Division 62
IT & Software
Requirements for all it & software
These requirements apply to all business activities in this division.
Health and Safety at Work etc. Act 1974 — general duties
Enforced by HSE
Health and Safety at Work etc. Act 1974
General duty to ensure the health, safety and welfare of employees and others affected by the business. For an office-based IT firm this is mostly display-screen-equipment (DSE) assessments and general workplace safety.
Employers' Liability (Compulsory) Insurance
Enforced by HSE
Employers' Liability (Compulsory Insurance) Act 1969
Required for any business employing at least one person. A sole-trader contractor with no employees is exempt.
UK GDPR + Data Protection Act 2018
Enforced by ICO
Data Protection Act 2018; UK General Data Protection Regulation (retained EU law)
Central to the industry. IT firms process personal data both as controllers (their own staff and customers) and, critically, as data PROCESSORS handling client data under software, hosting, support and consultancy contracts — which requires Article 28 processor contracts, security measures (Article 32) and breach-assistance duties. ICO data protection fee payable unless exempt.
PECR rules on electronic marketing
Enforced by ICO
Privacy and Electronic Communications (EC Directive) Regulations 2003
You need consent before sending marketing by email or text to an individual, unless they are an existing customer who bought something similar from you and was given a chance to opt out — the soft opt-in. Every message must say who it is from and give a free way to unsubscribe. Live and automated marketing calls have their own rules, including screening against the Telephone Preference Service. The ICO enforces this alongside the UK GDPR. Consent for cookies and similar tracking is a separate duty and is covered by the cross-sector PECR cookies rule.
Equality Act 2010 — protected characteristics
Enforced by EHRC
Equality Act 2010
No discrimination, harassment or victimisation in employment or in services provided to the public across the nine protected characteristics. For public-sector clients, digital products are also expected to meet accessibility standards (WCAG / PSBAR 2018), though that obligation falls on the public body, not the supplier.
Regulatory Reform (Fire Safety) Order 2005
Enforced by LOCAL_FIRE_AUTHORITY
Regulatory Reform (Fire Safety) Order 2005
The 'responsible person' for any office or other non-domestic workplace must carry out a fire risk assessment and maintain fire safety arrangements. Devolved variants: Fire (Scotland) Act 2005; Fire and Rescue Services (NI) Order 2006.