Skip to main content
Guidance

Tell the Building Safety Regulator about completed fibre optic cabling work in an existing higher-risk building: privacy notice

Published 18 September 2026

Applies to England

This privacy notice tells you how the Building Safety Regulator (BSR) will use your personal information under UK GDPR and other UK data protection laws. It explains what you can expect us to do with your personal information when you use our services or have an interaction with us.

For the purposes of this privacy notice, the data controller is the Building Safety Regulator (BSR), Redgrave Court, Merton Road, Bootle L20 7HS. A data controller determines how and why personal data is processed.

Why we collect and use your personal data

We collect your personal data to deliver a range of responsibilities and services that BSR delivers. We use your data to:

  • process your application to register a high-rise building
  • process your application to register as a registered building inspector
  • process your application to register as a registered building control approver
  • process your submission of a mandatory occurrence report
  • gather feedback to improve our services
  • send email alerts to users who request them
  • allow you to access government services and make transactions

We may also use personal data where required for any safety or assurance related work BSR may need to undertake. For example, where needed in investigations and inspections relating to building safety.

What data we collect

The data we collect from you includes:

  • personal data, including your name, email address, telephone number, and address
  • your questions, queries or feedback, including your email address if you provide this to us
  • information on how you use our emails, for example, whether you open them and which links you click on

Where you provide your consent, we use Google Analytics cookies and Microsoft Clarity to collect information about how you use GOV.UK. This includes IP addresses.

Google Analytics processes information about:

  • the pages you visit
  • how long you spend on each page
  • how you got to the site
  • what you click on while you’re visiting the site

We make sure you cannot be directly identified by Google Analytics data. We do this by using Google Analytics’ IP address anonymisation feature and by removing any other personal data from the titles or URLs of the pages you visit.

We will not combine analytics information with other data sets in a way that would directly identify who you are.

With your permission, we use Microsoft Clarity to collect data about how you use our service. This information helps us to improve this service.

Microsoft is not allowed to use or share our analytics data with anyone.

Microsoft Clarity stores anonymised information about:

  • how you got to this page
  • any errors you see while using the service
  • JavaScript errors your device encountered
  • any fields, links or buttons you click on while using our service

How we get your information

Most of the personal information we process is directly provided by you when you use one of our services.

We may also receive personal information indirectly by someone who has provided your data through one of our services.

Article 6 of UK GDPR requires us to have an appropriate basis to process your data lawfully. We will use one of the following, depending on our purpose for using your data:

  • you have given informed consent to the processing of your personal data for one or more specific purposes (UK GDPR Article 6 (2)(a))
  • processing is necessary for the performance of a contract to which you are party, or in order to take steps at your request prior to entering into a contract (UK GDPR Article 6 (2)(b))
  • processing is necessary for compliance with a legal obligation to which BSR is subject (UK GDPR Article 6 (2)(c))
  • processing is necessary in order to protect your vital interests or that of another natural person (UK GDPR Article 6 (2)(d))
  • processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller (UK GDPR Article 6 (2)(e))
  • processing is necessary for the legitimate interests pursued by BSR or by a third party, except where these interests are overridden by your interests or fundamental rights and freedoms as a data subject (UK GDPR Article 6 (2)(f))

Where BSR processes particularly sensitive data about you (called special category data), we will use the following lawful basis:

  • processing is necessary for reasons of substantial public interest (UK GDPR Article 9 (2)(g)).
  • Schedule 1, Part 2, Paragraph 6 - Statutory and government purposes (Data Protection Act 2018)

How we might share your personal data

The data we collect may be shared with other government departments, agencies, and public bodies where necessary for our work to ensure building safety. It may also be shared with our technology suppliers who provide IT services to us.

Disclosure and sharing of personal information are made on a case-by-case basis. Only relevant information, specific to the purpose and circumstances, will be disclosed by us and with necessary controls in place.

We will share your data if we are required to do so by law, for example, by court order, to ensure the safety of people, or to prevent fraud or other crime. This may include sharing data with:

  • the Home Office
  • the courts
  • another regulatory body who can demonstrate that there is a legitimate purpose for the processing of your personal data

We may also disclose personal information on a discretionary basis for the purpose of legal proceedings or for obtaining legal advice.

We will not:

  • sell or rent your data to third parties
  • share your data with third parties for marketing purposes

How long we keep your data

We will only keep your personal data for as long as it is needed for the purposes set out in this document or for as long as the law requires us to.

Records that contain your personal information processed for your registration will be managed in accordance with BSR’s Business Classification Scheme and Disposal Policy.

Children’s privacy protection

Our service is not designed for or intentionally targeted at children 13 years of age or younger. We do not intentionally collect or maintain data about anyone under the age of 13. However, we may process a child’s personal information where it is supplied to us as part of a mandatory occurrence report (MOR), a complaint, or a regulatory investigation or intervention.

Where your data is processed and stored

We design, build and run our systems to make sure that your data is as safe as possible at all stages, both while it’s processed and when it’s stored.

BSR uses a Microsoft Azure tenant for storage. All personal data is stored in the UK and EEA European Economic Area.

How we protect your data and keep it secure

We are committed to doing all that we can to keep your data secure. Our systems meet appropriate industry and government security standards, and we comply with the relevant parts of legislation relating to data security. We have set up systems and processes to prevent unauthorised access or disclosure of your data – for example, we protect your data using varying levels of encryption.

BSR ensures that appropriate policy, training, technical and procedural measures are in place. These will include ensuring our buildings are secure and protected by adequate physical means. The areas restricted to our staff and staff of partner agencies are only accessible by those holding the appropriate identification and have legitimate reasons for entry.

We carry out regular monitoring and checks to protect our manual and electronic information systems from data loss and misuse and only permit access to them when there is a legitimate reason.

Our standard operating procedures, and policies contain guidelines as to what use may be made of any personal information. These procedures are reviewed regularly to ensure security is kept up to date.

We also make sure that any third parties that we deal with keep secure all personal data they process on our behalf.

Your rights

You have the right to request:

  • information about how your personal data is processed
  • access to that personal data
  • that anything inaccurate in your personal data is corrected without undue delay
  • to withdraw your consent, where applicable

You can also:

  • raise an objection about how your personal data is processed
  • request that your personal data is erased if there is no longer justification for us keeping it
  • ask that the processing of your personal data is restricted in certain circumstances

Read about your data protection rights. If you have any of these requests, contact us.

Contact us

BSR is the controller for the personal information we process, unless otherwise stated.

There are many ways you can contact us, including by phone, email, and post.

Our postal address

Building Safety Regulator, Redgrave Court, Merton Road, Bootle L20 7HS

Telephone: 0203 028 3547

Your right to complain

We work to high standards when it comes to processing your personal information. If you have queries or concerns, you can make a complaint to BSR and we’ll respond.

If you remain dissatisfied, you can complain to our Data Protection Officer (DPO) who monitors our compliance with UK data protection laws. Our DPO can be reached at dpo@buildingsafety.gov.uk.

You can also make a complaint to the Information Commissioner’s Office (the UK supervisory authority) about the way we process your personal information.

Changes to this privacy notice

We keep our privacy notice under regular review to make sure it is up-to-date and accurate.

It was last updated on 18 September 2026.