Back
Back
Back
Back
Back
Back
Back
Back
Select your country and language preference

The page you are trying to navigate to is only avalible in the following regions, please select a country and language to proceed.

Back

GDPR and Data Protection in Construction Workforce Management | MSite

UK Construction Data Compliance: How MSite Protects People, Projects and Performance. 

We design and operate our services in line with the UK GDPR, the Data Protection Act 2018, and other relevant UK data laws. 

Our platform architecture helps Principal Contractors meet their obligations as controllers under data protection law. 

We continually review and improve our technical and organisational measures as legislation, security practice and industry standards evolve. 

MSite Data Protection and Cybersecurity for UK Construction Projects 

UK Data Hosting and Cloud Security

All MSite data is hosted in secure, backed-up UK cloud environments with multiple layers of protection and disaster recovery in place. 

Hosting is within ISO 27001 and ISO 9001 certified data centres, ensuring compliance with UK government and industry requirements. 

Granular User Permissions and Role-Based Access Control

Within your organisation, MSite sets least-privilege access controls so teams can only view the information they need. For example, a supervisor may only see their team’s data, while a project manager can view aggregated site-wide information. 

This protects personal data and supports accountability under the UK GDPR.

Privacy-by-Design and Data Minimisation Principles 

MSite collects only the minimum personal data required for identity verification, access control, and workforce compliance.

Our system architecture and processing activities follow the privacy-by-design principles outlined in the UK GDPR. 

27001

ISO 27001-Certified Information Security Management 

MSite maintains robust, documented controls aligned with ISO 27001, helping us manage information security in a consistent, auditable, and reliable manner.

We operate a continuous improvement cycle for risk management, access control, and security awareness across our business. 

ISO-9001-Qualco-News-Story-800-x-533

Quality and Service Excellence: ISO 9001 Certification

Our ISO 9001 certification demonstrates MSite’s commitment to service excellence and continuous improvement in delivering secure, high-quality products and support to the UK construction industry. 

Biometric Data Use in Construction: MSite’s GDPR-Compliant Approach 

Biometric information such as facial recognition or fingerprints is classed as special category data under UK GDPR. 

Its use is permitted under specific lawful conditions, and MSite applies strict measures to ensure full compliance on behalf of our customers. 

Through the MSite Workforce App, workers can link their profile to their phone’s biometric (for example, Apple Face ID) and use Bluetooth to verify their identity on site in a contactless, GDPR-compliant way. 

No biometric data is stored on the device or transferred outside the UK.

Alternative access methods are always available for workers who prefer not to use biometrics. 

Understanding GDPR Roles: Controller vs Processor in Construction Data

  • Principal Contractor (Controller): Decides why and how personal data is processed and provides privacy notices to workers explaining data use, lawful basis and rights. 

  • MSite (Processor): Processes personal data only under the controller’s documented instructions, following a signed Data Protection Agreement with appropriate technical and organisational safeguards. 

  • Workers: Should contact their Principal Contractor first for rights requests (e.g. access, rectification, deletion, or objection). The Principal Contractor manages these requests and coordinates with MSite as required. 

For privacy queries, contact:  dpo@msite.comor write to: 

Infobric Limited t/a MSite, The Bunker, 25 Innovation Boulevard, Liverpool, Merseyside, England, L7 9PW. 

FAQs

No. The MSite Workforce App does not store biometric or personal data on your device. 

It simply uses your phone’s native biometric function(such as Apple Face ID) to confirm identity and connect securely to MSite’sUK-hosted servers. 
No biometric information leaves your device or is accessed by MSite.

In MSite’sconstruction workforce management system, the Principal Contractor acts as the data controller, deciding how and why data is processed. 
MSite acts as the data processor, carrying out processing only under the controller’s written instructions.

This structure ensures full accountability under the UK GDPR and the Data Protection Act 2018. 

MSite applies end-to-end encryption, UK-based hosting, and ISO 27001-certified information security controls.

All biometric and personal data is stored in secure environments, access is role-based, and our processing agreements align with UK GDPR and industry best practice. 

Data retention periods are set by the Principal Contractor (controller). 
MSite provides configurable retention settings and automated deletion routines, supporting each contractor’s policies and GDPR obligations. 

Contractors should clearly state: 

  • What personal data is collected 
  • The lawful basis for processing 
  • Retention periods and worker rights 
  • Identification of MSite as their appointed data processor 

Guidance for construction controllers is available on the ICO’s website. 

Yes. MSite’s reporting tools help evidence compliance with health and safety law, Right to Work checks, working time regulations, and Building Safety Act requirements. 

Contractors can use MSite data to demonstrate adherence to framework or client standards. 

MSite provides documentation and system detail on request to help Principal Contractors complete Data Protection Impact Assessments (DPIAs). 

While contractors remain responsible for conducting DPIAs, MSite supplies information on processing activities, risks, and mitigations to support the process. 

All MSite data is hosted in secure UK cloud environments with daily backups, disaster recovery, and 24/7 monitoring. 

MSite provides a complete audit trail of workforce credentials, attendance, and access events.

This helps contractors demonstrate compliance with the Building Safety Act and maintain a reliable record for Golden Thread documentation. 

Back to store
Close