{{org_field_logo}}

{{org_field_name}}

Registration Number: {{org_field_registration_no}}


Online Safety Policy

1. Purpose

This policy sets out {{org_field_name}}’s arrangements for promoting a safe and secure online and digital environment for staff, the people we support and visitors, and for protecting personal information processed through digital systems.

The policy supports compliance with the Health and Social Care Act 2008; the Health and Social Care Act 2008 (Regulated Activities) Regulations 2014, as amended; the Care Quality Commission (Registration) Regulations 2009, as amended; the Care Act 2014; the Mental Capacity Act 2005; the Data Protection Act 2018 and UK GDPR, as amended by the Data (Use and Access) Act 2025; and other applicable legislation.

{{org_field_name}} will maintain appropriate technical and organisational measures to protect the confidentiality, integrity and availability of personal information and digital systems. Online and digital risks will be assessed and managed in a manner that protects people from avoidable harm while respecting their rights, choices, privacy, independence and autonomy.

2. Scope

This policy applies to all employees, including full-time, part-time, bank, and agency staff, as well as volunteers, contractors, and the people we support. It covers all digital systems, including internet access, email communication, social media, online learning platforms, and digital care management systems used within {{org_field_name}}.

3. Legal and Regulatory Framework

This policy must be read and implemented in accordance with the following legal and regulatory requirements:

4. Online Safety Measures and Management

Access Control and User Permissions

Internet Usage

Email and Phishing Protection

Social Media Use

Use of Personal Devices (Bring Your Own Device – BYOD)

5. Safeguarding the People We Support Online

Choice, Independence, Capacity and Consent

Online Abuse, Exploitation and Harm

Online Financial Activity

6. Digital Record-Keeping and Data Security

Security and Access to Digital Records

Creation, Amendment, Retention and Disposal

Backups and Availability

Audit and Monitoring

7. Cybersecurity Training and Awareness

Mandatory Staff Training

Ongoing Digital Awareness

8. Reporting and Managing Online Safety Incidents

Internal Reporting and Immediate Action

Personal Data Breaches and the Information Commissioner’s Office

CQC Notifications

Investigation and Learning

Staff Conduct

9. Data Protection Complaints

{{org_field_name}} will maintain an accessible process through which a person can make a complaint about the organisation’s processing of their personal information.

Information explaining how to make a data protection complaint, including an appropriate electronic means of submitting a complaint, must be made available to people whose personal information is processed by {{org_field_name}}.

Where a data protection complaint is received:

Data protection complaints must be recorded and handled in a manner that preserves confidentiality and enables {{org_field_name}} to demonstrate compliance with its statutory obligations.

Where a complaint also identifies a personal data breach, safeguarding concern, staff conduct concern or other regulatory incident, the relevant reporting and escalation procedures must be followed in addition to the data protection complaints process.

10. Monitoring and Compliance

11. Related Policies

12. Policy Review


Responsible Person: {{org_field_registered_manager_first_name}} {{org_field_registered_manager_last_name}}
Reviewed on:
{{last_update_date}}
Next Review Date:
{{next_review_date}}
Copyright © {{current_year}} – {{org_field_name}}. All rights reserved.

Leave a Reply

Your email address will not be published. Required fields are marked *