{{org_field_logo}}

{{org_field_name}}

Registration Number: {{org_field_registration_no}}


Caldicott Principles and Patient Information Policy

1. Purpose

This policy sets out how we collect, use, store, share and dispose of personal data and confidential care information lawfully, fairly and transparently, and in a way that protects the privacy, dignity and safety of people who use our service. It reflects the Caldicott Principles (including the duty to share appropriately and the duty to protect confidentiality), the UK GDPR and the Data Protection Act 2018 (as amended), including changes introduced by the Data (Use and Access) Act 2025 (phased implementation 2025–2026), and other relevant legal and professional duties of confidence. This policy also supports compliance with the Health and Social Care Act 2008 (Regulated Activities) Regulations 2014, particularly the provider’s duties under Regulation 17 (Good Governance) for secure, accurate and contemporaneous records and continuous improvement.

2. Scope

This policy applies to all staff members, volunteers, third-party contractors, and anyone handling personal data within our care home. It covers:

3. Related Policies

4. The Eight Caldicott Principles

We apply the Caldicott Principles whenever we handle confidential care information (including paper records, electronic care planning systems, email, photographs, CCTV where applicable, and verbal disclosures).

Principle 1 – Justify the purpose: We clearly define and record the purpose for using or sharing confidential information, and only use it for that purpose.

Principle 2 – Don’t use confidential information unless absolutely necessary: We avoid using identifiable information where anonymised or pseudonymised information would meet the need.

Principle 3 – Use the minimum necessary: Where identifiable information is required, we use the minimum amount needed to achieve the purpose.

Principle 4 – Access on a strict need-to-know basis: Access is role-based and limited to staff who need the information to provide safe care or fulfil their duties.

Principle 5 – Everyone must understand responsibilities: All staff, volunteers and contractors receive confidentiality and information governance training and understand their legal, professional and contractual duties.

Principle 6 – Comply with the law: We comply with the UK GDPR and Data Protection Act 2018 (as amended, including relevant DUAA 2025 changes), the common law duty of confidentiality, and any other applicable legal requirements.

Principle 7 – The duty to share can be as important as the duty to protect confidentiality: We share information appropriately for direct care, safeguarding, continuity of care, and where required by law, while ensuring the sharing is proportionate, secure and recorded.

Principle 8 – Inform service users about how their confidential information is used: We provide clear privacy information at admission and when circumstances change, explaining what we collect, why, who we may share with, how long we keep it, and what choices/rights people have.

5. Roles and Responsibilities

6. Legal and regulatory framework

We manage information in line with:

7. Information Security and Data Management

To ensure secure collection, storage, and disposal of personal information, we implement the following measures:

8. Information sharing and disclosure

We share information lawfully, proportionately and securely, in line with the Caldicott Principles and our confidentiality duties. We do not rely on “explicit consent” as the default for all sharing; instead, before sharing we identify and record the lawful basis for sharing under the UK GDPR and, where health/care information is involved, the relevant special category condition (for example, sharing necessary for health or social care purposes, safeguarding, vital interests, or legal obligations).

Consent and expectations: Where consent is the appropriate basis (for example, where sharing is optional and not needed for care/safety/legal duties), we seek and record consent and respect the person’s choices. Where sharing is necessary for direct care, safeguarding, public protection, or legal duties, we may share without consent, but we will only share what is necessary and we will record the decision and rationale.

Secure methods and minimum necessary: We use secure communication methods, verify recipient identity, and share the minimum information required.

Requests from regulators and statutory bodies: Requests from bodies such as the CQC or a local authority are handled promptly and lawfully. Where disclosure is required or permitted by law, we provide information while maintaining appropriate confidentiality controls and an audit trail of disclosures.

9. Privacy information (transparency)

We provide a privacy notice to people who use the service (and, where appropriate, their representatives) at admission and when there are material changes. The notice explains what information we collect, why we collect it, who we may share it with, how long we keep it, how we keep it secure, and the rights people have in relation to their personal data. This supports Caldicott Principle 8 (informing people about how their information is used).

10. Individual rights and Subject Access Requests (SARs)

People have rights over their personal data (including the right of access, rectification and erasure in some circumstances). We have a documented process for handling requests. We respond to subject access requests without undue delay and within one month of receipt, unless a lawful extension applies. We verify identity, clarify scope where needed, and carry out a reasonable and proportionate search in line with current legal requirements and ICO guidance. We provide information in a secure format and apply lawful exemptions/redactions (for example, to protect third-party confidentiality) where applicable.

11. Confidentiality and Staff Training

12. Handling Complaints and Concerns

If a person believes their information has been mishandled, they can raise a concern under CH14 – Receiving and Acting on Complaints Policy and/or directly with our Data Protection Lead/DPO. In line with the Data (Use and Access) Act 2025, we facilitate data protection complaints (including offering an electronic method to submit a complaint), acknowledge receipt within 30 days, and respond without undue delay, setting out the outcome and any action taken. Where the person remains dissatisfied after our response, they may escalate the matter to the ICO (or other relevant bodies as appropriate).

13. Policy Compliance and Monitoring

14. Policy Review

This policy will be reviewed at least annually and sooner where required (for example, following a serious incident/breach, significant service change, or changes to law/regulatory expectations). Reviews will specifically consider ongoing phased implementation of the Data (Use and Access) Act 2025 (2025–2026) and any updated ICO or CQC guidance relevant to information governance.


Responsible Person: {{org_field_registered_manager_first_name}} {{org_field_registered_manager_last_name}}
Reviewed on:
{{last_update_date}}
Next Review Date:
{{next_review_date}}
Copyright © {{current_year}} – {{org_field_name}}. All rights reserved.

Leave a Reply

Your email address will not be published. Required fields are marked *