{{org_field_logo}}

{{org_field_name}}

Registration Number: {{org_field_registration_no}}


Online Safety Policy

1. Purpose

The purpose of this policy is to establish clear arrangements for the safe, lawful and responsible use of the internet, digital technology, social media and electronic communications within {{org_field_name}}. The policy seeks to protect residents, staff and visitors from online harm while respecting residents’ rights to privacy, dignity, autonomy, independence, communication and access to information.

This policy supports compliance with the Regulation and Inspection of Social Care (Wales) Act 2016, the Regulated Services (Service Providers and Responsible Individuals) (Wales) Regulations 2017, as amended, the Social Services and Well-being (Wales) Act 2014, the Mental Capacity Act 2005, the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and applicable safeguarding requirements and Wales Safeguarding Procedures.

This policy aims to:

2. Scope

This policy applies to:

3. Related Policies

This policy aligns with:

4. Risks and Challenges of Online Use in Care Settings

The use of the internet in a care home setting presents various risks, which this policy is designed to address:

4.1. Data Protection and Confidentiality

4.2. Cybersecurity Threats

4.3. Online Exploitation and Abuse Risks

Residents may be at risk of online harm including financial scams, fraud, grooming, coercion, harassment, cyberbullying, identity theft, exploitation, abuse or inappropriate contact.

Staff must remain alert to signs that a resident may be experiencing online abuse, exploitation or financial harm and must respond promptly to concerns in accordance with the Safeguarding Adults from Abuse and Improper Treatment Policy and the Wales Safeguarding Procedures.

Staff must not routinely monitor, inspect or access a resident’s private online activity, accounts, messages or communications solely because the resident is considered vulnerable.

Where support, supervision or other intervention is considered necessary:

Where there is an allegation or evidence of abuse, neglect, exploitation or improper treatment, immediate action must be taken where necessary to protect the resident or other individuals. Appropriate referrals must be made to the relevant safeguarding authority, police or other agency as required, and an accurate record must be maintained of the concern, evidence, actions taken and referrals made.

4.4. Misuse of Social Media and Messaging Apps

5. Managing Online Safety in the Care Home

5.1. Internet and Wi-Fi Access

{{org_field_name}} will provide appropriate arrangements for residents to access the internet and digital communication in accordance with the facilities described in the service’s Statement of Purpose and written guide.

Secure network arrangements will be maintained to protect the organisation’s systems, information and personal data. Staff, resident and visitor access may be provided through separate networks or equivalent technical controls where this is necessary to maintain information and cyber security.

General technical security controls may be applied to organisational networks to prevent malware, malicious websites, cyber attacks and other threats to the security of the network.

A resident’s personal access to the internet must not be restricted solely because of their age, disability, diagnosis, cognitive impairment or perceived vulnerability.

Where consideration is being given to restricting a resident’s internet access because of an identified risk:

Where arrangements may amount to a deprivation of liberty, {{org_field_name}} will ensure that the requirements of the Mental Capacity Act 2005 and the applicable deprivation of liberty framework are followed and that lawful authority is obtained where required.

5.2. Use of Digital Devices (Tablets, Phones and Computers)

Residents will be supported to use personal and service-provided digital devices safely and in a way that promotes independence, communication, social inclusion and personal choice.

Residents who request assistance with using digital devices, online services or security settings will be provided with appropriate support according to their individual needs and preferences.

Staff must not automatically supervise a resident’s internet or device use because the resident is considered vulnerable or is considered to be at risk of scams, abuse or exploitation.

Where there is an identified online safety risk, staff must undertake or contribute to an individual assessment of the risk and agree appropriate support measures with the resident wherever possible.

Support may include:

Where there is reason to doubt a resident’s capacity to make a specific decision about their online activity, device use or associated risks, staff must follow the Mental Capacity Act 2005. Capacity must be considered in relation to the particular decision at the particular time and must not be assumed to be absent because of the person’s age, disability, dementia, learning disability or other diagnosis.

Any support or intervention must use the least restrictive option available and must respect the resident’s privacy, dignity, autonomy and independence.

Company-issued devices used by staff must only be used in accordance with the organisation’s authorised-use, information-security and data-protection requirements.

5.3. Social Media Guidelines

For Staff:

For Residents:

5.4. Email and Digital Communication

6. Staff Responsibilities in Online Safety

6.1. General Responsibilities

6.2. Reporting and Responding to Online Safety Incidents

All staff must immediately report online safety incidents, suspected incidents and concerns in accordance with this policy and the organisation’s relevant safeguarding, data protection, incident reporting and information-security procedures.

Staff must report, as applicable:

Reports must be made immediately to the Registered Manager or the person in charge. Suspected personal data breaches must also be escalated immediately in accordance with the organisation’s data-protection arrangements to the Data Protection Officer or other designated person responsible for data protection.

Safeguarding concerns

Where an online safety incident gives rise to an allegation, suspicion or evidence of abuse, neglect, exploitation or improper treatment, the organisation’s safeguarding procedures and the Wales Safeguarding Procedures must be followed.

The service must:

Where the allegation or concern relates to a member of staff, volunteer or other person working with adults at risk, the organisation must also follow the applicable Wales Safeguarding Procedures for allegations or concerns about practitioners and must consider any statutory referral requirements to the Disclosure and Barring Service, Social Care Wales or another professional regulator.

Personal data breaches

Every suspected personal data breach must be assessed promptly.

{{org_field_name}} will:

Staff must report suspected breaches immediately and must not delay internal reporting while attempting to establish all of the facts.

CIW notification

The Registered Manager, Responsible Individual and service provider must consider whether an online safety or related safeguarding incident is a notifiable event under the regulatory requirements applying to the service.

Where notification to Care Inspectorate Wales is required, it must be submitted through CIW Online in accordance with the applicable statutory notification requirements and timescale.

Making a notification to CIW does not replace any separate requirement to make a safeguarding referral, police referral, Information Commissioner’s Office notification, Disclosure and Barring Service referral or referral to a professional regulator.

7. Resident Online Safety and Support

7.1. Helping Residents Stay Safe Online

7.2. Supporting Residents with Cognitive Impairment or Communication Needs

Residents with dementia, a learning disability, cognitive impairment or communication needs have the same rights to privacy, dignity, autonomy, communication, access to information and participation in decisions about their lives as other residents.

A diagnosis of dementia, learning disability, cognitive impairment or any other condition must not in itself be treated as evidence that the resident lacks capacity to make decisions about internet access, digital devices, social media, financial transactions or online communication.

Staff must presume that a resident has capacity to make a particular decision unless it is established, in accordance with the Mental Capacity Act 2005, that the resident lacks capacity to make that specific decision at the relevant time.

Residents will be provided with appropriate support to enable them to make their own decisions wherever practicable. This may include:

Where there is reason to doubt the resident’s capacity to make a specific decision relating to internet or digital technology use, an assessment of that specific decision must be undertaken in accordance with the Mental Capacity Act 2005.

Where a resident lacks capacity to make the specific decision, any decision taken on their behalf must:

A family member, friend or other representative may support the resident where the resident wishes them to be involved. Where the resident lacks capacity, family members and others may be consulted as part of the best-interests process. However, no family member or other person may make decisions on behalf of the resident unless they have the relevant lawful authority to do so, such as an applicable Lasting Power of Attorney, deputyship or other lawful authority.

Content filtering, supervision, restricted access to websites, removal or control of devices, passwords or other restrictions on a resident’s online activity must not be imposed automatically because of a diagnosis or perceived vulnerability.

Where such measures are considered necessary, they must be based upon an individual risk assessment, be necessary and proportionate to the identified risk, comply with the Mental Capacity Act 2005 where applicable, use the least restrictive alternative available and be recorded and regularly reviewed.

Where the overall arrangements for a resident who lacks capacity may amount to a deprivation of liberty, the service must ensure that lawful authority is obtained and that the applicable Mental Capacity Act 2005 and deprivation of liberty requirements are followed.

8. Cybersecurity Measures

To protect residents, staff, and data, {{org_field_name}} implements strict cybersecurity protocols:

9. Monitoring and Compliance

9.1. Internal Audits and Inspections

9.2. Disciplinary Actions for Policy Breaches

Breaches of this policy may result in:

10. Policy Review

This policy will be reviewed annually or sooner if:


Responsible Person: {{org_field_registered_manager_first_name}} {{org_field_registered_manager_last_name}}
Reviewed on:
{{last_update_date}}
Next Review Date:
{{next_review_date}}
Copyright © {{current_year}} – {{org_field_name}}. All rights reserved.

Leave a Reply

Your email address will not be published. Required fields are marked *