{{org_field_logo}}

{{org_field_name}}

Registration Number: {{org_field_registration_no}}


Security and Access Control Policy

1. Purpose

The purpose of this policy is to provide clear, comprehensive, and effective guidance on security and access control arrangements applicable to all staff working for {{org_field_name}}. As a temporary staffing agency supplying registered nurses, healthcare assistants, and other healthcare workers to care homes and other social care environments, {{org_field_name}} has a legal and ethical responsibility to safeguard service users, staff, client property, confidential information, and organisational assets. This policy outlines how security will be maintained by both the agency and its staff while on duty in client premises and during agency operations. It is essential that all staff employed or supplied by {{org_field_name}} understand their responsibilities for maintaining security, controlling access to sensitive areas and information, and contributing to a culture of vigilance.

This policy supports compliance with applicable security, data protection, employment business, health and safety, confidentiality and contractual requirements. These include the UK General Data Protection Regulation, the Data Protection Act 2018 as amended, the Data (Use and Access) Act 2025, the Health and Safety at Work etc. Act 1974, the Employment Agencies Act 1973 and the Conduct of Employment Agencies and Employment Businesses Regulations 2003, as amended.

{{org_field_name}} operates as an employment business supplying temporary workers to client organisations. It does not itself carry on a regulated health or social care activity and does not direct or control the delivery of regulated care. The client organisation remains responsible for its premises, regulated activities, site security arrangements and service-user care. Agency workers must nevertheless follow lawful client procedures, professional standards and the requirements of this policy while on assignment.

2. Scope

This policy applies to:

Compliance with this policy is a condition of access to {{org_field_name}} systems, information and premises. A breach may result in withdrawal of access, removal from an assignment, disciplinary action, termination of engagement or referral to a client, professional regulator, law-enforcement body or other relevant authority.

3. Related Policies and Procedures

This policy should be read alongside:

4. Policy Statement

{{org_field_name}} is committed to maintaining proportionate physical, organisational and technical security measures appropriate to the nature of its activities and the risks presented by the information it processes.

The agency will:

Security measures will be risk based, proportionate and reviewed regularly. They will not be applied in a discriminatory, unnecessarily intrusive or unsafe manner.

5. Responsibilities

5.1 Directors

The directors are accountable for:

5.2 Data Protection or Information Security Lead

The appointed Data Protection or Information Security Lead is responsible for:

5.3 Recruitment, Compliance and Administrative Staff

Recruitment, compliance and administrative staff must:

5.4 Temporary Workers and Agency Workers

Temporary workers and agency workers must:

5.5 Client Organisations

The client organisation is ordinarily responsible for:

The agency will take reasonable steps before supply to obtain relevant information about the position and client requirements, including known health and safety risks, in accordance with the Conduct Regulations.

6. General Security Principles

All staff and workers must:

Security must never take priority over immediate personal safety. Staff must not place themselves or another person at unreasonable risk when responding to suspicious behaviour.

7. Access Control at Client Premises

Before or at the start of an assignment, the worker must receive sufficient information about the client’s:

Temporary workers must:

Where a client asks a worker to use shared credentials or bypass an established security control, the worker must refuse where reasonably practicable and report the request to the placement manager and {{org_field_name}}.

8. Access Authorisation and Access Lifecycle

Access to agency systems, records, premises and equipment must be based on the user’s role and legitimate business need.

The following controls will apply:

Access to sensitive or high-risk systems should be reviewed at least every six months. Other user access should be reviewed at least annually or more frequently where indicated by risk.

9. Confidential Information and Records Security

Personal data and confidential information must be processed in accordance with the UK GDPR, the Data Protection Act 2018 as amended by the Data (Use and Access) Act 2025, the agency’s privacy information, retention schedule and related policies.

Staff and workers must:

Confidentiality obligations continue after employment, engagement or an assignment has ended.

10. Physical Office Security

{{org_field_name}} will maintain proportionate physical security arrangements for its offices and storage areas.

These will include, where appropriate:

Visitors must not be left unaccompanied in areas containing personal data, confidential records, unlocked devices or sensitive equipment unless expressly authorised.

11. Lone Working and Personal Security

Lone working arrangements must be risk assessed where the agency has sufficient control over or knowledge of the work. Where work takes place on client premises, the agency will obtain relevant information from the client and the worker must follow the client’s lone-working arrangements.

Lone workers must:

No worker will be criticised for withdrawing to a place of safety where they reasonably believe that remaining would expose them or another person to serious and imminent danger.

12. Security Incidents and Personal Data Breaches

A security incident includes any event that compromises, or may compromise, the confidentiality, integrity or availability of premises, systems, equipment, personal data or confidential information.

Examples include:

A personal data breach includes accidental or unlawful destruction, loss, alteration, unauthorised disclosure of or access to personal data.

Any person who becomes aware of a suspected incident must:

{{org_field_name}} will:

Individual workers must not report a breach directly to the Information Commissioner’s Office on behalf of {{org_field_name}} unless specifically authorised to do so.

13. Training and Security Awareness

All relevant staff must complete security and data protection training:

Training will cover, as appropriate:

Completion of mandatory training will be recorded. Individuals who do not complete required training may have their access suspended until the training is completed.

14. Staff Conduct and Professionalism

All staff must:

Staff and workers must not:

Suspected deliberate misuse may be treated as gross misconduct and may also constitute a criminal offence, including under the Computer Misuse Act 1990.

15. Cybersecurity

{{org_field_name}} will implement proportionate cybersecurity measures appropriate to the sensitivity of the information it processes.

15.1 User Accounts and Authentication

15.2 Devices and Software

15.3 Email, Phishing and Social Engineering

15.4 Remote Working

15.5 Backup and Recovery

15.6 Privileged Access

16. Mobile Devices and Personally Owned Devices

Agency or client information must not be stored on a personally owned device unless this has been expressly authorised and appropriate technical safeguards are in place.

Where authorised:

Personal devices must not be used to photograph service users, client records, medication charts, rotas, identification documents or other confidential information.

17. Third-Party Suppliers and Cloud Services

Before appointing a supplier that will access, host, support or otherwise process agency information, {{org_field_name}} will carry out proportionate due diligence.

The agency will consider:

Where the supplier acts as a processor, a written contract containing the requirements of data protection law must be in place.

Suppliers must notify {{org_field_name}} of security incidents affecting agency information without undue delay and within any shorter contractual period specified by the agency.

18. Monitoring, Audit and Assurance

{{org_field_name}} may monitor access to its premises, systems, accounts and information where this is necessary and proportionate for security, compliance, investigation or service-continuity purposes.

Monitoring may include:

Monitoring will be conducted lawfully, fairly and transparently. Staff will be informed about relevant monitoring through this policy, privacy information and any applicable acceptable-use notice.

The agency will:

Monitoring information must not be used for unrelated purposes without a lawful and documented reason.

19. Equality, Accessibility and Inclusion

Security controls will be applied fairly and without unlawful discrimination in accordance with the Equality Act 2010.

{{org_field_name}} will consider reasonable adjustments for disabled staff and workers, including adjustments affecting:

Any adjustment must be assessed in consultation with the affected person and must maintain an appropriate level of security. A person must not be denied access merely because a standard security method is inaccessible where a reasonable and secure alternative can be provided.

20. Collaboration and Information Sharing with Clients

{{org_field_name}} will work with clients to establish clear security arrangements for temporary workers.

Before or at the beginning of an assignment, the agency will seek sufficient information about:

The agency and client should agree:

Information about a worker will be disclosed to a client only where there is an appropriate lawful basis and the disclosure is necessary, proportionate and consistent with applicable privacy information.

The agency must not accept a client instruction that would require unlawful disclosure, unjustified surveillance, credential sharing or circumvention of a security control.

21. Business Continuity and Security Emergencies

{{org_field_name}} will maintain proportionate arrangements for continuing or restoring critical services following:

Business-continuity arrangements will identify:

Continuity and recovery arrangements will be tested periodically and following significant changes.

22. Continuous Improvement

The directors and designated responsible persons will use:

to identify improvements to security arrangements.

Corrective actions must have a named owner and target completion date. Significant or overdue actions must be escalated to the directors.

Policies, training, system configurations, contractual requirements and working practices will be updated where an investigation or risk assessment identifies that existing controls are inadequate.

23. Records and Evidence of Compliance

{{org_field_name}} will maintain proportionate records demonstrating the operation of this policy, including:

Records will be retained only for as long as necessary for their documented purpose and in accordance with the agency’s retention schedule, legal obligations and limitation requirements. At the end of the retention period, records must be securely deleted or destroyed.

24. Legal and Regulatory Framework

This policy has been prepared with reference to the following legislation and official guidance, where applicable:

The Health and Social Care Act 2008 (Regulated Activities) Regulations 2014 and the CQC Fundamental Standards apply directly to organisations carrying on regulated activities. {{org_field_name}} supplies temporary personnel as an employment business and does not itself provide, direct or control regulated care. Agency workers must nevertheless follow lawful client procedures and professional requirements when working within a CQC-registered service.

If the agency’s business model changes so that it begins directing, controlling or delivering regulated care, the directors must obtain specialist advice and determine whether CQC registration is required before the changed service begins.

25. Policy Review

This policy will be reviewed:

The review will consider whether:

Material amendments must be approved by the directors and communicated to affected staff and workers.


Responsible Person: {{org_field_registered_manager_first_name}} {{org_field_registered_manager_last_name}}
Reviewed on:
{{last_update_date}}
Next Review Date:
{{next_review_date}}
Copyright © {{current_year}} – {{org_field_name}}. All rights reserved.

Leave a Reply

Your email address will not be published. Required fields are marked *