{{org_field_logo}}
{{org_field_name}}
Registration Number: {{org_field_registration_no}}
Online Safety Policy
1. Purpose
This policy sets out {{org_field_name}}’s arrangements for promoting a safe and secure online and digital environment for staff, the people we support and visitors, and for protecting personal information processed through digital systems.
The policy supports compliance with the Health and Social Care Act 2008; the Health and Social Care Act 2008 (Regulated Activities) Regulations 2014, as amended; the Care Quality Commission (Registration) Regulations 2009, as amended; the Care Act 2014; the Mental Capacity Act 2005; the Data Protection Act 2018 and UK GDPR, as amended by the Data (Use and Access) Act 2025; and other applicable legislation.
{{org_field_name}} will maintain appropriate technical and organisational measures to protect the confidentiality, integrity and availability of personal information and digital systems. Online and digital risks will be assessed and managed in a manner that protects people from avoidable harm while respecting their rights, choices, privacy, independence and autonomy.
2. Scope
This policy applies to all employees, including full-time, part-time, bank, and agency staff, as well as volunteers, contractors, and the people we support. It covers all digital systems, including internet access, email communication, social media, online learning platforms, and digital care management systems used within {{org_field_name}}.
3. Legal and Regulatory Framework
This policy must be read and implemented in accordance with the following legal and regulatory requirements:
- Health and Social Care Act 2008 and the Health and Social Care Act 2008 (Regulated Activities) Regulations 2014, as amended:
- Regulation 9 – Person-centred care: care and treatment must be appropriate, meet the person’s needs and, subject to lawful limitations, reflect their preferences. Where digital technology or online access forms part of a person’s care or support, their individual needs, preferences and involvement must be considered.
- Regulation 11 – Need for consent: care and treatment must only be provided with the consent of the relevant person. Where a person aged 16 or over lacks capacity to make the relevant decision, {{org_field_name}} must act in accordance with the Mental Capacity Act 2005.
- Regulation 12 – Safe care and treatment: risks to the health and safety of people receiving care must be assessed and reasonably mitigated. This includes risks arising from digital systems or technology where those systems affect the safe provision of care.
- Regulation 13 – Safeguarding service users from abuse and improper treatment: effective systems and processes must be operated to prevent abuse and respond appropriately to suspected, alleged or actual abuse. This includes abuse facilitated through digital or online means and financial abuse or exploitation.
- Regulation 17 – Good governance: effective systems and processes must be established and operated to assess, monitor and improve the quality and safety of services; assess, monitor and mitigate risks; and maintain securely accurate, complete and contemporaneous records relating to people receiving care, staff and the management of the service.
- Regulation 18 – Staffing: staff must receive appropriate support, training, professional development, supervision and appraisal necessary to enable them to perform their duties safely and competently, including relevant information governance and online safety responsibilities.
- Care Quality Commission (Registration) Regulations 2009, as amended – Regulation 18: {{org_field_name}} must notify the Care Quality Commission without delay of incidents that fall within the statutory notification requirements. A digital or online incident must therefore be considered for CQC notification where its circumstances or consequences fall within a notifiable category.
- Data Protection Act 2018 and UK GDPR, as amended by the Data (Use and Access) Act 2025: personal information must be processed lawfully, fairly and transparently and protected through appropriate technical and organisational measures. {{org_field_name}} must comply with applicable requirements concerning data security, individual rights, personal data breaches, accountability and data protection complaints.
- Data (Use and Access) Act 2025: {{org_field_name}} must comply with the amendments made to UK data protection legislation, including the statutory requirements applying to the handling of complaints concerning the organisation’s processing of personal information.
- Mental Capacity Act 2005 and associated Code of Practice: a person must be presumed to have capacity unless it is established that they lack capacity to make the particular decision at the relevant time. Where a person lacks capacity, decisions made on their behalf must comply with the Mental Capacity Act, including its best-interests and least-restrictive principles.
- Care Act 2014: {{org_field_name}} must fulfil its safeguarding responsibilities and work appropriately with the local authority and other relevant agencies where there is reasonable cause to suspect that an adult with care and support needs is experiencing, or is at risk of, abuse or neglect, including abuse or exploitation occurring through digital or online means.
- Computer Misuse Act 1990: unauthorised access to computer systems, unauthorised acts involving computer systems and other conduct prohibited by the Act must not be undertaken.
4. Online Safety Measures and Management
Access Control and User Permissions
- Staff are assigned appropriate access levels based on job roles.
- Restricted access to sensitive information to prevent unauthorised use.
- Strong password policies, requiring regular updates and multi-factor authentication.
Internet Usage
- The use of the internet for non-work-related activities is permitted only during designated breaks.
- Access to inappropriate or harmful websites is blocked via firewall and filtering software.
- Downloading unauthorised software or applications is strictly prohibited.
Email and Phishing Protection
- All staff must use work email accounts for professional communication.
- Emails containing confidential data must be encrypted.
- Staff must be trained to recognise phishing emails and report suspicious activity immediately.
Social Media Use
- Staff must not discuss work-related matters on personal social media accounts.
- No photos or information about the people we support should be shared without written consent.
- Official social media pages must be managed only by authorised personnel.
Use of Personal Devices (Bring Your Own Device – BYOD)
- Staff must not store confidential information on personal devices.
- Mobile devices used for work must have security software installed.
- Personal device use for work purposes must comply with CH34-Confidentiality and Data Protection (GDPR) Policy.
5. Safeguarding the People We Support Online
Choice, Independence, Capacity and Consent
- People we support must be enabled, so far as reasonably practicable, to use the internet, digital devices and online services in accordance with their individual wishes, needs, preferences and abilities.
- A person must not have their internet or digital access restricted merely because they are considered vulnerable, because they have a particular diagnosis or disability, or because staff consider that another choice would be safer.
- Where a person has capacity to make the relevant decision, their informed decision must be respected, including decisions that may involve an element of risk, unless there is a separate lawful basis for intervention.
- Where there is reason to doubt a person’s capacity to make a particular decision concerning online or digital activity, capacity must be assessed in accordance with the Mental Capacity Act 2005. Capacity is decision-specific and time-specific and must not be determined solely by reference to a person’s age, condition, diagnosis or behaviour.
- Where a person lacks capacity to make the relevant decision, any decision made on their behalf must be made in accordance with the Mental Capacity Act 2005, be in their best interests and use the least restrictive available option.
- Any agreed support, supervision or restriction relating to internet or digital access that forms part of a person’s care or support arrangements must be proportionate to the identified risk and documented within the person’s care plan or risk assessment. The reason for the measure, the person’s involvement, any capacity assessment or best-interests decision where applicable, and arrangements for review must be recorded.
Online Abuse, Exploitation and Harm
- Staff must remain alert to signs that a person may be experiencing online abuse, grooming, coercion, harassment, cyberbullying, fraud, financial exploitation, identity theft or other forms of abuse or neglect.
- Any concern that a person is experiencing, or is at risk of, abuse or neglect through online or digital means must be acted upon without delay and managed in accordance with CH13-Safeguarding Adults from Abuse and Improper Treatment Policy.
- Where the circumstances meet the criteria for referral to the local authority safeguarding adults service, the appropriate referral must be made without delay. Police or other relevant agencies must be contacted where the circumstances require this.
Online Financial Activity
- Staff must not undertake or assist with online financial transactions on behalf of a person unless this is within the employee’s authorised role, is expressly provided for within the person’s agreed care or support arrangements and complies with the person’s consent or, where the person lacks capacity, a lawful decision or authority under the Mental Capacity Act 2005.
- Staff must never use a person’s banking credentials, passwords, personal identification numbers or other financial security information for an unauthorised purpose.
- Suspected financial abuse, fraud, theft, coercion or misuse of a person’s money or property must be reported immediately in accordance with CH13-Safeguarding Adults from Abuse and Improper Treatment Policy and any other applicable financial safeguarding procedure.
6. Digital Record-Keeping and Data Security
Security and Access to Digital Records
- Digital records must be accurate, complete, contemporaneous and maintained securely.
- Access to personal information and confidential records must be limited to people who are authorised to access the information for legitimate work purposes.
- Appropriate technical and organisational measures must be implemented according to the nature, scope, context and purposes of the processing and the risks presented to the rights and freedoms of individuals. Measures must be kept under review and must protect the confidentiality, integrity and availability of personal information and systems.
- Encryption, password protection, access controls and other security measures must be used where they are appropriate to the risks associated with the information and the way in which it is stored, transmitted or accessed.
- Confidential or personal information must not be stored on unauthorised cloud services, devices, applications, removable media or other systems.
Creation, Amendment, Retention and Disposal
- Digital records must only be created, viewed, amended or deleted by authorised persons acting within their role and permissions.
- Records must be retained for the period required by applicable legislation, contractual requirements and {{org_field_name}}’s approved records retention arrangements.
- Personal information and confidential records must be securely destroyed or deleted when there is no longer a lawful or operational requirement to retain them, subject to any applicable statutory retention requirement, safeguarding requirement, legal hold or ongoing investigation.
Backups and Availability
- Appropriate backup and recovery arrangements must be maintained for systems and information necessary for the safe and effective delivery of the service.
- Backups must be protected against unauthorised access, loss and alteration and must be tested at appropriate intervals to provide assurance that information and essential systems can be restored following a physical or technical incident.
Audit and Monitoring
- Appropriate audit logs and monitoring arrangements must be maintained where necessary to protect personal information, investigate incidents and provide assurance concerning authorised access and use.
- Monitoring of staff or system activity must itself be undertaken lawfully, proportionately and in accordance with applicable data protection requirements.
- Suspected unauthorised access, loss, alteration, disclosure or destruction of personal information must be reported immediately in accordance with Section 8 of this policy.
7. Cybersecurity Training and Awareness
Mandatory Staff Training
- Staff must complete annual cybersecurity and online safety training.
- Training will cover password security, phishing awareness, and data protection.
Ongoing Digital Awareness
- Regular online safety updates via team meetings and digital newsletters.
- IT security drills to test staff responses to potential cyber threats.
8. Reporting and Managing Online Safety Incidents
Internal Reporting and Immediate Action
- Any suspected or actual personal data breach, cyber incident, unauthorised access, loss of information, malicious software incident, phishing compromise or other online safety incident affecting {{org_field_name}} must be reported immediately to the Registered Manager and to the person or function responsible for information governance or data protection.
- Immediate and proportionate action must be taken to contain the incident, protect affected people, preserve relevant evidence and minimise further harm or loss.
- Where an incident may involve abuse, neglect, financial exploitation or another safeguarding concern affecting a person we support, the matter must also be managed immediately in accordance with CH13-Safeguarding Adults from Abuse and Improper Treatment Policy.
Personal Data Breaches and the Information Commissioner’s Office
- All suspected personal data breaches must be assessed promptly to establish the nature of the breach, the personal information affected, the people affected and the likely risks to their rights and freedoms.
- {{org_field_name}} must maintain a record of personal data breaches, including the facts relating to the breach, its effects, remedial action taken and the reasons for any decision as to whether notification to the Information Commissioner’s Office was required.
- Where a personal data breach is likely to result in a risk to the rights and freedoms of individuals, {{org_field_name}} must notify the Information Commissioner’s Office without undue delay and, where feasible, no later than 72 hours after becoming aware of the breach.
- Where notification to the Information Commissioner’s Office is made after the applicable 72-hour period, the reasons for the delay must be documented and provided as required.
- Where a personal data breach is likely to result in a high risk to the rights and freedoms of affected individuals, those individuals must also be informed without undue delay unless a lawful exception to that requirement applies.
CQC Notifications
- A cyber incident, data breach or online safety incident is not automatically notifiable to CQC solely because it has occurred.
- The Registered Manager must assess each incident against the statutory CQC notification requirements. CQC must be notified without delay where the circumstances or consequences of the incident fall within a notifiable category under the Care Quality Commission (Registration) Regulations 2009 or another applicable notification requirement.
- This includes, where applicable, abuse or an allegation of abuse involving a person using the service, an incident reported to or investigated by the police, a specified serious injury, or an event that prevents or threatens to prevent the service from continuing to carry on the regulated activity safely or in accordance with registration requirements.
- Where a CQC notification is required, it must be submitted in the form and manner required by CQC and an appropriate record of the notification must be retained.
Investigation and Learning
- Online safety and information security incidents must be investigated to an extent proportionate to their nature and seriousness.
- The investigation must identify, where applicable, the immediate cause, contributing factors, consequences, actions required to protect affected people and measures required to reduce the likelihood of recurrence.
- Required actions and learning must be recorded, monitored through governance arrangements and communicated to relevant staff.
Staff Conduct
- Deliberate misuse of IT systems, unauthorised access, inappropriate disclosure of confidential information, cyberbullying, online harassment or inappropriate use of social media may be addressed under CH31-Disciplinary and Grievance Policy in addition to any safeguarding, regulatory, civil or criminal action that may be required.
9. Data Protection Complaints
{{org_field_name}} will maintain an accessible process through which a person can make a complaint about the organisation’s processing of their personal information.
Information explaining how to make a data protection complaint, including an appropriate electronic means of submitting a complaint, must be made available to people whose personal information is processed by {{org_field_name}}.
Where a data protection complaint is received:
- the complaint must be acknowledged within 30 days of receipt;
- appropriate steps must be taken, without undue delay, to investigate the subject matter of the complaint;
- the complainant must be kept appropriately informed about the progress of the investigation;
- once the investigation has been completed, the complainant must be informed of the outcome without undue delay; and
- the organisation must provide the complainant with the information concerning their right to complain to the Information Commissioner’s Office where required by applicable data protection legislation.
Data protection complaints must be recorded and handled in a manner that preserves confidentiality and enables {{org_field_name}} to demonstrate compliance with its statutory obligations.
Where a complaint also identifies a personal data breach, safeguarding concern, staff conduct concern or other regulatory incident, the relevant reporting and escalation procedures must be followed in addition to the data protection complaints process.
10. Monitoring and Compliance
- IT audits will be conducted regularly to ensure compliance with security policies.
- Compliance checks on staff device usage, access logs, and email security will be implemented.
- Feedback from staff and residents on online safety will be reviewed to improve policies.
11. Related Policies
- CH17-Infection Prevention and Control Policy
- CH18-Risk Management and Assessment Policy
- CH27-Staff Supervision, Training, and Development Policy
- CH30-Equality, Diversity, and Inclusion Policy
- CH31-Disciplinary and Grievance Policy
- CH34-Confidentiality and Data Protection (GDPR) Policy
12. Policy Review
- This policy will be reviewed annually or sooner if changes in CQC regulations, cybersecurity threats, or legal requirements arise.
- Amendments will be made to ensure continued compliance and best practice in online safety and data protection.
Responsible Person: {{org_field_registered_manager_first_name}} {{org_field_registered_manager_last_name}}
Reviewed on: {{last_update_date}}
Next Review Date: {{next_review_date}}
Copyright © {{current_year}} – {{org_field_name}}. All rights reserved.