Employment Rights Act 2025: What Employers Need to Know Before 30 October
From 30 October 2026, important changes to workplace harassment law will come into force under the Employment Rights Act 2025.
Employers will be required to take all reasonable steps to prevent sexual harassment of their workers. They will also face potential liability for harassment by third parties, such as customers, clients, patients, service users and members of the public, unless they can show they took all reasonable steps to prevent it.
For organisations with lone, remote or public-facing employees, the changes have particular significance. Preventing harassment is not simply about having an HR policy in place. Employers need to understand where risks arise in day-to-day work and consider practical measures to reduce them.
With recent Acas research finding that 41% of employers were unaware of the forthcoming strengthened sexual harassment duty, now is the time to review how employees are protected.
What changes on 30 October 2026?
There are two important changes employers need to understand.
A stronger duty to prevent sexual harassment
Since October 2024, employers have been under a legal duty to take reasonable steps to prevent sexual harassment at work.
From 30 October 2026, that duty becomes stronger. Employers will be expected to take all reasonable steps that are appropriate for their organisation, rather than selecting only some preventative measures.
New liability for third-party harassment
The Employment Rights Act 2025 also introduces employer liability for harassment carried out by third parties.
An employer can be liable where an employee is harassed by a third party in the course of their employment and the employer failed to take all reasonable steps to prevent it.
Importantly, the third-party provisions are broader than sexual harassment alone. They cover forms of harassment protected under the Equality Act 2010, including harassment related to relevant protected characteristics.
Who counts as a third party?
A third party is someone other than the employer or another employee. Depending on the workplace, this could include:
- Customers and clients
- Patients and service users
- Students
- Contractors and suppliers
- Visitors
- Members of the public
For organisations whose employees regularly deal with people outside the business, this means third-party harassment needs to be considered as part of wider workplace risk management and prevention.
Are you ready for the 30 October harassment law change?
Take our short readiness check to see how prepared your organisation is for the new third-party harassment requirements and identify areas that may need attention.
Start the readiness check →What do “all reasonable steps” look like in practice?
The law does not prescribe one universal set of actions that every employer must take.
Instead, employers need to consider the risks within their own organisation and take the preventative measures that are reasonable in those circumstances. Acas says this means focusing on prevention across the organisation rather than only reacting after an incident occurs.
Depending on the workplace and level of risk, reasonable steps could include:
- Assessing where and when employees could be exposed to harassment
- Reviewing harassment and lone working policies
- Making sure employees have clear ways to report concerns
- Providing appropriate training
- Setting expectations for customers, clients and service users
- Recording incidents and reviewing patterns or recurring risks
- Ensuring appropriate staffing in higher-risk environments
- Providing safety equipment such as personal alarms
- Considering body-worn or security cameras where appropriate
Acas specifically includes personal alarms, cameras and adequate staffing among measures that may be relevant in higher-risk environments.
The right measures will vary between organisations. Employers should therefore avoid treating compliance as a checklist exercise and instead assess what risks their people actually face.
Why this matters for lone and public-facing workers
Third-party harassment is an employment-law issue, but for many organisations it is also a personal safety risk.
Employees who work alone, remotely or away from a fixed workplace may interact with customers, patients, tenants, service users or members of the public without colleagues immediately nearby.
Examples could include:
- A community nurse visiting a patient
- A housing officer entering a tenant’s property
- A utility engineer attending a customer site
- An estate agent conducting a viewing
- An employee working a late retail or hospitality shift
- A field-based worker visiting an unfamiliar location
Lone working does not automatically mean that someone is at greater risk of harassment. However, if an incident occurs, the absence of immediate support can make it more difficult for an employee to remove themselves from the situation or summon assistance.
This is why Acas recommends that employers review existing policies covering lone working when preparing for the October 2026 changes.
Identifying where the risk is greatest
Employers should consider where third-party interaction occurs and whether certain roles, locations or working patterns create greater exposure.
A risk assessment might consider:
People
Who does the employee interact with, and are there known behavioural or violence and aggression risks?
Environment
Does the employee work alone, in isolated locations, inside customers’ homes or in places where immediate support is limited?
Task
Does their work involve challenging conversations, enforcement activity, handling complaints, refusing service or other interactions that could increase the risk of conflict?
Employers should also look at previous incidents and near misses. Patterns in reports can help identify particular locations, customers, working times or activities where stronger controls may be needed.
Peoplesafe’s lone worker risk assessment guide uses a similar people, environment and task approach when identifying risks to employees who work alone.
How employers can prepare before 30 October 2026
Employers do not need to wait for the new provisions to take effect before reviewing their arrangements. Acas encourages organisations to prepare in advance.
- Review harassment and lone working policies Check that policies recognise the possibility of harassment from customers, clients, patients, service users and other third parties. Policies should also explain how employees can raise concerns and what they should do if they feel unsafe.
- Identify roles and environments with greater exposure Review risk assessments to understand where third-party contact takes place and whether factors such as lone working, late shifts or remote locations create additional challenges.
- Give employees clear reporting routes Employees should know how to report harassment, concerns and near misses. Having clear reporting routes also helps employers identify recurring issues before they escalate.
- Monitor incidents and the actions taken Recording incidents is only part of the picture. Employers should also record how risks were addressed, whether controls were changed and whether similar incidents continue to occur. Where organisations use digital safety or EHS safety management software, this information can contribute to a clearer picture of workplace risk.
- Provide relevant training Training should reflect the situations employees may genuinely encounter rather than being treated purely as a compliance exercise. Depending on the role, that could include recognising harassment, reporting concerns, conflict management and knowing when to disengage from an unsafe situation.
- Consider appropriate safety measures In higher-risk environments, Acas guidance says reasonable steps may include appropriate staffing, personal alarms and body or security cameras. The appropriate control will depend on the role and risk assessment. Employers should document the decisions and actions they take and review measures regularly as risks or working practices change.
The objective is not simply to respond effectively when harassment occurs. It is to demonstrate that foreseeable risks have been considered and appropriate preventative steps have been taken.
Where personal safety technology fits
Policies, training and risk assessments are essential, but they cannot remove every situation in which an employee could face threatening, abusive or harassing behaviour.
Personal safety technology can provide employees with a practical way to summon help when an incident occurs. It also provides timestamped and auditable activities that can be used to evidence proactive steps taken to prevent harassment.
Depending on the role and level of risk, this could include:
- A personal safety alarm or lone worker device
- A safety app with SOS functionality
- Monitored check-ins or timed activities
- Access to a professionally monitored Alarm Receiving Centre
- Body-worn cameras where their use is appropriate
- Accurate location information to support an emergency response
Acas expressly identifies personal alarms as an example of appropriate safety equipment and also suggests panic buttons or alarms as ways employees can get help quickly.
For lone workers in particular, access to a monitored personal safety service can provide a direct route to support when colleagues are not immediately available.
For more practical guidance, read our guide to staying safe while lone working.
How Peoplesafe can support a wider prevention strategy
Peoplesafe provides technology-enabled employee safety solutions designed to give employees access to support when they feel unsafe or need urgent assistance.
Depending on an organisation’s risk profile, Peoplesafe solutions can support:
- Employees working alone or remotely
- Public-facing teams exposed to violence, aggression or harassment
- SOS alarm activation
- Monitored lone working activities
- Location information during an alarm
- 24/7 professional alarm monitoring and response
- Body-worn technology for appropriate environments
Our solutions are designed to complement an organisation’s wider safety policies, procedures, training and risk-management arrangements.
Need help assessing your personal safety measures?
Speak to our team about protecting lone and public-facing employees and building a safer, more resilient organisation.
Frequently Asked Questions
What changes to harassment law on 30 October 2026?
From 30 October 2026, employers will need to take all reasonable steps to prevent sexual harassment of their workers. Employers can also be liable for harassment by third parties unless they can show that they took all reasonable steps to prevent it.
Who counts as a third party?
A third party is someone who is not the employer or another employee. This could include a customer, client, patient, service user, contractor, supplier, visitor or member of the public.
What does “all reasonable steps” mean in practice?
It means taking all of the preventative measures that it is reasonable for the organisation to take in its particular circumstances. What is reasonable will depend on factors including the organisation’s size, sector and type of work.
Does the new law specifically apply to lone workers?
No, the law is not a separate lone working law. However, lone and public-facing workers may encounter third parties without immediate support from colleagues, so employers should consider these working arrangements when assessing harassment risk. Acas specifically recommends reviewing lone working policies when preparing for the third-party harassment changes.
Are personal alarms considered a reasonable step?
There is no universal list of measures that will automatically meet the legal test. However, Acas specifically identifies personal alarms as an example of appropriate safety equipment that may form part of the steps taken in higher-risk environments.
Can Peoplesafe make an organisation compliant with the Employment Rights Act?
Peoplesafe can support the personal safety element of a wider strategy through monitored alarms, lone worker technology and other safety solutions. No single technology or supplier can guarantee compliance. Employers need to consider all reasonable preventative steps appropriate to their circumstances.