Skip to main content
Safety Solutions TrainingSafety Solutions Training

Legislation guide

Workplace Safety Legislation Guide

Clear guidance on employer duties, preventative steps, and statutory compliance under UK law.

Practical recommendationNo obligationUK-wide delivery

Workplace safety legislation guidance

Practical recommendationNo obligationUK-wide delivery

Learning outcomes

What this guide will help you do

  • Identify the core health and safety duties that govern foreseeable frontline risk.
  • Separate legislation, regulator guidance and SST practical interpretation.
  • Recognise when equality, data protection, safeguarding, reporting or premises-security law needs separate attention.
  • Avoid treating training, technology or a checklist as proof of legal compliance.

How to use the guide

Start with the work and the foreseeable harm, not with a list of Acts. Identify who may be affected, the activities and environments involved, the known incident pattern and the controls currently relied upon. Then use the guide to locate the legal and official source that governs each part of the problem.

The same incident may engage several frameworks. A threat against a lone housing officer can involve health and safety management, internal incident reporting, possible police action, equality considerations, personal-data handling and safeguarding. Those frameworks should be connected without being treated as interchangeable.

  • Legal duty: a requirement created by legislation or regulations.
  • Official guidance: regulator or government material explaining expected practice.
  • Recognised practice: a standard or professional approach that may help shape controls.
  • SST interpretation: practical training and implementation guidance, clearly labelled as such.

Health and Safety at Work etc. Act 1974

Section 2 provides the central employer duty to ensure, so far as is reasonably practicable, employees' health, safety and welfare at work. For SST's subject areas, foreseeable violence, lone-working exposure, unsafe work design and ineffective emergency arrangements belong inside the employer's health and safety system rather than being treated only as staff behaviour problems.

The Act does not prescribe one conflict-management course, lone-worker device or communication script. Employers must decide proportionate controls from the actual risk. Training and technology can support those controls, but neither establishes compliance on its own.

Practical application for training and assurance

For training purposes, the important connection is between the employer's assessed system and the decisions staff make during real work. Delegates should understand the controls provided for their role, the limits of their authority, how to obtain help and when continuing the activity would move outside the agreed safe system.

Managers should be able to evidence that learning reflects foreseeable incidents and local arrangements rather than an off-the-shelf syllabus. Useful evidence includes role-specific objectives, attendance and competence records, scenario observations, supervision notes, worker consultation and changes made after incidents or control failures.

Public Order Act 1986

The Public Order Act 1986 defines specified public-order offences in England and Wales. It does not create a general workplace risk-management code for employers, and whether conduct meets an offence depends on the facts and the competent authorities.

For employers, its practical relevance is the response to threatening or abusive conduct connected with work. Preserve relevant information lawfully, support the affected worker, use 999 for immediate danger or a crime in progress, and use the appropriate non-emergency police route otherwise. Do not require staff to investigate suspected offences or remain in unsafe contact.

Practical application for training and assurance

Training should help staff respond safely to threatening or abusive conduct without asking them to make a legal finding. They need practical distinctions between poor behaviour, a breach of service boundaries, immediate danger and information that should be passed to police through the organisation's agreed route.

Managers should define who decides whether and how a police report is made, what information can be preserved, how staff leave or end contact and what happens afterwards. Exercises should test emergency calls, non-emergency reporting, witness information, body-worn or telephone evidence and support for the affected worker.

  • Set a clear emergency and police-reporting route for staff.
  • Record the incident and preserve available evidence without unlawful access or confrontation.
  • Review whether work design, staffing, information or security controls exposed staff to foreseeable risk.
  • Avoid stating that conduct is criminal unless that conclusion has been made by a competent authority.

Protection from Harassment Act 1997

The Protection from Harassment Act 1997 addresses courses of conduct involving harassment and includes civil and criminal routes. Application depends on the pattern, knowledge, facts and jurisdiction; an employer should not promise that a reported pattern meets a legal threshold.

Employers should provide a safe reporting route, assess continuing workplace exposure, preserve relevant records lawfully and consider police, legal, safeguarding or security advice where stalking, fixation, repeated contact or online targeting continues. The worker should not be asked to investigate or confront the person responsible.

Practical application for training and assurance

A single interaction may appear minor while a connected pattern creates serious risk. Training should therefore show staff how repeated calls, visits, messages, online posts, unwanted gifts, surveillance or contact through colleagues can be recorded and linked without requiring the worker to prove harassment.

Managers need a cross-team method for identifying repeated behaviour, restricting unnecessary access to staff details and agreeing a safety plan with the affected worker. Records should show escalation decisions, protective changes, advice obtained and review dates while maintaining confidentiality and lawful information handling.

  • Join repeated incidents across teams and channels so a course of conduct is not missed.
  • Protect contact details, schedules and lone-working information where targeting is foreseeable.
  • Agree escalation, communication and support arrangements with the affected worker.
  • Seek specialist advice where injunctions, criminal reporting or evidence handling may be relevant.

Management of Health and Safety at Work Regulations 1999

Regulation 3 requires a suitable and sufficient assessment of relevant risks. Other provisions support effective arrangements, competent assistance, procedures for serious and imminent danger, information, cooperation and worker capability. The practical requirement is a living control system that reflects real work, not a generic risk-assessment form stored without review.

Practical application for training and assurance

The risk assessment should drive the learning content. Staff need to understand the foreseeable hazards, who may face additional exposure, the preventive controls, the warning signs that conditions have changed and the action authorised when a planned control is missing or ineffective.

Managers should test whether information, supervision and emergency arrangements work across different shifts, locations and contact channels. Evidence should connect significant findings to induction, refresher learning, equipment checks, lone-worker monitoring, incident review and action ownership rather than treating the assessment as a static document.

  • Assess roles, tasks, locations, public contact and lone-working conditions.
  • Consider who may face different or additional exposure.
  • Record significant findings where the legal threshold applies.
  • Review after incidents, material change, control failure or new information.
  • Connect training content to the organisation's procedures and decision limits.

Equality Act 2010

The Equality Act 2010 governs protected characteristics and workplace discrimination, harassment and victimisation. For frontline work, employers should consider whether role design, reporting confidence, lone working, night work, public contact or management response creates different exposure or weaker protection for particular workers.

Employers can be liable for unlawful acts committed by workers in the course of employment, subject to the statutory framework and available defences. They should maintain effective equality and anti-harassment arrangements, provide safe reporting routes, respond consistently and avoid decisions that disadvantage workers because of a protected characteristic.

Practical application for training and assurance

Training should use realistic examples of discrimination, harassment and victimisation involving colleagues, managers and members of the public. Staff need accessible reporting options, confidence that reasonable concerns will be taken seriously and clear boundaries where protected-characteristic abuse occurs during service delivery.

Managers should examine whether risk controls, work allocation, lone working, reporting and post-incident support operate fairly in practice. Useful assurance includes equality-informed risk assessment, reasonable adjustments, alternative reporting routes, consistent investigation standards and review of patterns affecting particular groups.

Employment Rights Act 2025

How to update your risk assessments and training before legal duties shift to taking all reasonable steps. The Employment Rights Act 2025 introduces employment-law changes in stages across 2026 and 2027. Acas states that many provisions are not yet in force, so employers must separate current duties from future requirements and check the official timetable before changing legal statements.

For SST's scope, sexual-harassment disclosures became qualifying whistleblowing disclosures on 6 April 2026. Acas states that October 2026 changes are planned to introduce employer liability for third-party harassment unless all reasonable steps were taken and to strengthen the preventative sexual-harassment duty from reasonable steps to all reasonable steps. Employers should prepare policies, risk assessment, reporting and manager capability without presenting future provisions as already operative.

Practical application for training and assurance

Because provisions commence in stages, training material must separate current rights and duties from planned changes. Staff and managers should know the present whistleblowing and harassment routes, how qualifying disclosures are handled and where to obtain updated HR or legal advice.

The organisation should maintain a commencement tracker with named ownership and version-controlled policies, briefings and course materials. Assurance should show when content was checked, what changed, who was informed and how managers were prepared before each operative provision took effect.

Reporting of Injuries, Diseases and Dangerous Occurrences Regulations 2013

RIDDOR requires specified responsible persons to report defined work-related deaths, injuries, diseases and dangerous occurrences. HSE states that work-related violence resulting in death, a specified injury or a physical injury causing more than seven days' incapacity may be reportable, subject to the work-related test and the facts.

Internal recording must be broader than statutory reporting. Threats, verbal abuse, near misses and lower-level events can reveal patterns and control failures even when they are not reportable under RIDDOR. Managers should check current HSE criteria rather than using this guide as a reporting decision tool.

Practical application for training and assurance

Staff training should encourage prompt internal reporting of injuries, threats, abuse and near misses without suggesting that every event is reportable under RIDDOR. The responsible person, not the affected worker, should apply the current statutory criteria and obtain competent advice where the position is uncertain.

Managers should preserve the facts needed for that decision, including the work connection, injury, incapacity and event circumstances. The wider incident record should still drive welfare support and risk-control review even when the statutory reporting threshold is not met.

Children Act 1989

The Children Act 1989 is a principal foundation for child welfare and protection in England and Wales, including local-authority duties where there is reasonable cause to suspect significant harm. It does not impose the same safeguarding function on every employer.

Employers whose staff work with children should identify the statutory and sector guidance that applies to their organisation, maintain a verified reporting route, train staff to recognise and record concerns, and ensure urgent risks reach police or children's social care promptly. General personal-safety guidance must not replace child-protection procedures.

Practical application for training and assurance

Role-appropriate training should help staff notice indicators of harm, listen without leading questions, record the child's words accurately and act through the verified safeguarding route. It should also explain immediate-danger action and why staff must not investigate, promise secrecy or wait for proof.

Managers should evidence current safeguarding leads, deputy arrangements, local contact details, induction and refreshers, supervision and escalation checks. Scenarios should reflect the service and should test what happens when the usual lead is unavailable or the concern involves a colleague or manager.

  • Name the safeguarding lead and an alternative route when that person is unavailable.
  • Record facts, actions and decisions without conducting an unauthorised investigation.
  • Control information sharing according to safeguarding need and data-protection requirements.
  • Check jurisdiction and sector rules before relying on a generic procedure.

Adult Support and Protection (Scotland) Act 2007

This Act provides the principal Scottish framework for identifying and protecting adults at risk of harm. Statutory functions fall on councils and specified public bodies; not every employer becomes an adult-protection authority.

Employers operating in Scotland should know whether their service or staff fall within sector duties, maintain a route to the relevant council or emergency service, support staff to record concerns accurately and follow the current Scottish code of practice rather than an England-only safeguarding process.

Practical application for training and assurance

Scottish services need training grounded in the Act, current code of practice and relevant council arrangements. Staff should understand the adult-at-risk framework, recognise possible harm, take immediate safety action and pass factual information to the correct route without assuming an investigative role.

Managers should confirm which statutory or sector responsibilities apply to their organisation and maintain reliable council, police and emergency contacts. Evidence should include Scottish-specific learning, role levels, supervision, referral quality and lessons from cases rather than an unmodified England procedure.

Care Act 2014

In England, section 42 places an enquiry duty on a local authority where the statutory conditions for an adult at risk of abuse or neglect are met. The Act does not make every employer responsible for conducting that enquiry.

Employers in relevant services should maintain a reliable referral route, act on immediate danger, preserve factual records, cooperate with authorised safeguarding enquiries and ensure staff do not substitute an internal HR or incident process for the statutory safeguarding pathway.

Practical application for training and assurance

In England, learning should distinguish the responsibility to recognise and report a concern from the local authority's section 42 enquiry duty. Different staff groups require different depth: general awareness for all relevant staff, procedural competence for managers and specialist capability for people supporting or undertaking enquiries.

Employers should maintain a rolling programme supported by supervision and reflective practice. Assurance should show that temporary staff and volunteers are included, local procedures are current, referrals are reviewed for quality and internal HR or incident processes do not delay the statutory safeguarding pathway.

Social Services and Well-being (Wales) Act 2014

The Act is the Welsh statutory framework for social services and includes safeguarding provisions for adults and children. Duties differ according to the organisation and function, including duties on relevant partners to report specified concerns.

Employers in Wales should use current Welsh safeguarding procedures, identify whether they are a relevant partner or regulated provider, train staff on the correct local-authority route and avoid applying England-only Care Act wording to Welsh cases.

Practical application for training and assurance

Welsh training should use the terminology, reporting duties and safeguarding procedures applying in Wales. Staff need to recognise adult and child concerns, respond to immediate danger, record facts and understand the local-authority route relevant to their role and organisation.

Managers should verify whether the service is a relevant partner or regulated provider and tailor learning accordingly. Evidence should include Wales-specific materials, current regional procedures, referral contacts, supervision and learning from safeguarding practice reviews.

Modern Slavery Act 2015

The Act addresses slavery, servitude, forced labour and human trafficking. Section 54 requires qualifying commercial organisations meeting the statutory turnover and business tests to publish an annual slavery and human trafficking statement.

Employers should know whether the transparency requirement applies, maintain a route for concerns about exploitation in work or supply chains, protect people raising concerns and seek police, safeguarding or specialist advice where facts may indicate an offence. A modern-slavery statement is not a substitute for operational controls or safe reporting.

Practical application for training and assurance

Training should make exploitation recognisable in practical contexts such as recruitment debt, withheld documents or pay, controlled movement, fearful behaviour, unsafe accommodation and coercion within supply chains or service use. Staff must know that one indicator is not proof and that confrontation may increase danger.

Managers should define confidential reporting, urgent police or safeguarding routes and access to specialist advice. Procurement, HR and operational teams need connected but role-specific learning, with records showing how concerns, supplier due diligence and any transparency statement lead to operational action.

Domestic Abuse Act 2021

The Act provides statutory definitions and measures concerning domestic abuse. The statutory guidance recognises that domestic abuse can affect work, that perpetrators may target a victim at work and that employers have an important supporting role.

Employers should consider domestic-abuse risks within applicable health and safety, employment and safeguarding duties; provide a confidential route; agree practical safety and communication measures with the affected worker; signpost specialist support; and avoid asking managers to investigate abuse or mediate with a suspected perpetrator.

Practical application for training and assurance

Training should prepare managers to receive a disclosure calmly, respect the worker's choices and recognise that abuse may reach the workplace through calls, visits, stalking, surveillance or technology. It should avoid turning managers into investigators, counsellors or mediators.

Organisations should evidence confidential reporting, immediate-danger procedures, flexible workplace safety measures, secure handling of contact information and specialist signposting. Any plan should be agreed with the affected worker where possible and reviewed as circumstances change.

Data Protection Act 2018

The UK GDPR and Data Protection Act 2018 can apply when an employer collects, stores, shares or monitors information about workers and incidents. ICO guidance states that worker monitoring must be lawful and fair, and that high-risk processing may require a data protection impact assessment.

Employers should define the purpose and lawful basis, use necessary and proportionate monitoring, tell workers what is happening, limit access and retention, protect special-category data and complete a data protection impact assessment where required. A member of the public recording a worker and an employer monitoring workers are different issues and should not be treated as one legal question.

Practical application for training and assurance

Staff need practical guidance on the information they may collect during incidents, why it is needed, who may access it and when it can be shared. Training should cover accurate factual notes, special-category data, secure storage and the difference between preserving evidence and circulating it unnecessarily.

Managers should connect monitoring and recording decisions to a defined purpose, lawful basis, transparency, retention and access controls. Assurance may include privacy information, data-protection impact assessments where required, authorisation records, deletion schedules and review of inappropriate access or disclosure.

Terrorism (Protection of Premises) Act 2025

The Act, commonly known as Martyn's Law, received Royal Assent in 2025. Statutory guidance was published in 2026, but that guidance states that the substantive requirements of the Act have not yet been commenced and that further commencement details will be provided.

Organisations should use the Home Office material to understand potential scope and prepare proportionately, but must not present future requirements as already operational. Premises security and emergency preparedness should also remain distinct from general workplace-violence training.

Practical application for training and assurance

Preparatory learning should focus on proportionate emergency capability without describing uncommenced duties as current law. Staff need simple role-based actions for recognising urgent information, raising an alert, communicating, evacuating, invacuating or supporting people who may need assistance.

A named owner should monitor commencement and statutory guidance and translate confirmed requirements into premises-specific procedures. Exercises, debriefs, accessibility considerations, contractor arrangements and corrective actions provide stronger evidence than a generic awareness certificate.

Worker Protection (Amendment of Equality Act 2010) Act 2023

A practical guide to taking reasonable steps to prevent harassment and aggression in public-facing roles. The Act introduced the current positive duty for employers to take reasonable steps to prevent sexual harassment of workers in the course of employment. EHRC guidance emphasises that prevention requires active, evidence-based measures rather than a policy that is not implemented.

Employers should assess where sexual harassment may arise, including customer and third-party contact; maintain an effective policy and confidential reporting routes; train staff and managers; respond to concerns; monitor patterns; and review whether controls work. The current duty must remain distinct from stronger Employment Rights Act 2025 provisions that Acas says are planned for October 2026.

Practical application for training and assurance

Preventative training should cover what sexual harassment can look like, including conduct by customers, clients, patients or other third parties where that exposure is foreseeable. Workers need safe ways to report, intervene where appropriate, obtain support and understand protection from victimisation.

Managers require additional competence in receiving concerns, preserving confidentiality, taking immediate protective action and avoiding victim-blaming or informal suppression. Employers should evaluate learning, repeat it at suitable intervals and combine it with risk assessment, policy, leadership action and monitoring of themes.

  • Assess role, location, lone-working, power and third-party contact risks.
  • Make reporting routes safe, accessible and known to workers.
  • Train managers to respond without retaliation, victim-blaming or informal suppression.
  • Record actions and review themes while protecting confidentiality and personal data.

Lone working: no separate risk-assessment shortcut

HSE's current guidance explains that employers should include risks to lone workers in the general risk assessment and take steps to avoid or control those risks. A separate document is not automatically required, but lone-working conditions must be examined properly.

Effective arrangements may include supervision, contact, monitoring, escalation, emergency response, information sharing, training and suitable equipment. A phone, app or alarm is one possible control. Its value depends on coverage, usability, staff confidence, response arrangements and management follow-through.

Work-related violence and aggression

HSE defines work-related violence as abuse, threats or assault in circumstances relating to work. Its employer guidance connects the legal framework to assessment, preventive controls, incident response, reporting, support and learning.

Employers should not normalise abuse as part of a public-facing role. They need usable reporting, reliable action on patterns, support after incidents and review of the organisational factors that created or increased exposure.

HSE psychosocial risk guidance: work-related stress and work design

HSE describes psychosocial risk factors as features of work and workplace conditions that can affect workers' psychological response. Examples include excessive demands, tight deadlines, limited control, poor support, restricted social interaction and work systems that encourage people to work too quickly or skip breaks.

For employers, this sits alongside physical risk assessment rather than replacing it. HSE's work-related stress guidance identifies demands, control, support, relationships, role and change as six areas to assess and manage. The same issues can be especially important for lone workers, who may have less access to immediate support and fewer opportunities to raise concerns during the working day.

The practical test is whether the organisation has identified the work factors creating pressure, consulted workers, agreed actions, assigned ownership and checked whether those actions reduce risk. A wellbeing message or resilience course is not a substitute for changing unsafe work design or inadequate support arrangements.

Practical application for training and assurance

For training purposes, psychosocial risk should be treated as a feature of work design and management, not as a weakness in individual resilience. Staff and managers should be able to identify excessive demands, poor contact, isolation, limited control, inadequate support and repeated exposure to abuse, then use the agreed route to raise the concern.

Managers should connect HSE's six areas of work-related stress risk, demands, control, support, relationships, role and change, to the actual roles and locations they oversee. Evidence should include worker consultation, action ownership, review dates and changes to staffing, supervision, contact, recovery or escalation arrangements where the risk assessment shows a problem.

  • Include workload, work patterns, isolation, contact arrangements and exposure to abuse in risk assessment.
  • Give lone workers reliable ways to seek advice, report concerns and receive timely support.
  • Review whether staffing, supervision, escalation and recovery arrangements match the foreseeable demands of the role.
  • Use incident, absence, turnover and worker feedback carefully, protecting confidentiality and avoiding assumptions about individual resilience.

ISO 45003:2021 and psychological harm from abuse and aggression

ISO 45003:2021 is international guidance for managing psychosocial risk within an occupational health and safety management system based on ISO 45001. It is not UK legislation and it does not create a standalone legal duty, but it provides a useful framework for organisations that want psychological health and safety to be managed with the same discipline as other workplace risks.

Applied to public-facing and lone-working roles, violence and aggression can be treated as a psychosocial hazard as well as a possible physical-safety hazard. Verbal abuse, threats, bullying, harassment, victimisation and repeated exposure to hostile behaviour may affect psychological safety, dignity and wellbeing even when there is no physical injury. The organisation should therefore consider foreseeable psychological harm when it assesses work-related violence.

The useful shift is from treating abuse as an unavoidable service problem to examining the work system around it. This includes lone-worker support, staffing, workload, contact arrangements, leadership, reporting routes, conflict-resolution capability, post-incident support and whether workers can withdraw or escalate without fear of blame or reprisal.

Practical application for training and assurance

ISO 45003 can help an organisation examine the psychological effects of violence and aggression alongside physical injury. Training should use realistic examples of verbal abuse, threats, bullying, harassment, victimisation and repeated hostile contact, and should show staff how to report, withdraw and obtain support without requiring them to diagnose a mental-health condition or prove a legal case.

Managers should use the standard's psychosocial-risk perspective to examine root causes and system controls: lone-worker arrangements, staffing, workload, leadership, communication, conflict-resolution capability, incident learning and post-incident support. Evidence should show worker consultation, action ownership and review of whether controls reduce exposure, rather than relying on attendance at resilience training as proof of prevention.

  • Assess psychological as well as physical effects of abuse, threats and aggression, including repeated lower-level incidents.
  • Identify work-system factors that increase exposure, such as isolation, poor support, high-pressure public-facing work or inadequate training.
  • Provide reporting routes for abuse, threats and near misses that workers can use without fear of retaliation.
  • Use worker consultation, incident learning and management review to improve the system rather than placing responsibility on individual resilience alone.

What a defensible employer system looks like

The legal frameworks differ, but the practical management disciplines connect. A defensible system makes ownership, evidence and review visible without claiming that paperwork guarantees an outcome.

  • Named ownership for each risk and legal subject.
  • Risk assessments based on actual work and worker consultation.
  • Controls addressing work design before relying on individual skill.
  • Clear emergency, withdrawal, reporting and support procedures.
  • Training linked to local roles, equipment, limits and escalation routes.
  • Incident records that support learning and statutory reporting decisions.
  • Scheduled and event-driven review of law, guidance and operational evidence.

Related resources

Discuss your requirements

Ready to equip your team with practical safety skills?

Contact our team to discuss your training needs, review course options, or request a clear, no-obligation proposal.

Practical recommendationNo obligationUK-wide delivery