Employer's guide to reference requests

Reference requests sit in an awkward legal middle ground. There is often no obligation to respond to them, however, once an employer chooses to do so, it may lead to a range of legal responsibilities that are frequently underestimated.
HR
Employment law
Published: 21 September 202610 minutes read

An ex employee's new employer emails asking for a reference. A line manager takes a quick phone call from a recruiter and answers a few "off the record" questions about someone who left last year. HR receives a template from a bank requesting six years of employment history for a candidate applying to a senior role.

Each of these scenarios carries different legal risks, yet some businesses handle them informally, inconsistently, or without a written policy. That inconsistency is often where risk creeps in. Handled badly, a reference can expose the former employer to claims and leave future employers hiring someone whose history has been fabricated.

Reference practice has also become more scrutinised as data protection regulators tighten guidance. The Information Commissioner's Office updated its right of access guidance in December 2025 [1], and the Data (Use and Access) Act 2025 came into force in February 2026, changing how employers must respond to subject access requests that touch on reference material [2].

Summary

  • GB employers are generally not legally required to provide references. Exceptions apply for FCA- and PRA-regulated firms, roles under the Senior Managers and Certification Regime, and any contractual or settlement obligations [3].
  • Once an employer chooses to provide a reference, it should be true, accurate, fair, and not misleading [4].
  • Employers may owe a duty of care to both the subject and the requesting employer. Providing incorrect information about a dismissed employee can expose employers to claims [5].
  • Centralised handling may reduce risks. Informal verbal references from line managers are one of the most common sources of reference-related claims [5].
  • Data protection rules apply. Personal data in references require a lawful basis, and confidential references are treated differently under UK GDPR [6].
  • Reference fraud is a growing concern. Cifas research published in 2025 found that 19% of UK professionals have either used a fraudulent reference house or know someone who has, and 30% consider the practice justifiable [7].
  • FCA rules under SYSC 22 require regulatory references covering six years, with no time limit on serious misconduct [8].

Is there a duty to provide a reference?

For most employers in Great Britain, there is no general obligation to provide a reference. An employer may therefore decide, as a matter of policy, whether it will provide references on request, provide only limited factual references, or decline reference requests altogether. However, there are circumstances in which a reference may be required.

  • Contractual obligation. If the employment contract or a separate agreement requires a reference in a specified form, the employer must provide it. Settlement agreements commonly contain an agreed form of reference annexed to the agreement. Where this occurs, an employer should take care to comply with the agreed wording and any associated obligations. Departing from that wording - even verbally - could, depending on the circumstances and the terms of the agreement, create contractual risk [9].
  • Regulatory obligation. Firms authorised by the Financial Conduct Authority (FCA) and Prudential Regulation Authority (PRA) may be required to provide regulatory references in prescribed form for candidates entering specified regulated roles. These are governed by FCA Handbook SYSC 22 and cover a minimum of six years of employment history, with no time limit on the disclosure of serious misconduct [8].
  • Risks associated with discrimination. Refusing selectively in a way that ties back to a protected characteristic could give rise to a discrimination or victimisation claim under the Equality Act 2010, or could amount to a detriment on other protected grounds such as whistleblowing or trade union activity. Whether a claim could arise, and the nature of that claim, will depend on the facts [10].

The practical implication tends to be straightforward: consistency might matter more than the decision itself. An employer may be able to decide to provide references for everyone, provide references for no one, or provide only factual "tombstone" references. What can create risk is providing detailed references for some employees and refusing or downgrading for others.

The duties that apply once a reference is given

Once an employer chooses to provide a reference, three distinct duties apply.

The duty to the subject of the reference

In Spring v Guardian Assurance (1994), the House of Lords established that an employer providing a reference owes a duty of care in the tort of negligence to the subject of that reference [4]. The employer must take reasonable care in preparing it, which typically involves making reasonable enquiries into the factual basis of any statements before including them. A former employee who suffers financial loss - typically the withdrawal of a job offer - because of a negligently prepared reference can bring a claim for damages.

The duty to the requesting employer

The employer receiving a reference also may have legal recourse if it is misled. A referring employer who provides a glowing reference for someone dismissed for misconduct, and the new employer relies on it and suffers loss, may face a claim from the new employer for negligent misstatement [5]. This is part of the reason why many organisations have moved to short, factual references only - it reduces the temptation to soften the reality of a departure to help someone move on.

The duty under data protection law

References contain personal data. Under UK GDPR and the Data Protection Act 2018, employers need a lawful basis to process that data - typically legitimate interests or, where health information is involved, more specific conditions [6].

The ICO recognises an exemption for confidential references - these may be exempt from disclosure under a subject access request when given for the purposes of education, training, employment, appointment to office, or the provision of a service. The exemption applies whether the reference was given or received. However, it only applies where the reference is genuinely treated as confidential, which the employer should make clear in privacy notices, staff handbooks, or a reference policy [6].

Since the Data (Use and Access) Act 2025 took effect in February 2026, employers must apply a "reasonable and proportionate" search standard when responding to subject access requests, but the confidential reference exemption continues to apply [2].

Handling outgoing reference requests

Decide on the standard format

The policy should specify the type of reference the business provides. A typical factual reference might confirm:

  • the individual's job title
  • start and end dates of employment.

One important point is consistency. If the standard is factual references, that standard should apply to everyone - including senior leavers, popular leavers, and those the business would rather see move on.

Handle requests for detail

When a requesting employer pushes for more information than the standard policy provides, the answer may be a polite refusal: "It is our policy to provide factual references only" [5].

If the business does choose to answer specific questions, the answers should be based on documented fact, supportable by contemporaneous records (performance reviews, disciplinary notes, attendance data), limited to what is genuinely relevant to the role, and handled carefully where sensitive information is involved.

An employer providing a reference may disclose the number of days an employee has been absent due to sickness without necessarily breaching data protection legislation, as this information does not, in itself, reveal special category health data. However, caution should be exercised when disclosing the reasons for an absence or any details relating to an employee's illness, injury, or medical condition.

Information about an individual's health is classified as special category data under the UK General Data Protection Regulation (UK GDPR) and should only be shared where it is necessary, proportionate, and supported by a lawful basis, such as the employee's explicit consent or a specific employment law obligation. Medical records or detailed health information should not be included in a reference without the employee's express consent.

Employers should also ensure that any information disclosed does not give rise to unlawful discrimination, including disability discrimination under the Equality Act 2010.

Handling incoming references from candidates

The rise of fake reference services means the receiving employer also needs a robust process.

The Cifas Workplace Fraud Trends Report 2025, based on a nationally representative survey of 2,000 UK employees, found that 19% of UK professionals have either used a fraudulent reference house or know someone who has, and 30% consider the use of reference houses to fabricate qualifications to be justifiable [7]. The Better Hiring Institute, Cifas, and Reed Screening have identified reference houses and AI-assisted fraud as among the fastest-growing risks in the hiring process [12]. Some of these services - companies that sell fabricated references, complete with functioning websites, phone numbers, and fake company presence - have reportedly become sophisticated enough to pass casual verification.

Here are a few practical steps to verify a reference.

  • Contact the referee through independently verified channels. Use a phone number from the company website, not one supplied on the reference itself, or an email address on the company domain.
  • Cross-check the referee's identity. LinkedIn profiles, corporate directories, or a direct call to the switchboard can confirm the person exists and holds the role claimed.
  • Look for red flags. Generic phrasing, mismatches between the reference address and the company's registered address, personal email domains for what should be a corporate contact, and reluctance to speak by phone.
  • Verify the company itself. A quick Companies House check confirms whether the business exists and whether the trading history is consistent with the candidate's claimed role.
  • Consider a specialist screening provider for higher-risk roles. Roles involving financial responsibility, safeguarding, or access to sensitive data may justify the additional cost.

Conditional offers should specify that they are subject to satisfactory references. This preserves the ability to withdraw the offer if references cannot be verified or contain material concerns.

Building a reference policy

An effective policy does not need to be lengthy. It should cover:

  1. Who is authorised to provide references (usually HR or a named individual).
  2. The standard form of reference the business provides.
  3. The confidentiality position, so the UK GDPR exemption applies.
  4. How verbal reference requests are handled (typically declined, with a request to submit in writing).
  5. How the business verifies incoming references.
  6. What happens with settlement-agreement references and regulatory references, where applicable.
  7. Record-keeping: what copy is retained, for how long, and in what system.

The policy should be referenced in the staff handbook and covered during manager training. Templates for standard responses can save time and help ensure consistency across the business.

This article is intended for informational purposes only and does not constitute legal advice. The information is accurate at the time of writing but may be subject to change. For advice specific to your situation, please consult a qualified professional.

[1] Information Commissioner's Office, Right of access guidance, December 2025.

[2] Data (Use and Access) Act 2025, in force February 2026.

[3] ACAS, References for work.

[4] Spring v Guardian Assurance plc [1994] UKHL 7; [1995] 2 AC 296.

[5] EmployerKit, Employment References: What UK Employers Can and Cannot Say, 2026.

[6] Information Commissioner's Office, Subject access request Q and As for employers.

[7] Cifas, Workplace Fraud Trends Report 2025, November 2025 (survey of 2,000 UK employees conducted by Opinion Matters).

[8] FCA Handbook, SYSC 22 - Regulatory References.

[9] Sprintlaw UK, Providing References in the UK: Employer Obligations and Risks, December 2025.

[10] Equality Act 2010.

[11] ACAS, References for work - employer guidance.

[12] Better Hiring Institute, Cifas and Reed Screening, Tackling Hiring Fraud, 2024-2025.

RBS
Mentor is a trading name of Mentor Advisory Services Limited.
Registered Office: 250 Bishopsgate, London EC2M 4AA.
Registered in England and Wales No. 16896022.