Workplace harassment is not a new legal issue, but the expectations of employers have changed a lot in two years. Before October 2024, employers were mainly judged on how they responded once harassment had happened. The Worker Protection (Amendment of Equality Act 2010) Act 2023 changed that by introducing a preventative duty: employers had to act before an incident, not just after it.
The Employment Rights Act 2025 goes further. From 30th October 2026, employers must take all reasonable steps to prevent sexual harassment, and they can be held liable when customers, clients, contractors, or members of the public harass their staff. That second change is not limited to sexual harassment – it covers harassment linked to a range of protected characteristics.
For organisations whose people regularly deal with customers or the public – retail, hospitality, logistics, healthcare, facilities management, transport – the impact could be significant. This article sets out what the law requires and what a defensible approach looks like in practice.
If you already manage the risk of violence and aggression at work, you’re closer to compliance than you might think. Third-party harassment is a workplace risk like any other. You identify where it happens, put controls in place, make it easy to report, act on what you find, and check your controls are working. That’s the same cycle health and safety teams run every day. What changes from 30th October is that a tribunal or the EHRC can ask you to show it.
Key takeaways: preventing workplace harassment
- From 30th October 2026, UK employers must take “all reasonable steps” to prevent sexual harassment – a higher bar than the “reasonable steps” duty in force since 26th October 2024.
- Employers become expressly liable for harassment of employees by third parties, such as customers, clients, and contractors, if they cannot show they took all reasonable steps to prevent it.
- This third-party liability covers harassment related to age, disability, gender reassignment, race, religion or belief, sex, and sexual orientation – not only sexual harassment.
- Tribunals can increase compensation by up to 25% where an employer has breached the duty to prevent sexual harassment, and the Equality and Human Rights Commission (EHRC) can take enforcement action.
- What counts as “reasonable” depends on your size, sector, and the type of work, so documented risk assessments and incident data are central to showing compliance.
- Notify Technology helps employers evidence these steps with risk assessment, incident reporting, audit, safety intelligence, and document management tools in one central platform.
What is the duty of an employer when it comes to workplace harassment?
UK employers have a legal duty to protect their workers from harassment and, since 26th October 2024, a proactive duty to take reasonable steps to prevent sexual harassment of their employees. From 30th October 2026, that becomes a duty to take all reasonable steps.
Under the Equality Act 2010, harassment is unwanted conduct that has the purpose or effect of violating someone’s dignity, or creating an intimidating, hostile, degrading, humiliating, or offensive environment for them. The Act recognises three forms:
- Harassment related to a protected characteristic – age, disability, gender reassignment, race, religion or belief, sex, or sexual orientation.
- Sexual harassment – unwanted conduct of a sexual nature.
- Less favourable treatment because someone rejected or submitted to sexual harassment, or harassment related to sex or gender reassignment.
Employers have long been liable for harassment carried out by their own staff in the course of employment, unless they can show they took all reasonable steps to prevent it. The preventative duty introduced by the Worker Protection Act 2023 changed the focus – employers must anticipate the risk of sexual harassment and act before anything happens, rather than waiting for a complaint.
The key point is that the duty is about prevention, not just response. A good grievance procedure is still essential, but on its own it will not show that you have met the duty.

Change 1: employers must take all reasonable steps to prevent sexual harassment
From 30th October 2026, employers must take “all reasonable steps” to prevent sexual harassment of their employees – a higher standard than the “reasonable steps” required since October 2024.
The difference sounds small, but in practice it shifts the burden. Under the 2024 duty, an employer might show it had taken some sensible measures, such as a policy and annual training. Under the new duty, the question becomes whether there was any further reasonable step the employer could have taken and didn’t. If there was, the employer is likely to fall short.
What is reasonable still depends on context – your organisation’s size and resources, your sector, the type of work, and the risks your people actually face. Acas puts it simply: taking all reasonable steps means doing what is possible with the resources available.
The Government has also said it will make regulations setting out steps that count as reasonable, expected in 2027. Until then, the EHRC’s technical guidance on sexual harassment and harassment at work is the main reference point for employers.
For organisations where employees regularly deal with customers or the public, this change is significant. A generic policy that hasn’t been tested against the real risks in your workplace is unlikely to meet the new standard.
What does “all reasonable steps” to prevent sexual harassment mean?
“All reasonable steps” means doing everything you reasonably can to prevent sexual harassment, not just a handful of sensible measures. From 30th October 2026, you can no longer pick and choose a few easy preventative measures and consider the duty met.
If a claim reaches an employment tribunal, the question will effectively be: “Was there anything else this business could reasonably have done to prevent this incident?” If the answer is yes, you’re likely to fall short.
What counts as “all reasonable steps” depends on your organisation’s size, resources, and risk profile, but it could include:
- Systematic risk management: assess the specific risk factors for each role, especially customer-facing ones, such as shift patterns, lone working, alcohol, and power imbalances.
- Quality training: go beyond tick-box e-learning. Training should be tailored to your sector, refreshed regularly, and backed by completion records.
- Clear policies: make sure employees understand the harassment duty, what behaviour is unacceptable, and what happens when it occurs.
- Clear reporting routes: give staff simple, accessible ways to raise a concern, and tell them what happens after they report.
- Communication with third parties: use clear signage, booking terms, and messages to let customers, clients, and visitors know that harassment won’t be tolerated.
- Trauma-informed investigations: investigators should understand how trauma can affect someone’s memory of an incident, so accounts aren’t wrongly dismissed as inconsistent. We covered this in our webinar on understanding the psychology of witness memory and recall.
- Regular contact between managers and staff: use one-to-ones, check-ins, and feedback surveys to spot concerns early and test whether your measures are working.
Whichever steps you take, record them. You’ll need to be able to show what you did and when, as well as having done it.
Change 2: employers become liable for third-party harassment
From 30th October 2026, employers can be held liable when a third party harasses an employee in the course of their employment, unless they can show they took all reasonable steps to prevent it.
A third party is anyone your people come into contact with through work who isn’t a colleague. That includes:
- Customers and clients
- Patients, students, and other service users
- Contractors, suppliers, and agency workers
- Delegates and attendees at events
- Members of the public, including people who harass staff online
Crucially, this goes beyond sexual harassment. Third-party liability covers harassment related to:
- Age
- Disability
- Gender reassignment
- Race
- Religion or belief
- Sex
- Sexual orientation
There is no requirement for previous incidents, and a single incident can be enough for a claim. That marks a clear break from the old third-party harassment rules, repealed in 2013, which applied only after an employer knew an employee had been harassed on at least two previous occasions.
The Government chose not to exempt particular kinds of conversation, such as political or religious opinions overheard by staff. Instead, it says a step that would disproportionately interfere with a third party’s freedom of expression would not be a “reasonable” step – so you are not expected to police every customer conversation.
Acas guidance gives a sense of what reasonable steps might look like, scaled to risk:
- Lower-risk environments: a risk assessment for third-party harassment, incident monitoring, a clear harassment policy, staff training on de-escalation, and telling customers that harassment won’t be tolerated.
- Higher-risk environments: adequate security staffing, personal alarms, and body-worn cameras or CCTV.
If your people work front of house, on the road, in customers’ homes, or in busy public settings, now is the time to map where third-party contact happens and what could go wrong.

What happens if employers don’t comply with the new duties?
Employers that fail to take all reasonable steps face higher tribunal awards, enforcement action from the EHRC, and lasting reputational damage.
- Uncapped compensation. Compensation for harassment and discrimination claims has no upper limit. With third-party liability, employees can bring claims about harassment by customers or contractors directly against their employer.
- A 25% uplift for sexual harassment claims. Where an employee wins a sexual harassment claim and the tribunal finds the employer breached the preventative duty, it can increase compensation by up to 25%.
- EHRC enforcement. The Equality and Human Rights Commission can enforce the preventative duty even when no individual has made a complaint – including investigations, unlawful act notices, and legally binding action plans.
- Reputational damage. Tribunal judgments are public, and EHRC enforcement can be too. The cost to trust, recruitment, and retention often outweighs the award itself.
Two related changes are worth knowing. Since 6th April 2026, reporting sexual harassment counts as a protected disclosure under whistleblowing law, so employees who speak up are protected from detriment. And from 2027, confidentiality clauses that stop workers from speaking about harassment or discrimination are expected to become void, with limited exceptions.
How can employers comply with the duty?
To comply, employers need to identify where harassment could happen, put proportionate controls in place, and keep evidence that those controls work. The EHRC’s technical guidance sets out eight steps employers should take. We’ve grouped them into five practical steps below, and the table further down maps each EHRC step to the evidence you’ll need.
1. Carry out and maintain risk assessments
A harassment risk assessment is the foundation of everything else. Map where your people interact with colleagues and third parties, which roles carry the highest risk, and the situations that increase it – lone working, night shifts, travel, social events, customer complaints, and online communication.
Then record the controls you’ll put in place and review them regularly. A risk assessment written once and filed away won’t show you’ve taken all reasonable steps; one that’s reviewed after incidents and when work changes will.
2. Make reporting of incidents easy, accessible, and secure
You can’t prevent what you don’t know about, and harassment is widely under-reported. Give people several ways to report – on a phone, tablet, or computer, or by scanning a QR code at the point of work – so reporting takes minutes, rather than a formal meeting.
Reports must be handled confidentially, with access limited to the people who need it. Tell staff what happens after they report, and make sure third-party incidents are captured as clearly as those involving colleagues.
3. Have an action plan in place
An action plan turns your risk assessment into commitments: who will do what, and by when. Include training, policy updates, changes to working arrangements, and clear steps for responding to a report, including how investigations will be run fairly.
Assign an owner and a due date to every action, and track progress. Open and overdue actions are exactly what a tribunal or the EHRC will look for when judging whether you did all you reasonably could.
4. Update your policies and procedures
Review your harassment policy so it reflects the new law. It should:
- Explain the “all reasonable steps” duty in plain language, with practical examples.
- Explicitly cover harassment by customers, clients, contractors, and other third parties.
- Make clear that one incident can be enough.
- Set out how to report, what happens next, and the support available.
Make sure people have read and understood the policy. Read-and-sign records help you evidence this, and the policy should be reviewed at least annually and after any significant incident.
5. Promote a culture of psychological safety
Policies only work if people feel safe to use them. Psychological safety means employees can speak up, raise concerns, and share feedback without fear of blame or retaliation.
Leaders set the tone. Act visibly on reports, thank people for raising concerns, and train managers to respond well. Bystander training, staff surveys, and focus groups help you understand what’s really happening. Review your measures regularly to check they’re working – and to evidence that they are.
For more information on fostering a positive safety culture in the workplace, check out our eBook.

How can Notify help you comply?
No software can make you compliant on its own, but the right tools help you carry out each of the steps above consistently and keep evidence that you’ve done so.
Notify Technology brings these together in one modular platform, used by more than 300,000 workers globally.
- Risk Assessment Software – build harassment and third-party risk assessments from templates, just as you would any other health and safety risk assessment. Use configurable risk matrices and set review reminders so assessments stay current. Keep a record of who has read and signed each risk assessment to demonstrate understanding, while version control shows how your controls have developed over time.
- Incident Reporting Software – let employees report any event digitally and in real time from a computer, tablet, or mobile device, even when offline. Role-based permissions protect sensitive information, and automated notifications make sure high-priority reports reach the right people quickly. Anonymous reporting is also available, so employees can raise concerns about harassment they experience or witness.
- Audits and Inspections Software – schedule and complete regular checks of your prevention measures, from signage and lone-working arrangements to security provision, and capture photo evidence as you go. Assign each check to a named person with a due date, then monitor whether it’s completed on time and to the right standard, supporting compliance with the new duty.
- Safety Intelligence Software – spot trends in harassment reports by site, role, time of day, or type of third party, so you can target action where it’s needed and show leaders the data behind your decisions.
- Document Management Software – keep your harassment policy and procedures in one place, control versions, and use digital read-and-sign to evidence that staff have read and understood them.
- Action Tracking – assign, track, and follow up actions raised from risk assessments, incidents, and audits in one system, giving you a single, time-stamped record of the steps you’ve taken.
The table below maps each step in the EHRC’s eight-step guidance to the questions a tribunal is likely to ask and the evidence Notify helps you keep.
| EHRC step | What a tribunal will ask | Notify solution | Evidence you're left with |
| 1. Anti-harassment policy | Is it current, and have people read it? | Document Management | Version history, read-and-sign records |
| 2. Engaging with staff | Did you ask staff where they feel at risk? | Audits and Inspections | Survey or consultation records, dated |
| 3. Risk assessment | Did you identify where harassment risk sits, including from third parties? | Risk Assessment | Dated assessments and review history |
| 4. Reporting | Could people report easily and safely? | Incident Reporting | Time-stamped reports from mobile, QR code, or offline |
| 5. Training | Was training relevant, regular, and completed? | Document Management | Completion records by person and date |
| 6. Handling complaints | What did you do about it? | Incident Reporting and Action Tracking | Investigation records, actions assigned and closed |
| 7. Third-party harassment | What controls did you put in place? | Audits and Inspections | Completed checks on lone working, security, and signage |
| 8. Monitoring and evaluating | How did you know it was working? | Safety Intelligence | Trends by site, role, and type of third party |
Book a demo
The new duties take effect on 30th October 2026. Book a demo to see how Notify can help you prevent workplace harassment and evidence the steps you’ve taken.