DutyOS

Your waste records, and what happens to them: the security questions the GOV.UK list cannot answer

Published 27 September 2026 · every claim below checked against the certificate, the register and the live system on 27 September 2026

From 1 October 2026 a permitted site in England and Wales sends DEFRA a digital record of every load it receives, and most sites will do that through software from the GOV.UK provider list. Being on that list means one thing: the product is connected to DEFRA’s service and has been through the production approval tests. It says nothing about how the records you file through it are protected. Where they are stored. Who can read them. Whether the company behind the product has ever had its own security checked. Whether a record can be quietly changed after it was filed.

Those are separate questions, and the answers are yours to ask for, because you are the data controller for the personal data in your own records. This post gives DutyOS Ltd’s answers in one place, with the evidence, so that you can hold any provider to the same standard.

What Cyber Essentials tested

Cyber Essentials is the UK government backed scheme run by IASME for the National Cyber Security Centre. It tests the five controls that stop the common attacks: firewalls, secure configuration, security update management, user access control and malware protection. It is a whole organisation assessment, not a product badge: every device, every cloud service and every account the company uses is in scope.

DutyOS Ltd holds a Cyber Essentials certificate for the whole organisation, assessed on 18 September 2026 by an independent certification body under the IASME scheme. Around eighty questions, every one answered and every one marked compliant. The certificate is valid for twelve months and is renewed by a fresh assessment, because it describes the position at the time of testing, not for ever.

Every current certificate is on a public register. Ours is here: verify it on the IASME registry. The entry names the organisation, the level and the expiry date. A badge on a website is not a certificate. The register entry is.

Two things the certificate is not, so that nobody reads more into it than it says. It is not Cyber Essentials Plus, which adds an audited technical test. And it is not an approval by the National Cyber Security Centre, which approves nobody. It is an independent assessment against a published standard, with the result on a public register.

Insurance that runs with it

Cyber liability insurance is in place, underwritten by AIG UK through the IASME scheme, with an incident response line. Not a guarantee of anything, but a company that has been underwritten has been asked the questions above by someone whose money depends on the answers. The cover runs with the certificate.

Where your records live

The database, the sign in service and the files you attach to a receipt are in London. The software that processes them runs in Amsterdam. Both are inside the UK and the EEA, so no international transfer safeguards are needed and none are relied on. When you ask a provider this question, ask for both places: where the records are stored, and where the software runs. If either is outside the UK or the EEA, ask what transfer safeguards are in place.

What happens to a record after it is filed

A duty of care record that can be quietly edited afterwards is worth less to you in an inspection than one that cannot. So the rules are enforced in the database, not in a setting someone remembers to tick.

  • A signed transfer note is locked. Once a note is filed with a signature, the signature and its evidence become immutable. Even a typo in a signed name cannot be edited away afterwards.
  • A receipt DEFRA already holds is corrected, never silently changed. A wrong record can be corrected for a month after it was filed, and the correction goes to DEFRA as an update to the same record. The original filing is not overwritten in place.
  • Roles are separate. A gate operator logs, corrects and submits. A read only viewer, an auditor or an insurer for example, sees every record and can change nothing. The account owner invites people and sets their role. The database refuses a write from a role that is not allowed to make it, whatever the screen shows.
  • Statutory records are kept for as long as the law says. Waste transfer notes for at least two years and hazardous waste consignment notes for at least three, because duty of care rules require it. A deletion request cannot remove them early.

Backups

The database is on a paid plan with daily backups taken by the provider. On top of that, DutyOS Ltd takes its own daily copy and keeps it outside the provider, so that the records do not depend on one company’s systems staying up. Backups are taken every day; that is the claim, and it is the one to ask any provider about.

Your data is yours

  • Two factor sign in. Every person on the account can turn on two factor authentication with an authenticator app, from their own profile page.
  • A full export. Everything held for your account, as one file, from the Your data page, whenever you want it. No request, no waiting.
  • Deletion, with the law in front of it. The same page shows what a deletion would remove and what it would keep, and nothing is deleted until a confirmation link sent to your registered address is opened.

One question for any provider

Ask for the Cyber Essentials registry link and open it. A provider that holds a certificate can send the link in seconds. Then ask where the records are stored, where the software runs, whether cyber insurance is in place, who in your own business can see and change a record, and whether a filed record can be changed afterwards. Five questions. The answers tell you more about where your records will be for the next three years than anything on the provider list can.

The five questions, and our answers, are also on the Is your data safe page.

The list: GOV.UK, Report receipt of waste: choose a software provider. DutyOS Ltd is one of the providers on it and is not affiliated with DEFRA.