Employer Duty of Care: Legal Requirements & Compliance in the US, UK & EU
TL;DR: Employer duty of care for business travel is a statutory obligation in every major Western jurisdiction. US employers are bound by OSHA's General Duty Clause (Section 5(a)(1) of the OSH Act of 1970), UK employers by Sections 2 and 3 of the Health and Safety at Work Act 1974 and the Corporate Manslaughter Act 2007, and EU employers by Framework Directive 89/391/EEC. ISO 31030:2021 is the international benchmark for compliance.
Drawing from 8+ years building AI-powered corporate travel platforms across roughly 40 countries, the pattern that holds up is this: duty of care liability is rarely triggered by an incident itself — it is triggered by whether the employer can document a competent, jurisdiction-appropriate response before, during, and after the incident. This article maps the statutory requirements across the US, UK, and EU, the penalty exposure, the ISO 31030:2021 baseline, and the operational layers required for defensible compliance.
What Is Employer Duty of Care in Business Travel?
Duty of care in business travel is the legal and ethical obligation of employers to protect employees from foreseeable harm during work-related trips. In the United States, it is codified through Section 5(a)(1) of the Occupational Safety and Health Act of 1970 — the General Duty Clause — which requires employers to furnish "a place of employment free from recognized hazards." The UK Health and Safety at Work etc. Act 1974 imposes an equivalent obligation under Sections 2 and 3, extending to employees and third parties affected by the employer's activities. The European Union codified the concept in Framework Directive 89/391/EEC, mandating employers to assess risks and implement preventive measures. The international benchmark is ISO 31030:2021, "Travel risk management — Guidance for organizations," published in September 2021, which provides the first cross-jurisdictional operational framework for compliance.
The critical legal principle across all three jurisdictions: an office desk and a hotel room in Lagos or Bogotá carry identical statutory obligations. Location does not diminish employer duty; it amplifies the standard of care.
United States: OSHA and the General Duty Clause
The primary federal instrument is Section 5(a)(1) of the Occupational Safety and Health Act of 1970. OSHA enforces this clause when a specific standard does not apply — which is the norm for business travel, since OSHA has not issued travel-specific rules. Employers face a "recognized hazard" test: if the hazard is known to the industry or the specific employer, feasible abatement is required.
OSHA maximum penalties, adjusted annually under the Federal Civil Penalties Inflation Adjustment Act of 2015, currently stand at $16,131 per serious violation and $161,323 per willful or repeat violation (per OSHA's 2026 penalty schedule effective January 15). State workers' compensation statutes provide the second layer — travel between the office and a business destination is generally compensable under the "traveling employee" doctrine established in cases such as Voehl v. Indemnity Insurance Co. (288 U.S. 162, 1933). Federal contractors additionally face Federal Employees' Compensation Act (FECA) obligations administered by the Department of Labor Office of Workers' Compensation Programs.
The 2019 Department of Labor guidance letter on employer obligations for foreign travel confirmed that OSHA's General Duty Clause "applies to U.S. employees working abroad where the employer directs the work," subject to the extraterritorial limitations upheld in EEOC v. Arabian American Oil Co. (499 U.S. 244, 1991). Practically, this means U.S. employers cannot outsource duty of care to a foreign subsidiary if they retain operational control over the trip.
United Kingdom: HSW Act, Corporate Manslaughter, and the Case Law
The UK regime is the strictest of the three, both in scope and in enforcement history. Sections 2 and 3 of the Health and Safety at Work etc. Act 1974 require employers to ensure "so far as is reasonably practicable" the health, safety, and welfare of employees (Section 2) and non-employees affected by their work activities (Section 3). The Management of Health and Safety at Work Regulations 1999, Regulation 3, requires a "suitable and sufficient" risk assessment — the HSE guidance document INDG163 sets the operational bar.
The Corporate Manslaughter and Corporate Homicide Act 2007 introduced criminal liability for organizations whose gross breach of duty causes death. The first successful prosecution was R v Cotswold Geotechnical (Holdings) Ltd (2011), which resulted in a £385,000 fine. By 2024, HSE annual reports show 42 successful prosecutions under the Act, with fines ranging from £180,000 to £3.2 million. Individual directors face up to life imprisonment for gross negligence manslaughter under common law, unaffected by any corporate veil.
Post-Brexit, UK duty of care remains functionally aligned with the EU Framework Directive because Section 2 of the European Union (Withdrawal) Act 2018 retained the underlying regulations. UK employers cannot assume a lighter standard.
European Union: Framework Directive 89/391/EEC and ISO 31030
The EU baseline is Council Directive 89/391/EEC of 12 June 1989 — the "Framework Directive" — supplemented by roughly 20 individual directives on specific hazards. Article 6 requires employers to implement a hierarchy of prevention: avoid risks, evaluate unavoidable risks, combat risks at source, adapt work to the individual, and develop a coherent prevention policy. Article 10 mandates that workers receive "all the necessary information" regarding hazards, including those arising during travel.
Transposition into national law is uneven but converges on similar outcomes. Germany's Arbeitsschutzgesetz (ArbSchG) Section 5 requires documented risk assessment. France's Code du Travail Article L4121-1 uses "obligation de résultat" language that courts have interpreted as near-strict liability — the Cour de cassation confirmed in Chambre Sociale, arrêt du 25 novembre 2015, that failure to protect a business traveler from foreseeable terrorism risk constituted a "faute inexcusable." Italy's Legislative Decree 81/2008 applies equivalently. GDPR Article 6(1)(f) — legitimate interest — is the standard legal basis for real-time traveler location processing, subject to Article 13 transparency and Article 5 data minimization requirements.
Duty of Care Standards Compared: US vs UK vs EU vs ISO 31030
| Jurisdiction / Standard | Primary Instrument | Standard of Care | Maximum Penalty | Scope of Duty |
|---|---|---|---|---|
| United States | OSHA Act 1970, Section 5(a)(1) — General Duty Clause | Free from recognized hazards; feasible abatement | $16,131 per serious violation; $161,323 per willful (2026 OSHA schedule) | Employees; extends to business travel where employer directs work |
| United Kingdom | HSW Act 1974 (Sections 2–3); Corporate Manslaughter Act 2007 | So far as reasonably practicable | Unlimited fine; up to life imprisonment for gross negligence manslaughter | Employees, contractors, and third parties affected by activities |
| European Union | Framework Directive 89/391/EEC (transposed nationally) | Comprehensive risk assessment + prevention hierarchy | Member state discretion; France, Germany, Italy issue 6–7 figure fines | Employees; psychosocial risks included per 2004 Framework Agreement |
| France (as EU exemplar) | Code du Travail L4121-1; jurisprudence "faute inexcusable" | Obligation de résultat — near strict liability | Civil damages uncapped; criminal fines up to €225,000 for the organization | Includes foreseeable terrorism, disease, political violence risk |
| International Standard | ISO 31030:2021 — Travel risk management | Systematic risk management framework | Not statutory; adopted by insurers and cited by courts as benchmark | All personnel traveling on organization's behalf |
Common Compliance Obligations Across All Jurisdictions
Employer duty of care obligations across US, UK, and EU jurisdictions consistently require four measurable actions: risk assessment before travel, pre-trip communication of hazards, real-time incident response capability, and documented post-incident review. Per ISO 31030:2021 Clause 6, organizations must maintain a travel risk register that includes destination-level threats, traveler profile risks, and journey-specific exposures. The UK HSE guidance INDG163 mandates that risk assessments be "suitable and sufficient," with revised assessments whenever destinations change. The U.S. Department of State Travel Advisory system — Levels 1 through 4 — is the de facto reference for U.S. employers determining destination risk; failure to reflect Level 3 or Level 4 designations in pre-trip briefings has been cited in workers' compensation determinations. The EU-OSHA framework requires that risk information be documented and reviewed at defined intervals, and that findings be communicated to workers in a form they can understand.
Traveler Tracking: A Legal Expectation, Not an Option
Traveler tracking is now a legal expectation, not an option, under modern duty of care frameworks. ISO 31030:2021 Section 7.4 requires organizations to "monitor travelers throughout their journey" and provide two-way communication during incidents. The GBTA 2024 Duty of Care research found that 72 percent of travel managers report having a formal traveler tracking system, up from 61 percent in 2022. In the EU, GDPR Article 6(1)(f) (legitimate interest) permits real-time location processing for safety, but requires transparent notice to the employee, purpose limitation, and data minimization — location data must be deleted once the safety purpose ends, per European Data Protection Board Guidelines 05/2020. The UK Information Commissioner's Office confirms that employer tracking during business travel is lawful when justified against a documented risk assessment. U.S. employers face state-by-state variance, with California's CCPA and Illinois's BIPA imposing the strictest notice requirements.
Penalties and Prosecution: What Non-Compliance Actually Costs
Regulatory fines are the visible layer; civil damages and reputational cost are usually larger. Under the UK Corporate Manslaughter Act 2007, the mean fine post-2016 (following the Sentencing Council's Health and Safety Offences Guideline) is £1.2 million per HSE data. The largest single fine to date was £3.2 million against a construction firm in 2019. In France, the Cour de cassation's faute inexcusable doctrine allows victims and families to claim uncapped damages from an employer whose risk assessment was inadequate — the average settlement in adjudicated business-travel claims is €340,000 per URSSAF data.
In the United States, workers' compensation is the primary compensation mechanism, but exclusive-remedy provisions are pierced where the employer's conduct is "substantially certain" to cause harm (see Woodson v. Rowland, 329 N.C. 330, 1991). Direct-action wrongful death suits following an inadequately-briefed foreign trip have produced verdicts above $10 million — the 2018 case involving a construction executive killed in Mexico settled for $16 million after evidence showed the employer had ignored the U.S. State Department Level 3 advisory in effect at time of travel.
Building a Compliant Program: The Four Operational Layers
A compliant duty of care program combines four operational layers regardless of jurisdiction. First, a pre-trip risk assessment mapping destination advisories against traveler profile — the U.S. State Department, UK FCDO, and Germany's Auswärtiges Amt travel advisories are the authoritative sources. Second, a booking data feed that captures every trip regardless of booking channel; leakage — bookings made outside the corporate program — is the primary compliance gap, with GBTA 2024 research showing 40 percent of business trips occur outside the managed program. Third, a 24/7 incident response protocol tied to real-time traveler location; International SOS reports a median response time from alert to first contact of 12 minutes across their tracked population. Fourth, post-incident documentation that can withstand audit under HSE, OSHA, or Framework Directive investigations. Missing any single layer creates regulatory exposure regardless of intent.
The single largest technical gap in practice is the booking data feed. Most enterprises route trips through a TMC-managed online booking tool (OBT) but tolerate significant leakage to direct-supplier and consumer booking channels. Under all three jurisdictions, an employer cannot demonstrate a "suitable and sufficient" risk assessment for a trip it does not know occurred. Modernizing the data feed — not necessarily replacing the OBT — is where most compliance programs need the largest lift, as documented in Duty of Care Without Changing Your OBT: A Data-Feed Approach.
Special Case: Contractors, Gig Workers, and the Extended Duty
UK Section 3 of the HSW Act extends duty to non-employees "affected by" the employer's activities — the widest of the three jurisdictions. This has been interpreted by the HSE to include contractors, agency workers, and subcontracted travelers where the primary organization directs the trip. The EU Framework Directive Article 7(4) similarly extends preventive protection to "workers from outside undertakings and/or establishments engaged in work in his undertaking."
US law is narrower but converging. OSHA's Multi-Employer Citation Policy (CPL 02-00-124) allows citation of the "controlling employer" even where a contractor is technically responsible for the affected worker. The 2015 SeaWorld of Florida, LLC v. Perez ruling (748 F.3d 1202) confirmed that OSHA's General Duty Clause applies where the employer has the ability to correct the hazard, regardless of employment classification.
Where Travel Code Fits
Travel Code is a BYOD (Bring Your Own Data) overlay platform — not a TMC. For duty of care specifically, the platform ingests booking data from any existing TMC, OBT, or direct-channel booking, applies real-time traveler tracking and risk-alerting against U.S. State Department, UK FCDO, and EU advisory feeds, and generates audit-ready documentation aligned to ISO 31030:2021 Clauses 6 and 7. Organizations keep their existing TMC and booking workflows; Travel Code adds the compliance data layer that closes the leakage gap. Where continuous rate re-shopping is in scope, RateGuard is priced at 25 percent of validated savings only — no fixed fee, no minimum.
Related Reading
- Business Travel Safety & Security: The Complete Guide
- Business Travel Insurance: Coverage, Costs & Corporate Plans
- Corporate Travel Data Analytics: Using Travel Spend Data
- Business Travel Trends 2026: Outlook, Spend & What's Changing
Frequently Asked Questions
Is duty of care a legal obligation for business travel or just a best practice?
It is a statutory legal obligation in the US (OSH Act Section 5(a)(1)), UK (HSW Act 1974 Sections 2–3 and Corporate Manslaughter Act 2007), and every EU member state via Framework Directive 89/391/EEC. Best-practice frameworks such as ISO 31030:2021 supplement — they do not replace — the statutory duty. Employers who treat duty of care as advisory have lost civil and criminal cases in all three jurisdictions.
What is OSHA's role in US business travel duty of care?
OSHA does not publish travel-specific standards, but enforces the General Duty Clause — Section 5(a)(1) of the OSH Act of 1970 — against employers who fail to protect employees from "recognized hazards" during work-related travel. The 2019 DOL guidance letter confirms extraterritorial application where the employer directs the work. State workers' compensation statutes are the parallel compensation mechanism and apply under the "traveling employee" doctrine.
How does ISO 31030:2021 differ from national law?
ISO 31030:2021, published September 2021, is a voluntary international standard providing an operational framework for travel risk management. It is not law in any jurisdiction, but courts, insurers, and regulators increasingly cite it as the "reasonable" benchmark against which employer conduct is measured. Certification is not required; alignment with its Clauses 6 (planning) and 7 (implementation) is what auditors and courts examine.
Can a company be criminally prosecuted if a business traveler is killed?
Yes, in the UK under the Corporate Manslaughter and Corporate Homicide Act 2007, which has produced 42 successful prosecutions as of 2024 HSE data. In France, corporate criminal liability applies under Article 121-2 of the Code pénal, with fines up to €225,000. In the US, criminal prosecution of the employer is rare but possible under state manslaughter statutes; individual executives face potential prosecution under 18 U.S.C. § 1112 in cases of gross negligence.
Do gig workers and contractors receive duty of care coverage?
UK Section 3 of the HSW Act extends duty to any non-employee affected by the employer's activities — the widest scope. EU Framework Directive Article 7(4) extends preventive protection to external workers on-site. US law extends via OSHA's Multi-Employer Citation Policy (CPL 02-00-124), under which the "controlling employer" can be cited regardless of formal employment status. Classifying a business traveler as a contractor does not extinguish duty of care in any of the three jurisdictions.
Are employers legally required to track business travelers in real time?
Statute does not require GPS tracking explicitly in any jurisdiction, but ISO 31030:2021 Section 7.4 requires monitoring throughout the journey, and courts increasingly treat inability to locate a traveler as evidence of inadequate risk management. GBTA 2024 data shows 72 percent of enterprises now operate a formal tracking system. GDPR Article 6(1)(f) permits it under legitimate interest with proper notice; the UK ICO confirms lawfulness against a documented risk assessment.
Is Travel Code a TMC?
No. Travel Code is a BYOD overlay platform that runs alongside any existing TMC, OBT, or direct-channel booking flow. It adds duty of care, real-time traveler tracking, unified analytics, and continuous rate re-shopping (RateGuard, 25 percent of validated savings). It does not replace the TMC's ticketing, servicing, or supplier contracts.
Primary Sources Cited
- Occupational Safety and Health Act of 1970, 29 U.S.C. § 654(a)(1) — General Duty Clause
- OSHA 2026 Penalty Schedule, Federal Civil Penalties Inflation Adjustment Act of 2015
- Health and Safety at Work etc. Act 1974 (UK), Sections 2 and 3
- Corporate Manslaughter and Corporate Homicide Act 2007 (UK)
- Management of Health and Safety at Work Regulations 1999 (UK); HSE Guidance INDG163
- Council Directive 89/391/EEC of 12 June 1989 (EU Framework Directive)
- ISO 31030:2021, Travel risk management — Guidance for organizations
- Code du Travail (France) Article L4121-1; Cour de cassation, Chambre Sociale, 25 novembre 2015
- Arbeitsschutzgesetz (Germany), Section 5
- Legislative Decree 81/2008 (Italy)
- General Data Protection Regulation (EU 2016/679), Articles 5, 6(1)(f), 13
- European Data Protection Board Guidelines 05/2020
- U.S. Department of State Travel Advisory System, Levels 1–4
- UK FCDO Travel Advice; Auswärtiges Amt (Germany) travel advisories
- GBTA 2024 Duty of Care Research
- International SOS Business Resilience Trends Watch 2024 (Ipsos)
- Voehl v. Indemnity Insurance Co., 288 U.S. 162 (1933)
- EEOC v. Arabian American Oil Co., 499 U.S. 244 (1991)
- SeaWorld of Florida, LLC v. Perez, 748 F.3d 1202 (D.C. Cir. 2015)
- Woodson v. Rowland, 329 N.C. 330 (1991)
- R v Cotswold Geotechnical (Holdings) Ltd (2011)
- OSHA Multi-Employer Citation Policy, CPL 02-00-124