Enforcement expected spring 2027
Data and security

Where the records live, and who can see them

Musterlog holds names of staff, dates of training and photographs of premises. That is personal data and it belongs to the organisation that collected it, not to us. This page says plainly how that works.

Short answer

You are the controller of your records. Musterlog Ltd is the processor. Data is held in the UK. Nobody outside your organisation sees an individual record unless you decide they should. Musterlog Ltd is currently in formation, and registration with the Information Commissioner's Office will be in place before any customer records are held.

What is actually stored

HeldWhy
Staff name and role, per siteStandard tier requires that staff are made aware of the procedures. A record of awareness needs to identify who.
Training completion date and signatureEvidence that awareness happened, and when.
Procedure documents and their versionsSo you can show what was in force on a given date.
Drill entries, with photographsEvidence a drill took place. Photographs are of premises, not of people.
Site name, address and busiest reasonable occupancyTo establish scope and tier per premises.

Musterlog does not ask for dates of birth, home addresses, right to work documents, payroll numbers or anything else that is not needed to evidence awareness. If a field is not required by the duty, it is not collected.

Controller and processor

Under UK GDPR your organisation is the controller: you decide what is collected and why. Musterlog Ltd is the processor, acting on your instructions under a written agreement. That agreement covers retention, deletion, sub-processors, breach notification and what happens at the end of the licence.

You can export everything, at any time, in a format you can read without us. If the licence ends, you take your records with you and we delete our copy. A records product that holds your evidence hostage is not a records product.

Where an insurer or broker funds the licence

This is the arrangement most likely to go wrong, so it is worth being explicit. When a broker funds Musterlog across a book, the policyholder remains the controller of their own records. The funder sees aggregate figures only: how much of the funded book has procedures in place, training completion rates, and which sign-ups have never been opened. They do not see named staff, the content of anyone's procedures, or any assessment of whether what a policyholder did was adequate. Policyholders are told exactly this before they start. The full broker model.

Practical measures

  • Data held in the UK, with encryption in transit and at rest.
  • Access scoped per site, so a site manager sees their own premises and not the estate.
  • An audit trail on record changes, because a record you can silently edit afterwards is worth less as evidence.
  • Retention set by you, with a default that keeps training evidence for as long as the duty could reasonably be examined.

Being straight about maturity

Musterlog is an early product built by a small operation. It does not hold ISO 27001 or a SOC 2 report, and claiming otherwise would be a lie you could check. If your procurement process requires those, we are not yet a supplier you can buy from, and that is a reasonable position for you to take.

What is planned before any customer records are held is ICO registration, a written processor agreement and UK hosting. What is in place today is a willingness to answer a security questionnaire honestly, including the questions where the answer is no.

Questions about data handling are best asked directly rather than inferred from a page like this. Ask them.