{{org_field_logo}}

{{org_field_name}}

Registration Number: {{org_field_registration_no}}


Confidentiality and Data Protection (UK GDPR) – Staff Policy

1. Purpose

The purpose of this policy is to ensure that all staff members at {{org_field_name}} understand their responsibilities in maintaining confidentiality and complying with data protection law, including the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and (as commenced) the Data (Use and Access) Act 2025, together with any other applicable legislation and regulatory guidance relevant to adult social care.

This policy ensures that:

2. Scope

This policy applies to:

3. Principles of Confidentiality and Data Protection

3.1 Lawful, Fair, and Transparent Processing

3.2 Purpose Limitation

3.3 Data Minimisation

3.4 Accuracy

3.5 Storage Limitation

Retention and disposal must follow {{org_field_name}}’s Records Retention Schedule and nationally recognised guidance (for example, the Records Management Code of Practice for Health and Social Care), and staff must not destroy or delete records unless authorised to do so.

3.6 Integrity and Confidentiality (Security)

3.7 Records must be fit for purpose (CQC Regulation 17)

Records about people we support and our regulated activities must be complete, legible, accurate, up to date and created/updated without undue delay. Records must be accessible to authorised staff and authorised external professionals where necessary for safe and effective care, while remaining secure at all times.

3.8 Accountability

3.9 Common law confidentiality and Caldicott Principles

In addition to data protection law, staff must follow the common law duty of confidentiality: information given in confidence should not be disclosed without a clear justification. We apply the Caldicott Principles to ensure information sharing is necessary, proportionate, and on a need-to-know basis, while recognising that sharing relevant information for individual care can be as important as protecting confidentiality.

4. Staff Responsibilities in Data Protection

4.1 Handling Personal Data Securely

4.2 IT and Digital Security

4.3 Secure Disposal of Data

4.4 Confidential Conversations

4.5 Reporting Data Breaches

Any suspected or actual personal data breach must be reported immediately to the Data Protection Officer (DPO) – {{org_field_data_protection_officer_first_name}} {{org_field_data_protection_officer_last_name}} (or the senior manager on duty if the DPO is unavailable). Staff must preserve evidence and take immediate steps to contain the breach where safe to do so (for example, recalling an email, recovering paperwork, or isolating a device).

The DPO will follow the breach response plan, including assessment of risk to individuals, mitigation actions, and completion of a breach log. Where the breach is notifiable, {{org_field_name}} will report it to the ICO without undue delay and, where feasible, within 72 hours of becoming aware of it. Where the breach is likely to result in a high risk to individuals’ rights and freedoms, affected individuals will also be informed without undue delay.

4.6 Record keeping, amendments and capacity decisions (CQC Regulation 17)

Staff must ensure care records are accurate, complete, contemporaneous, and attributable (it must be clear who made the entry and when). Entries must be legible, factual, and timely.

Where a person lacks capacity, staff must record the capacity assessment and the best-interests decision-making process, including who was consulted and why the decision was made, in line with the Mental Capacity Act and associated guidance.

5. Information Sharing and Consent

5.1 Sharing Data with External Parties

Personal data may only be shared where there is a lawful basis under the UK GDPR and a clear confidentiality justification. Depending on the context, lawful bases may include legal obligation, vital interests, contract, legitimate interests, and (where applicable) recognised legitimate interests introduced by the Data (Use and Access) Act 2025 (for example, safeguarding, responding to emergencies, and crime prevention).

Because much of our information is health and care information (special category data), sharing will also require a valid UK GDPR special category condition (for example, where processing is necessary for health or social care, safeguarding, or protecting vital interests).

Staff must not assume that consent is always required for safe care. Where consent is appropriate, it must be properly obtained and recorded.

5.2 Obtaining Consent for Data Use

5.3 Confidentiality in Safeguarding Situations

5.4 Sharing information with family, friends and representatives

Staff may only share personal information with family or friends where:

(a) the person has capacity and has consented to that specific sharing;

(b) the person lacks capacity and sharing is necessary and in their best interests, and the decision is recorded;

(c) the recipient has legal authority (for example, Health and Welfare LPA acting within scope, or a court-appointed deputy).

Staff must share the minimum necessary information and record what was shared, with whom, the lawful basis/justification, and the outcome.

5.5 Requests for information from CQC, safeguarding authorities, police, or courts

Any external request for personal information must be referred to the DPO (or senior manager on duty) before disclosure, unless there is an immediate risk of serious harm. We must verify the requester’s identity and authority, disclose only what is necessary, and keep a record of the disclosure decision.

Staff must cooperate with CQC inspections and information requests. CQC has legal powers to require information and access to records (including personal and medical records) for its regulatory functions. Where CQC requests information, we will provide it within required timescales and in a way that maintains privacy (for example, providing records in a private area and limiting access to authorised persons).

6. Training and Compliance

6.1 Staff Training on GDPR and Confidentiality

6.2 Monitoring and Audits

7. Data Subject Rights

Under the UK GDPR (as amended), individuals have rights over their personal data, subject to specific legal limitations (for example, where we must keep records to meet legal and regulatory obligations).

Requests can be made in writing or verbally and must be passed immediately to the DPO: {{org_field_data_protection_officer_first_name}} {{org_field_data_protection_officer_last_name}}. We will respond without undue delay and within one month, unless the law allows an extension for complex requests. Where we reasonably require additional information to confirm identity or to clarify the request, the response time may be paused (“stop-the-clock”) until the information is provided, and we will carry out reasonable and proportionate searches when responding.

7.1 Complaints about how we use personal information

Individuals may complain if they believe we have not handled their personal information lawfully or fairly. {{org_field_name}} will make it easy to complain (including an electronic option) and will inform the individual of the outcome and any actions taken. Individuals will also be signposted to their right to complain to the Information Commissioner.

7.2 Requests for records of deceased people

Requests for access to the health and care records of a deceased person must be referred to the DPO. Access may be available to the personal representative of the estate (for example, executor/administrator) or someone with a claim arising from the death, in line with applicable law and guidance. No disclosure must be made by staff without DPO authorisation and a recorded decision.

8. Related Policies

This policy should be read alongside:

9. Policy Review

This policy is reviewed annually or sooner if:

This Confidentiality and Data Protection (GDPR) – Staff Policy ensures that staff understand their legal obligations, personal data is protected, and our care home remains compliant with GDPR and CQC requirements.


Responsible Person: {{org_field_registered_manager_first_name}} {{org_field_registered_manager_last_name}}
Reviewed on:
{{last_update_date}}
Next Review Date:
{{next_review_date}}
Copyright © {{current_year}} – {{org_field_name}}. All rights reserved.

Leave a Reply

Your email address will not be published. Required fields are marked *