{{org_field_logo}}
{{org_field_name}}
Registration Number: {{org_field_registration_no}}
Online Safety Policy
1. Purpose
The purpose of this policy is to establish clear arrangements for the safe, lawful and responsible use of the internet, digital technology, social media and electronic communications within {{org_field_name}}. The policy seeks to protect residents, staff and visitors from online harm while respecting residents’ rights to privacy, dignity, autonomy, independence, communication and access to information.
This policy supports compliance with the Regulation and Inspection of Social Care (Wales) Act 2016, the Regulated Services (Service Providers and Responsible Individuals) (Wales) Regulations 2017, as amended, the Social Services and Well-being (Wales) Act 2014, the Mental Capacity Act 2005, the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and applicable safeguarding requirements and Wales Safeguarding Procedures.
This policy aims to:
- Protect residents, staff and visitors from online risks, including fraud, scams, financial abuse, exploitation, cyberbullying, harassment, harmful or inappropriate contact and malicious online content.
- Ensure that residents’ use of digital technology is supported in a way that respects their rights, choices, privacy, dignity, autonomy and independence.
- Ensure that any restriction, supervision or intervention relating to a resident’s use of digital technology is lawful, necessary, proportionate and individually assessed.
- Protect personal and special category data and ensure that confidential information is processed and communicated securely.
- Establish clear arrangements for secure internet access, social media use and digital communication.
- Prevent, identify and respond appropriately to personal data breaches, cyber security incidents, online safeguarding concerns and misuse of digital systems.
- Ensure that safeguarding concerns arising through online activity are managed in accordance with the organisation’s safeguarding procedures and the Wales Safeguarding Procedures.
- Provide staff with appropriate information, instruction and training relating to online safety, cyber security, safeguarding and data protection.
2. Scope
This policy applies to:
- All employees, including permanent, agency, and voluntary staff.
- Residents, ensuring their safe and responsible use of the internet.
- Visitors and external professionals, setting guidelines for online access within the care home.
- Company-issued digital devices, including tablets, phones, and computers.
3. Related Policies
This policy aligns with:
- Confidentiality and Data Protection (GDPR) Policy (CHW34).
- Safeguarding Adults from Abuse and Improper Treatment Policy (CHW13).
- Communication and Engagement with Service Users and Families Policy (CHW42).
- Mobile Devices (Phones and Tablets) Policy.
- Whistleblowing (Speaking Up) Policy (CHW29).
4. Risks and Challenges of Online Use in Care Settings
The use of the internet in a care home setting presents various risks, which this policy is designed to address:
4.1. Data Protection and Confidentiality
- Personal and sensitive data about residents must not be shared online.
- Staff must not discuss resident care or workplace matters on social media.
- Resident digital records and care plans must be securely stored with access control.
4.2. Cybersecurity Threats
- Risks include phishing attacks, malware, and hacking attempts.
- All staff using company-issued devices must follow cybersecurity training.
- Firewalls and secure password policies are in place to protect company networks.
4.3. Online Exploitation and Abuse Risks
Residents may be at risk of online harm including financial scams, fraud, grooming, coercion, harassment, cyberbullying, identity theft, exploitation, abuse or inappropriate contact.
Staff must remain alert to signs that a resident may be experiencing online abuse, exploitation or financial harm and must respond promptly to concerns in accordance with the Safeguarding Adults from Abuse and Improper Treatment Policy and the Wales Safeguarding Procedures.
Staff must not routinely monitor, inspect or access a resident’s private online activity, accounts, messages or communications solely because the resident is considered vulnerable.
Where support, supervision or other intervention is considered necessary:
- the resident’s wishes, preferences, privacy, dignity and independence must be respected;
- the specific risk must be assessed;
- the least restrictive and proportionate approach must be used;
- the resident’s consent must be sought where the resident has capacity to make the relevant decision;
- where there is reason to doubt the resident’s capacity to make the particular decision, capacity must be assessed in accordance with the Mental Capacity Act 2005;
- where the resident lacks capacity for the particular decision, any action taken on their behalf must comply with the Mental Capacity Act 2005, including the best-interests and least-restrictive principles; and
- any safeguarding concern must be reported and managed in accordance with the organisation’s safeguarding procedures.
Where there is an allegation or evidence of abuse, neglect, exploitation or improper treatment, immediate action must be taken where necessary to protect the resident or other individuals. Appropriate referrals must be made to the relevant safeguarding authority, police or other agency as required, and an accurate record must be maintained of the concern, evidence, actions taken and referrals made.
4.4. Misuse of Social Media and Messaging Apps
- Staff must not share resident photos or information on social media.
- Inappropriate conversations between staff and residents online are strictly prohibited.
- Residents and families are advised on safe social media use.
5. Managing Online Safety in the Care Home
5.1. Internet and Wi-Fi Access
{{org_field_name}} will provide appropriate arrangements for residents to access the internet and digital communication in accordance with the facilities described in the service’s Statement of Purpose and written guide.
Secure network arrangements will be maintained to protect the organisation’s systems, information and personal data. Staff, resident and visitor access may be provided through separate networks or equivalent technical controls where this is necessary to maintain information and cyber security.
General technical security controls may be applied to organisational networks to prevent malware, malicious websites, cyber attacks and other threats to the security of the network.
A resident’s personal access to the internet must not be restricted solely because of their age, disability, diagnosis, cognitive impairment or perceived vulnerability.
Where consideration is being given to restricting a resident’s internet access because of an identified risk:
- the specific risk and the resident’s individual circumstances must be assessed;
- the resident must be involved in the decision as far as practicable;
- their wishes, feelings, privacy, autonomy and personal outcomes must be considered;
- any restriction must be necessary and proportionate to the identified risk;
- the least restrictive available option must be used;
- where the resident has capacity to make the relevant decision, their decision must be respected, subject to any lawful limitations necessary to protect other people or the security of the service’s systems;
- where there is reason to doubt the resident’s capacity to make the relevant decision, capacity must be assessed in accordance with the Mental Capacity Act 2005;
- where the resident lacks capacity, any decision made on their behalf must be made in accordance with the Mental Capacity Act 2005, including its best-interests and least-restrictive principles; and
- any restriction forming part of care arrangements must be recorded, regularly reviewed and reflected within the resident’s relevant assessment, risk assessment and personal plan where appropriate.
Where arrangements may amount to a deprivation of liberty, {{org_field_name}} will ensure that the requirements of the Mental Capacity Act 2005 and the applicable deprivation of liberty framework are followed and that lawful authority is obtained where required.
5.2. Use of Digital Devices (Tablets, Phones and Computers)
Residents will be supported to use personal and service-provided digital devices safely and in a way that promotes independence, communication, social inclusion and personal choice.
Residents who request assistance with using digital devices, online services or security settings will be provided with appropriate support according to their individual needs and preferences.
Staff must not automatically supervise a resident’s internet or device use because the resident is considered vulnerable or is considered to be at risk of scams, abuse or exploitation.
Where there is an identified online safety risk, staff must undertake or contribute to an individual assessment of the risk and agree appropriate support measures with the resident wherever possible.
Support may include:
- explaining common scams, fraud and online safety risks;
- helping the resident to use privacy and security settings;
- helping the resident to block or report suspicious contacts;
- assisting with secure passwords or account recovery where the resident requests this;
- helping the resident to obtain specialist advice or support;
- making a safeguarding referral where the circumstances meet the safeguarding threshold; and
- implementing proportionate supervision or restrictions where these are lawfully justified following assessment.
Where there is reason to doubt a resident’s capacity to make a specific decision about their online activity, device use or associated risks, staff must follow the Mental Capacity Act 2005. Capacity must be considered in relation to the particular decision at the particular time and must not be assumed to be absent because of the person’s age, disability, dementia, learning disability or other diagnosis.
Any support or intervention must use the least restrictive option available and must respect the resident’s privacy, dignity, autonomy and independence.
Company-issued devices used by staff must only be used in accordance with the organisation’s authorised-use, information-security and data-protection requirements.
5.3. Social Media Guidelines
For Staff:
- No sharing of work-related or resident information on personal social media.
- No online contact with residents or their families outside of professional platforms.
- Report any inappropriate or concerning online content that could affect resident safety.
For Residents:
- Residents will be supported to set up privacy settings on social media.
- Staff will provide guidance on recognising fake profiles and scams.
- Any cases of online abuse or cyberbullying will be reported to management immediately.
5.4. Email and Digital Communication
- All professional communication must be through work emails or secure platforms.
- Staff must not share confidential information via personal emails or messaging apps.
- Encrypted emails must be used when sharing sensitive information externally.
6. Staff Responsibilities in Online Safety
6.1. General Responsibilities
- Staff must follow online safety training and report concerns immediately.
- No unauthorised downloading of software on company devices.
- Regular updates on cybersecurity threats and best practices must be provided.
6.2. Reporting and Responding to Online Safety Incidents
All staff must immediately report online safety incidents, suspected incidents and concerns in accordance with this policy and the organisation’s relevant safeguarding, data protection, incident reporting and information-security procedures.
Staff must report, as applicable:
- suspected or confirmed personal data breaches;
- loss, theft or unauthorised access to devices containing personal or confidential information;
- phishing, malware, ransomware or other suspected cyber attacks;
- inappropriate or unauthorised disclosure of information concerning a resident;
- suspected online fraud, scams or financial exploitation involving a resident;
- online abuse, harassment, grooming, coercion, exploitation or cyberbullying;
- inappropriate online contact involving a resident and a member of staff, volunteer or other person;
- concerns that a resident or another individual may be at immediate risk of harm; and
- any other online incident that may affect the safety, rights or well-being of a resident or the safe operation of the service.
Reports must be made immediately to the Registered Manager or the person in charge. Suspected personal data breaches must also be escalated immediately in accordance with the organisation’s data-protection arrangements to the Data Protection Officer or other designated person responsible for data protection.
Safeguarding concerns
Where an online safety incident gives rise to an allegation, suspicion or evidence of abuse, neglect, exploitation or improper treatment, the organisation’s safeguarding procedures and the Wales Safeguarding Procedures must be followed.
The service must:
- take immediate and proportionate action where necessary to secure the safety of the resident and any other individual who may be at risk;
- preserve relevant information or evidence where appropriate;
- make appropriate referrals to the local authority safeguarding service, police or other relevant agencies as required;
- cooperate with any safeguarding enquiry or investigation; and
- maintain an accurate record of the concern or allegation, available evidence, immediate protective measures, decisions made, action taken and referrals made.
Where the allegation or concern relates to a member of staff, volunteer or other person working with adults at risk, the organisation must also follow the applicable Wales Safeguarding Procedures for allegations or concerns about practitioners and must consider any statutory referral requirements to the Disclosure and Barring Service, Social Care Wales or another professional regulator.
Personal data breaches
Every suspected personal data breach must be assessed promptly.
{{org_field_name}} will:
- take immediate steps, where practicable, to contain the breach and protect affected information;
- establish the nature and extent of the breach;
- assess the likely risk to the rights and freedoms of affected individuals;
- maintain a record of every personal data breach, including breaches that do not require notification to the Information Commissioner’s Office;
- where the breach is likely to result in a risk to individuals’ rights and freedoms, notify the Information Commissioner’s Office without undue delay and, where feasible, no later than 72 hours after becoming aware of the breach;
- document the reasons where a breach is assessed as not requiring notification to the Information Commissioner’s Office; and
- where a breach is likely to result in a high risk to the rights and freedoms of an individual, inform the affected individual without undue delay unless a lawful exception applies.
Staff must report suspected breaches immediately and must not delay internal reporting while attempting to establish all of the facts.
CIW notification
The Registered Manager, Responsible Individual and service provider must consider whether an online safety or related safeguarding incident is a notifiable event under the regulatory requirements applying to the service.
Where notification to Care Inspectorate Wales is required, it must be submitted through CIW Online in accordance with the applicable statutory notification requirements and timescale.
Making a notification to CIW does not replace any separate requirement to make a safeguarding referral, police referral, Information Commissioner’s Office notification, Disclosure and Barring Service referral or referral to a professional regulator.
7. Resident Online Safety and Support
7.1. Helping Residents Stay Safe Online
- Staff provide guidance on online safety and fraud awareness.
- Residents are encouraged to use strong passwords and privacy settings.
- Staff will help residents identify online scams and report suspicious activity.
7.2. Supporting Residents with Cognitive Impairment or Communication Needs
Residents with dementia, a learning disability, cognitive impairment or communication needs have the same rights to privacy, dignity, autonomy, communication, access to information and participation in decisions about their lives as other residents.
A diagnosis of dementia, learning disability, cognitive impairment or any other condition must not in itself be treated as evidence that the resident lacks capacity to make decisions about internet access, digital devices, social media, financial transactions or online communication.
Staff must presume that a resident has capacity to make a particular decision unless it is established, in accordance with the Mental Capacity Act 2005, that the resident lacks capacity to make that specific decision at the relevant time.
Residents will be provided with appropriate support to enable them to make their own decisions wherever practicable. This may include:
- information provided in a simpler or accessible format;
- additional time to consider information;
- communication aids or assistive technology;
- practical demonstrations;
- support to recognise scams or suspicious communications;
- support to use privacy and security settings; and
- support from a person chosen by the resident.
Where there is reason to doubt the resident’s capacity to make a specific decision relating to internet or digital technology use, an assessment of that specific decision must be undertaken in accordance with the Mental Capacity Act 2005.
Where a resident lacks capacity to make the specific decision, any decision taken on their behalf must:
- be made in their best interests;
- take account of the resident’s past and present wishes and feelings, beliefs and values;
- involve relevant persons in accordance with the Mental Capacity Act 2005;
- consider all practicable alternatives;
- use the least restrictive option available; and
- be appropriately recorded and reviewed.
A family member, friend or other representative may support the resident where the resident wishes them to be involved. Where the resident lacks capacity, family members and others may be consulted as part of the best-interests process. However, no family member or other person may make decisions on behalf of the resident unless they have the relevant lawful authority to do so, such as an applicable Lasting Power of Attorney, deputyship or other lawful authority.
Content filtering, supervision, restricted access to websites, removal or control of devices, passwords or other restrictions on a resident’s online activity must not be imposed automatically because of a diagnosis or perceived vulnerability.
Where such measures are considered necessary, they must be based upon an individual risk assessment, be necessary and proportionate to the identified risk, comply with the Mental Capacity Act 2005 where applicable, use the least restrictive alternative available and be recorded and regularly reviewed.
Where the overall arrangements for a resident who lacks capacity may amount to a deprivation of liberty, the service must ensure that lawful authority is obtained and that the applicable Mental Capacity Act 2005 and deprivation of liberty requirements are followed.
8. Cybersecurity Measures
To protect residents, staff, and data, {{org_field_name}} implements strict cybersecurity protocols:
- Strong password policies for all staff and company devices.
- Regular security updates and software patches for all systems.
- Antivirus and firewall protections on all company devices.
- Regular cybersecurity training for staff.
9. Monitoring and Compliance
9.1. Internal Audits and Inspections
- Quarterly audits are conducted to assess online safety compliance.
- CIW inspectors may review online safety protocols and data protection policies.
- Staff feedback is used to improve online safety training.
9.2. Disciplinary Actions for Policy Breaches
Breaches of this policy may result in:
- Formal warnings or retraining.
- Loss of digital access privileges.
- Dismissal for serious breaches (e.g., data leaks, safeguarding failures).
10. Policy Review
This policy will be reviewed annually or sooner if:
- CIW regulations change.
- New cyber threats emerge requiring updated safety measures.
- Incidents highlight areas for improvement.
Responsible Person: {{org_field_registered_manager_first_name}} {{org_field_registered_manager_last_name}}
Reviewed on: {{last_update_date}}
Next Review Date: {{next_review_date}}
Copyright © {{current_year}} – {{org_field_name}}. All rights reserved.