Skip to main content

What the DBS Code of Practice Is

Summarise the DBS Code of Practice obligations for handling, sharing, storing and deleting DBS information, and why following it protects your organisation.

Written by Ben Nicholas

The DBS Code of Practice sets rules for how you must:

  • Receive, use, share, store, and delete information from DBS checks

It applies to:

  • All Registered Bodies with DBS under section 120 of the Police Act 1997

  • Recipients of Update Service information under section 116A

Key duties include:

  • Having a written policy explaining how you handle DBS data securely

  • Ensuring you only share DBS information with people who need to know for legitimate purposes

  • Holding DBS information for no longer than necessary (normally no more than 6 months post‑decision)

  • Protecting the information in line with the Data Protection Act and broader data protection law

Failing to follow the Code could:

  • Lead to ICO enforcement if data protection is breached

  • Damage your organisation’s reputation

You must also respect DBS consent codes or share codes, which allow you to view an online certificate but must not be used to print it.

Did this answer your question?