Statutory register inspection requests are a routine yet sensitive aspect of UK corporate governance. Handling these requests carefully is essential for company secretaries and directors, as it involves a balance between statutory openness and the duty to protect confidential information. This guide provides actionable advice on statutory register inspection requests in the UK, covering response timelines, legal grounds for refusal, the management of digital and remote requests, and best practices for safeguarding sensitive data.
Understanding Statutory Register Inspection Requests
UK companies, under the Companies Act 2006, must maintain statutory registers such as the register of members, directors, and persons with significant control (PSC). These registers underpin corporate transparency and are, in many cases, open to inspection by the public, shareholders, and regulators. Requests to inspect or obtain copies of these records are common, especially for companies with complex shareholdings, active investor engagement, or during events such as takeovers or shareholder disputes. Understanding which registers must be disclosed and the correct format for doing so is fundamental for legal compliance and good financial governance.
Who Can Request Inspection and What Can Be Accessed?
Any individual can request to inspect or obtain copies of certain statutory registers, most notably the register of members and the PSC register. However, the rights and level of access vary:
- Shareholders and some creditors may enjoy extended inspection rights compared to the general public.
- Registers such as directors’ usual residential addresses are generally restricted to regulators or law enforcement agencies.
- The PSC register is open to inspection by anyone, though companies can require the requester to state their purpose and intended use of the information.
Company secretarial and finance teams must be clear on these distinctions to ensure compliance and to prevent data breaches or unwarranted refusals.
Timelines for Responding to Statutory Register Inspection Requests
Statutory registers must usually be made available for inspection within five working days of a valid request being received. The same five-day deadline applies to requests for copies, subject to payment of the permitted fee. These statutory timeframes are strict; failure to comply may result in criminal liability for both the company and its officers. Therefore, establishing clear internal workflows and designating responsibility for managing statutory register inspection requests is critical. Automated reminders and digital tracking systems can help ensure deadlines are never missed.
Assessing the Validity of Requests
Not all statutory register inspection requests must be granted automatically. For example, requests for the PSC register must include the requester’s name, address, and a statement of purpose. The company must assess whether the stated use is proper and permissible, especially to prevent misuse for marketing or other prohibited activities. If the company has concerns, it can apply to the court within five working days to refuse the request. For the register of members, companies cannot unreasonably refuse access, but may challenge requests that are vexatious, improperly completed, or non-compliant with statutory requirements.
Grounds for Refusal and the Proper Purpose Test
For the PSC register, the Companies Act 2006 allows a company to reject a statutory register inspection request if it believes the information will be used for improper purposes, such as unsolicited marketing. The company must seek a court order within five working days, and the court will determine whether the stated purpose is valid. If the court sides with the company, the request can be lawfully denied. Refusal to allow inspection of the register of members is rare but may be justified if the request is not made in accordance with statutory procedures or is manifestly improper.
Real-World Scenarios: Statutory Register Inspection Requests in Practice
Consider the following scenarios:
- Shareholder activism: An activist investor requests the register of members to rally support for a resolution. The company must respond promptly, only redacting data not legally disclosable, and may not refuse unless the request is clearly improper.
- Due diligence in M&A: A prospective acquirer requests the PSC register as part of due diligence. The company must verify the request, ensure the purpose is proper, and seek a court order if the purpose appears to be for competitive intelligence rather than legitimate due diligence.
- Marketing misuse: A marketing company requests the PSC register, citing research. The company can challenge this under the proper purpose test and apply to the court for guidance.
- Remote requests: A request arrives by email for a digital copy of the register. The company must verify the requester’s identity, check the completeness of the request, and supply the information securely—ideally using encrypted methods or secure portals to prevent unauthorised access or data leaks.
Handling Digital and Remote Inspection Requests
The increase in remote working and digital communication has changed how statutory register inspection requests are managed. Companies should establish secure digital channels for receiving and responding to requests. This includes verifying requester identities, using encrypted email or secure file-sharing platforms when sending copies, and maintaining digital audit trails of all correspondence and disclosures. For in-person inspections, consider offering supervised video calls or controlled screen-sharing sessions, especially if physical access is impractical.
Practical Steps for Responding to Statutory Register Inspection Requests
- Log the request: Document the date, method, and the requester’s details.
- Verify the request: Ensure all statutory requirements are met—including the requester’s identity and stated purpose, if relevant.
- Assess the purpose: For PSC register requests, judge whether the stated purpose is legitimate and consider risks of misuse.
- Decide on the response: Grant access, provide copies (physical or digital), or, if necessary, apply to the court for refusal.
- Prepare the records: Redact sensitive information not required for disclosure, such as directors’ home addresses.
- Respond within deadlines: Meet the five working day statutory period for all valid requests.
- Maintain an audit trail: Keep detailed records of all requests, correspondence, and actions taken for future reference and compliance checks.
Companies with outsourced company secretarial arrangements can benefit from streamlined workflows and template documentation provided by specialist providers. For more information, review your arrangements for corporate company secretarial services.
Protecting Sensitive Data During Inspections
Transparency does not mean unlimited disclosure. Companies must ensure that only legally mandated information is provided. For example, the register of directors must not include home addresses for public inspection, and the PSC register must not disclose data protected under the relevant protection regime. Implement robust redaction protocols, and ensure staff are trained on statutory requirements and data minimisation. When managing digital or high-volume requests, use secure access controls and maintain a comprehensive audit trail of accesses and disclosures.
Compliance with UK GDPR is also required. This means having clear privacy policies, minimising the risk of data leaks, and integrating company law obligations with privacy and security best practices. For expert assistance in aligning legal obligations with practical business processes, consider consulting legal and compliance guidance.
Managing Complex or High-Volume Statutory Register Inspection Requests
Organisations subject to frequent or complex statutory register inspection requests—such as those with large shareholder bases or under activist scrutiny—should establish scalable, digital-first processes. This includes digital recordkeeping, regular staff training, and clear communication protocols. For high-growth or data-sensitive companies, external corporate services such as those provided by Company Junction may help maintain efficiency and compliance in response to statutory register inspection requests.
Conclusion
Timely, compliant, and secure responses to statutory register inspection requests are a vital aspect of UK corporate governance. By implementing robust procedures, understanding statutory rights and obligations, embracing digital solutions, and protecting sensitive data, finance teams and directors can limit legal risks and maintain the trust of shareholders and stakeholders.

