IT and programming business: compliance checklist
Use this checklist to confirm your IT, programming or consultancy business (SIC division 62) meets its obligations. Work …
Computer programming, consultancy and IT services work is office- and screen-intensive, with display screen equipment, mental health and — in data centres — electrical and environmental risks. This is the universal spine. It takes you through your core workplace health and safety duties, fire safety, employers' liability insurance, equality, data protection and, where it applies, NIS digital service provider duties.
Assess display screen equipment workstations, manage stress and lone working, and carry out a fire risk assessment. Hold employers' liability insurance and follow equality and data protection law. If you run a large digital service, comply with the Network and Information Systems Regulations 2018.
Use this checklist to confirm your IT, programming or consultancy business (SIC division 62) meets its obligations. Work …
Understand your legal obligations when using, developing, or distributing software - including open source licensing, commercial agreements, and …
Legal requirements for selling online - including consumer contracts, pre-contract information, cancellation rights, and digital content regulations.
Complete IP protection guide for software businesses - automatic copyright for source code, patent eligibility under the technical …
Making glass, ceramics, cement, lime, concrete and stone products is machinery- and dust-intensive, and respirable crystalline silica is …
Running an IT or programming business means employing people who spend long hours at screens, often working remotely or in shifting teams. The duties in this guide apply to running the business and employing people, whatever services you provide. Display screen equipment assessments, mental health and wellbeing, and lone-working arrangements are the particular workplace risks in this sector. If you also provide a relevant digital service — an online marketplace, online search engine or cloud computing service — above the NIS threshold, you must comply with the Network and Information Systems Regulations 2018.
Health and safety law here is largely reserved. The Health and Safety Executive (HSE) is the regulator in Great Britain and the Health and Safety Executive for Northern Ireland (HSENI) in Northern Ireland; the underlying duties are equivalent across the UK. Work through the sections below in order.
The Health and Safety at Work etc. Act 1974 is the foundation. You must ensure, so far as is reasonably practicable, the health, safety and welfare of your employees and of anyone else affected by your work. In an IT business that means risk-assessing display screen equipment workstations under the Health and Safety (Display Screen Equipment) Regulations 1992 — workstation assessments, eye tests on request and adequate breaks — managing stress and mental health, and, if your people work from home or client sites, putting lone-working arrangements in place. If you have five or more employees, you must record your risk assessments in writing under the Management of Health and Safety at Work Regulations 1999.
Even in a low-risk office environment, you must carry out a fire risk assessment and maintain fire-safety arrangements. The responsible person — usually you as the employer or premises occupier — must identify fire hazards, assess the risk, and put measures in place to reduce it. The duty is devolved: the Regulatory Reform (Fire Safety) Order 2005 in England and Wales; the Fire (Scotland) Act 2005 and Fire Safety (Scotland) Regulations 2006 in Scotland; and the Fire and Rescue Services (Northern Ireland) Order 2006 in Northern Ireland.
As soon as you employ anyone, you must hold employers' liability compulsory insurance — normally at least £5 million of cover — and display or make available the certificate. This is a legal requirement across Great Britain, with an equivalent duty in Northern Ireland.
As an employer you must not discriminate against, harass or victimise people because of a protected characteristic. In Great Britain this is governed by the Equality Act 2010; in Northern Ireland separate equality legislation applies, enforced by the Equality Commission for Northern Ireland.
IT and programming businesses routinely process personal data — about your own staff, and often about your clients' customers and users too. You must comply with the UK GDPR and the Data Protection Act 2018 (as amended by the Data (Use and Access) Act 2025), and in most cases pay the data protection fee to the Information Commissioner's Office (ICO). If you process personal data on behalf of clients, you are a data processor and must meet the specific processor obligations under the UK GDPR. If you send marketing emails or texts, or set cookies and similar technologies in websites or apps, you must also comply with the Privacy and Electronic Communications Regulations 2003 (PECR), enforced by the ICO. This applies UK-wide.
If you provide one of the relevant digital services — an online marketplace, an online search engine, or a cloud computing service — and you meet the threshold (headquartered or with a representative in the UK, and not a micro or small enterprise), the Network and Information Systems Regulations 2018 require you to take appropriate and proportionate technical and organisational measures to manage the risks to your network and information systems, and to report significant incidents to the Information Commissioner's Office (ICO) as the competent authority. This applies UK-wide.
If your business operates a user-to-user service, a search service, or an online marketplace where users interact — for example a platform, app, forum or marketplace with reviews, messaging or user-generated content — you also have duties under the Online Safety Act 2023, regulated by Ofcom. The illegal-content duties have applied since 17 March 2025 and the duties to protect children since 25 July 2025. See Understanding the Online Safety Act to work out whether your service is in scope and what you must do. This applies UK-wide.
Assess display screen equipment workstations, manage stress and mental health risks, and put lone-working arrangements in place for remote and client-site workers under HASAWA 1974.
Identify fire hazards in your office or data centre, assess the risk, and put fire-safety measures in place under the regime for your nation.
Arrange at least £5 million of cover before anyone starts work, and pay the data protection fee unless you are exempt.
If you process personal data on behalf of clients, confirm you have data processing agreements in place and meet the UK GDPR processor obligations. If you do electronic marketing or set cookies, confirm you comply with PECR.
If you provide an online marketplace, search engine or cloud computing service and are not a micro or small enterprise, register with the ICO as a relevant digital service provider and put your NIS security measures in place.
If you run a user-to-user service, search service or marketplace where users interact, confirm whether you are in scope of the Online Safety Act 2023 and meet your Ofcom duties — see Understanding the Online Safety Act.
This spine covers the duties of running the business and employing people. Confirm you have covered everything with the IT and programming business: compliance checklist.
Authoritative health and safety, data protection, NIS and online safety guidance.