Short answer: Third party harassment means someone outside your organisation mistreating your staff. A customer, a patient, a client, a supplier, a member of the public. It used to happen face to face, in your building, where somebody else could see it. Now it mostly arrives by phone: a direct message to a named employee’s personal account, a review that names her, a comment under your social media post.
In short:
- Third party harassment is abuse of your staff by customers, patients, clients or the public.
- Your website, your booking system and your social accounts put your employees’ names within reach of anyone.
- A receptionist can be found on Instagram in about four minutes by somebody who knows her first name and where she works.
- Front-line staff almost never report it, because managing difficult customers is the job as they understand it.
- You cannot discipline a customer, which is why this needs a different answer from ordinary harassment.
What third party harassment actually means
Most harassment policies describe colleagues. Somebody in your organisation behaves badly towards somebody else in your organisation, and you have a process for that.
Third party harassment is the other kind. The person doing it does not work for you at all. They are a customer, a client, a patient, a parent at the school gate, a delivery driver, somebody at the end of a phone line.
ACAS sets out what it expects employers to do about harassment at work, including harassment by people outside the organisation, and Parliament passed the Worker Protection (Amendment of Equality Act 2010) Act 2023. Your own advisers will tell you what any of that means for your organisation, because those are legal questions.
This post is about the part of third party harassment that has changed fastest, which is where the behaviour now happens.
How it used to work, and what replaced it
A rude customer used to have to turn up.
He came into the shop, or the surgery, or the office. He said something unpleasant at the counter. Other people heard it. A manager could step in, ask him to leave, and write it down afterwards. The whole thing had a beginning and an end, and it ended when he walked out.
Very little of that is still true.
Now he goes home, looks at your website, and finds the person’s name. Perhaps it sits under a photograph on a “meet the team” page. Perhaps it was on the email he received, or the booking confirmation, or the badge she was wearing. From there it takes a few minutes to find her on Instagram or Facebook, because most people’s first name, surname and town are enough.
Then he messages her directly. Not a complaint to your complaints address. A message to her, personally, on the phone she uses for everything else in her life, at whatever hour suits him.
What it looks like in practice
The shapes are fairly consistent, and knowing them helps, because staff rarely describe any of this in the language of harassment.
A customer messages a named employee’s personal account after a dispute. A patient leaves a review that names the receptionist and describes her appearance. Somebody posts under your Facebook advert and tags the member of staff who served him. A parent sends messages to a teaching assistant’s own account about something that happened at school. A man you refused to serve turns up in the comments on every post your organisation makes for a fortnight.
Some of it is furious and obvious. A good deal of it is worse than that, because it is friendly. Repeated, personal, entirely polite messages from a customer who will not stop are far harder for an employee to report than a burst of swearing, and they frighten people more.
Why your staff will not report third party harassment
Three reasons come up again and again, and none of them are about courage.
The first is that managing difficult customers is the job, as your staff understand it. You trained them to de-escalate, stay professional and keep the customer happy. Reporting a customer feels like admitting they could not handle one.
The second is the phone. It is hers, you did not issue it, and the message arrived on it at home. The whole thing feels like it sits outside work, even though the only reason it happened is that she works for you.
The third is that she cannot see what reporting would achieve. You cannot sack a customer. Unless somebody tells her what actually happens next, silence looks like the option with the fewest consequences.
So she absorbs it, and you do not find out until she resigns, or until it has gone on for months.
What an employer can actually do
More than you might think, and none of it needs a new policy document.
Start by saying out loud that this counts. Name it in the training you already run, using the examples above rather than the word “harassment”, because your staff do not recognise their own experience in that word. Somebody who has heard a manager describe the polite, persistent customer will bring you the polite, persistent customer.
Then decide what you are willing to do, before you need it. Will you reply from the organisation’s account rather than leaving her to handle it? Are you prepared to refuse service? Does somebody report the account to the platform, and who? At what point do you involve the police? None of those answers has to be dramatic, but having one in advance is the difference between a member of staff who reports and one who does not.
Look at what your own website gives away, too. There is a real balance here. Customers like knowing who they are dealing with, and “meet the team” pages do genuine good. But a full name, a photograph and a location together are enough for anybody to find that person online in minutes. First names only, or a shared team inbox rather than individual addresses, costs you very little and closes the easiest route.
And give people somewhere to put it. Even “tell your manager and we will log it with the date” changes whether anybody speaks, because most silence comes from not knowing the next step rather than from any doubt that the behaviour was wrong.
What organisations tend to miss on the digital side
Three things come up almost every time.
The first is treating a message to a personal account as a private matter. It reached her because of her job, it affects her work, and ruling it out of scope only guarantees you never hear about it.
The second is asking for one screenshot. A single message from a customer usually reads as odd rather than alarming. Fifteen of them across three weeks, with the dates, read very differently, and the dates are what show that she asked him to stop.
The third is forgetting that reviews are harassment’s favourite hiding place. A review that names an employee and comments on her looks is not feedback about your service, and it sits in public where her family and her next employer can read it.
Kids n Clicks has written about neighbouring ground in our post on workplace bullying online, our post on staff wellbeing and online harassment, and our post on cyberflashing.
Where the training fits
The remaining gap is usually knowledge rather than process. Your HR team knows the policy and the grievance route very well. Nobody in the building is tracking how quickly a name on a website turns into a personal account, or what a platform will actually act on when you report something.
Our training programmes cover exactly that. A session shows how somebody finds a named employee from a first name and a workplace, what your own site and social accounts reveal, how to report an account so that something happens, and what a usable record looks like when the messages are polite. Kids n Clicks also runs continuing support for corporate organisations, because the platforms keep changing.
The session teaches the technology, not the law. Your advisers already know the law. What often goes missing is a clear read of what actually happened on the phones, the apps and the accounts, and that is the gap this session fills. It is a specialist session, delivered online or in person, to a whole workforce or to a single team.
If you lead people, wellbeing or inclusion in your organisation, connect with Parven on LinkedIn or explore our training programmes to book a session for your team.
Parven Kaur is a digital parenting and online safety expert, and the founder of Kids n Clicks. She works with employers on the technology side of online harm and its effect on staff wellbeing. She won the Scottish Cyber Security Award, and she sits on the National Board of Advisors for Barnardo’s Scotland.
Was this helpful?
Good job! Please give your positive feedback
How could we improve this post? Please Help us.


