One document, two violations. Most teams log once, names and addresses and the story in one file, then hand that same file to everyone who asks.
The law asks for seven fields, kept five years, with a private master and a copy you can show employees. Get the fields wrong and you are out of compliance. Get privacy wrong and you create a second violation while trying to prove the first.
The seven fields every entry needs
Cal/OSHA does not accept a memo or a three column spreadsheet. An entry without these seven fields is incomplete.
| # | Required field | What to record |
|---|---|---|
| 1 | Date, time and location | When and where, specific worksite and area, for example Fresno yard, dock |
| 2 | Detailed description | What happened, in plain language, acts and Type 1 to 4 category |
| 3 | Classification | Which of the four types under §6401.9 it falls in |
| 4 | Perpetrator classification | Client, coworker, family or partner, or stranger, no names in shared copy |
| 5 | Circumstances at time | Alone, cash handled, doors unsecured, opening or closing |
| 6 | Location details | Where on premises and where help was sought |
| 7 | Consequences and response | Injuries, police contact, time off, correction triggered |
The problem is not that you are not logging. It is that a single spreadsheet forces a bad choice. Hide fields to protect names and you have an incomplete record. Show everything and you have exposed names. Both fail.
Private versus employee-safe
Section §6401.9(d)(4) limits disclosure. Medical details and identifiers stay private. The version you make available to employees must be redacted.
| Employee-safe view | Private master only |
|---|---|
| Date, time, location | Victim, witness and perpetrator names and contacts |
| Violence type (1 to 4) and general description | Medical details beyond first aid, ER or none |
| Perpetrator category (customer, coworker, stranger) | Personnel file refs, footage links |
| Circumstances and corrections made | Investigator notes, retaliation checks |
| Consequences (police called, restriction, fix) | SSNs, DOBs, addresses, never in shared view |
Subilu keeps one entry with two views. You enter once. The master keeps everything for five years. The employee view replaces names with chips like Witness, redacted, so you can answer a request without hand redacting. It follows the DIR model log, with separation actually enforced.
Your WVPP and your log export separately for the same reason. Mixing them into one ZIP is how names leak.
Five year retention and an export that holds up
You must keep the log five years and produce it within fifteen days of a request from employees, their reps or Cal/OSHA. Two details decide whether the file survives.
CSV with BOM and formula guard. Exports include UTF8 BOM so Excel on Windows does not mangle timestamps. A leading equals, plus, minus or at sign is escaped so a description like =2+2 threatened does not run as a formula. Small things, but they keep data intact across five years and every manager laptop.
Separate from the WVPP. The log is not Appendix D of your plan. It exports as violent-incident-log.csv or pdf on its own. Training exports as training-roster.csv on its own. Three separate files, not one ZIP.
Copy the seven field table into your current sheet and run one past incident through it. A blank cell or a name you would not post in the break room is the trap.
Not legal advice. Source: Labor Code §6401.9(d) and DIR violent incident log guidance. Pair with Your WVPP in 21 Sections.