Confidentiality, customers and compliance: what employers can learn from the Mandelson vetting row
24 August 2026
Make an enquiry
When the appointment of Peter Mandelson as UK Ambassador to the US was followed by reports that his security vetting had been ‘pushed through’ by the Foreign, Commonwealth and Development Office (FCDO), it did more than create a political crisis – it put the UK’s notoriously mysterious National Security Vetting (UKSV) process under an unusually bright spotlight.
If your business employs staff who are the subject of clearance by UKSV, for example because you contract directly or indirectly with the Ministry of Defence or other government departments and have access to classified information, you can understand more about your obligations as an employer through our previous article.
Quite apart from the recent spotlight on UKSV, however, the Mandelson vetting row served as a reminder of the issues that can arise when an employee’s ability to do their job is contingent on the permission of a third party and that permission is withheld, delayed or revoked.
How do you manage when your obligations regarding confidentiality and compliance collide with your commercial and contractual obligations to customers and clients?
Employment implications and commercial risks
Employing staff who are subject to some form of external regulation or oversight that impacts their ability to practise brings with it significant employment and HR risk. In addition, there are often much wider commercial implications to consider.
In most circumstances, you will have little to no control over whether employees are granted, or retain, the necessary clearance, licence or permission where that clearance, licence or permission is granted by a third party. In the case of security clearance in particular, you will likely be told very little, if anything, about the reasons behind the decision. UKSV and the relevant government department responsible for granting clearance, such as the Ministry of Defence or the FCDO, will not wish to increase any risk to national security by providing details of the information used to make their decisions and/or the source of that information.
Obtaining information from other regulatory bodies and organisations, such as the Disclosure and Barring Service (DBS) and the Security Industry Authority (SIA), can likewise be challenging for data protection reasons. Even where you are privy to the necessary information as an employer, disclosure of that information to clients, customers and partners will be regulated by data protection legislation and subject to your express and implied contractual obligations to your employee.
That can create several issues:
- The employee is unable to attend the site at which you employ them to work, requiring potential redeployment where alternative work may not be available. This can be particularly problematic in circumstances where the regulatory issue has not been resolved but remains under investigation, as the relevant process can take several months before a decision is made
- The circumstances leading to the refusal or revocation of a clearance, licence or permission may not immediately amount to misconduct from an employment perspective. For example, being in financial difficulty or having an extramarital affair could result in security clearance being revoked. Even where it does amount to misconduct, it may not be sufficiently serious to warrant dismissal
- The risk of discrimination claims – vetting and regulatory outcomes can disproportionately affect some groups. While the decision to refuse or revoke clearance or a licence may not lie with you as the employer, any employment-related decision taken because of that refusal or revocation will. This creates a risk that any employment-related decision could be ‘tainted’ by discrimination
- Your business is unable to deliver on its contractual obligations to customers because of an absence of sufficiently cleared or licensed staff, exposing you to proceedings for breach of contract, penalties for delay or termination of the contract by the client, as well as the risk of reputational damage.
Key takeaways
So, what practical steps can you take to mitigate some of the risks associated with employing security-cleared, licensed or regulated staff?
Simple but key mitigations include:
- Ensuring that any offer of employment is conditional and that, unlike Mandelson, the employee does not commence employment until the relevant clearance, licence or permission has been obtained. This also means making sure that you do not commit the business to any deliverables for customers or clients where those deliverables are contingent on a new employee being in-post
- Making the relevant clearance or licence (and maintaining it) an express condition of employment within the contracts of employment for relevant roles
- Where work depends on other permissions, such as permission to attend certain sites including government, secure or client sites, make it clear in the employment contract that employment can be terminated if the necessary permission is refused or revoked, and be clear about the period of notice (if any) that will apply. Where an employee has sufficient service to bring an unfair dismissal claim (which will be six months from 1 January 2027), the revocation of essential third-party permission will not negate the need for a fair reason for dismissal or a fair procedure. However, it may help avoid allegations of wrongful dismissal or other breach of contract claims and may allow you to rely on the revocation of permission as the starting point for a ‘some other substantial reason’ (SOSR) dismissal
- Placing clear contractual obligations on employees to comply with the requirements imposed on them as clearance or licence holders, making the potential implications for staff who fail to comply clear. The requirements on staff may include giving a warranty as to their suitability to hold clearance (to the best of their knowledge), declaring overseas travel or undertaking certain mandatory training or CPD. It may also require them to declare potential conflicts of interest or wider risks than would apply to non-cleared or non-regulated staff
- Having clear policies and procedures in place to manage security clearance, licensing or regulatory issues in employment. For example, ensure you have a clear data protection policy in place regarding the disclosure of relevant information to third parties, which may often be classified as sensitive personal data and will almost certainly go beyond the ‘usual’ categories of data processed by employers
- Reviewing commercial contracts to ensure services can still be delivered in the absence of sufficiently cleared or licensed staff, or where there are delays in appointing such employees. Where possible, build in appropriate lead times, the right of substitution and agreed protocols, for example around when a client has the right to refuse access or permission to your employees and how that refusal will be managed and communicated.