{{org_field_logo}}
{{org_field_name}}
Registration Number: {{org_field_registration_no}}
Confidentiality and Data Protection (UK GDPR) – Staff Policy
1. Purpose
The purpose of this policy is to ensure that all staff members at {{org_field_name}} understand their responsibilities in maintaining confidentiality and complying with data protection law, including the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and (as commenced) the Data (Use and Access) Act 2025, together with any other applicable legislation and regulatory guidance relevant to adult social care.
This policy ensures that:
- Personal data of the people we support, staff, and stakeholders is handled securely and lawfully.
- Staff understand their legal and ethical duties concerning confidentiality and data protection.
- Our care home remains compliant with CQC requirements, including Regulation 17 (Good Governance), by maintaining secure, accurate, complete and contemporaneous records, ensuring information is accessible to authorised persons when needed for safe care, and managing confidentiality in line with the Data Protection Act 2018 and UK GDPR.
- Robust systems are in place to prevent data breaches and safeguard confidential information.
2. Scope
This policy applies to:
- All staff members (permanent, temporary, agency, and volunteers) handling personal data.
- Personal and sensitive data of the people we support, their families, staff members, and external stakeholders.
- Any data held in physical and digital formats, including paper records, emails, databases, and IT systems.
3. Principles of Confidentiality and Data Protection
3.1 Lawful, Fair, and Transparent Processing
- All personal data must be processed lawfully, fairly, and in a transparent manner.
- Individuals must be informed about how their data is used, including through privacy notices.
3.2 Purpose Limitation
- Data should only be collected for specified, explicit, and legitimate purposes.
- Staff must not use personal data for any purpose beyond their professional duties.
3.3 Data Minimisation
- Only necessary data should be collected and retained.
- Staff must not collect excessive or irrelevant personal information.
3.4 Accuracy
- Personal data must be kept accurate and up to date.
- Individuals have the right to request corrections to inaccurate information.
3.5 Storage Limitation
- Personal data must not be kept for longer than necessary.
- Retention periods are defined based on legal and operational requirements.
Retention and disposal must follow {{org_field_name}}’s Records Retention Schedule and nationally recognised guidance (for example, the Records Management Code of Practice for Health and Social Care), and staff must not destroy or delete records unless authorised to do so.
3.6 Integrity and Confidentiality (Security)
- Data must be stored securely to prevent unauthorised access, loss, or breaches.
- Staff must follow secure handling, storage, and disposal procedures.
3.7 Records must be fit for purpose (CQC Regulation 17)
Records about people we support and our regulated activities must be complete, legible, accurate, up to date and created/updated without undue delay. Records must be accessible to authorised staff and authorised external professionals where necessary for safe and effective care, while remaining secure at all times.
3.8 Accountability
- {{org_field_name}} is responsible for demonstrating compliance with the UK GDPR, Data Protection Act 2018, and applicable regulatory expectations (including CQC Regulation 17), and for being able to evidence this through training, audits, risk management, and secure record keeping.
- The Data Protection Officer (DPO) – {{org_field_data_protection_officer_first_name}} {{org_field_data_protection_officer_last_name}} oversees compliance and data protection policies.
3.9 Common law confidentiality and Caldicott Principles
In addition to data protection law, staff must follow the common law duty of confidentiality: information given in confidence should not be disclosed without a clear justification. We apply the Caldicott Principles to ensure information sharing is necessary, proportionate, and on a need-to-know basis, while recognising that sharing relevant information for individual care can be as important as protecting confidentiality.
4. Staff Responsibilities in Data Protection
4.1 Handling Personal Data Securely
- Staff must only access, use, and share data as necessary for their role.
- Staff must not share confidential information unless there is a valid lawful basis under the UK GDPR and an appropriate confidentiality justification (for example: the person has consented; sharing is required by law; sharing is necessary for safeguarding or to prevent serious harm; or sharing is necessary for the provision of health or social care and is in the person’s best interests where they lack capacity).
- Personal data should be kept secure at all times (e.g., locked cabinets, password-protected systems).
4.2 IT and Digital Security
- Staff must use strong passwords and two-factor authentication (where applicable).
- Personal and confidential information must not be shared via unsecured channels (e.g., personal emails, social media, or unauthorised USB devices).
- Staff must log out of systems and lock screens when leaving their workstation.
4.3 Secure Disposal of Data
- Physical documents must be shredded or securely disposed of when no longer required.
- Digital files must be deleted or archived securely in line with data retention policies.
4.4 Confidential Conversations
- Staff must only discuss confidential matters in private areas.
- Conversations about the people we support must not be held in public areas (e.g., reception, hallways).
4.5 Reporting Data Breaches
Any suspected or actual personal data breach must be reported immediately to the Data Protection Officer (DPO) – {{org_field_data_protection_officer_first_name}} {{org_field_data_protection_officer_last_name}} (or the senior manager on duty if the DPO is unavailable). Staff must preserve evidence and take immediate steps to contain the breach where safe to do so (for example, recalling an email, recovering paperwork, or isolating a device).
The DPO will follow the breach response plan, including assessment of risk to individuals, mitigation actions, and completion of a breach log. Where the breach is notifiable, {{org_field_name}} will report it to the ICO without undue delay and, where feasible, within 72 hours of becoming aware of it. Where the breach is likely to result in a high risk to individuals’ rights and freedoms, affected individuals will also be informed without undue delay.
4.6 Record keeping, amendments and capacity decisions (CQC Regulation 17)
Staff must ensure care records are accurate, complete, contemporaneous, and attributable (it must be clear who made the entry and when). Entries must be legible, factual, and timely.
Where a person lacks capacity, staff must record the capacity assessment and the best-interests decision-making process, including who was consulted and why the decision was made, in line with the Mental Capacity Act and associated guidance.
5. Information Sharing and Consent
5.1 Sharing Data with External Parties
Personal data may only be shared where there is a lawful basis under the UK GDPR and a clear confidentiality justification. Depending on the context, lawful bases may include legal obligation, vital interests, contract, legitimate interests, and (where applicable) recognised legitimate interests introduced by the Data (Use and Access) Act 2025 (for example, safeguarding, responding to emergencies, and crime prevention).
Because much of our information is health and care information (special category data), sharing will also require a valid UK GDPR special category condition (for example, where processing is necessary for health or social care, safeguarding, or protecting vital interests).
Staff must not assume that consent is always required for safe care. Where consent is appropriate, it must be properly obtained and recorded.
5.2 Obtaining Consent for Data Use
- Consent must be freely given, specific, informed, and unambiguous.
- Individuals can withdraw consent at any time, and their request must be respected.
5.3 Confidentiality in Safeguarding Situations
- In safeguarding cases, data may be shared without consent if it is necessary to prevent harm.
- Staff must follow the Safeguarding Adults from Abuse and Improper Treatment Policy (CH13).
5.4 Sharing information with family, friends and representatives
Staff may only share personal information with family or friends where:
(a) the person has capacity and has consented to that specific sharing;
(b) the person lacks capacity and sharing is necessary and in their best interests, and the decision is recorded;
(c) the recipient has legal authority (for example, Health and Welfare LPA acting within scope, or a court-appointed deputy).
Staff must share the minimum necessary information and record what was shared, with whom, the lawful basis/justification, and the outcome.
5.5 Requests for information from CQC, safeguarding authorities, police, or courts
Any external request for personal information must be referred to the DPO (or senior manager on duty) before disclosure, unless there is an immediate risk of serious harm. We must verify the requester’s identity and authority, disclose only what is necessary, and keep a record of the disclosure decision.
Staff must cooperate with CQC inspections and information requests. CQC has legal powers to require information and access to records (including personal and medical records) for its regulatory functions. Where CQC requests information, we will provide it within required timescales and in a way that maintains privacy (for example, providing records in a private area and limiting access to authorised persons).
6. Training and Compliance
6.1 Staff Training on GDPR and Confidentiality
- All staff must complete mandatory GDPR training upon induction and annually thereafter.
- Training includes:
- Recognising and handling personal data correctly.
- Understanding the legal basis for processing data.
- Preventing and responding to data breaches.
6.2 Monitoring and Audits
- Regular audits of data protection practices are conducted.
- Staff non-compliance may lead to disciplinary action under the Staff Conduct and Code of Ethics Policy (CH28).
7. Data Subject Rights
Under the UK GDPR (as amended), individuals have rights over their personal data, subject to specific legal limitations (for example, where we must keep records to meet legal and regulatory obligations).
- Right to be informed – knowing how their data is used.
- Right of access – requesting copies of their data.
- Right to rectification – correcting inaccurate data.
- Right to erasure (“Right to be forgotten”) – requesting deletion of personal data.
- Right to restrict processing – limiting how data is used.
- Right to data portability – transferring data to another provider.
- Right to object – challenging data processing in certain cases.
- Rights in relation to automated decision-making – ensuring human intervention in significant decisions.
Requests can be made in writing or verbally and must be passed immediately to the DPO: {{org_field_data_protection_officer_first_name}} {{org_field_data_protection_officer_last_name}}. We will respond without undue delay and within one month, unless the law allows an extension for complex requests. Where we reasonably require additional information to confirm identity or to clarify the request, the response time may be paused (“stop-the-clock”) until the information is provided, and we will carry out reasonable and proportionate searches when responding.
7.1 Complaints about how we use personal information
Individuals may complain if they believe we have not handled their personal information lawfully or fairly. {{org_field_name}} will make it easy to complain (including an electronic option) and will inform the individual of the outcome and any actions taken. Individuals will also be signposted to their right to complain to the Information Commissioner.
7.2 Requests for records of deceased people
Requests for access to the health and care records of a deceased person must be referred to the DPO. Access may be available to the personal representative of the estate (for example, executor/administrator) or someone with a claim arising from the death, in line with applicable law and guidance. No disclosure must be made by staff without DPO authorisation and a recorded decision.
8. Related Policies
This policy should be read alongside:
- Safeguarding Adults from Abuse and Improper Treatment Policy (CH13).
- Good Governance Policy (CH04).
- IT and Digital Security Policy.
- Staff Conduct and Code of Ethics Policy (CH28).
9. Policy Review
This policy is reviewed annually or sooner if:
- Legislative changes occur.
- DUAA commencement regulations or ICO guidance introduce new operational requirements (for example, changes to subject access, complaint handling, or automated decision safeguards).
- CQC guidance is updated.
- New risks or incidents highlight the need for revision.
This Confidentiality and Data Protection (GDPR) – Staff Policy ensures that staff understand their legal obligations, personal data is protected, and our care home remains compliant with GDPR and CQC requirements.
Responsible Person: {{org_field_registered_manager_first_name}} {{org_field_registered_manager_last_name}}
Reviewed on: {{last_update_date}}
Next Review Date: {{next_review_date}}
Copyright © {{current_year}} – {{org_field_name}}. All rights reserved.