{{org_field_logo}}
{{org_field_name}}
Registration Number: {{org_field_registration_no}}
Caldicott Principles and Patient Information Policy
1. Purpose
This policy sets out how we collect, use, store, share and dispose of personal data and confidential care information lawfully, fairly and transparently, and in a way that protects the privacy, dignity and safety of people who use our service. It reflects the Caldicott Principles (including the duty to share appropriately and the duty to protect confidentiality), the UK GDPR and the Data Protection Act 2018 (as amended), including changes introduced by the Data (Use and Access) Act 2025 (phased implementation 2025–2026), and other relevant legal and professional duties of confidence. This policy also supports compliance with the Health and Social Care Act 2008 (Regulated Activities) Regulations 2014, particularly the provider’s duties under Regulation 17 (Good Governance) for secure, accurate and contemporaneous records and continuous improvement.
2. Scope
This policy applies to all staff members, volunteers, third-party contractors, and anyone handling personal data within our care home. It covers:
- Collection, processing, storage, sharing, and disposal of patient information.
- Confidentiality in verbal, written, and electronic records.
- People’s rights in relation to their personal data, including access requests, rectification, restriction and objection, and how we respond within required timescales.
- How people and their representatives can raise concerns or complaints about how we use personal information, including our internal data protection complaints process.
- Compliance with the seven Caldicott Principles to protect individuals’ personal and medical data.
- Responsibilities of the Caldicott Guardian within our organisation.
3. Related Policies
- CH04 – Good Governance Policy (Ensuring appropriate record-keeping and data protection).
- CH08 – Dignity and Respect Policy (Protecting personal information as a component of dignity).
- CH34 – Confidentiality and Data Protection (GDPR) Policy (Managing data access and security).
- CH35 – Duty of Candour Policy (Ensuring transparency when handling incidents involving patient data breaches).
- CH42 – Communication and Engagement with Service Users and Families Policy (Ensuring appropriate information sharing).
4. The Eight Caldicott Principles
We apply the Caldicott Principles whenever we handle confidential care information (including paper records, electronic care planning systems, email, photographs, CCTV where applicable, and verbal disclosures).
Principle 1 – Justify the purpose: We clearly define and record the purpose for using or sharing confidential information, and only use it for that purpose.
Principle 2 – Don’t use confidential information unless absolutely necessary: We avoid using identifiable information where anonymised or pseudonymised information would meet the need.
Principle 3 – Use the minimum necessary: Where identifiable information is required, we use the minimum amount needed to achieve the purpose.
Principle 4 – Access on a strict need-to-know basis: Access is role-based and limited to staff who need the information to provide safe care or fulfil their duties.
Principle 5 – Everyone must understand responsibilities: All staff, volunteers and contractors receive confidentiality and information governance training and understand their legal, professional and contractual duties.
Principle 6 – Comply with the law: We comply with the UK GDPR and Data Protection Act 2018 (as amended, including relevant DUAA 2025 changes), the common law duty of confidentiality, and any other applicable legal requirements.
Principle 7 – The duty to share can be as important as the duty to protect confidentiality: We share information appropriately for direct care, safeguarding, continuity of care, and where required by law, while ensuring the sharing is proportionate, secure and recorded.
Principle 8 – Inform service users about how their confidential information is used: We provide clear privacy information at admission and when circumstances change, explaining what we collect, why, who we may share with, how long we keep it, and what choices/rights people have.
5. Roles and Responsibilities
- Caldicott Guardian: Senior person responsible for ensuring confidential care information is used ethically and lawfully, balancing the duty to share for safe care with the duty to protect confidentiality. Provides advice on complex information sharing decisions and ensures decisions are appropriately recorded.
- Data Protection Officer (DPO) / Data Protection Lead: Responsible for data protection compliance oversight (UK GDPR / DPA 2018), advising on lawful basis, data protection impact assessments (DPIAs), breach management, and supporting responses to individual rights requests (including subject access). If the organisation is not legally required to appoint a DPO, we appoint a Data Protection Lead to fulfil these functions.
- Registered Manager: Accountable for implementing this policy day-to-day, ensuring staff follow secure record-keeping and information sharing processes, and ensuring governance evidence is available for CQC.
- Care Staff: Handle personal information responsibly, maintain confidentiality, and only share data where necessary. Must report any breaches immediately.
- IT and Administration Staff: Maintain secure electronic records and storage, ensuring access control measures are upheld.
6. Legal and regulatory framework
We manage information in line with:
- UK GDPR and the Data Protection Act 2018, as amended (including relevant provisions of the Data (Use and Access) Act 2025, phased in between June 2025 and June 2026).
- The Health and Social Care Act 2008 (Regulated Activities) Regulations 2014, including Regulation 17 (Good Governance) requirements for secure, accurate, complete and contemporaneous records and continual improvement of information processing practice.
- The common law duty of confidentiality and professional expectations of confidentiality.
- Information sharing duties and safeguarding expectations (sharing where necessary, proportionate and lawful).
Where requirements overlap, we apply the highest standard necessary to protect people’s rights, safety and dignity.
7. Information Security and Data Management
To ensure secure collection, storage, and disposal of personal information, we implement the following measures:
- Paper Records: Stored in locked cabinets with access limited to authorised personnel.
- Electronic Records: Stored securely on encrypted servers with role-based access control.
- Email and Digital Communication: Only secure email systems are used for sharing patient-identifiable information. No personal emails are permitted for data transfer.
- NHS Data Security and Protection Toolkit (DSPT): Where we have access to NHS patient data or NHS systems (e.g., NHSmail or shared care records) we complete the DSPT as required and use it to evidence our performance against the National Data Guardian data security standards.
- Mobile Devices and Laptops: Staff using portable devices must encrypt and password-protect them. Unauthorised removal of patient records from the care home is strictly prohibited.
- Data Retention: We follow a documented Retention and Disposal Schedule which sets out how long each type of record is kept and the lawful basis for retention. Records are reviewed regularly, disposed of securely at end of retention, and we keep a disposal log (what was destroyed, when, how, and by whom).
- Breach Management: All suspected data breaches must be reported immediately to the Data Protection Lead/DPO and recorded. We assess risk and, where a breach is notifiable, we report it to the ICO within 72 hours of becoming aware, where feasible. Where a breach is likely to result in a high risk to individuals’ rights and freedoms, we also inform affected individuals without undue delay, and we take immediate steps to contain, investigate and prevent recurrence.
8. Information sharing and disclosure
We share information lawfully, proportionately and securely, in line with the Caldicott Principles and our confidentiality duties. We do not rely on “explicit consent” as the default for all sharing; instead, before sharing we identify and record the lawful basis for sharing under the UK GDPR and, where health/care information is involved, the relevant special category condition (for example, sharing necessary for health or social care purposes, safeguarding, vital interests, or legal obligations).
Consent and expectations: Where consent is the appropriate basis (for example, where sharing is optional and not needed for care/safety/legal duties), we seek and record consent and respect the person’s choices. Where sharing is necessary for direct care, safeguarding, public protection, or legal duties, we may share without consent, but we will only share what is necessary and we will record the decision and rationale.
Secure methods and minimum necessary: We use secure communication methods, verify recipient identity, and share the minimum information required.
Requests from regulators and statutory bodies: Requests from bodies such as the CQC or a local authority are handled promptly and lawfully. Where disclosure is required or permitted by law, we provide information while maintaining appropriate confidentiality controls and an audit trail of disclosures.
9. Privacy information (transparency)
We provide a privacy notice to people who use the service (and, where appropriate, their representatives) at admission and when there are material changes. The notice explains what information we collect, why we collect it, who we may share it with, how long we keep it, how we keep it secure, and the rights people have in relation to their personal data. This supports Caldicott Principle 8 (informing people about how their information is used).
10. Individual rights and Subject Access Requests (SARs)
People have rights over their personal data (including the right of access, rectification and erasure in some circumstances). We have a documented process for handling requests. We respond to subject access requests without undue delay and within one month of receipt, unless a lawful extension applies. We verify identity, clarify scope where needed, and carry out a reasonable and proportionate search in line with current legal requirements and ICO guidance. We provide information in a secure format and apply lawful exemptions/redactions (for example, to protect third-party confidentiality) where applicable.
11. Confidentiality and Staff Training
- All staff sign a Confidentiality Agreement upon joining the organisation.
- Mandatory training on GDPR, Caldicott Principles, and information security is provided.
- Regular audits are conducted to identify any risks related to patient information handling.
- Disciplinary action will be taken against staff members who breach confidentiality protocols.
12. Handling Complaints and Concerns
If a person believes their information has been mishandled, they can raise a concern under CH14 – Receiving and Acting on Complaints Policy and/or directly with our Data Protection Lead/DPO. In line with the Data (Use and Access) Act 2025, we facilitate data protection complaints (including offering an electronic method to submit a complaint), acknowledge receipt within 30 days, and respond without undue delay, setting out the outcome and any action taken. Where the person remains dissatisfied after our response, they may escalate the matter to the ICO (or other relevant bodies as appropriate).
13. Policy Compliance and Monitoring
- The Data Protection Officer and Registered Manager are responsible for ensuring ongoing compliance with this policy.
- Annual audits and staff compliance checks will be carried out to identify and address risks.
- Audit activity includes review of record completeness, accuracy and timeliness, access controls, information sharing decisions, breaches/near misses, and learning outcomes. Evidence is collated in a way that supports CQC’s approach to assessing governance, management and sustainability, including how we use information about risk, performance and outcomes and share it securely when appropriate.
- Any non-compliance with this policy will result in corrective actions, further training, or disciplinary action where necessary.
14. Policy Review
This policy will be reviewed at least annually and sooner where required (for example, following a serious incident/breach, significant service change, or changes to law/regulatory expectations). Reviews will specifically consider ongoing phased implementation of the Data (Use and Access) Act 2025 (2025–2026) and any updated ICO or CQC guidance relevant to information governance.
Responsible Person: {{org_field_registered_manager_first_name}} {{org_field_registered_manager_last_name}}
Reviewed on: {{last_update_date}}
Next Review Date: {{next_review_date}}
Copyright © {{current_year}} – {{org_field_name}}. All rights reserved.