{{org_field_logo}}
{{org_field_name}}
Registration Number: {{org_field_registration_no}}
Mobile Devices (Phones and Tablets) Policy
1. Purpose
The purpose of this policy is to establish clear requirements for the safe, lawful and appropriate use of mobile devices, including mobile telephones, smartphones and tablets, within {{org_field_name}}. The policy is intended to protect the safety, privacy, dignity, confidentiality and rights of individuals receiving care and support while enabling appropriate use of technology for communication, care delivery and service administration.
This policy aims to:
- protect individuals’ personal and confidential information and reduce the risk of unauthorised access, disclosure, loss or other personal data breaches;
- protect the privacy, dignity, confidentiality, safety and well-being of individuals receiving care and support;
- ensure that the use of mobile devices does not distract staff from the delivery of safe, person-centred care and support;
- establish clear requirements for the use of personal and organisation-issued mobile devices by staff;
- ensure that mobile devices used for electronic care planning, record keeping or other work-related purposes are accessed and used only by authorised persons;
- support individuals to use mobile devices and digital communication in accordance with their rights, wishes, needs, personal outcomes and any relevant risk assessment or personal plan;
- prevent inappropriate photography, filming, recording, sharing or other processing of personal or confidential information;
- ensure that concerns involving mobile devices which indicate possible abuse, neglect, exploitation or improper treatment are managed in accordance with the organisation’s safeguarding procedures; and
- support compliance with the Regulation and Inspection of Social Care (Wales) Act 2016, the Regulated Services (Service Providers and Responsible Individuals) (Wales) Regulations 2017, as amended, applicable statutory guidance, the UK General Data Protection Regulation, the Data Protection Act 2018 and other applicable legal requirements.
2. Scope
This policy applies to:
- All staff members, including permanent, agency, and voluntary staff.
- Residents, ensuring safe use of personal mobile devices.
- Visitors and external professionals, setting clear expectations regarding device usage.
- Company-issued mobile devices, ensuring appropriate usage for care purposes.
3. Related Policies
This policy aligns with:
- Confidentiality and Data Protection (GDPR) Policy (CHW34).
- Safeguarding Adults from Abuse and Improper Treatment Policy (CHW13).
- Communication and Engagement with Service Users and Families Policy (CHW42).
- Whistleblowing (Speaking Up) Policy (CHW29).
- Health and Safety at Work Policy (CHW16).
4. Use of Mobile Devices by Staff
Mobile devices can be beneficial for work-related tasks, but inappropriate use can compromise privacy, professionalism, and resident care.
4.1. Personal Mobile Phones
- Staff must not use personal mobile phones while on duty, except in designated areas during breaks.
- Mobile phones must be kept on silent or vibrate mode during working hours.
- Personal mobile phones must never be used to:
- Take photos or videos within the care home.
- Access resident records or confidential information.
- Communicate with residents or their families outside official channels.
- Emergency calls may be made or received with the Registered Manager’s permission.
4.2. Company-Issued Mobile Devices
Company-issued mobile telephones and tablets may be provided where their use is necessary for legitimate work-related purposes, including:
- electronic care planning, care recording and documentation;
- authorised communication between staff members, managers and relevant professionals;
- emergency response and safeguarding-related communication;
- accessing authorised training, policies, procedures and other work-related information; and
- other purposes specifically authorised by {{org_field_name}}.
Where a company-issued mobile device provides access to personal, confidential, health or care information:
- access must be restricted to authorised persons;
- each member of staff must use their own authorised user account, access code or other individual authentication credentials where the system provides for individual access;
- staff must not share passwords, PINs, authentication codes or user accounts with another person;
- electronic care records must provide an identifiable audit trail, where supported by the system, so that entries and amendments can be attributed to the person who made them;
- staff must access only information which they are authorised to access and which is necessary for the performance of their duties;
- the device must be appropriately secured against unauthorised access and locked whenever it is left unattended;
- personal or confidential information must not be copied, downloaded, photographed, screen-captured, transferred or stored outside authorised systems unless expressly authorised and lawfully required;
- security controls, including encryption where implemented by the organisation as an appropriate security measure, must not be disabled or circumvented;
- authorised software, operating-system and security updates must not be deliberately prevented or disabled;
- devices must not be shared with residents, visitors or other unauthorised persons where this would provide access to confidential information or systems;
- any suspected unauthorised access, loss, theft, malware, compromise or other security incident must be reported immediately in accordance with Section 7.2 of this policy; and
- the device and all associated equipment must be returned to {{org_field_name}} when requested or when the person’s employment, engagement or authorised use ends.
Company-issued devices remain the property of {{org_field_name}} and must be used in accordance with the organisation’s data protection, confidentiality, record-keeping, information security and safeguarding requirements.
4.3. Disciplinary Actions for Misuse
Misuse of mobile devices includes:
- Using devices to record, store, or share confidential resident information.
- Accessing social media or personal entertainment during working hours.
- Ignoring resident care needs due to mobile phone distractions.
Breaches may lead to disciplinary action, including warnings or dismissal.
5. Use of Mobile Devices by Residents
Residents have the right to access and use mobile devices, provided this does not:
- Compromise their own or others’ privacy.
- Interfere with care routines and safety procedures.
- Facilitate exploitation or financial abuse (e.g., scam calls).
5.1. Supporting Residents’ Digital Inclusion
Staff will:
- Assist residents in using mobile devices safely.
- Educate them about online safety and fraud prevention.
- Help residents with hearing, visual, or mobility impairments to use adapted devices.
5.2. Restrictions on Use
Residents must not use mobile devices to:
- Record other residents or staff without consent.
- Access inappropriate content.
- Engage in harassing or abusive communication.
Where misuse is identified, staff will work with residents and families to manage concerns.
6. Use of Mobile Devices by Visitors and External Professionals
6.1. Visitor Mobile Device Policy
Visitors may use mobile phones in designated areas, provided they:
- Do not record or photograph residents or staff.
- Do not disrupt care routines.
- Follow GDPR regulations regarding privacy.
Any breaches may result in restricted access to the care home.
6.2. External Professionals, Contractors and Inspectors
Healthcare professionals and other authorised external professionals may use mobile devices where this is necessary for the lawful performance of their professional duties, including accessing or recording clinical or professional information.
External professionals and contractors must:
- protect the privacy, dignity and confidentiality of individuals receiving care and support;
- comply with applicable data protection and confidentiality requirements;
- access, photograph, record or process information about individuals only where they have lawful authority and a legitimate professional reason to do so;
- take reasonable precautions to prevent unauthorised persons from viewing or accessing confidential information displayed or stored on their devices; and
- comply with reasonable safety and security arrangements applying within the care home, provided those arrangements do not prevent the lawful performance of their professional or statutory functions.
Nothing in this policy restricts or makes conditional the lawful exercise of statutory powers by Care Inspectorate Wales inspectors or another person exercising statutory regulatory, investigatory or enforcement functions.
Where required in connection with an inspection, CIW inspectors must be given access to information, records and documentation in accordance with the Regulation and Inspection of Social Care (Wales) Act 2016 and other applicable legal requirements.
7. Data Protection and Security Measures
All personal and confidential information accessed, recorded, transmitted or otherwise processed through a mobile device must be handled in accordance with the UK General Data Protection Regulation, the Data Protection Act 2018, the organisation’s data protection and confidentiality policies and other applicable legal requirements.
Mobile devices must be managed in a manner that protects personal information against unauthorised or unlawful processing and against accidental loss, destruction, damage, disclosure or access.
7.1. Secure Handling of Personal and Confidential Information
The following requirements apply:
- Personal, health, care or other confidential information relating to an individual receiving care and support must not be stored on a staff member’s personal mobile telephone, tablet or other personal device.
- Personal devices must not be used to photograph, screen-capture, copy or download residents’ care records or other confidential information.
- Organisation-issued devices used to access personal or confidential information must be protected by appropriate technical and organisational security measures.
- Staff must use only their individually authorised accounts, passwords, PINs or access credentials and must not share these with another person.
- Devices must be locked whenever they are left unattended.
- Electronic information must be accessed, recorded and transmitted only through systems, applications and communication methods authorised by {{org_field_name}}.
- Personal or confidential information must not be sent through personal email accounts, personal messaging applications, personal cloud-storage accounts, social media or other unauthorised communication channels.
- Electronic care-record systems must, where applicable, provide an audit trail that identifies the person making entries or amendments.
- Staff must not attempt to disable or bypass device-management, access-control, encryption or other security measures implemented by {{org_field_name}}.
- Personal and confidential information must only be accessed by persons who require access for an authorised work-related purpose.
- Any suspected inappropriate access to, disclosure of, alteration of, destruction of or loss of personal information must be treated as a potential personal data breach and reported immediately.
7.2. Lost or Stolen Devices and Personal Data Breaches
A member of staff must immediately report to the Registered Manager, or other person designated under the organisation’s data breach procedure:
- the loss or theft of an organisation-issued device;
- loss or theft of a personal device where there is reason to believe that work-related information or access credentials may be stored on or accessible through the device;
- unauthorised access to a device, account, application or electronic care-record system;
- accidental or unauthorised disclosure of personal or confidential information;
- information being sent or disclosed to the wrong recipient;
- unauthorised photography, filming, recording, copying, downloading or sharing of personal information;
- suspected malware, hacking, account compromise or other cyber-security incident involving personal information; or
- any other incident which may constitute a personal data breach.
Following such a report, {{org_field_name}} must take immediate and proportionate action to contain the incident and protect individuals. This may include remotely locking or wiping an organisation-issued device, changing or disabling access credentials, preserving relevant evidence and preventing further unauthorised access.
The incident must be documented and assessed promptly in accordance with the organisation’s personal data breach procedure to establish:
- the nature and extent of the personal information affected;
- the individuals affected;
- how the breach occurred;
- the potential consequences for affected individuals;
- the likelihood and severity of any risk to their rights and freedoms; and
- the action required to contain, investigate and mitigate the breach.
Where a personal data breach is likely to result in a risk to the rights and freedoms of individuals, {{org_field_name}}, as data controller where applicable, must notify the Information Commissioner’s Office without undue delay and, where feasible, no later than 72 hours after becoming aware of the breach.
Where the applicable legal threshold requiring communication of a personal data breach to affected individuals is met, {{org_field_name}} must ensure that the affected individual or individuals are informed without undue delay in accordance with data protection law.
All personal data breaches must be recorded in accordance with the organisation’s data breach procedure, including breaches which are assessed as not requiring notification to the Information Commissioner’s Office.
Where the circumstances also indicate possible abuse, neglect, exploitation, improper treatment or another safeguarding concern, the safeguarding procedure must be followed immediately in addition to the data breach procedure.
8. Mobile Devices in Emergencies
Mobile devices play a vital role in emergency communication.
- Staff may use mobile devices to call emergency services (999) if landlines are unavailable.
- Company-issued devices may be used for:
- Incident reporting and communication during lockdowns or fire drills.
- Notifying managers of safeguarding concerns.
- In cases of resident medical emergencies, staff must prioritise care before using devices.
9. Training and Awareness
All staff whose role involves the use of mobile devices, electronic records or access to personal or confidential information must receive training and information appropriate to their role.
Relevant training and induction must include:
- the requirements of this policy;
- confidentiality and data protection requirements, including the UK General Data Protection Regulation and Data Protection Act 2018;
- secure use of organisation-issued devices and electronic care-record systems;
- individual responsibility for passwords, access credentials and preventing unauthorised access;
- appropriate record keeping and the requirement to use individual authorised accounts where applicable;
- recognising and immediately reporting lost or stolen devices, unauthorised access and suspected personal data breaches;
- the prohibition on unauthorised photography, filming, recording, copying or sharing of personal or confidential information;
- safeguarding risks associated with mobile devices, including exploitation, financial abuse, harassment, inappropriate contact and unauthorised recording; and
- the action staff must take where mobile-device use creates a safeguarding, confidentiality, privacy or information-security concern.
Staff must be made aware of this policy during induction and whenever material changes are made to it.
The service provider must maintain appropriate records of training completed by staff and must ensure that staff understanding of relevant policies and procedures is monitored through supervision, appraisal or other appropriate management arrangements.
Additional or refresher training must be provided where required because of changes in legislation, guidance, systems, identified risks, incidents, audit findings or deficiencies in staff knowledge or practice.
Residents must be offered appropriate support to use digital communication devices safely where this is relevant to their needs, wishes and personal outcomes.
10. Compliance and Monitoring
{{org_field_name}} must have arrangements in place to monitor compliance with this policy and to identify and address risks associated with the use of mobile devices.
Monitoring arrangements must include, where applicable:
- reviewing compliance with requirements governing access to electronic care records and confidential information;
- reviewing incidents involving lost or stolen devices, unauthorised access, inappropriate recording or disclosure of information and personal data breaches;
- ensuring that organisation-issued devices and authorised systems remain subject to appropriate security and access controls;
- reviewing whether staff have received the training and information required for their roles;
- taking appropriate action where audits, incidents, complaints, safeguarding concerns or other monitoring identify non-compliance or weaknesses in practice; and
- using relevant findings to improve the safety, quality and governance of the service.
The Registered Manager must ensure that identified breaches or deficiencies are addressed promptly and escalated to the service provider, Responsible Individual, data protection lead, safeguarding authorities, Information Commissioner’s Office or other relevant authority where required.
The Responsible Individual and service provider must maintain appropriate oversight of matters which may affect the quality, safety or regulatory compliance of the service.
CIW may examine mobile-device practices, electronic records, confidentiality, information security and associated governance arrangements when exercising its regulatory and inspection functions. Staff must co-operate with CIW and provide information and access to records as required by law.
A breach of this policy by a member of staff may result in action under the organisation’s disciplinary procedure. Where the circumstances indicate a safeguarding concern, personal data breach, criminal offence or matter affecting a person’s fitness to practise, the organisation must also make any referral or notification required by law.
11. Policy Review
This policy will be reviewed annually or sooner if:
- CIW regulations change.
- New risks are identified in mobile device usage.
- Employee or resident feedback suggests improvements.
Responsible Person: {{org_field_registered_manager_first_name}} {{org_field_registered_manager_last_name}}
Reviewed on: {{last_update_date}}
Next Review Date: {{next_review_date}}
Copyright © {{current_year}} – {{org_field_name}}. All rights reserved.