoids the most paper |
| Would a version with less data do? | Ask for that one: it almost always exists |
| How long do I need it? | If you cannot answer, it will stay forever |
| Who in my company needs to see it? | «Everyone» is never the right answer |

> [!IMPORTANT]
> The practical rule that settles 90 % of cases: **ask for the proof, not the whole document**. To know someone is registered and covered you almost never need their payslip; to know a driver may drive that lorry you do not need their full medical history. Every extra piece of data entering your files is data you must protect, justify and one day delete — and that can be demanded back from you. **The paper you never ask for is the only one that never causes trouble.**

## What does need setting up

1. **State what you need it for, in the request itself** — One line. It is what turns a demand into a justified request.
2. **Give the document an expiry date** — Keeping things «just in case» is the decision nobody remembers taking.
3. **Restrict who can open it** — Sensitive material does not live in a folder shared with the whole office.
4. **And delete when due, recording that you did** — Deleting without a trace leaves you unable to show you complied.

> [!WARNING]
> The point most often missed: **whoever sends you the document cannot send whatever they like either**. If your request is so open that it nudges them into oversharing, you have created a problem for them and one for yourself. That is why a specific request —«the clearance certificate», not «the employment paperwork»— is not just convenience: it is how both sides end up holding only what is needed. And when too much arrives, the healthy move is to say so and ask for the reduced version, not to file it quietly.

## When someone asks for their data back

**En corto**

- It will happen: someone will ask what you hold about them, and it will not be your employee.
- Answering quickly hinges on one thing: knowing which files it sits in and why.
- And on having recorded who sent it and for what purpose, which is what justifies holding it.

> [!NOTE]
> What data may be required from a third party, on what basis and for how long it may be kept is data-protection territory and depends on context —a subcontractor on site is not the same as a service provider—. **Your adviser or DPO settles that**; here we cover the part that is genuinely yours: asking for less and knowing what you hold.

**Can I ask for my supplier's workers' ID numbers?**

It depends what for. Ask first whether a certificate from the supplier would do.

**They sent more than I asked for — do I delete it?**

Say so, ask for the reduced version and record it. Filing it quietly is the worst option.

**Is a shared folder good enough?**

Not for personal data. The question is not where it sits, it is who can open it.

## Ejemplos

**You ask a subcontractor for «the employment paperwork» and it arrives with twelve people's payslips.**

- Replaces the request with the specific certificate needed
- Asks for the reduced version and records it

→ The file stops holding payslips of people who do not work for you.

**Someone who worked for a subcontractor asks what data you hold about them.**

- Searches their name across the files and answers with what is held and why

→ The reply goes out in hours because it is on record who sent each document and for what purpose.

**A certificate containing personal data has sat for four years in a folder shared with the whole office.**

- Restricts who can open it and sets a deletion date

→ Sensitive material stops being within reach of people who do not need it, and now has an expiry.

**A certificate arrives with payslips inside and is filed as-is.**

- Checks what it contains before storing it

→ You know what you are holding.

**The whole team can open that folder.**

- Limits who sees anything containing personal data

→ Access stops being general by default.

**It is kept indefinitely just in case.**

- Applies a retention period

→ What is kept has a reason and a period.
