{{org_field_logo}}

{{org_field_name}}

Registration Number: {{org_field_registration_no}}


Confidentiality and Data Protection (UK GDPR) – Service User Policy

1. Purpose

The purpose of this policy is to ensure that the care home handles confidential information and personal data lawfully, fairly, securely and transparently, in accordance with the UK General Data Protection Regulation, the Data Protection Act 2018, the common law duty of confidentiality, the Human Rights Act 1998, the Care Act 2014, the Health and Social Care Act 2008, the Health and Social Care Act 2008 (Regulated Activities) Regulations 2014 and relevant Care Quality Commission requirements, including Regulation 17, Good governance. We are committed to maintaining the highest standards of privacy, security, and lawful processing of personal data to protect the dignity and rights of individuals.

This policy supports compliance with CQC’s current regulatory expectations, including safe care, dignity and respect, consent, safeguarding, complaints, staffing, duty of candour and good governance. The service will maintain clear responsibilities, secure records, effective audit systems and lawful information sharing arrangements so that people receive safe, person-centred care.

This policy ensures that personal and sensitive data of people we support is collected, stored, processed, shared, and disposed of in a lawful and ethical manner. It also defines the responsibilities of staff in protecting confidentiality and upholding data security. Failure to comply with this policy may result in disciplinary action and legal consequences.

Confidentiality is not an absolute duty. Staff must protect private information, but they must also share relevant and necessary information where there is a lawful basis to do so. This includes sharing information to provide safe care, protect vital interests, prevent abuse or neglect, meet safeguarding duties, comply with legal obligations, support a regulator, respond to a court order or protect others from serious harm. Any information shared must be necessary, proportionate, secure and recorded.

2. Scope

This policy applies to all employees, agency workers, volunteers, contractors, and any third-party organisations handling personal data within our care home. It covers:

This policy also applies to digital care records, paper files, daily notes, risk assessments, medicines records, safeguarding records, complaints records, incident records, photographs, video recordings, audio recordings, CCTV images where used, call bell records, door access records, emails, text messages, digital systems, mobile devices, archived records and back-up systems. It also applies to information about relatives, representatives, next of kin, advocates, attorneys, deputies, visitors and professionals involved in a person’s care.

3. Related Policies

This policy works alongside:

4. Policy Statement

Our care home is committed to protecting the privacy and confidentiality of the people we support. We ensure that:

The service will demonstrate accountability by keeping appropriate records of processing activities, privacy notices, consent records where consent is used, information sharing decisions, data protection impact assessments, breach logs, training records, audits and action plans.

The service will apply data protection by design and by default when introducing new systems, digital care records, monitoring equipment, apps, technology, suppliers or new ways of sharing information.

Care records, risk records, medicines records, incident records, safeguarding records, complaints records and governance records will be accurate, complete, contemporaneous, securely stored and available to authorised staff when needed to provide safe and effective care.

5. Implementation – How We Manage Confidentiality and Data Protection Lawfully, Safely and Effectively

5.1 Lawful Basis for Processing Personal Data

We will identify and record a lawful basis under Article 6 of the UK GDPR before processing personal data. Depending on the circumstances, this may include contract, legal obligation, vital interests, legitimate interests, public task where this applies, or consent where consent is appropriate.

Consent will not usually be relied upon as the lawful basis for core care records, care planning, risk management, safeguarding, medicines management, CQC compliance or legal record keeping, because the service often needs to process this information to provide safe care and meet legal obligations.

Where the service processes special category data, including health and care information, the service will also identify and record a separate Article 9 UK GDPR condition. This may include the provision of health or social care, management of health or social care systems and services, reasons of substantial public interest such as safeguarding, protection of vital interests, legal claims, or explicit consent where appropriate.

Where the service processes criminal offence data, including information linked to safeguarding, police involvement, risk assessments, allegations or offences, it will ensure there is a lawful basis, an appropriate condition under the Data Protection Act 2018 and suitable safeguards.

The lawful basis and special category condition will be recorded in the service’s Record of Processing Activities or equivalent information governance record.

5.2 Privacy Notices and Transparency

The service will provide a clear privacy notice to people using the service and, where appropriate, to relatives, representatives, attorneys, deputies and advocates. The privacy notice will explain what information is collected, why it is collected, the lawful bases used, who information may be shared with, how long records are kept, what rights people have, how to raise a data protection concern and how to contact the Information Commissioner’s Office.

Privacy information will be provided in a way the person can understand. This may include verbal explanation, easy read information, large print, translated information or other communication support where needed.

Staff must not give blanket assurances that information will never be shared. Staff must explain that information is kept confidential but may be shared where necessary and lawful, including for care, safeguarding, emergency treatment, legal duties or regulatory requirements.

5.3 Confidentiality and Secure Data Handling

All staff must maintain strict confidentiality and adhere to the following principles:

Staff must keep usernames, passwords, smartcards, access tokens and multi-factor authentication details confidential. Staff must not share log-in details with anyone or use another person’s log-in details.

Staff must lock screens or log out when leaving a computer, tablet, mobile device or digital care system unattended. Printed records must not be left unattended on desks, printers, medication trolleys, handover areas or in vehicles.

Staff must not use personal email accounts, personal messaging apps or personal devices to send, store or photograph confidential information unless this has been formally authorised, risk assessed and secured.

Staff must not discuss confidential information in communal areas, corridors, reception areas, dining rooms, public places or anywhere they may be overheard.

Staff must not post, share or discuss information about people using the service on social media. Photographs, videos or audio recordings must only be taken where there is a clear lawful purpose, appropriate authorisation and secure storage on an approved system.

5.4 Access to Personal Data

Access to personal data will be controlled on a need-to-know basis. Staff will only access information where it is necessary for their role and for the purpose of providing, managing, auditing or regulating care.

Access permissions will be based on role, responsibility, location and the type of information needed. The service will apply the principle of least privilege, meaning staff will only have the minimum access required to carry out their duties.

Care staff may access information necessary to provide safe care and support. Nurses and senior staff may access clinical, medicines and risk information necessary for their role. Managers and nominated leads may access wider records for oversight, safeguarding, complaints, quality assurance and governance. Administrative staff may only access information necessary for their administrative duties. External professionals must only receive information that is relevant, necessary and lawful for the purpose requested.

Access to digital systems must be removed promptly when staff leave the service or change roles. Audit trails must be reviewed where appropriate to identify inappropriate access, unusual activity or security concerns.

People using the service have the right to request access to their personal data. A subject access request can be made verbally or in writing and does not need to refer to “subject access” or data protection law. Staff must forward any request for personal information to the Registered Manager or Data Protection Lead / Information Governance Lead without delay. The service will normally respond without undue delay and within one month of receipt, unless an extension is permitted by law. Identity and authority must be checked before information is disclosed.

Where a request is made by a relative, attorney, deputy, advocate or representative, the service will check their authority before sharing information. Where a person lacks capacity to make a request, the service will act in accordance with the Mental Capacity Act 2005, any valid legal authority and the person’s best interests.

5.5 Sharing Data with External Organisations

The service will share personal data only where there is a lawful basis and where sharing is necessary, proportionate and relevant. Information may be shared with health professionals, local authorities, safeguarding teams, commissioners, the Care Quality Commission, emergency services, police, coroners, courts, advocates, attorneys, deputies, representatives, insurers, legal advisers, auditors, IT suppliers, digital care record providers and other approved processors where this is necessary and lawful.

Consent will be sought where consent is the appropriate lawful basis. However, information may be shared without consent where this is necessary and lawful, including for safeguarding, serious risk, emergency treatment, legal obligations, regulatory compliance, prevention or detection of crime, public interest reasons or vital interests.

Before sharing information, staff must confirm the identity and authority of the person or organisation requesting the information, check the purpose of the request, share only the minimum necessary information, use a secure method of transfer and record what was shared, with whom, when, why and by whom.

Staff must never delay urgent information sharing where delay may place a person at risk of serious harm. The reason for urgent sharing must be recorded as soon as possible afterwards.

5.6 Safeguarding and Confidentiality

Confidentiality must never be used as a reason to ignore, minimise or fail to report abuse, neglect, exploitation or unsafe care. Staff must report safeguarding concerns in line with the Safeguarding Adults from Abuse Policy and local safeguarding procedures.

Information shared for safeguarding purposes must be relevant, necessary, proportionate, accurate, timely and secure. Where possible and safe, the person will be informed about what information is being shared and why. However, information may be shared without consent where seeking consent would increase risk, prejudice an investigation, prevent effective safeguarding action or where there is another lawful basis for sharing.

Safeguarding records must be factual, dated, signed or attributable, securely stored and only accessible to staff who need to know.

5.7 Data Breaches and Incident Reporting

A data breach occurs when personal data is lost, accessed without authorisation, disclosed unlawfully, or compromised in any way.

Examples of personal data breaches include records being lost, stolen or left unattended; an email, letter or text being sent to the wrong person; unauthorised access to a care record; staff accessing records without a work-related reason; cyber attack; ransomware; phishing; loss of a laptop, tablet, mobile phone or paper file; accidental deletion or alteration of records; verbal disclosure to the wrong person; and photographs or videos being taken or shared without authority.

If a data breach occurs:

  1. Staff must report it immediately to the Registered Manager.
  2. An internal investigation will be conducted to determine the cause and extent of the breach.
  3. The Registered Manager and Data Protection Lead / Information Governance Lead will assess whether the breach is likely to result in a risk to the rights and freedoms of individuals. Where the breach is reportable, the Information Commissioner’s Office will be notified without undue delay and, where feasible, within 72 hours of the service becoming aware of the breach.
  4. Where the breach is likely to result in a high risk to the rights and freedoms of an affected person, the person will be informed without undue delay, unless a lawful exception applies. The information provided will include the nature of the breach, likely consequences, steps taken, protective measures and contact details for further support.

All data breaches should be reported to:

Failure to report a data breach may result in disciplinary action.

All suspected and confirmed personal data breaches, including near misses, must be recorded in the Data Breach Log. The log must include the date and time of the incident, date and time discovered, who reported it, people affected, type of data involved, likely impact, containment action, risk assessment, whether the ICO was notified, whether affected people were informed, lessons learned and actions completed.

Breach trends will be reviewed as part of governance and quality assurance meetings to identify learning, training needs and improvements.

5.8 Staff Training and Responsibilities

All staff must complete confidentiality, information governance and UK GDPR training during induction and at least annually thereafter. Staff must complete training before being given access to care records or digital systems.

Training will cover confidentiality, UK GDPR principles, lawful basis, special category data, secure record keeping, CQC expectations, safe information sharing, safeguarding information sharing, subject access requests, data protection complaints, personal data breaches, cyber security, phishing, ransomware, password security, social media, photographs, video recordings and secure use of digital care systems.

Managers are responsible for monitoring compliance through regular audits, spot checks, supervision, record reviews, access reviews, breach trend analysis, training compliance checks and quality assurance meetings. Audit findings must be recorded, acted upon and reviewed until actions are completed. Where risks are identified, the Registered Manager must ensure prompt action is taken to protect people and improve practice.

5.9 Data Retention and Disposal

Personal data must only be kept for as long as it is necessary, lawful and justifiable. The service will follow the Records Management Code of Practice for Health and Social Care, CQC requirements, contractual requirements, safeguarding requirements, insurance requirements and legal limitation periods.

Retention periods are minimum periods. Records must not be destroyed if they are required for an ongoing complaint, safeguarding enquiry, investigation, coroner’s process, legal claim, police matter, regulatory matter, audit or other legitimate hold.

Adult care records will be retained for at least 8 years after the last entry, discharge, death or end of service, unless a longer period is required. Safeguarding records will be retained in line with local safeguarding procedures, legal requirements and records management guidance, and longer where risk, investigation or legal action requires this. Financial records will be retained for at least 6 years, or longer where required by law, contract or audit.

Records due for disposal must be reviewed before destruction to confirm that no retention hold applies. Paper records must be destroyed by secure shredding or approved confidential waste arrangements. Electronic records must be securely deleted, destroyed or anonymised so that they cannot be recovered by unauthorised persons.

Destruction must be recorded, including the type of records destroyed, date range, date of destruction, method of destruction, authorising person and certificate of destruction where applicable. Archived records must remain secure, retrievable and protected against loss, damage, unauthorised access, fire, flood and system failure.

5.10 Data Protection Impact Assessments

A Data Protection Impact Assessment must be completed before introducing processing that is likely to result in a high risk to people’s rights and freedoms. This includes new digital care record systems, electronic medicines systems, CCTV or surveillance, monitoring technology, sensor-based care technology, artificial intelligence or automated decision-making tools, large-scale sharing of health or care information, new suppliers processing service user data, or new ways of collecting, analysing or linking personal data.

The Data Protection Impact Assessment must identify the purpose of processing, lawful basis, risks, safeguards, consultation needs, security measures, retention arrangements and actions required before implementation. The Registered Manager and Data Protection Lead / Information Governance Lead must review and approve the assessment before new systems or processes go live.

5.11 Data Processors and Third-Party Suppliers

Where a third party processes personal data on behalf of the service, the service will complete appropriate checks before the supplier is used. This applies to digital care record providers, IT support, payroll providers, cloud hosting providers, confidential waste providers, eMAR providers, audit providers and other relevant suppliers.

A written contract or data processing agreement must be in place before a processor handles personal data on behalf of the service. The agreement must cover confidentiality, security, breach reporting, sub-processors, assistance with individual rights requests, retention, return or deletion of data, and audit or assurance arrangements.

Suppliers must only process personal data on documented instructions from the service and must not use the information for their own purposes unless legally permitted.

5.12 Cyber Security and Digital Systems

The service will maintain appropriate technical and organisational measures to protect personal data and confidential information. These will include secure user accounts, strong passwords, multi-factor authentication where available, role-based access controls, anti-virus protection, software updates, secure back-ups, encryption where appropriate, secure disposal of IT equipment, audit logs, business continuity arrangements and disaster recovery arrangements.

Staff must report suspected cyber incidents immediately, including phishing emails, suspicious links, ransomware messages, lost devices, unusual system activity, unauthorised access or accidental disclosure.

Where the service accesses NHS patient data or NHS systems, the service will complete and maintain the Data Security and Protection Toolkit where required and will use the outcome to support information governance improvement.

5.13 Data Protection Complaints

People using the service, relatives, representatives, staff and others may make a complaint if they are unhappy about how their personal data has been handled.

A data protection complaint may include concerns about inaccurate information, unfair or unlawful use of information, failure to provide privacy information, delay in responding to an information rights request, inappropriate disclosure, failure to keep information secure, excessive collection of information or inappropriate access to records.

Complaints may be made verbally or in writing. Staff must pass any data protection complaint to the Registered Manager or Data Protection Lead / Information Governance Lead without delay.

The service will acknowledge, investigate and respond to data protection complaints in line with the Complaints Policy and data protection law. The response will explain the outcome, any action taken, any right to escalate internally and the person’s right to complain to the Information Commissioner’s Office.

Data protection complaints will be logged, monitored and reviewed to identify trends, learning and service improvements.

5.14 CCTV, Photographs, Recordings and Monitoring

CCTV, photographs, video, audio recording, monitoring devices and sensor technology must only be used where there is a clear, lawful and proportionate purpose. The service will complete a risk assessment and, where required, a Data Protection Impact Assessment before using CCTV, monitoring or recording technology.

People using the service, visitors and staff will be informed where CCTV or monitoring is in use, unless there is a lawful reason not to do so.

Photographs or recordings of people using the service must only be taken using approved equipment and stored on approved secure systems. Staff must not use personal devices to take or store photographs, videos or recordings of people using the service.

Images and recordings must not be used for publicity, social media, training or marketing unless there is a clear lawful basis, appropriate consent where needed and recorded approval.

5.15 Mental Capacity, Consent and Representatives

The service will presume that adults have capacity to make decisions about their information unless there is evidence to the contrary. Where there is reason to believe a person may lack capacity to make a specific information-sharing decision, staff must follow the Mental Capacity Act 2005 and the Consent and Mental Capacity Policy.

Where a person lacks capacity, information sharing decisions must be made in their best interests, taking account of any valid and applicable lasting power of attorney, Court of Protection deputyship, advance decision, known wishes, feelings, beliefs and values.

Relatives and next of kin do not automatically have a right to access personal information. Information may be shared with them where the person has agreed, where they have legal authority, where sharing is in the person’s best interests, or where another lawful basis applies.

Staff must record the reason for sharing or refusing to share information with relatives, representatives, attorneys, deputies or advocates.

6. Compliance with Legislation and CQC Standards

This policy supports compliance with:

7. Monitoring and Review

The Registered Manager is responsible for ensuring that this policy is implemented, monitored and reviewed.

Compliance with this policy will be monitored through:

Audits and reviews will check that:

Where concerns are identified, an action plan will be completed and monitored until actions are finished.

This policy will be reviewed annually, or sooner if legislation, CQC guidance, ICO guidance, systems, suppliers or service arrangements change, or if an incident, complaint, audit or inspection identifies the need for improvement.


Responsible Person: {{org_field_registered_manager_first_name}} {{org_field_registered_manager_last_name}}
Reviewed on:
{{last_update_date}}
Next Review Date:
{{next_review_date}}
Copyright © {{current_year}} – {{org_field_name}}. All rights reserved.

Leave a Reply

Your email address will not be published. Required fields are marked *