{{org_field_logo}}
{{org_field_name}}
Registration Number: {{org_field_registration_no}}
Sharing Information with Third-Party Organisations Policy
1. Purpose
The purpose of this policy is to ensure that {{org_field_name}} shares personal, confidential and other information with third-party organisations lawfully, fairly, securely and only where there is a clear and legitimate purpose for doing so. Appropriate information sharing is essential for safe and effective care, continuity of care, safeguarding, regulatory compliance and the effective management of the service.
{{org_field_name}} will ensure that information sharing complies with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 as amended, including amendments made by the Data (Use and Access) Act 2025, the common law duty of confidentiality and other legislation applicable to the circumstances of the disclosure.
This policy ensures that:
- Personal information is processed and shared lawfully, fairly and transparently.
- A valid lawful basis under Article 6 of the UK GDPR is identified before personal information is shared.
- Where special category data, including health information, is shared, an appropriate condition under Article 9 of the UK GDPR and, where required, the Data Protection Act 2018 is also identified.
- Criminal offence information is processed and shared only where the requirements of Article 10 of the UK GDPR and the Data Protection Act 2018 are satisfied.
- Only information that is adequate, relevant and limited to what is necessary for the particular purpose is shared.
- Confidential information is not disclosed merely because an organisation or individual requests it; the identity, authority, purpose and legal basis for the disclosure must first be established.
- People we support are provided with appropriate privacy information about how and why their personal information may be used and shared.
- Information necessary for safe and coordinated care is available to authorised persons when required.
- Information is protected against unauthorised or unlawful access, disclosure, alteration, loss or destruction.
- Information-sharing decisions, including decisions to share without consent where appropriate, are recorded where necessary to demonstrate lawful, safe and accountable practice.
- The requirements of the Care Quality Commission, including those relating to consent, safe care and treatment, safeguarding and good governance, are met.
2. Scope
This policy applies to:
- All employees, including full-time, part-time, agency, and voluntary staff who handle or share information.
- Management teams, responsible for ensuring compliance with data-sharing regulations.
- Third-party organisations, including healthcare providers, regulatory bodies, safeguarding teams, local authorities, legal representatives, law enforcement, and external service providers.
- People we support and their families, ensuring their data is handled securely and transparently.
3. Legal and Regulatory Compliance
This policy must be implemented in accordance with the legislation and regulatory requirements applicable to information sharing by an adult social care provider in England.
CQC Requirements – Health and Social Care Act 2008 (Regulated Activities) Regulations 2014
Regulation 9 – Person-centred care
Information must be used and shared appropriately where this is necessary to assess, plan and deliver care and treatment that meets the person’s individual needs and preferences. People must, so far as reasonably practicable, be enabled and supported to participate in decisions concerning their care and treatment.
Regulation 10 – Dignity and respect
The privacy, dignity and confidentiality of people receiving care must be respected. Personal and confidential information must not be disclosed in circumstances that unnecessarily intrude upon a person’s privacy.
Regulation 11 – Need for consent
Care and treatment must only be provided with the consent of the relevant person unless an applicable legal provision permits otherwise. Where a person aged 16 or over lacks capacity to give the relevant consent, {{org_field_name}} must act in accordance with the Mental Capacity Act 2005. Consent to care and treatment must not be confused with consent used as a lawful basis for processing personal data under the UK GDPR.
Regulation 12 – Safe care and treatment
Where responsibility for a person’s care and treatment is shared with or transferred to another person or organisation, {{org_field_name}} must work with that person or organisation, the person receiving care and other appropriate persons to ensure timely care planning and the person’s health, safety and welfare.
Relevant information required for safe care must therefore be shared promptly with authorised health and social care professionals where there is a lawful basis for doing so, while ensuring that unnecessary information is not disclosed.
Regulation 13 – Safeguarding service users from abuse and improper treatment
Information must be shared appropriately where this is necessary to prevent, identify, report, investigate or respond to suspected or actual abuse, neglect or improper treatment. Information must not be withheld solely because consent has not been obtained where there is a lawful basis or legal requirement permitting or requiring the disclosure.
Regulation 17 – Good governance
{{org_field_name}} must maintain accurate, complete and contemporaneous records concerning people receiving care and other records necessary for the management of the regulated activity.
Records and information must:
- Be accurate and kept up to date where necessary.
- Be available to authorised persons when required for safe and effective care.
- Be kept secure against unauthorised access, alteration, disclosure, loss or destruction.
- Be managed, retained and securely destroyed in accordance with applicable legislation and recognised guidance.
- Include appropriate records of significant information-sharing decisions, consent and decisions made on behalf of a person who lacks capacity.
Data Protection Legislation
{{org_field_name}} must comply with:
- The UK General Data Protection Regulation (UK GDPR), as amended.
- The Data Protection Act 2018, as amended.
- The Data (Use and Access) Act 2025 and amendments made by that Act to the UK data protection framework.
These requirements apply whenever personal data is collected, recorded, used, disclosed, transferred, stored or otherwise processed.
Common Law Duty of Confidentiality
Information provided in circumstances where a duty of confidence arises, including confidential health and care information, must not be disclosed without an appropriate justification.
Confidential information may be shared where:
- The person has given valid consent for the disclosure;
- The disclosure is required or permitted by law;
- The disclosure is necessary to comply with a court order or other binding legal requirement; or
- There is a sufficiently strong public interest justification for disclosure, for example to prevent serious harm, subject to the circumstances of the individual case.
The UK GDPR lawful basis and the duty of confidentiality must both be considered where both apply.
Care Act 2014
Information must be shared appropriately for adult safeguarding purposes. This includes cooperating with local authority safeguarding enquiries under section 42 of the Care Act 2014 and complying with a lawful requirement to provide information where the statutory requirements for disclosure apply.
Mental Capacity Act 2005
Where a person’s capacity to make a particular decision is in question, capacity must be assessed in accordance with the Mental Capacity Act 2005.
A person must be presumed to have capacity unless it is established that they lack capacity. A person must not be treated as lacking capacity merely because they make a decision that others consider unwise.
Where a person lacks capacity to make the relevant decision, any decision made on their behalf must comply with the Mental Capacity Act 2005, including the statutory best-interests requirements and consideration of whether the purpose can be achieved in a less restrictive way.
Freedom of Information Act 2000
The Freedom of Information Act 2000 applies to public authorities and to information held by another person on behalf of a public authority. {{org_field_name}} must therefore cooperate appropriately where information held in connection with commissioned services is subject to a lawful request made through a relevant public authority.
The Freedom of Information Act 2000 must not be treated as a general authority for {{org_field_name}} to disclose personal or confidential information.
NHS Data Security and Protection Requirements
Where {{org_field_name}} is contractually or otherwise required to comply with the NHS Data Security and Protection Toolkit, NHS information standards or associated requirements, the organisation must meet those requirements in addition to its statutory data protection obligations.
4. Principles of Information Sharing
All processing and sharing of personal data must comply with the principles of the UK GDPR.
{{org_field_name}} will ensure that personal data is:
- Processed lawfully, fairly and transparently – There must be a lawful basis for processing and people must be provided with appropriate information about how their personal data is used and shared, subject to any lawful exemption.
- Collected for specified, explicit and legitimate purposes – Personal data must not be used or shared for an incompatible purpose unless further processing is permitted by law.
- Adequate, relevant and limited to what is necessary – Only the information reasonably required to achieve the identified purpose may be shared.
- Accurate and, where necessary, kept up to date – Reasonable steps must be taken to ensure that inaccurate personal data is corrected or not relied upon where this could affect the person.
- Kept for no longer than necessary – Personal data must be retained in accordance with the organisation’s retention requirements and securely disposed of when there is no lawful reason to retain it.
- Processed securely – Appropriate technical and organisational measures must protect information against unauthorised or unlawful processing and against accidental loss, destruction or damage.
{{org_field_name}} must also comply with the accountability requirement. The organisation must be able to demonstrate its compliance with the data protection principles through appropriate policies, records, contracts, risk assessments, audits, staff training and documented decision-making.
5. Organisations with Whom Information May Be Shared
The inclusion of an organisation or category of organisation in this section does not, by itself, authorise the disclosure of personal or confidential information.
Before information is shared, staff must establish:
- The identity of the proposed recipient.
- The recipient’s authority to receive the information.
- The purpose for which the information is requested or required.
- The Article 6 UK GDPR lawful basis for sharing personal data.
- Where special category data is involved, the applicable Article 9 condition and any additional Data Protection Act 2018 requirements.
- Where criminal offence data is involved, the applicable Article 10 and Data Protection Act 2018 requirements.
- Whether the common law duty of confidentiality or another duty of confidence applies.
- Whether consent is required or is being relied upon.
- Whether the information requested is adequate, relevant and limited to what is necessary.
- Whether the proposed method of sharing is sufficiently secure.
- Whether the disclosure and the reason for it should be documented.
Subject to these requirements, information may be shared with the following organisations where lawful and necessary.
5.1 Health and Social Care Providers
Information may be shared with:
- GPs.
- Hospitals and NHS trusts.
- District and community nursing services.
- Mental health services.
- Pharmacists and medicines-management services.
- Tissue viability nurses.
- Physiotherapists.
- Dietitians.
- Other health or social care professionals involved in the person’s care.
Information necessary to provide safe, coordinated care must be shared promptly with authorised professionals where there is a lawful basis for doing so.
5.2 Regulatory, Commissioning and Safeguarding Bodies
Information may be shared where lawful and necessary with:
- The Care Quality Commission.
- Local authority safeguarding teams.
- Local authorities carrying out statutory functions.
- Integrated Care Boards.
- Other NHS bodies.
- The Office of the Public Guardian.
- Other regulatory or statutory bodies that have lawful authority to receive the information.
Information must be supplied to a statutory or regulatory body where {{org_field_name}} is under a legal obligation to provide it.
5.3 Police, Courts, Coroners and Legal Bodies
Information may be shared with:
- The police and other law-enforcement bodies.
- Courts and tribunals.
- Coroners.
- Legal representatives who have appropriate authority.
- Other persons or bodies exercising lawful investigatory or judicial functions.
A request from the police or another law-enforcement organisation does not automatically authorise disclosure. Staff must establish the lawful basis and necessity for the disclosure unless an immediate emergency makes this impracticable.
Where disclosure is required by legislation, a court order or another binding legal requirement, {{org_field_name}} will comply with that requirement and will disclose only the information falling within its scope.
5.4 External Service Providers
Personal data may be provided to external service providers including:
- IT and software providers.
- Electronic care-record providers.
- Cloud and data-hosting providers.
- Payroll and human-resources service providers.
- Pension administrators.
- Professional advisers.
- Insurers and claims handlers.
Before personal data is made available to an external organisation processing information on behalf of {{org_field_name}}, the organisation must determine whether the recipient is acting as a processor, joint controller or independent controller and must put the legally required arrangements in place.
6. Lawful Bases and Conditions for Information Sharing
Personal data must not be shared unless {{org_field_name}} has identified and documented an appropriate lawful basis under Article 6 of the UK GDPR.
Depending upon the circumstances, the applicable Article 6 lawful basis may include:
- Consent – The person has given valid consent to the processing for one or more specified purposes.
- Contract – Processing is necessary for the performance of a contract with the person or to take steps at the person’s request before entering into a contract.
- Legal obligation – Processing is necessary for compliance with a legal obligation to which {{org_field_name}} is subject.
- Vital interests – Processing is necessary to protect the vital interests of the person or another individual.
- Public task – Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority, where this basis lawfully applies to {{org_field_name}} and the task or authority has an appropriate basis in law.
- Recognised legitimate interests – Processing is necessary for a recognised legitimate interest specified in Annex 1 to the UK GDPR, where the statutory conditions for that basis are satisfied.
- Legitimate interests – Processing is necessary for the purposes of a legitimate interest pursued by {{org_field_name}} or a third party, except where those interests are overridden by the interests or fundamental rights and freedoms of the person. Where this basis is used, the organisation must consider necessity and the effect of the processing on the person’s rights and interests.
The lawful basis must be determined from the actual purpose and circumstances of the processing. Staff must not select consent simply because information is personal or confidential.
6.1 Special Category Data
Health information and certain other particularly sensitive categories of personal information constitute special category data.
Where special category data is processed or shared, identifying an Article 6 lawful basis is not sufficient. {{org_field_name}} must also identify a valid condition under Article 9 of the UK GDPR.
Depending upon the circumstances, relevant Article 9 conditions may include:
- Explicit consent.
- Protection of vital interests where the person is physically or legally incapable of giving consent.
- Establishment, exercise or defence of legal claims.
- Substantial public interest where the applicable requirements of the Data Protection Act 2018 are satisfied.
- Provision or management of health or social care where the statutory requirements and confidentiality safeguards are satisfied.
- Public-health purposes where the statutory requirements are satisfied.
Where a condition requires an additional condition under the Data Protection Act 2018 or an appropriate policy document, that requirement must also be satisfied before the processing takes place.
6.2 Criminal Offence Data
Information concerning criminal convictions, offences or related security measures must only be processed or shared where Article 10 of the UK GDPR and the applicable requirements of the Data Protection Act 2018 are satisfied.
Staff must seek advice from the organisation’s designated data protection lead where there is uncertainty about the lawful basis or condition for sharing criminal offence information.
6.3 Recording the Basis for Sharing
Where appropriate to the risk and nature of the disclosure, records must identify:
- What information was shared.
- With whom it was shared.
- The purpose of the disclosure.
- The lawful basis relied upon.
- The special category or criminal offence condition relied upon, where applicable.
- Whether consent was sought or relied upon.
- Any relevant safeguarding, capacity or best-interests considerations.
- The date of disclosure and the member of staff making or authorising the disclosure.
7. Consent, Confidentiality, Capacity and Transparency
7.1 Consent to Care and Treatment
Consent to care and treatment must be obtained and managed in accordance with Regulation 11 of the Health and Social Care Act 2008 (Regulated Activities) Regulations 2014 and other applicable law.
Consent must be recorded appropriately within the person’s care records, including significant changes or withdrawals of consent.
Consent to care or treatment must not automatically be treated as consent to every subsequent use or disclosure of personal information.
7.2 Consent as a UK GDPR Lawful Basis
Consent is one possible lawful basis for processing personal data but it is not the default lawful basis for all information sharing.
Where {{org_field_name}} relies upon consent under the UK GDPR, it must be able to demonstrate that the consent meets the applicable legal requirements and was given for the relevant processing purpose.
Consent must not be relied upon where the person has no genuine choice or where {{org_field_name}} intends to continue the processing irrespective of whether consent is withdrawn.
Where explicit consent is required for special category data, the records must demonstrate an express statement or other sufficiently explicit indication of the person’s agreement.
A person may withdraw consent relied upon under the UK GDPR. Withdrawal must be as easy as giving consent and must not affect processing that was lawful before consent was withdrawn.
7.3 Sharing Without Consent
Personal or confidential information may be shared without consent where there is a lawful and proportionate justification for doing so.
Examples may include circumstances where:
- Disclosure is required by law.
- Disclosure is required by a court order.
- Sharing is necessary to protect vital interests.
- Sharing is necessary for a lawful safeguarding purpose.
- Sharing is necessary for the provision of health or social care and the applicable legal conditions are satisfied.
- There is an overriding public interest justification, such as the prevention of serious harm.
- Another lawful basis and, where relevant, special-category condition permits the processing.
A refusal of consent must therefore not automatically prevent information being shared where another lawful basis permits or requires the disclosure.
The reason for sharing without consent must be documented where appropriate, particularly where the disclosure involves sensitive information, safeguarding concerns or a significant decision affecting the person.
Legal or specialist data protection advice must be obtained where the position is unclear or particularly complex.
7.4 Mental Capacity
Capacity must be considered in relation to the specific decision that needs to be made.
A person must be presumed to have capacity unless it is established that they lack capacity in accordance with the Mental Capacity Act 2005.
Where a person lacks capacity to make the relevant decision, {{org_field_name}} must:
- Follow the principles of the Mental Capacity Act 2005.
- Consider the person’s past and present wishes, feelings, beliefs and values.
- Consult relevant persons as required by the Act.
- Consider whether a person holds a valid and applicable lasting power of attorney or whether a deputy has authority in relation to the relevant decision.
- Make any decision on the person’s behalf in their best interests.
- Choose the least restrictive available option where the statutory requirements apply.
- Record the capacity assessment and best-interests decision where appropriate.
A relative or friend does not acquire authority to consent to disclosure simply because of their relationship with the person. Their legal authority, if any, must be established.
7.5 Privacy Information
People must be provided with privacy information required by the UK GDPR unless a lawful exemption applies.
Privacy information must explain, as applicable:
- What personal information is used.
- The purposes for which it is used.
- The lawful basis for the processing.
- The relevant special category condition where required.
- The recipients or categories of recipients with whom information may be shared.
- Applicable retention information.
- Relevant data protection rights.
- How to contact {{org_field_name}} concerning data protection matters.
- The right to complain to the Information Commissioner’s Office.
- Information concerning international transfers where applicable.
8. Data Security and Confidentiality in Information Sharing
8.1 Secure Methods for Sharing Information
Information must only be shared using methods that provide a level of security appropriate to the nature, sensitivity, volume and risk of the information being disclosed.
Before sending or disclosing personal or confidential information, staff must:
- Confirm the identity and authority of the recipient.
- Confirm that the contact details are correct.
- Check that the information being disclosed is necessary for the identified purpose.
- Remove information that the recipient does not need.
- Use an organisation-approved communication or information-sharing system.
- Apply encryption, password protection, secure portals, access controls or other safeguards where appropriate to the risk.
- Take reasonable precautions to prevent the information being seen or heard by unauthorised persons.
- Record significant disclosures where necessary.
Approved methods may include:
- NHSmail or another appropriately secured organisational email system.
- Secure electronic health or social care systems.
- Approved secure portals or encrypted file-transfer systems.
- Telephone communication where the identity and authority of the recipient have been appropriately verified.
- Face-to-face professional communication in an environment where confidentiality can be maintained.
- Secure tracked post or courier services where physical documents must be transferred.
Personal information must not be sent to an incorrect or unverified recipient merely because the request appears urgent.
In a genuine emergency, staff must use professional judgement to share information necessary to protect life, health or safety and must document the disclosure as soon as practicable afterwards.
8.2 Restrictions on Informal or Unauthorised Information Sharing
Staff must not:
- Use personal email accounts to send personal or confidential information relating to {{org_field_name}}.
- Use unapproved messaging, cloud-storage or social-media services to share personal or confidential information.
- Access or disclose personal information unless this is necessary for their role or another authorised purpose.
- Discuss identifiable information where unauthorised people may overhear the conversation.
- Leave paper or electronic records accessible to unauthorised persons.
- Photograph, copy, download or remove information for personal use.
- Share passwords or authentication credentials.
- Disclose information about a person to a relative, friend or other third party without first establishing the recipient’s authority and a lawful justification for disclosure.
8.3 External Data Processors – New Subsection
Where an external organisation processes personal data on behalf of {{org_field_name}}, {{org_field_name}} must use only a processor that provides sufficient guarantees that appropriate technical and organisational measures will be implemented to protect personal data and comply with data protection law.
A written contract or other binding legal act meeting Article 28 of the UK GDPR must be in place before the processor is permitted to process personal data on behalf of {{org_field_name}}.
The contract must address the legally required matters, including:
- The subject matter and duration of the processing.
- The nature and purpose of the processing.
- The types of personal data and categories of data subjects.
- The rights and obligations of {{org_field_name}}.
- Processing only on documented instructions.
- Confidentiality.
- Appropriate security measures.
- Conditions concerning sub-processors.
- Assistance with individuals’ data protection rights.
- Assistance with security, personal data breaches and other applicable compliance obligations.
- Return or deletion of personal data at the end of the arrangement, as applicable.
- Provision of information necessary to demonstrate compliance and permit appropriate audits or inspections.
Contracts and processor arrangements must be reviewed when material processing arrangements change.
8.4 International Transfers – New Subsection
Before personal data is transferred to, accessed from or made available in a country or territory outside the United Kingdom, {{org_field_name}} must establish whether the transfer is restricted under the UK GDPR.
Where the international-transfer rules apply, the transfer must not take place unless an appropriate lawful transfer mechanism or exception is available and all applicable UK GDPR requirements have been satisfied.
This requirement applies to direct transfers and may also apply where cloud, software, support or other service providers make personal data accessible from outside the United Kingdom.
8.5 Personal Data Breaches – New Subsection
All actual or suspected personal data breaches must be reported immediately to the Registered Manager and to the Data Protection Officer, where appointed or legally required, or the organisation’s designated data protection/information governance lead.
A personal data breach includes a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.
Examples include:
- Information being sent to the wrong person.
- Loss or theft of records or equipment containing personal data.
- Unauthorised access to care records.
- Disclosure of information to an unauthorised relative or third party.
- Cyber-attacks or ransomware affecting the confidentiality, integrity or availability of personal data.
- Accidental deletion or alteration of information where this compromises availability or integrity.
On becoming aware of a personal data breach, {{org_field_name}} must:
- Take immediate action to contain the breach and reduce the risk of harm.
- Establish what information and individuals are affected.
- Assess the likely risk to the rights and freedoms of affected individuals.
- Record the facts relating to the breach, its effects and the remedial action taken.
- Notify the Information Commissioner’s Office without undue delay and, where feasible, no later than 72 hours after becoming aware of the breach where the breach is likely to result in a risk to individuals’ rights and freedoms.
- Record the reasons where a breach is assessed as not requiring notification to the Information Commissioner’s Office.
- Inform affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms, unless a lawful exception applies.
- Preserve evidence and cooperate with any regulatory or law-enforcement investigation where required.
- Review the incident and implement measures to reduce the likelihood of recurrence.
Staff must not delay internal reporting while attempting to investigate or resolve the incident themselves.
9. Staff Training and Responsibilities
All employees who handle personal or confidential information must receive appropriate data protection, confidentiality and information-security training relevant to their role.
{{org_field_name}} requires staff to complete data protection and information-governance training at the frequency specified by the organisation and to complete additional or refresher training where required because of changes in law, systems, responsibilities, identified risks or incidents.
All staff must:
- Understand the importance of confidentiality and secure information handling.
- Understand that information must not be shared merely because another person or organisation requests it.
- Establish the identity, authority and purpose of the recipient before sharing information.
- Share only the information that is necessary and relevant for the identified purpose.
- Understand that consent is not the only lawful basis for information sharing and must not automatically be sought where another lawful basis is the appropriate basis.
- Seek advice where there is uncertainty about the lawful basis, special category condition, confidentiality requirement, safeguarding justification or authority of the proposed recipient.
- Follow the Mental Capacity Act 2005 where a person’s capacity is relevant to a decision.
- Use only organisation-approved systems and methods for sharing information.
- Immediately report any actual or suspected personal data breach, loss of information, unauthorised access or inappropriate disclosure.
- Cooperate with investigations, audits and corrective actions relating to information governance.
Where advice is required, staff must contact the Data Protection Officer where one has been appointed or is legally required, or otherwise the organisation’s designated data protection/information governance lead.
The Registered Manager must ensure that appropriate arrangements are in place to monitor compliance with this policy and that significant information-governance concerns are escalated appropriately.
10. Monitoring, Audits, and Compliance
To ensure compliance with this policy:
- Regular audits will check that information is being shared correctly.
- Incidents of unauthorised data sharing will be investigated and reported.
- CQC inspections will review information governance procedures.
- Staff feedback will be gathered to ensure understanding and compliance.
11. Related Policies
This policy should be read alongside:
- CH34 – Confidentiality and Data Protection (GDPR) Policy.
- CH13 – Safeguarding Adults from Abuse and Improper Treatment Policy.
- CH17 – Information Security and Record-Keeping Policy.
12. Policy Review
This policy will be reviewed annually or sooner if:
- Legislation changes.
- CQC guidance updates occur.
- A data breach or compliance concern arises.
Responsible Person: {{org_field_registered_manager_first_name}} {{org_field_registered_manager_last_name}}
Reviewed on: {{last_update_date}}
Next Review Date: {{next_review_date}}
Copyright © {{current_year}} – {{org_field_name}}. All rights reserved.