blog

Martyn’s Law: Who is the responsible person?

When Martyn’s Law comes into force, one of the first questions venue operators and security professionals will face is deceptively simple: who is actually responsible? The Terrorism (Protection of Premises) Act 2025 places formal obligations on a defined “responsible person.” As Counter Terror Business, reports, the SIA has now clarified both who that person is and the notification requirements they will face. For alarm installers and security integrators, this matters, because it shapes who you’ll be working with and what they’re legally required to do.

What the SIA has clarified

The Home Office recently published new guidance on the notification requirement under Martyn’s Law, and the SIA has followed up with practical detail. Once the Act comes into force, expected from April 2027, those responsible for qualifying premises and events will need to formally notify the SIA that they are in scope.

The notification portal is currently being built. In the meantime, the SIA has confirmed the key timelines:

  • Qualifying premises: A three-month window from commencement of the relevant section in the Act to submit notification. Any changes after that must be reported within 28 days.
  • Qualifying events: In most cases, the responsible person must notify the SIA within 14 days of the event date being made publicly available.

These are formal notification requirements under the Act, so venues need to understand the timelines well before commencement.

Defining the responsible person

For qualifying premises, the responsible person is the individual, organisation, or company with control of the premises for the use that makes it subject to Martyn’s Law. That last clause is important. It’s not simply whoever owns or manages the building, it’s whoever controls how it’s used in a way that brings it within scope.

For qualifying events, the responsible person is the individual, organisation, or company with control of the premises at which the qualifying event is taking place, for the purposes of the event. A venue owner might control the premises for day-to-day use, while responsibility for a qualifying event may sit elsewhere if another organisation has control of the premises for the purposes of that event.

In practice, this means the responsible person may change depending on context. A hotel is one scenario. A conference centre that regularly hosts third-party events is another entirely.

What this means for installers and integrators

Security installers are increasingly being pulled into conversations that used to sit with facilities managers or legal teams. Understanding who holds legal responsibility under Martyn’s Law affects how you scope a project, who signs off on the system design, and, critically, what the system actually needs to do.

Standard tier venues need to have procedures in place and staff trained to respond to a terrorist attack. Enhanced tier venues face more demanding requirements, including structured public protection procedures. In both cases, venues need appropriate public protection procedures and, where necessary, systems that can support those procedures in practice. For some premises, that may mean going beyond a traditional fire alarm to provide more flexible emergency communication.

This is where AddSecure’s AddAlert becomes relevant. For venues that need targeted emergency communication, mass notification can support lockdown, invacuation and evacuation procedures without implying that one specific technology is mandated by the Act.

Why acting now makes sense

April 2027 sounds like a long way off. It isn’t. The notification portal isn’t yet live, and many venues haven’t yet identified who their responsible person is, let alone assessed what tier they fall under or what procedures they need to implement. As the SIA’s update makes clear, the regulatory machinery is already being built, which means the compliance window is already narrowing.

For alarm installers and ARCs, the practical opportunity is to get ahead of this with existing clients. Identifying which venues are likely to be in scope, helping them understand who the responsible person is, and introducing systems like AddAlert as part of a compliant solution is a more useful conversation than waiting for a panicked call in early 2027.

Our Martyn’s Law guide for security professionals provides additional guidance on preparing clients for the new requirements and the role emergency communication can play.

The notification requirement in plain terms

To summarise what the SIA has confirmed:

  • Responsible persons for premises have three months from commencement to notify the SIA, then 28 days to report any changes.
  • Responsible persons for events must notify within 14 days of the event date becoming public.
  • The responsible person is defined by control and purpose, not just ownership.

For security integrators, knowing this puts you in a better position to advise clients clearly, scope systems accurately, and demonstrate the kind of informed, compliance-aware approach that builds long-term relationships.

Want to understand how AddAlert supports Martyn’s Law compliance for your clients? Get in touch with the AddSecure team to discuss venue-specific requirements and how to position mass notification as part of a compliant security solution.

Related