{{org_field_logo}}
{{org_field_name}}
Registration Number: {{org_field_registration_no}}
Security and Access Control Policy
1. Purpose
The purpose of this policy is to provide clear, comprehensive, and effective guidance on security and access control arrangements applicable to all staff working for {{org_field_name}}. As a temporary staffing agency supplying registered nurses, healthcare assistants, and other healthcare workers to care homes and other social care environments, {{org_field_name}} has a legal and ethical responsibility to safeguard service users, staff, client property, confidential information, and organisational assets. This policy outlines how security will be maintained by both the agency and its staff while on duty in client premises and during agency operations. It is essential that all staff employed or supplied by {{org_field_name}} understand their responsibilities for maintaining security, controlling access to sensitive areas and information, and contributing to a culture of vigilance.
This policy supports compliance with applicable security, data protection, employment business, health and safety, confidentiality and contractual requirements. These include the UK General Data Protection Regulation, the Data Protection Act 2018 as amended, the Data (Use and Access) Act 2025, the Health and Safety at Work etc. Act 1974, the Employment Agencies Act 1973 and the Conduct of Employment Agencies and Employment Businesses Regulations 2003, as amended.
{{org_field_name}} operates as an employment business supplying temporary workers to client organisations. It does not itself carry on a regulated health or social care activity and does not direct or control the delivery of regulated care. The client organisation remains responsible for its premises, regulated activities, site security arrangements and service-user care. Agency workers must nevertheless follow lawful client procedures, professional standards and the requirements of this policy while on assignment.
2. Scope
This policy applies to:
- all directors, employees, recruitment consultants, administrative staff, temporary workers and agency workers engaged or supplied by {{org_field_name}};
- contractors, consultants, IT support providers and other third parties who are given access to agency premises, equipment, systems or information;
- agency offices, home-working environments, client premises and any other location from which agency work is performed;
- agency-owned, client-owned and, where expressly authorised, personally owned devices used for agency business;
- paper records, electronic records, email accounts, recruitment systems, payroll systems, cloud services, mobile devices and removable media;
- personal data, special category data, criminal offence data, confidential business information, access credentials and client or service-user information; and
- physical assets, keys, identification badges, access cards, security codes and other access-control devices.
Compliance with this policy is a condition of access to {{org_field_name}} systems, information and premises. A breach may result in withdrawal of access, removal from an assignment, disciplinary action, termination of engagement or referral to a client, professional regulator, law-enforcement body or other relevant authority.
3. Related Policies and Procedures
This policy should be read alongside:
- Acceptable Use of IT and Communications Policy;
- Business Continuity and Disaster Recovery Plan;
- Confidentiality and Data Protection Policy;
- Data Breach and Cyber Incident Response Procedure;
- Data Retention and Secure Disposal Policy;
- Disciplinary Policy;
- Information Governance and Cybersecurity Policy;
- Incident Reporting and Investigation Policy;
- Lone Working Policy;
- Mobile Device and Remote Working Policy;
- Recruitment and Vetting Policy;
- Safeguarding Adults Policy;
- Staff Code of Conduct;
- Whistleblowing Policy; and
- client-specific information security, confidentiality and access-control procedures notified to the worker before or during an assignment.
4. Policy Statement
{{org_field_name}} is committed to maintaining proportionate physical, organisational and technical security measures appropriate to the nature of its activities and the risks presented by the information it processes.
The agency will:
- protect the confidentiality, integrity and availability of personal data and confidential information;
- restrict access according to the principles of least privilege and need to know;
- provide each authorised user with an individual account wherever technically possible;
- prevent unauthorised access to premises, systems, records, equipment and restricted areas;
- ensure that access is granted, changed, reviewed and withdrawn through an authorised process;
- protect workers, clients, service users, visitors and agency assets from reasonably foreseeable security risks;
- maintain procedures for detecting, reporting, containing, investigating and learning from security incidents;
- maintain proportionate backup, recovery and business-continuity arrangements;
- provide appropriate security awareness training; and
- cooperate with clients while maintaining a clear distinction between the agency’s responsibilities and the client’s responsibilities.
Security measures will be risk based, proportionate and reviewed regularly. They will not be applied in a discriminatory, unnecessarily intrusive or unsafe manner.
5. Responsibilities
5.1 Directors
The directors are accountable for:
- approving this policy and ensuring that adequate resources are available to implement it;
- assigning responsibility for data protection, information security and incident management;
- ensuring that risks to agency information, systems, premises and workers are assessed and appropriately controlled;
- ensuring that contracts with clients and suppliers clearly allocate relevant security, confidentiality and incident-reporting responsibilities;
- ensuring that serious incidents are escalated to insurers, legal advisers, the Information Commissioner’s Office, law-enforcement bodies, professional regulators or other authorities where required;
- reviewing significant security incidents, audit findings and remedial actions; and
- ensuring that the agency does not represent itself as a CQC-registered provider unless its activities change and registration becomes legally required.
5.2 Data Protection or Information Security Lead
The appointed Data Protection or Information Security Lead is responsible for:
- maintaining this policy and associated procedures;
- coordinating security risk assessments;
- administering or overseeing user-access approval and review processes;
- maintaining a security-incident and personal-data-breach register;
- assessing suspected personal data breaches;
- advising the directors whether notification to the Information Commissioner’s Office or affected individuals is required;
- coordinating staff training and awareness;
- monitoring completion of remedial actions; and
- maintaining appropriate evidence of compliance.
5.3 Recruitment, Compliance and Administrative Staff
Recruitment, compliance and administrative staff must:
- access only information required for their duties;
- verify the identity and authority of persons requesting information or system access;
- avoid sending personal data to unverified recipients;
- use approved systems, communication channels and document-sharing methods;
- report suspected security incidents immediately;
- ensure that worker and client records are stored and disposed of securely; and
- notify the responsible manager promptly when an individual joins, changes role, begins extended leave or leaves the organisation so that access can be updated or removed.
5.4 Temporary Workers and Agency Workers
Temporary workers and agency workers must:
- follow this policy and all lawful client security procedures communicated to them;
- use only the access rights and information required for their assignment;
- keep identification badges, keys, access cards, passwords and security codes secure;
- never permit another person to use their credentials or identification;
- report lost equipment, access devices, suspected phishing, unauthorised access and other security concerns immediately;
- protect client and service-user confidentiality;
- avoid accessing client information after the relevant assignment or task has ended; and
- return all client and agency property at the end of a shift or assignment.
5.5 Client Organisations
The client organisation is ordinarily responsible for:
- controlling access to its premises, systems, clinical records, medication areas and restricted facilities;
- providing an appropriate site and assignment induction;
- informing the agency and worker about relevant hazards, emergency arrangements and access restrictions;
- determining the worker’s permitted level of access within the client environment;
- providing or authorising client-system accounts;
- supervising access to client records and equipment;
- removing client-system access at the end of the assignment; and
- notifying the agency promptly of security incidents involving an agency worker.
The agency will take reasonable steps before supply to obtain relevant information about the position and client requirements, including known health and safety risks, in accordance with the Conduct Regulations.
6. General Security Principles
All staff and workers must:
- display agency or client identification where required, but must not leave identification badges unattended or permit another person to use them;
- access only areas, information, systems and equipment for which they have been authorised;
- use individual accounts and credentials and never share passwords, access codes, authentication tokens or security answers;
- prevent “tailgating” or unauthorised entry where it is safe to do so;
- politely direct unidentified visitors to reception or an authorised member of client staff, in accordance with site procedures;
- never physically confront, restrain or pursue a suspected intruder unless specifically trained, authorised and required to do so as part of their role;
- move to a place of safety and contact security staff, the placement manager or emergency services where there is an immediate threat;
- report lost, stolen or damaged identification, keys, access cards, devices or documents immediately;
- lock screens whenever leaving a device unattended;
- keep desks and work areas clear of exposed personal or confidential information;
- avoid leaving confidential records in vehicles or other insecure locations;
- use only approved storage and communication systems;
- comply with lone-working and personal-safety procedures; and
- return agency and client property promptly when requested or when their work ends.
Security must never take priority over immediate personal safety. Staff must not place themselves or another person at unreasonable risk when responding to suspicious behaviour.
7. Access Control at Client Premises
Before or at the start of an assignment, the worker must receive sufficient information about the client’s:
- sign-in and sign-out arrangements;
- identification requirements;
- visitor and contractor procedures;
- emergency exits, fire arrangements and evacuation procedures;
- restricted areas;
- keys, alarms and door-access systems;
- information systems and record-access procedures;
- arrangements for reporting security incidents; and
- procedures for returning client property.
Temporary workers must:
- comply with the access restrictions that apply to their assignment;
- sign in and out accurately where required;
- use only the account, badge, access card or key assigned to them;
- not allow another person to enter using their badge, key or credentials;
- not photograph, copy, download or remove client information unless authorised and necessary for their role;
- access clinical records, medication areas, equipment and restricted locations only where authorised and competent;
- report defective locks, damaged security equipment, missing property and unauthorised access promptly;
- immediately report the loss of any key, badge, access card or client device;
- return keys, cards, devices and other property at the end of the shift or assignment; and
- cease accessing client premises and systems when the assignment or relevant authorisation ends.
Where a client asks a worker to use shared credentials or bypass an established security control, the worker must refuse where reasonably practicable and report the request to the placement manager and {{org_field_name}}.
8. Access Authorisation and Access Lifecycle
Access to agency systems, records, premises and equipment must be based on the user’s role and legitimate business need.
The following controls will apply:
- access must be approved by an authorised manager before it is granted;
- each user must have a unique account wherever technically possible;
- privileged or administrator access must be separately authorised and restricted to individuals who require it;
- access rights must be limited to the minimum necessary for the role;
- access must not be granted solely because it may be convenient in the future;
- access rights must be reviewed periodically and after any significant role change;
- dormant, duplicate, generic and unnecessary accounts must be disabled or removed;
- access must be amended promptly when an individual changes role or responsibilities;
- access must be suspended where an individual is absent for an extended period and continued access is not justified;
- access must be withdrawn promptly when employment, engagement or an assignment ends;
- agency and client property must be recovered as part of the leaver process; and
- access approvals, significant changes and withdrawals must be documented.
Access to sensitive or high-risk systems should be reviewed at least every six months. Other user access should be reviewed at least annually or more frequently where indicated by risk.
9. Confidential Information and Records Security
Personal data and confidential information must be processed in accordance with the UK GDPR, the Data Protection Act 2018 as amended by the Data (Use and Access) Act 2025, the agency’s privacy information, retention schedule and related policies.
Staff and workers must:
- access personal information only where required for an authorised purpose;
- apply particular care to special category data, criminal offence data, health information, DBS information, safeguarding records, right-to-work records and payroll information;
- verify the recipient and, where appropriate, the attachment before sending personal or confidential information;
- use approved encrypted systems or secure transfer methods when sending sensitive information;
- not send agency or client information to personal email accounts;
- not store agency or client information in personal cloud-storage accounts;
- not use public generative artificial-intelligence services or other unapproved online tools to process identifiable worker, client or service-user information;
- not photograph or record confidential documents or screens using a personal device;
- lock paper records in secure storage when not in use;
- keep confidential conversations private and avoid discussing identifiable information in communal, public or social settings;
- use confidential-waste facilities or approved secure-destruction arrangements;
- avoid printing information unless necessary;
- collect printed material immediately from printers;
- report information sent to the wrong recipient as a potential personal data breach;
- report lost paperwork or devices immediately; and
- comply with applicable retention and secure-disposal requirements.
Confidentiality obligations continue after employment, engagement or an assignment has ended.
10. Physical Office Security
{{org_field_name}} will maintain proportionate physical security arrangements for its offices and storage areas.
These will include, where appropriate:
- controlled entry to non-public areas;
- arrangements for identifying and supervising visitors;
- secure storage for personnel files, DBS information, identification documents and other sensitive records;
- procedures for issuing, recording, returning and cancelling keys and access cards;
- secure positioning of screens and workstations;
- a clear-desk and clear-screen requirement;
- secure disposal containers for confidential waste;
- protection of networking and communications equipment;
- closing checks for windows, doors, alarms and exposed information;
- procedures for responding to lost keys or compromised access codes; and
- periodic reviews of physical security risks.
Visitors must not be left unaccompanied in areas containing personal data, confidential records, unlocked devices or sensitive equipment unless expressly authorised.
11. Lone Working and Personal Security
Lone working arrangements must be risk assessed where the agency has sufficient control over or knowledge of the work. Where work takes place on client premises, the agency will obtain relevant information from the client and the worker must follow the client’s lone-working arrangements.
Lone workers must:
- have access to a reliable means of communication;
- know how to summon assistance;
- understand local alarm, emergency and escalation arrangements;
- follow any agreed check-in or welfare-call procedure;
- inform the appropriate manager where planned arrangements change;
- avoid sharing unnecessary personal information with service users, relatives or members of the public;
- leave the area and seek assistance where they reasonably believe there is an immediate risk of violence, aggression or other serious harm; and
- report threats, harassment, stalking, violence, security concerns or near misses promptly.
No worker will be criticised for withdrawing to a place of safety where they reasonably believe that remaining would expose them or another person to serious and imminent danger.
12. Security Incidents and Personal Data Breaches
A security incident includes any event that compromises, or may compromise, the confidentiality, integrity or availability of premises, systems, equipment, personal data or confidential information.
Examples include:
- lost or stolen identification, keys, access cards, paperwork or devices;
- unauthorised entry or attempted entry;
- unauthorised access to an account, system or record;
- suspected phishing, malware, ransomware or account compromise;
- disclosure of information to the wrong recipient;
- misuse or sharing of credentials;
- theft, damage or loss of agency or client property;
- unauthorised photography, recording, copying or downloading;
- failure to remove access when an individual leaves or changes role;
- deliberate or accidental alteration, deletion or destruction of information;
- aggressive, threatening or suspicious behaviour; and
- any event that may constitute a personal data breach.
A personal data breach includes accidental or unlawful destruction, loss, alteration, unauthorised disclosure of or access to personal data.
Any person who becomes aware of a suspected incident must:
- report it immediately to their manager, the client manager where applicable, and the agency’s designated incident contact;
- take reasonable immediate steps to reduce harm, provided this can be done safely;
- preserve relevant evidence and not delete emails, logs, messages or files connected with the incident;
- avoid making public statements or contacting affected individuals unless authorised;
- cooperate with the investigation; and
- provide accurate information about what occurred, when it occurred and what information or assets may have been affected.
{{org_field_name}} will:
- record every suspected personal data breach, including breaches not reported externally;
- assess the nature, scale, likely consequences and affected individuals;
- contain and investigate the incident;
- determine whether contractual notification to a client is required;
- notify the Information Commissioner’s Office without undue delay and, where feasible, within 72 hours of becoming aware of a reportable breach;
- inform affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms;
- document the reasons for any decision not to notify the Information Commissioner’s Office;
- consider notification to insurers, law enforcement, professional regulators or other bodies; and
- identify and complete corrective and preventive actions.
Individual workers must not report a breach directly to the Information Commissioner’s Office on behalf of {{org_field_name}} unless specifically authorised to do so.
13. Training and Security Awareness
All relevant staff must complete security and data protection training:
- during induction and before being given access to sensitive agency systems;
- at appropriate intervals thereafter;
- following a material change to systems, legislation or working practices;
- following a significant incident or identified weakness; and
- when additional role-specific training is required.
Training will cover, as appropriate:
- physical security and visitor controls;
- password and multi-factor authentication requirements;
- phishing, impersonation and social-engineering risks;
- secure email and document sharing;
- personal data breach recognition and reporting;
- mobile device and remote-working security;
- clear-desk and secure-disposal requirements;
- confidentiality and special category data;
- client-specific security procedures;
- incident reporting and preservation of evidence;
- lone working and personal safety; and
- the consequences of deliberate or negligent security breaches.
Completion of mandatory training will be recorded. Individuals who do not complete required training may have their access suspended until the training is completed.
14. Staff Conduct and Professionalism
All staff must:
- Conduct themselves professionally and in a manner that upholds the security of the placement and the safety of service users.
- Avoid behaviours that may compromise security (e.g., propping open locked doors, sharing passwords).
- Challenge and report suspicious behaviour appropriately.
- Support the maintenance of a secure environment as part of their duty of care.
Staff and workers must not:
- attempt to gain access to information, systems or areas outside their authority;
- use another person’s identification or system account;
- disable, bypass or interfere with a security control;
- connect unauthorised equipment to agency or client networks;
- install unapproved software;
- remove or copy information without authority;
- use confidential information for personal benefit;
- disclose security arrangements on social media; or
- conceal or deliberately delay reporting a security incident.
Suspected deliberate misuse may be treated as gross misconduct and may also constitute a criminal offence, including under the Computer Misuse Act 1990.
15. Cybersecurity
{{org_field_name}} will implement proportionate cybersecurity measures appropriate to the sensitivity of the information it processes.
15.1 User Accounts and Authentication
- Users must have individual accounts wherever technically possible.
- Passwords must not be shared or reused across agency and personal accounts.
- Default passwords must be changed before a system is placed into use.
- Multi-factor authentication must be enabled for email, cloud systems, remote access, administrator accounts and other high-risk services where technically available.
- Authentication codes and approval prompts must never be disclosed or approved unless the user initiated the relevant login.
- Suspected credential compromise must be reported immediately and the affected credentials reset.
15.2 Devices and Software
- Agency information may be accessed only from approved devices or through an expressly approved secure arrangement.
- Devices must use supported operating systems and security updates must be installed promptly.
- Anti-malware and protective security controls must not be disabled.
- Devices must be protected by screen locks, encryption where appropriate and automatic locking after inactivity.
- Users must not install unapproved software, browser extensions or applications.
- Removable media must not be used unless authorised and appropriately protected.
15.3 Email, Phishing and Social Engineering
- Unexpected requests for payments, credentials, personal information or changes to bank details must be independently verified using a trusted contact method.
- Suspicious links, attachments, QR codes, login pages or authentication prompts must not be opened or approved.
- Suspected phishing messages must be reported through the approved reporting channel.
- Staff must be alert to impersonation of directors, workers, clients, IT support personnel, payroll providers and public authorities.
15.4 Remote Working
- Confidential work must be undertaken in a location where conversations and screens cannot reasonably be overheard or viewed.
- Public or shared computers must not be used for agency work.
- Public Wi-Fi must not be used for sensitive work unless an approved secure connection is in place.
- Paper records must not be retained at home unless expressly authorised and securely stored.
- Family members or other unauthorised persons must not use agency devices.
15.5 Backup and Recovery
- Important agency information must be stored on approved systems included within the agency’s backup arrangements.
- Backups must be protected against unauthorised access and, where proportionate, separated from the live environment.
- Restoration arrangements must be tested periodically.
- Suspected ransomware or destructive malware must be reported immediately. The affected device should be disconnected from networks where safe and practicable, but must not be wiped or reset without authorisation.
15.6 Privileged Access
- Administrator access must be restricted to authorised personnel.
- Administrator accounts must not be used for routine email or general browsing where separate standard accounts are available.
- Privileged access must be reviewed more frequently than ordinary user access.
- Significant administrator activity should be logged and monitored proportionately.
16. Mobile Devices and Personally Owned Devices
Agency or client information must not be stored on a personally owned device unless this has been expressly authorised and appropriate technical safeguards are in place.
Where authorised:
- the device must be protected by a passcode or biometric security;
- the operating system must remain supported and updated;
- information must be accessed through approved applications;
- agency information must be kept separate from personal information where technically possible;
- automatic cloud backup to personal accounts must be disabled for agency information;
- the device must not be shared with family members or other unauthorised persons;
- loss or theft must be reported immediately;
- the agency must be able to remove agency information when access ends; and
- the user must cooperate with reasonable security checks relating to the agency information held on the device.
Personal devices must not be used to photograph service users, client records, medication charts, rotas, identification documents or other confidential information.
17. Third-Party Suppliers and Cloud Services
Before appointing a supplier that will access, host, support or otherwise process agency information, {{org_field_name}} will carry out proportionate due diligence.
The agency will consider:
- the supplier’s security controls;
- access-control and authentication arrangements;
- data location and international-transfer implications;
- encryption and backup arrangements;
- incident notification timescales;
- use of subcontractors;
- data return and deletion arrangements;
- business continuity and disaster recovery;
- audit or assurance evidence; and
- contractual obligations concerning confidentiality and data protection.
Where the supplier acts as a processor, a written contract containing the requirements of data protection law must be in place.
Suppliers must notify {{org_field_name}} of security incidents affecting agency information without undue delay and within any shorter contractual period specified by the agency.
18. Monitoring, Audit and Assurance
{{org_field_name}} may monitor access to its premises, systems, accounts and information where this is necessary and proportionate for security, compliance, investigation or service-continuity purposes.
Monitoring may include:
- user access records;
- login and authentication activity;
- administrator activity;
- email and system-security alerts;
- malware and device-compliance alerts;
- document access or sharing logs;
- access-card records; and
- incident and audit records.
Monitoring will be conducted lawfully, fairly and transparently. Staff will be informed about relevant monitoring through this policy, privacy information and any applicable acceptable-use notice.
The agency will:
- review access rights at planned intervals;
- conduct proportionate security audits;
- review security incidents and recurring weaknesses;
- track corrective actions to completion;
- retain logs for a proportionate period consistent with their purpose and the agency’s retention schedule; and
- restrict access to monitoring information to authorised persons.
Monitoring information must not be used for unrelated purposes without a lawful and documented reason.
19. Equality, Accessibility and Inclusion
Security controls will be applied fairly and without unlawful discrimination in accordance with the Equality Act 2010.
{{org_field_name}} will consider reasonable adjustments for disabled staff and workers, including adjustments affecting:
- physical entry systems;
- identification processes;
- authentication methods;
- security training;
- alarm arrangements;
- emergency communications; and
- reporting procedures.
Any adjustment must be assessed in consultation with the affected person and must maintain an appropriate level of security. A person must not be denied access merely because a standard security method is inaccessible where a reasonable and secure alternative can be provided.
20. Collaboration and Information Sharing with Clients
{{org_field_name}} will work with clients to establish clear security arrangements for temporary workers.
Before or at the beginning of an assignment, the agency will seek sufficient information about:
- site-specific security and access procedures;
- assignment-related risks;
- required identification;
- restricted areas and systems;
- emergency and incident-reporting procedures;
- client induction requirements;
- confidentiality requirements; and
- the return or cancellation of access devices and accounts.
The agency and client should agree:
- who will authorise system and premises access;
- who will provide training and supervision;
- how incidents will be reported between the parties;
- which party will investigate particular categories of incident;
- applicable notification timescales;
- responsibility for preserving evidence;
- arrangements for removing access at the end of an assignment; and
- restrictions on onward disclosure of personal information.
Information about a worker will be disclosed to a client only where there is an appropriate lawful basis and the disclosure is necessary, proportionate and consistent with applicable privacy information.
The agency must not accept a client instruction that would require unlawful disclosure, unjustified surveillance, credential sharing or circumvention of a security control.
21. Business Continuity and Security Emergencies
{{org_field_name}} will maintain proportionate arrangements for continuing or restoring critical services following:
- cyberattack or ransomware;
- loss of access to agency systems;
- failure of telecommunications or cloud services;
- loss of premises;
- fire, flood or other physical damage;
- theft or loss of critical equipment;
- compromise of an administrator account; or
- unavailability of a key supplier.
Business-continuity arrangements will identify:
- critical systems and information;
- responsible decision-makers;
- emergency contact arrangements;
- manual or alternative working procedures;
- secure backup and restoration arrangements;
- client and worker communication arrangements;
- supplier escalation routes;
- legal, contractual and insurance notification requirements; and
- recovery priorities.
Continuity and recovery arrangements will be tested periodically and following significant changes.
22. Continuous Improvement
The directors and designated responsible persons will use:
- incident investigations;
- audit results;
- access reviews;
- staff and client feedback;
- threat information;
- changes in legislation and regulatory guidance;
- supplier assurance information; and
- lessons from business-continuity exercises
to identify improvements to security arrangements.
Corrective actions must have a named owner and target completion date. Significant or overdue actions must be escalated to the directors.
Policies, training, system configurations, contractual requirements and working practices will be updated where an investigation or risk assessment identifies that existing controls are inadequate.
23. Records and Evidence of Compliance
{{org_field_name}} will maintain proportionate records demonstrating the operation of this policy, including:
- access requests and approvals;
- access reviews and removals;
- issued keys, identification and access cards;
- mandatory training completion;
- security risk assessments;
- incident and personal data breach records;
- decisions concerning notification of personal data breaches;
- audit findings and corrective actions;
- supplier security assessments;
- equipment allocation and return records;
- backup and recovery test results; and
- policy approvals and review history.
Records will be retained only for as long as necessary for their documented purpose and in accordance with the agency’s retention schedule, legal obligations and limitation requirements. At the end of the retention period, records must be securely deleted or destroyed.
24. Legal and Regulatory Framework
This policy has been prepared with reference to the following legislation and official guidance, where applicable:
- Computer Misuse Act 1990;
- Conduct of Employment Agencies and Employment Businesses Regulations 2003, as amended;
- Data Protection Act 2018, as amended;
- Data (Use and Access) Act 2025;
- Employment Agencies Act 1973;
- Equality Act 2010;
- Health and Safety at Work etc. Act 1974;
- UK General Data Protection Regulation;
- relevant Information Commissioner’s Office guidance concerning information security and personal data breach management; and
- relevant National Cyber Security Centre guidance concerning access control, passwords, multi-factor authentication, phishing, device security and incident response.
The Health and Social Care Act 2008 (Regulated Activities) Regulations 2014 and the CQC Fundamental Standards apply directly to organisations carrying on regulated activities. {{org_field_name}} supplies temporary personnel as an employment business and does not itself provide, direct or control regulated care. Agency workers must nevertheless follow lawful client procedures and professional requirements when working within a CQC-registered service.
If the agency’s business model changes so that it begins directing, controlling or delivering regulated care, the directors must obtain specialist advice and determine whether CQC registration is required before the changed service begins.
25. Policy Review
This policy will be reviewed:
- at least annually;
- following a significant security or personal data incident;
- following a material change to legislation or official guidance;
- following the introduction of a significant new system, supplier or working practice;
- following a material change to the agency’s business model;
- where audit findings show that controls are ineffective;
- following significant client or worker feedback; or
- where the agency begins to provide, direct or control care in a manner that may affect its CQC registration position.
The review will consider whether:
- responsibilities remain accurate;
- access controls remain appropriate;
- training remains current;
- incident and breach procedures remain effective;
- suppliers continue to provide sufficient assurance;
- legislative references are current; and
- identified actions have been completed.
Material amendments must be approved by the directors and communicated to affected staff and workers.
Responsible Person: {{org_field_registered_manager_first_name}} {{org_field_registered_manager_last_name}}
Reviewed on: {{last_update_date}}
Next Review Date: {{next_review_date}}
Copyright © {{current_year}} – {{org_field_name}}. All rights reserved.