{{org_field_logo}}
{{org_field_name}}
Registration Number: {{org_field_registration_no}}
Confidentiality and Data Protection (GDPR) – Staff Policy
1. Purpose
The purpose of this policy is to ensure that {{org_field_name}} complies with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 when handling staff information. It sets out clear guidelines for the confidentiality, security, and lawful processing of employee data, ensuring that personal and sensitive information is managed responsibly and ethically.
This policy ensures compliance with:
- UK GDPR and the Data Protection Act 2018 (as amended) – including the data protection principles, lawful processing, security, and staff rights.
- Data (Use and Access) Act 2025 (DUAA) – which amends the UK GDPR/DPA 2018 in areas including subject access (including “stop the clock”) and complaint handling.
- Regulated Services (Service Providers and Responsible Individuals) (Wales) Regulations 2017 (as amended) and the Welsh Ministers’ statutory guidance (Guidance for Care Home and Domiciliary Suppliers 2024) – including expectations on confidentiality/data protection awareness, record keeping, and secure record storage.
- Regulation and Inspection of Social Care (Wales) Act 2016.
- Social Care Wales Codes of Practice (as applicable) – expected standards of conduct and practice for the workforce.
2. Scope
This policy applies to:
- All employees, contractors, agency staff, and volunteers at {{org_field_name}}.
- Personal and sensitive staff data, including employment records, health information, disciplinary records, and payroll details.
- Confidentiality obligations regarding service users, colleagues, and company information.
It covers:
- Staff responsibilities in data protection and confidentiality.
- How personal staff data is collected, processed, and stored.
- Access control and data security.
- Staff rights under GDPR.
- Data breaches and reporting procedures.
3. Principles of Confidentiality and Data Protection
{{org_field_name}} follows the seven key principles of the UK GDPR. Personal data must be:
- processed lawfully, fairly and transparently;
- collected for specified, explicit and legitimate purposes;
- adequate, relevant and limited to what is necessary (data minimisation);
- accurate and, where necessary, kept up to date;
- kept for no longer than necessary (storage limitation);
- processed securely to ensure integrity and confidentiality (security); and
- accountable – we must be able to demonstrate compliance (including having appropriate records, controls and training).
4. Staff Responsibilities
All staff are responsible for ensuring that confidentiality and data security are upheld at all times. This includes:
- Maintaining strict confidentiality when handling sensitive staff, service user, or business-related data.
- Not sharing passwords, access credentials, or confidential documents with unauthorised persons.
- Securely disposing of confidential paperwork (shredding or confidential waste disposal).
- Reporting data breaches immediately to the Data Protection Officer:
Data Protection Officer: {{org_field_data_protection_officer_first_name}} {{org_field_data_protection_officer_last_name}}.
Email: {{org_field_data_protection_officer_email}}. - Maintain accurate, timely and factual records in line with the service’s record-keeping requirements, and never access, alter or disclose records without a legitimate work reason and appropriate authorisation.
5. Collection, Processing, and Storage of Staff Data
5.1 What Personal Data We Collect
{{org_field_name}} collects and processes staff information necessary for employment, payroll, and compliance. This includes:
- Identification details (name, address, date of birth, contact details).
- Employment records (contracts, job applications, performance reviews, disciplinary records).
- Payroll and tax information (salary, pension, National Insurance details).
- Health and safety records (medical conditions affecting work, accident reports).
- Training and professional qualifications.
5.2 How Staff Data is Processed
- Staff personal data is only used for employment purposes (e.g., payroll, compliance, performance management).
- Data is processed in line with employment contracts and GDPR legal requirements.
Special category data (for example health information) will only be processed where we have:
- (a) a valid UK GDPR Article 6 lawful basis;
- (b) a valid UK GDPR Article 9 condition (and where required, the additional safeguards in Schedule 1 to the Data Protection Act 2018).
We will document the lawful basis/condition before processing begins. Explicit consent will only be relied upon where it is appropriate and can be freely given in an employment context.
5.3 How Staff Data is Stored
- Electronic records are stored on secure, password-protected systems.
- Paper records are kept in locked cabinets with restricted access.
- Only authorised personnel (HR, management) have access to confidential staff data.
5.4 Retention and secure disposal
We keep staff records only for as long as necessary for employment, legal, regulatory and safeguarding purposes, and in line with our retention schedule. Staff records are disposed of securely at end of retention (for example cross-shredding or approved confidential waste; secure deletion for electronic records).
HR will ensure staff files include and retain the information required by the Regulated Services Regulations/statutory guidance (for example key identity/DBS/employment/disciplinary records) for the appropriate period and store them securely with access controls.
6. Access Control and Data Security
6.1 Who Has Access to Staff Data?
- HR, payroll, and management teams handling staff records.
- Regulatory bodies (CIW, HMRC, local authorities) when legally required.
- External service providers (e.g., payroll processors) under strict confidentiality agreements.
6.2 Secure Access Procedures
- Staff must not share logins or passwords for data systems.
- Company-issued devices must be used for accessing sensitive information, with two-factor authentication where applicable.
- Staff must lock screens when leaving computers unattended.
7. Staff Rights Under GDPR
Employees have the following rights regarding their personal data (subject to legal limitations): the right to be informed, the right of access, rectification, erasure, restriction, data portability, the right to object, and rights relating to automated decision-making and profiling.
7.1 Right to Access (Subject Access Requests – SARs)
Staff may request access to their personal data by submitting a SAR to the Data Protection Officer (or Data Protection Lead). We will normally respond within one month.
Under the Data (Use and Access) Act 2025, where we reasonably need further information to confirm identity or clarify the request, we may pause the response timeframe (“stop the clock”) until that information is received. We will carry out reasonable and proportionate searches when responding.
Where requests are complex or numerous, the response time may be extended in line with UK GDPR requirements, and we will explain the reason for any extension.
7.2 Right to Rectification
- If personal data is inaccurate or outdated, staff can request corrections.
7.3 Right to Erasure (Right to Be Forgotten)
- Employees can request the deletion of personal data if there is no legal obligation to retain it (e.g., tax records must be retained for 6 years).
7.4 Right to Restrict Processing
- If a staff member disputes the accuracy of their data, processing can be temporarily restricted while it is verified.
7.5 Right to Data Portability
- Staff can request their data in a portable format if they change employment.
8. Data Breaches and Reporting Procedures
8.1 What Constitutes a Data Breach?
A data breach occurs when unauthorised access, loss, or disclosure of personal data occurs. This includes:
- Lost or stolen devices containing staff records.
- Unauthorised access to HR databases.
- Accidental sharing of confidential emails or files.
8.2 Reporting a Data Breach
- Report the breach immediately to the Data Protection Officer.
- The Data Protection Officer will assess severity, contain the incident, and take remedial action.
- Where required, we will notify the ICO within 72 hours of becoming aware of a notifiable breach.
- If the breach is likely to result in a high risk to individuals’ rights and freedoms, we will also inform affected individuals without undue delay, including advice on protective steps they can take.
- We will keep an internal record of all personal data breaches (including facts, effects and remedial action), even where the breach is not reported to the ICO.
8.3 CIW notification and service-impact escalation
Where a breach involves service user information, affects continuity/safety of the service, or is otherwise a significant incident, the Registered Manager/Responsible Individual will consider whether the incident must also be notified to Care Inspectorate Wales (CIW) via CIW Online in line with CIW notification requirements and the service’s incident/notification procedures
9. Staff Training and Awareness
- All employees must complete data protection training during induction.
- Annual refresher training covers:
- Understanding GDPR principles.
- Safe handling of personal and service user data.
- Recognising and reporting data breaches.
- The Registered Manager and HR team ensure staff compliance with data protection policies.
10. Data protection complaints
Staff who are concerned that their personal data has been handled in a way that breaches data protection law can raise a complaint to the Data Protection Officer (or Data Protection Lead).
We will:
- make a complaint route available (including electronically);
- acknowledge the complaint and investigate promptly;
- inform the staff member of the outcome and any actions taken.
Staff may also raise concerns with the Information Commissioner’s Office (ICO) at any time.
11. Monitoring and Compliance
- The Data Protection Officer conducts regular audits to ensure GDPR compliance.
- Confidentiality agreements are signed by all employees as part of their contract.
- Service user and staff feedback is reviewed to monitor data handling effectiveness.
- CIW will assess data protection practices during regulatory inspections.
Managers will ensure staff have access to up-to-date policies and will assess ongoing understanding through supervision and performance reviews, taking action where gaps are identified.
12. Related Policies
This policy should be read in conjunction with:
- Confidentiality and Data Protection (GDPR) – Service User Policy (DCW34).
- Whistleblowing (Speaking Up) Policy (DCW29).
- IT and Cybersecurity Policy (DCW40).
- Disciplinary and Grievance Policy (DCW31).
13. Policy Review
This policy will be reviewed annually or sooner if required by legislative changes, CIW regulations, or operational needs.
Responsible Person: {{org_field_registered_manager_first_name}} {{org_field_registered_manager_last_name}}
Reviewed on: {{last_update_date}}
Next Review Date: {{next_review_date}}
Copyright © {{current_year}} – {{org_field_name}}. All rights reserved.