{{org_field_logo}}

{{org_field_name}}

Registration Number: {{org_field_registration_no}}


Caldicott Principles and Service user Information Policy

1. Purpose

The purpose of this policy is to ensure that {{org_field_name}} upholds the highest standards of confidentiality, integrity, and lawful processing of service user information in line with the Caldicott Principles, UK GDPR, and Care Inspectorate Wales (CIW) regulations. This policy sets out clear procedures for handling service user data securely, maintaining confidentiality, and ensuring that information is shared appropriately to protect service users’ rights and privacy.

This policy ensures compliance with:

2. Scope

This policy applies to:

It covers:

This policy also applies to information handled during domiciliary care delivery, including records kept in an individual’s home (e.g., daily notes / MAR or visit logs), information carried on paper between visits, and information accessed or recorded using mobile devices or remote systems. It includes verbal information shared in the individual’s home and information exchanged with families/representatives and partner professionals.

3. The Caldicott Principles

The Caldicott Principles provide a framework for managing service user information securely and ethically. {{org_field_name}} ensures that all staff understand and apply these principles:

Principle 1: Justify the Purpose for Using Confidential Information

Principle 2: Use Confidential Information Only When Absolutely Necessary

Principle 3: Use the Minimum Necessary Confidential Information

Principle 4: Access to Confidential Information Should Be on a Strict Need-to-Know Basis

Principle 5: Everyone Must Understand Their Responsibilities

Principle 6: Comply with the Law

Principle 7: The Duty to Share Information Can Be as Important as the Duty to Protect It

Principle 8: Inform Service users About How Their Information Is Used

4. Responsibilities of Staff in Handling Service user Information

4.1 Responsibilities of the Service Provider and Responsible Individual (RI)

The Service Provider and Responsible Individual are accountable for ensuring effective information governance arrangements are in place. This includes:

4.2 Responsibilities of the Registered Manager

4.3 Responsibilities of Care Staff

4.4 Responsibilities of the Data Protection Officer (DPO)

5. Sharing Service user Information Safely

5.1 When Can Service user Information Be Shared?

Service user-identifiable data can only be shared:

5.2 Secure Methods of Sharing Data

5.3 Documenting Data Sharing

6. Individuals’ information rights and access to records

{{org_field_name}} will support individuals (and where appropriate their authorised representatives) to understand and exercise their rights under UK GDPR and the Data Protection Act 2018. This includes the right to: access a copy of their personal data, request correction of inaccurate data, request deletion where applicable, restrict processing, object to certain processing, and complain to the Information Commissioner’s Office (ICO).

Subject Access Requests (SARs): Any request (verbal or written) from an individual/representative to see or obtain copies of records must be treated as a SAR and forwarded to the Data Protection Officer immediately. Identity and authority will be verified before disclosure. Responses will be issued within statutory timescales and disclosures will be recorded.

Transparency: Privacy notices must be provided in accessible formats and explained in a way the individual can understand, including what data is collected, why, who it may be shared with, and how long it is retained.

7. Records management, retention and disposal

Records must be accurate, complete, contemporaneous and attributable, and stored in a way that maintains confidentiality and integrity. Records include (but are not limited to) assessments, personal plans, visit notes, risk assessments, medication records, incident records, safeguarding records, staff records and data-sharing logs.

Retention: Records will be retained for periods defined in {{org_field_name}}’s Record Retention Schedule, aligned to legal, regulatory and best-practice requirements for health and social care records.

Secure disposal: At the end of the retention period, paper records must be cross-shredded or disposed of via an approved confidential waste contractor. Electronic records must be securely deleted in line with IT procedures, ensuring data cannot be reconstructed. Disposal actions must be logged where required.

8. Data Security and Breach Reporting

8.1 How Data is Stored

8.2 What Constitutes a Data Breach?

A data breach includes:

8.3 Reporting a Data Breach

  1. Report the breach immediately to the Data Protection Officer.
  2. The DPO assesses the impact and determines if ICO notification is required.
  3. The breach is documented, and corrective action is taken to prevent recurrence.

9. Staff Training and Compliance

10. Monitoring and Compliance

As inspection outcomes contribute to published ratings, the service will maintain clear audit trails for training, access controls, breaches, and corrective actions relating to information governance.

11. Related Policies

This policy should be read in conjunction with:

12. Policy Review

This policy will be reviewed annually or sooner if required by legislative changes, CIW regulations, or operational needs.


Responsible Person: {{org_field_registered_manager_first_name}} {{org_field_registered_manager_last_name}}
Reviewed on:
{{last_update_date}}
Next Review Date:
{{next_review_date}}
Copyright © {{current_year}} – {{org_field_name}}. All rights reserved.

Leave a Reply

Your email address will not be published. Required fields are marked *