{{org_field_logo}}

{{org_field_name}}

Registration Number: {{org_field_registration_no}}


Sharing Information with Third-Party Organisations Policy

1. Purpose

The purpose of this policy is to ensure that {{org_field_name}} shares personal, confidential and other information with third-party organisations lawfully, fairly, securely and only where there is a clear and legitimate purpose for doing so. Appropriate information sharing is essential for safe and effective care, continuity of care, safeguarding, regulatory compliance and the effective management of the service.

{{org_field_name}} will ensure that information sharing complies with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 as amended, including amendments made by the Data (Use and Access) Act 2025, the common law duty of confidentiality and other legislation applicable to the circumstances of the disclosure.

This policy ensures that:

2. Scope

This policy applies to:

3. Legal and Regulatory Compliance

This policy must be implemented in accordance with the legislation and regulatory requirements applicable to information sharing by an adult social care provider in England.

CQC Requirements – Health and Social Care Act 2008 (Regulated Activities) Regulations 2014

Regulation 9 – Person-centred care

Information must be used and shared appropriately where this is necessary to assess, plan and deliver care and treatment that meets the person’s individual needs and preferences. People must, so far as reasonably practicable, be enabled and supported to participate in decisions concerning their care and treatment.

Regulation 10 – Dignity and respect

The privacy, dignity and confidentiality of people receiving care must be respected. Personal and confidential information must not be disclosed in circumstances that unnecessarily intrude upon a person’s privacy.

Regulation 11 – Need for consent

Care and treatment must only be provided with the consent of the relevant person unless an applicable legal provision permits otherwise. Where a person aged 16 or over lacks capacity to give the relevant consent, {{org_field_name}} must act in accordance with the Mental Capacity Act 2005. Consent to care and treatment must not be confused with consent used as a lawful basis for processing personal data under the UK GDPR.

Regulation 12 – Safe care and treatment

Where responsibility for a person’s care and treatment is shared with or transferred to another person or organisation, {{org_field_name}} must work with that person or organisation, the person receiving care and other appropriate persons to ensure timely care planning and the person’s health, safety and welfare.

Relevant information required for safe care must therefore be shared promptly with authorised health and social care professionals where there is a lawful basis for doing so, while ensuring that unnecessary information is not disclosed.

Regulation 13 – Safeguarding service users from abuse and improper treatment

Information must be shared appropriately where this is necessary to prevent, identify, report, investigate or respond to suspected or actual abuse, neglect or improper treatment. Information must not be withheld solely because consent has not been obtained where there is a lawful basis or legal requirement permitting or requiring the disclosure.

Regulation 17 – Good governance

{{org_field_name}} must maintain accurate, complete and contemporaneous records concerning people receiving care and other records necessary for the management of the regulated activity.

Records and information must:

Data Protection Legislation

{{org_field_name}} must comply with:

These requirements apply whenever personal data is collected, recorded, used, disclosed, transferred, stored or otherwise processed.

Common Law Duty of Confidentiality

Information provided in circumstances where a duty of confidence arises, including confidential health and care information, must not be disclosed without an appropriate justification.

Confidential information may be shared where:

The UK GDPR lawful basis and the duty of confidentiality must both be considered where both apply.

Care Act 2014

Information must be shared appropriately for adult safeguarding purposes. This includes cooperating with local authority safeguarding enquiries under section 42 of the Care Act 2014 and complying with a lawful requirement to provide information where the statutory requirements for disclosure apply.

Mental Capacity Act 2005

Where a person’s capacity to make a particular decision is in question, capacity must be assessed in accordance with the Mental Capacity Act 2005.

A person must be presumed to have capacity unless it is established that they lack capacity. A person must not be treated as lacking capacity merely because they make a decision that others consider unwise.

Where a person lacks capacity to make the relevant decision, any decision made on their behalf must comply with the Mental Capacity Act 2005, including the statutory best-interests requirements and consideration of whether the purpose can be achieved in a less restrictive way.

Freedom of Information Act 2000

The Freedom of Information Act 2000 applies to public authorities and to information held by another person on behalf of a public authority. {{org_field_name}} must therefore cooperate appropriately where information held in connection with commissioned services is subject to a lawful request made through a relevant public authority.

The Freedom of Information Act 2000 must not be treated as a general authority for {{org_field_name}} to disclose personal or confidential information.

NHS Data Security and Protection Requirements

Where {{org_field_name}} is contractually or otherwise required to comply with the NHS Data Security and Protection Toolkit, NHS information standards or associated requirements, the organisation must meet those requirements in addition to its statutory data protection obligations.

4. Principles of Information Sharing

All processing and sharing of personal data must comply with the principles of the UK GDPR.

{{org_field_name}} will ensure that personal data is:

  1. Processed lawfully, fairly and transparently – There must be a lawful basis for processing and people must be provided with appropriate information about how their personal data is used and shared, subject to any lawful exemption.
  2. Collected for specified, explicit and legitimate purposes – Personal data must not be used or shared for an incompatible purpose unless further processing is permitted by law.
  3. Adequate, relevant and limited to what is necessary – Only the information reasonably required to achieve the identified purpose may be shared.
  4. Accurate and, where necessary, kept up to date – Reasonable steps must be taken to ensure that inaccurate personal data is corrected or not relied upon where this could affect the person.
  5. Kept for no longer than necessary – Personal data must be retained in accordance with the organisation’s retention requirements and securely disposed of when there is no lawful reason to retain it.
  6. Processed securely – Appropriate technical and organisational measures must protect information against unauthorised or unlawful processing and against accidental loss, destruction or damage.

{{org_field_name}} must also comply with the accountability requirement. The organisation must be able to demonstrate its compliance with the data protection principles through appropriate policies, records, contracts, risk assessments, audits, staff training and documented decision-making.

5. Organisations with Whom Information May Be Shared

The inclusion of an organisation or category of organisation in this section does not, by itself, authorise the disclosure of personal or confidential information.

Before information is shared, staff must establish:

Subject to these requirements, information may be shared with the following organisations where lawful and necessary.

5.1 Health and Social Care Providers

Information may be shared with:

Information necessary to provide safe, coordinated care must be shared promptly with authorised professionals where there is a lawful basis for doing so.

5.2 Regulatory, Commissioning and Safeguarding Bodies

Information may be shared where lawful and necessary with:

Information must be supplied to a statutory or regulatory body where {{org_field_name}} is under a legal obligation to provide it.

5.3 Police, Courts, Coroners and Legal Bodies

Information may be shared with:

A request from the police or another law-enforcement organisation does not automatically authorise disclosure. Staff must establish the lawful basis and necessity for the disclosure unless an immediate emergency makes this impracticable.

Where disclosure is required by legislation, a court order or another binding legal requirement, {{org_field_name}} will comply with that requirement and will disclose only the information falling within its scope.

5.4 External Service Providers

Personal data may be provided to external service providers including:

Before personal data is made available to an external organisation processing information on behalf of {{org_field_name}}, the organisation must determine whether the recipient is acting as a processor, joint controller or independent controller and must put the legally required arrangements in place.

6. Lawful Bases and Conditions for Information Sharing

Personal data must not be shared unless {{org_field_name}} has identified and documented an appropriate lawful basis under Article 6 of the UK GDPR.

Depending upon the circumstances, the applicable Article 6 lawful basis may include:

The lawful basis must be determined from the actual purpose and circumstances of the processing. Staff must not select consent simply because information is personal or confidential.

6.1 Special Category Data

Health information and certain other particularly sensitive categories of personal information constitute special category data.

Where special category data is processed or shared, identifying an Article 6 lawful basis is not sufficient. {{org_field_name}} must also identify a valid condition under Article 9 of the UK GDPR.

Depending upon the circumstances, relevant Article 9 conditions may include:

Where a condition requires an additional condition under the Data Protection Act 2018 or an appropriate policy document, that requirement must also be satisfied before the processing takes place.

6.2 Criminal Offence Data

Information concerning criminal convictions, offences or related security measures must only be processed or shared where Article 10 of the UK GDPR and the applicable requirements of the Data Protection Act 2018 are satisfied.

Staff must seek advice from the organisation’s designated data protection lead where there is uncertainty about the lawful basis or condition for sharing criminal offence information.

6.3 Recording the Basis for Sharing

Where appropriate to the risk and nature of the disclosure, records must identify:

7. Consent, Confidentiality, Capacity and Transparency

7.1 Consent to Care and Treatment

Consent to care and treatment must be obtained and managed in accordance with Regulation 11 of the Health and Social Care Act 2008 (Regulated Activities) Regulations 2014 and other applicable law.

Consent must be recorded appropriately within the person’s care records, including significant changes or withdrawals of consent.

Consent to care or treatment must not automatically be treated as consent to every subsequent use or disclosure of personal information.

7.2 Consent as a UK GDPR Lawful Basis

Consent is one possible lawful basis for processing personal data but it is not the default lawful basis for all information sharing.

Where {{org_field_name}} relies upon consent under the UK GDPR, it must be able to demonstrate that the consent meets the applicable legal requirements and was given for the relevant processing purpose.

Consent must not be relied upon where the person has no genuine choice or where {{org_field_name}} intends to continue the processing irrespective of whether consent is withdrawn.

Where explicit consent is required for special category data, the records must demonstrate an express statement or other sufficiently explicit indication of the person’s agreement.

A person may withdraw consent relied upon under the UK GDPR. Withdrawal must be as easy as giving consent and must not affect processing that was lawful before consent was withdrawn.

7.3 Sharing Without Consent

Personal or confidential information may be shared without consent where there is a lawful and proportionate justification for doing so.

Examples may include circumstances where:

A refusal of consent must therefore not automatically prevent information being shared where another lawful basis permits or requires the disclosure.

The reason for sharing without consent must be documented where appropriate, particularly where the disclosure involves sensitive information, safeguarding concerns or a significant decision affecting the person.

Legal or specialist data protection advice must be obtained where the position is unclear or particularly complex.

7.4 Mental Capacity

Capacity must be considered in relation to the specific decision that needs to be made.

A person must be presumed to have capacity unless it is established that they lack capacity in accordance with the Mental Capacity Act 2005.

Where a person lacks capacity to make the relevant decision, {{org_field_name}} must:

A relative or friend does not acquire authority to consent to disclosure simply because of their relationship with the person. Their legal authority, if any, must be established.

7.5 Privacy Information

People must be provided with privacy information required by the UK GDPR unless a lawful exemption applies.

Privacy information must explain, as applicable:

8. Data Security and Confidentiality in Information Sharing

8.1 Secure Methods for Sharing Information

Information must only be shared using methods that provide a level of security appropriate to the nature, sensitivity, volume and risk of the information being disclosed.

Before sending or disclosing personal or confidential information, staff must:

Approved methods may include:

Personal information must not be sent to an incorrect or unverified recipient merely because the request appears urgent.

In a genuine emergency, staff must use professional judgement to share information necessary to protect life, health or safety and must document the disclosure as soon as practicable afterwards.

8.2 Restrictions on Informal or Unauthorised Information Sharing

Staff must not:

8.3 External Data Processors – New Subsection

Where an external organisation processes personal data on behalf of {{org_field_name}}, {{org_field_name}} must use only a processor that provides sufficient guarantees that appropriate technical and organisational measures will be implemented to protect personal data and comply with data protection law.

A written contract or other binding legal act meeting Article 28 of the UK GDPR must be in place before the processor is permitted to process personal data on behalf of {{org_field_name}}.

The contract must address the legally required matters, including:

Contracts and processor arrangements must be reviewed when material processing arrangements change.

8.4 International Transfers – New Subsection

Before personal data is transferred to, accessed from or made available in a country or territory outside the United Kingdom, {{org_field_name}} must establish whether the transfer is restricted under the UK GDPR.

Where the international-transfer rules apply, the transfer must not take place unless an appropriate lawful transfer mechanism or exception is available and all applicable UK GDPR requirements have been satisfied.

This requirement applies to direct transfers and may also apply where cloud, software, support or other service providers make personal data accessible from outside the United Kingdom.

8.5 Personal Data Breaches – New Subsection

All actual or suspected personal data breaches must be reported immediately to the Registered Manager and to the Data Protection Officer, where appointed or legally required, or the organisation’s designated data protection/information governance lead.

A personal data breach includes a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.

Examples include:

On becoming aware of a personal data breach, {{org_field_name}} must:

Staff must not delay internal reporting while attempting to investigate or resolve the incident themselves.

9. Staff Training and Responsibilities

All employees who handle personal or confidential information must receive appropriate data protection, confidentiality and information-security training relevant to their role.

{{org_field_name}} requires staff to complete data protection and information-governance training at the frequency specified by the organisation and to complete additional or refresher training where required because of changes in law, systems, responsibilities, identified risks or incidents.

All staff must:

Where advice is required, staff must contact the Data Protection Officer where one has been appointed or is legally required, or otherwise the organisation’s designated data protection/information governance lead.

The Registered Manager must ensure that appropriate arrangements are in place to monitor compliance with this policy and that significant information-governance concerns are escalated appropriately.

10. Monitoring, Audits, and Compliance

To ensure compliance with this policy:

11. Related Policies

This policy should be read alongside:

12. Policy Review

This policy will be reviewed annually or sooner if:


Responsible Person: {{org_field_registered_manager_first_name}} {{org_field_registered_manager_last_name}}
Reviewed on:
{{last_update_date}}
Next Review Date:
{{next_review_date}}
Copyright © {{current_year}} – {{org_field_name}}. All rights reserved.

Leave a Reply

Your email address will not be published. Required fields are marked *