{{org_field_logo}}

{{org_field_name}}

Registration Number: {{org_field_registration_no}}


Mobile Devices (Phones and Tablets) Policy

1. Purpose

The purpose of this policy is to establish clear requirements for the safe, lawful and appropriate use of mobile devices, including mobile telephones, smartphones and tablets, within {{org_field_name}}. The policy is intended to protect the safety, privacy, dignity, confidentiality and rights of individuals receiving care and support while enabling appropriate use of technology for communication, care delivery and service administration.

This policy aims to:

2. Scope

This policy applies to:

3. Related Policies

This policy aligns with:

4. Use of Mobile Devices by Staff

Mobile devices can be beneficial for work-related tasks, but inappropriate use can compromise privacy, professionalism, and resident care.

4.1. Personal Mobile Phones

4.2. Company-Issued Mobile Devices

Company-issued mobile telephones and tablets may be provided where their use is necessary for legitimate work-related purposes, including:

Where a company-issued mobile device provides access to personal, confidential, health or care information:

Company-issued devices remain the property of {{org_field_name}} and must be used in accordance with the organisation’s data protection, confidentiality, record-keeping, information security and safeguarding requirements.

4.3. Disciplinary Actions for Misuse

Misuse of mobile devices includes:

Breaches may lead to disciplinary action, including warnings or dismissal.

5. Use of Mobile Devices by Residents

Residents have the right to access and use mobile devices, provided this does not:

5.1. Supporting Residents’ Digital Inclusion

Staff will:

5.2. Restrictions on Use

Residents must not use mobile devices to:

Where misuse is identified, staff will work with residents and families to manage concerns.

6. Use of Mobile Devices by Visitors and External Professionals

6.1. Visitor Mobile Device Policy

Visitors may use mobile phones in designated areas, provided they:

Any breaches may result in restricted access to the care home.

6.2. External Professionals, Contractors and Inspectors

Healthcare professionals and other authorised external professionals may use mobile devices where this is necessary for the lawful performance of their professional duties, including accessing or recording clinical or professional information.

External professionals and contractors must:

Nothing in this policy restricts or makes conditional the lawful exercise of statutory powers by Care Inspectorate Wales inspectors or another person exercising statutory regulatory, investigatory or enforcement functions.

Where required in connection with an inspection, CIW inspectors must be given access to information, records and documentation in accordance with the Regulation and Inspection of Social Care (Wales) Act 2016 and other applicable legal requirements.

7. Data Protection and Security Measures

All personal and confidential information accessed, recorded, transmitted or otherwise processed through a mobile device must be handled in accordance with the UK General Data Protection Regulation, the Data Protection Act 2018, the organisation’s data protection and confidentiality policies and other applicable legal requirements.

Mobile devices must be managed in a manner that protects personal information against unauthorised or unlawful processing and against accidental loss, destruction, damage, disclosure or access.

7.1. Secure Handling of Personal and Confidential Information

The following requirements apply:

7.2. Lost or Stolen Devices and Personal Data Breaches

A member of staff must immediately report to the Registered Manager, or other person designated under the organisation’s data breach procedure:

Following such a report, {{org_field_name}} must take immediate and proportionate action to contain the incident and protect individuals. This may include remotely locking or wiping an organisation-issued device, changing or disabling access credentials, preserving relevant evidence and preventing further unauthorised access.

The incident must be documented and assessed promptly in accordance with the organisation’s personal data breach procedure to establish:

Where a personal data breach is likely to result in a risk to the rights and freedoms of individuals, {{org_field_name}}, as data controller where applicable, must notify the Information Commissioner’s Office without undue delay and, where feasible, no later than 72 hours after becoming aware of the breach.

Where the applicable legal threshold requiring communication of a personal data breach to affected individuals is met, {{org_field_name}} must ensure that the affected individual or individuals are informed without undue delay in accordance with data protection law.

All personal data breaches must be recorded in accordance with the organisation’s data breach procedure, including breaches which are assessed as not requiring notification to the Information Commissioner’s Office.

Where the circumstances also indicate possible abuse, neglect, exploitation, improper treatment or another safeguarding concern, the safeguarding procedure must be followed immediately in addition to the data breach procedure.

8. Mobile Devices in Emergencies

Mobile devices play a vital role in emergency communication.

9. Training and Awareness

All staff whose role involves the use of mobile devices, electronic records or access to personal or confidential information must receive training and information appropriate to their role.

Relevant training and induction must include:

Staff must be made aware of this policy during induction and whenever material changes are made to it.

The service provider must maintain appropriate records of training completed by staff and must ensure that staff understanding of relevant policies and procedures is monitored through supervision, appraisal or other appropriate management arrangements.

Additional or refresher training must be provided where required because of changes in legislation, guidance, systems, identified risks, incidents, audit findings or deficiencies in staff knowledge or practice.

Residents must be offered appropriate support to use digital communication devices safely where this is relevant to their needs, wishes and personal outcomes.

10. Compliance and Monitoring

{{org_field_name}} must have arrangements in place to monitor compliance with this policy and to identify and address risks associated with the use of mobile devices.

Monitoring arrangements must include, where applicable:

The Registered Manager must ensure that identified breaches or deficiencies are addressed promptly and escalated to the service provider, Responsible Individual, data protection lead, safeguarding authorities, Information Commissioner’s Office or other relevant authority where required.

The Responsible Individual and service provider must maintain appropriate oversight of matters which may affect the quality, safety or regulatory compliance of the service.

CIW may examine mobile-device practices, electronic records, confidentiality, information security and associated governance arrangements when exercising its regulatory and inspection functions. Staff must co-operate with CIW and provide information and access to records as required by law.

A breach of this policy by a member of staff may result in action under the organisation’s disciplinary procedure. Where the circumstances indicate a safeguarding concern, personal data breach, criminal offence or matter affecting a person’s fitness to practise, the organisation must also make any referral or notification required by law.

11. Policy Review

This policy will be reviewed annually or sooner if:


Responsible Person: {{org_field_registered_manager_first_name}} {{org_field_registered_manager_last_name}}
Reviewed on:
{{last_update_date}}
Next Review Date:
{{next_review_date}}
Copyright © {{current_year}} – {{org_field_name}}. All rights reserved.

Leave a Reply

Your email address will not be published. Required fields are marked *