{{org_field_logo}}
{{org_field_name}}
Registration Number: {{org_field_registration_no}}
Using Social Media Platforms Policy
1. Purpose
This policy outlines {{org_field_name}}’s approach to the lawful, responsible and professional use of social media by staff. It is intended to protect the privacy, dignity, rights, safety and confidentiality of people we support and to ensure that the use of social media is consistent with applicable legislation, CQC regulatory requirements and the organisation’s safeguarding and information-governance responsibilities.
The purpose of this policy is to:
- Ensure compliance, where relevant, with the Health and Social Care Act 2008, the Health and Social Care Act 2008 (Regulated Activities) Regulations 2014, the Care Quality Commission (Registration) Regulations 2009, the Data Protection Act 2018, the UK General Data Protection Regulation (UK GDPR), the Mental Capacity Act 2005, the Equality Act 2010 and applicable employment and whistleblowing legislation.
- Safeguard the privacy, dignity, rights and well-being of people we support.
- Prevent unauthorised disclosure or misuse of personal, confidential or special category personal data.
- Prevent social media from being used in a way that constitutes or contributes to abuse, harassment, discrimination, exploitation or improper treatment.
- Support appropriate professional boundaries and professional conduct online.
- Ensure that photographs, recordings, information and other personal data are only obtained, used or disclosed where {{org_field_name}} has identified a lawful basis and complied with any additional legal requirements applying to the information.
- Ensure staff understand how to recognise and immediately report safeguarding concerns, personal data breaches and other incidents arising from social media use.
- Ensure that nothing in this policy prevents a worker from raising a safeguarding concern, reporting a criminal matter or making a protected disclosure in accordance with applicable whistleblowing legislation.
2. Scope
This policy applies to:
- All employees, including full-time, part-time, agency staff, volunteers, and contractors.
- Social media platforms, including but not limited to Facebook, Twitter, Instagram, TikTok, LinkedIn, WhatsApp, YouTube, and blogs.
- Official and personal use of social media, whether inside or outside of work.
- Posts, comments, messages, images, and videos related to {{org_field_name}}, its employees, or the people we support.
3. Legal and Regulatory Compliance
{{org_field_name}} will ensure that its use and management of social media complies with applicable legislation and regulatory requirements, including the following.
Health and Social Care Act 2008 and the Health and Social Care Act 2008 (Regulated Activities) Regulations 2014
Relevant requirements include:
- Regulation 10 – Dignity and respect: People who use the service must be treated with dignity and respect. This includes respecting and maintaining their privacy. Photographs, recordings, posts, comments or other social media activity must not compromise a person’s dignity, privacy or confidentiality.
- Regulation 11 – Need for consent: Where a decision or activity falls within the scope of Regulation 11, consent must be obtained lawfully and in accordance with applicable law. Where a person aged 16 or over lacks capacity to make the relevant decision, the requirements of the Mental Capacity Act 2005 must be followed.
- Regulation 13 – Safeguarding service users from abuse and improper treatment: People who use the service must be protected from abuse and improper treatment. Systems and processes must be operated effectively to prevent abuse and to ensure that allegations or evidence of abuse are acted upon immediately. Social media-related bullying, harassment, exploitation, psychological ill-treatment, neglect or other abuse must therefore be treated as a safeguarding concern where applicable.
- Regulation 17 – Good governance: {{org_field_name}} must operate effective systems and processes to assess, monitor and mitigate risks and must maintain required records securely. Records relating to social media consent, safeguarding concerns, investigations, personal data breaches and relevant management decisions must therefore be accurate, appropriate and securely maintained.
- Regulation 20 – Duty of candour: Where a social media-related event forms part of a notifiable safety incident within the meaning of Regulation 20, the registered person must comply with the statutory duty of candour requirements.
Care Quality Commission (Registration) Regulations 2009
The Registered Person must make statutory notifications to the Care Quality Commission where required.
In particular, under Regulation 18, specified incidents occurring whilst services are being provided in the carrying on of a regulated activity, or as a consequence of carrying on that regulated activity, must be notified to CQC without delay. These include, where applicable:
- abuse or an allegation of abuse in relation to a person using the service;
- specified serious injuries;
- incidents reported to or investigated by the police; and
- other events specified by Regulation 18.
Social media involvement does not remove or replace these statutory notification duties.
Data Protection Act 2018 and UK GDPR
Photographs, videos, audio recordings, names, contact details and other information capable of identifying a living person may constitute personal data. Information revealing matters such as a person’s health may also constitute special category personal data.
{{org_field_name}} must:
- identify and document an appropriate lawful basis for processing personal data;
- satisfy any additional legal condition required for processing special category personal data;
- use personal data only for specified, explicit and legitimate purposes;
- ensure that personal data is adequate, relevant and limited to what is necessary;
- ensure that personal data is accurate where required;
- retain personal data only for as long as necessary;
- protect personal data against unauthorised or unlawful processing and against accidental loss, destruction or damage; and
- comply with applicable transparency, individual-rights, accountability and personal-data-breach requirements.
Consent is not the only lawful basis available under UK GDPR. However, where {{org_field_name}} relies upon consent, that consent must be freely given, specific, informed and unambiguous, demonstrated by a clear affirmative action and capable of being withdrawn. Appropriate records must be retained to demonstrate the consent obtained.
Where explicit consent is required under data protection law, it must expressly confirm the person’s consent to the relevant processing.
Mental Capacity Act 2005
Where an adult’s capacity to make a particular decision concerning the proposed use or disclosure of their information is in question, capacity must be considered in accordance with the Mental Capacity Act 2005.
A person must be presumed to have capacity unless it is established that they lack capacity in relation to the particular decision at the relevant time.
A relative, friend or informal carer does not automatically have legal authority to give consent on behalf of an adult who lacks capacity. Before relying upon another person to make a decision on someone’s behalf, {{org_field_name}} must establish whether that person has lawful authority relevant to the decision, for example under an applicable Lasting Power of Attorney or deputyship order, and must obtain appropriate advice where necessary.
Identifiable information about a person who lacks capacity must not be published on social media merely because a relative or other person has agreed to publication.
Equality Act 2010
Social media must not be used in a way that unlawfully discriminates against, harasses or victimises another person because of a protected characteristic.
The protected characteristics under the Equality Act 2010 are:
- age;
- disability;
- gender reassignment;
- marriage and civil partnership;
- pregnancy and maternity;
- race;
- religion or belief;
- sex; and
- sexual orientation.
Whistleblowing and Protected Disclosures
Nothing in this policy is intended to prevent or discourage a worker from making a protected disclosure in accordance with the Employment Rights Act 1996, as amended, or from raising a concern with an appropriate prescribed person or regulatory body, including CQC, where the legal requirements for doing so are met.
Staff must refer to {{org_field_name}}’s whistleblowing procedure when raising concerns about wrongdoing in the public interest.
4. Managing Social Media Use
4.1. Acceptable Use of Social Media
Social media can be a valuable tool for professional networking, community engagement, and positive promotion of the care home. Employees may use social media in the following ways:
- Sharing positive news and events related to the care home, only through official accounts and with management approval.
- Engaging in relevant discussions about care sector improvements, innovation, and training, as long as they adhere to professional standards.
- Using LinkedIn and other platforms for professional development and networking, ensuring that no confidential information is shared.
- Promoting recruitment campaigns or fundraising events that benefit the organisation, with prior approval.
4.2. Unacceptable Use of Social Media
The following actions are prohibited, whether using personal or official social media accounts:
- Posting, uploading, forwarding, sharing or otherwise disclosing identifiable photographs, videos, audio recordings, personal information or confidential information relating to a person we support unless the disclosure has been authorised by {{org_field_name}} and all applicable confidentiality and data protection requirements have been satisfied.
- Taking or recording photographs, videos or audio recordings of people we support on a personal device unless this has been expressly authorised for a legitimate work purpose and is permitted under the organisation’s applicable information-governance procedures.
- Assuming that consent given for one purpose permits information or images to be used for another purpose. Consent for care, internal activities, photography or communication with family members does not automatically constitute consent to publication on social media.
- Where {{org_field_name}} relies on consent for social media publication, publishing material unless the consent obtained is valid for that particular use and an appropriate record of the consent is retained.
- Publishing identifiable information relating to an adult who lacks capacity on the basis of informal agreement from a relative, friend or carer without first establishing the lawful basis and any lawful authority required for the decision.
- Making derogatory, discriminatory, abusive, harassing, threatening or defamatory comments about people we support, relatives, representatives, colleagues or other persons.
- Posting material which humiliates, ridicules, degrades, exploits or otherwise compromises the dignity or safety of a person we support.
- Disclosing information concerning a person’s health, care, treatment, medication, behaviour, finances, safeguarding circumstances or other confidential information unless disclosure is lawful and specifically authorised.
- Discussing, commenting upon or disclosing confidential information concerning safeguarding enquiries, disciplinary proceedings, investigations, complaints or legal proceedings unless authorised or legally entitled to do so.
- Engaging in cyberbullying, harassment, exploitation or inappropriate online contact with a person we support.
- Impersonating {{org_field_name}}, another member of staff, a person we support or another individual.
- Creating an unauthorised social media account using {{org_field_name}}’s name, logo, branding or other identifying material.
- Presenting a personal view as an official statement or authorised position of {{org_field_name}}.
- Publishing confidential commercial, employment, security or operational information belonging to {{org_field_name}} without authority.
Nothing in this section prevents:
- the reporting of a safeguarding concern;
- reporting suspected criminal conduct to an appropriate authority;
- making a statutory notification;
- co-operating lawfully with CQC, the local authority, the police, the Information Commissioner’s Office or another competent authority; or
- making a protected disclosure in accordance with applicable whistleblowing legislation.
4.3. Safeguarding, Confidentiality, Consent and Capacity on Social Media
The privacy, dignity, confidentiality and safety of people we support must be protected at all times, including when social media, messaging applications, photographs, videos or other digital communications are used.
Staff must not disclose information concerning a person’s care, treatment, health, medication, behaviour, family circumstances, finances, safeguarding arrangements or other confidential or personal information unless the disclosure is lawful, necessary for an authorised purpose and made through an approved method.
Photographs, videos, recordings or other identifiable material must not be published on an official social media account unless:
- publication has been authorised in accordance with {{org_field_name}}’s procedures;
- {{org_field_name}} has identified an appropriate lawful basis for processing the personal data;
- any additional requirements relating to special category personal data have been satisfied;
- the person has been given appropriate information about how and where their information will be used;
- where consent is relied upon, valid consent covering the particular publication has been obtained and recorded; and
- publication will not compromise the person’s dignity, safety, rights or welfare.
Where consent is relied upon, the person must be able to refuse without experiencing disadvantage in relation to their care or support. They must also be informed that consent can be withdrawn.
Withdrawal of consent does not make previous lawful processing unlawful, but {{org_field_name}} must take appropriate action in relation to continued processing for which it can no longer rely upon consent. Where material has already been shared or reproduced by third parties, complete removal from the internet may not always be possible, and this must be explained as part of the consent process where relevant.
Where there is reason to doubt whether a person can make the relevant decision, staff must refer the matter to the Registered Manager before any material is published.
Capacity must be considered in relation to the specific decision and at the time it needs to be made. A diagnosis of dementia, learning disability, mental illness or another condition does not by itself establish that the person lacks capacity.
Staff must not assume that a family member, next of kin or informal carer has legal authority to consent to publication on behalf of an adult who lacks capacity.
Staff must maintain appropriate professional boundaries with people we support and their relatives or representatives when using personal social media accounts.
Staff must report immediately any social media activity that:
- constitutes or may constitute abuse, harassment, exploitation or improper treatment;
- places a person at risk of harm;
- discloses confidential or personal information without authorisation;
- appears to constitute a personal data breach;
- involves inappropriate contact between a member of staff and a person we support; or
- may require notification to CQC, the local authority safeguarding service, the police, the Information Commissioner’s Office or another relevant body.
Any allegation or evidence of abuse must be acted upon without delay in accordance with the organisation’s safeguarding procedures.
4.4. Managing Organisation’s Official Social Media Accounts
{{org_field_name}} may use social media to engage with the community, promote events, and share positive stories. However, this must be managed professionally.
- Only designated staff are authorised to post on official accounts.
- Posts must be pre-approved by management before being shared.
- All social media interactions must align with CQC standards, safeguarding policies, and Regulation 10 (Dignity and Respect).
- The marketing or communications team will regularly monitor the organisation’s accounts to ensure compliance and manage any inappropriate comments.
4.5. Personal Social Media Use and Conduct
Staff are entitled to use personal social media accounts, but their use must not breach legal obligations, contractual obligations, confidentiality requirements, professional standards or this policy.
Staff must:
- maintain the confidentiality of people we support and confidential organisational information;
- maintain appropriate professional boundaries;
- not disclose photographs, recordings, personal information or confidential information obtained through their employment unless lawfully authorised;
- not represent personal views as the official views of {{org_field_name}};
- not use social media to bully, harass, discriminate against, threaten, abuse or exploit another person;
- not publish content that compromises the dignity, privacy, rights or safety of a person we support; and
- comply with lawful organisational requirements concerning the use of the organisation’s name, branding, systems and information.
Staff should be aware that material posted to a private account may be copied, forwarded, screenshotted or otherwise made public.
Personal employment grievances should normally be raised through the organisation’s grievance procedure.
However, a concern involving wrongdoing in the public interest may constitute whistleblowing rather than a personal grievance. Nothing in this policy prevents or restricts a worker from:
- raising a safeguarding concern;
- reporting suspected criminal conduct;
- raising concerns with CQC or another appropriate prescribed person;
- providing information where required by law; or
- making any other protected disclosure in accordance with applicable whistleblowing legislation.
Staff will not be subjected to disciplinary action merely because they have made a legally protected disclosure. The organisation’s Whistleblowing Policy must be followed where applicable.
4.6. Reporting and Managing Social Media Breaches
Any member of staff who becomes aware of an actual or suspected breach of this policy must report it immediately.
This includes:
- unauthorised photographs, recordings or posts concerning a person we support;
- disclosure of confidential or personal information;
- abusive, discriminatory, degrading or inappropriate online content;
- cyberbullying, exploitation or inappropriate contact;
- suspected safeguarding concerns;
- loss or compromise of an official social media account;
- unauthorised access to an account;
- accidental disclosure of information; and
- any other incident that may constitute a personal data breach or statutory notifiable incident.
Internal Reporting
Staff must immediately report the concern to the Registered Manager or Safeguarding Lead using the organisation’s established reporting arrangements.
Reports may also be made by:
- email to the Registered Manager at {{org_field_registered_manager_email}};
- telephone on {{org_field_phone_no}}; or
- the out-of-hours number {{out_of_hours}}, where urgent action is required outside normal working hours.
Where there is an immediate risk of serious harm or an emergency requiring police, ambulance or other emergency assistance, staff must contact the emergency services without delay and then follow the organisation’s incident-reporting arrangements.
Staff must preserve relevant evidence where it is safe and lawful to do so. This may include recording the web address, account details, date and time and taking an appropriate screenshot. Staff must not unnecessarily copy, forward or redistribute confidential or abusive material.
Where possible, unauthorised content must be contained or removed promptly, but removal of the material must not prevent appropriate evidence from being retained for safeguarding, regulatory, disciplinary or legal purposes.
Safeguarding Concerns
Where social media activity amounts to, or may indicate, abuse, neglect, exploitation or improper treatment:
- immediate action must be taken to protect the person;
- the organisation’s Safeguarding Adults from Abuse and Improper Treatment Policy must be followed;
- the concern must be referred to the appropriate safeguarding authority where required; and
- any statutory CQC notification requirement must be considered and completed without delay.
An internal investigation must not delay urgent safeguarding action or a statutory notification.
CQC Statutory Notifications
The Registered Person is responsible for ensuring that statutory notifications are submitted to CQC where required.
Where a social media incident falls within Regulation 18 of the Care Quality Commission (Registration) Regulations 2009, the required notification must be made to CQC without delay using the method or form required by CQC.
This includes, where the statutory criteria are met:
- abuse or allegations of abuse concerning a person using the service;
- specified serious injuries;
- incidents reported to or investigated by the police; and
- other incidents specified under the Registration Regulations.
The wording “CQC may be informed” must not be used where a statutory notification is required.
Personal Data Breaches
Any actual or suspected unauthorised loss, disclosure, alteration, destruction or access involving personal data must be immediately reported internally to the person responsible for data protection within {{org_field_name}}.
The organisation must promptly:
- contain the breach where possible;
- establish what information has been affected;
- assess the potential consequences for affected individuals;
- assess the likelihood and severity of risks to individuals’ rights and freedoms;
- document the breach and the assessment made;
- determine whether notification to the Information Commissioner’s Office is legally required; and
- determine whether affected individuals must also be informed.
Where a personal data breach is likely to result in a risk to the rights and freedoms of individuals, {{org_field_name}} must notify the Information Commissioner’s Office without undue delay and, where feasible, no later than 72 hours after becoming aware of the breach.
Where a personal data breach is likely to result in a high risk to the rights and freedoms of individuals, affected individuals must also be informed without undue delay unless an applicable legal exception applies.
All personal data breaches must be documented, including breaches that do not meet the threshold for notification to the Information Commissioner’s Office.
Other External Reporting
Where appropriate, the Registered Manager must also consider whether the incident requires:
- referral to the local authority safeguarding team;
- reporting to the police;
- notification to another professional or regulatory body;
- action under the Duty of Candour Policy; or
- another statutory or contractual notification.
The fact that an incident has been reported to one organisation does not automatically remove the requirement to report it separately to another organisation where a separate statutory duty applies.
Investigation and Disciplinary Action
All reported breaches must be considered promptly and proportionately.
Breaches of this policy may be managed under the organisation’s disciplinary procedures. The outcome will depend upon the circumstances, seriousness of the breach and applicable employment law and may include disciplinary action up to and including dismissal.
No disciplinary action must be taken against a worker because they have made a protected disclosure in accordance with applicable whistleblowing legislation.
Records of the concern, action taken, investigation, decisions, notifications and outcomes must be maintained securely in accordance with applicable record-keeping and data protection requirements.
5. Related Policies
This policy should be read in conjunction with:
- CH08 – Dignity and Respect Policy
- CH13 – Safeguarding Adults from Abuse and Improper Treatment Policy
- CH34 – Confidentiality and Data Protection (GDPR) Policy
- CH35 – Duty of Candour Policy
- CH28 – Staff Conduct and Code of Ethics Policy
6. Policy Review
This policy will be reviewed annually, or sooner if legislative changes, new CQC regulations, or serious incidents require updates. Any amendments will be communicated to all staff.
Responsible Person: {{org_field_registered_manager_first_name}} {{org_field_registered_manager_last_name}}
Reviewed on: {{last_update_date}}
Next Review Date: {{next_review_date}}
Copyright © {{current_year}} – {{org_field_name}}. All rights reserved.