The DBS Code of Practice sets rules for how you must:
Receive, use, share, store, and delete information from DBS checks
It applies to:
All Registered Bodies with DBS under section 120 of the Police Act 1997
Recipients of Update Service information under section 116A
Key duties include:
Having a written policy explaining how you handle DBS data securely
Ensuring you only share DBS information with people who need to know for legitimate purposes
Holding DBS information for no longer than necessary (normally no more than 6 months post‑decision)
Protecting the information in line with the Data Protection Act and broader data protection law
Failing to follow the Code could:
Lead to ICO enforcement if data protection is breached
Damage your organisation’s reputation
You must also respect DBS consent codes or share codes, which allow you to view an online certificate but must not be used to print it.
