{{org_field_logo}}
{{org_field_name}}
Registration Number: {{org_field_registration_no}}
Sharing Information with Third Party Organisations Policy
1. Purpose
The purpose of this policy is to ensure that {{org_field_name}} shares personal information with third party organisations lawfully, fairly, transparently, securely and only where there is an identified and documented need to do so.
This policy supports compliance with the Regulation and Inspection of Social Care (Wales) Act 2016; the Regulated Services (Service Providers and Responsible Individuals) (Wales) Regulations 2017, as amended; the Social Services and Well-being (Wales) Act 2014; the UK General Data Protection Regulation (UK GDPR); the Data Protection Act 2018; the Data (Use and Access) Act 2025; the Mental Capacity Act 2005; applicable human rights and equality legislation; and relevant statutory guidance and requirements issued by the Welsh Government, Care Inspectorate Wales and the Information Commissioner’s Office.
{{org_field_name}} recognises each individual’s right to privacy, dignity and confidentiality. Information will nevertheless be shared where this is necessary and lawful to provide safe and effective care and support, protect an individual or another person from abuse, neglect or harm, comply with a legal or regulatory obligation, support legitimate health or social care purposes, or otherwise fulfil a lawful purpose.
Only information that is necessary, relevant, adequate and proportionate for the identified purpose will be shared. Decisions about information sharing will take account of the individual’s rights, wishes and circumstances and will be documented where appropriate.
2. Scope
This policy applies to all staff at {{org_field_name}}, including permanent, temporary, and agency workers, as well as any volunteers or contractors who may have access to confidential information. It covers the sharing of personal and sensitive information with any external organisations or individuals, including:
- Health and social care professionals (e.g. GPs, nurses, social workers)
- Local authorities
- CIW and other regulatory bodies
- Police or emergency services
- Contractors and service providers (e.g. IT or maintenance providers)
- Legal representatives or advocates
- Family members or representatives (where appropriate)
3. Related Policies
This policy should be read in conjunction with:
- CHW34 – Confidentiality and Data Protection (GDPR) – Service User Policy
- CHW13 – Safeguarding Adults from Abuse and Improper Treatment Policy
- CHW42 – Communication and Engagement with Service Users and Families Policy
- CHW04 – Good Governance
- CHW05 – Statement of Purpose Policy
- CHW26 – Recruitment, Selection and Retention Policy
4. Policy Statement and Implementation
4.1 Legal and Regulatory Framework
{{org_field_name}} will process and share personal information in accordance with applicable data-protection legislation, including the UK GDPR, the Data Protection Act 2018 and the Data (Use and Access) Act 2025.
As a provider of a regulated care home service in Wales, {{org_field_name}} will also comply with the Regulation and Inspection of Social Care (Wales) Act 2016 and the Regulated Services (Service Providers and Responsible Individuals) (Wales) Regulations 2017, as amended.
In particular, the service will ensure that:
- individuals’ privacy, dignity and rights to confidentiality are respected;
- personal information and care records are accurate, kept up to date where required and stored securely;
- staff understand their responsibilities in relation to confidentiality, information governance and data protection;
- information-sharing decisions are lawful, necessary, proportionate and appropriately recorded;
- safeguarding information is shared with relevant agencies where this is necessary and lawful to protect an individual or another person from abuse, neglect, improper treatment or other harm; and
- policies and procedures concerning confidentiality, records and information sharing are kept under review and updated when legislation, statutory guidance or regulatory requirements change.
Where personal information is to be shared, the service will consider both the requirements of data-protection legislation and any separate statutory, common-law, professional or regulatory obligations affecting the disclosure.
Lawful Basis for Sharing Information
Personal information must not be shared merely because sharing would be convenient or because another organisation has requested it. Before personal information is shared, {{org_field_name}} must identify and document an appropriate lawful basis under Article 6 of the UK GDPR.
Depending upon the circumstances, a lawful basis may include:
- consent, where the individual has freely given a valid indication that their personal information may be used for the specified purpose;
- performance of a contract, where processing is necessary for a contract with the individual or to take steps at their request before entering into a contract;
- compliance with a legal obligation;
- protection of the vital interests of the individual or another person;
- performance of a task carried out in the public interest or in the exercise of official authority, where this basis lawfully applies;
- legitimate interests, where the service has established that the processing is necessary for a legitimate purpose and those interests are not overridden by the individual’s interests, rights or freedoms; or
- a recognised legitimate interest where expressly permitted by current data-protection legislation and all statutory conditions for relying upon that basis are satisfied.
Consent will not be used as the lawful basis where the processing would continue regardless of whether consent was given or withdrawn.
4.2 Special Category Personal Data
Information concerning an individual’s health, racial or ethnic origin, religious or philosophical beliefs, genetic information, biometric information used for identification, sex life or sexual orientation is special category personal data.
Where special category personal data is shared, {{org_field_name}} must identify:
- an appropriate Article 6 UK GDPR lawful basis; and
- a separate condition under Article 9 UK GDPR.
Depending upon the circumstances, relevant Article 9 conditions may include:
- explicit consent;
- protection of vital interests where the individual is physically or legally incapable of giving consent;
- establishment, exercise or defence of legal claims;
- substantial public interest where supported by UK law; or
- provision or management of health or social care where the relevant statutory requirements and duties of confidentiality are satisfied.
Where reliance is placed upon a condition requiring an additional condition under Schedule 1 of the Data Protection Act 2018, that Schedule 1 condition must also be identified and any requirement for an Appropriate Policy Document must be met.
For safeguarding disclosures, this may include an applicable substantial public interest condition under the Data Protection Act 2018 relating to safeguarding children or individuals at risk, where the statutory criteria are satisfied.
Data Protection Principles
Before sharing information, staff must ensure that:
- the disclosure is lawful, fair and transparent;
- the purpose of sharing has been clearly identified;
- only the minimum personal information necessary for that purpose is disclosed;
- the information is sufficiently accurate and up to date for the purpose for which it is being shared;
- the information is disclosed securely;
- applicable retention requirements are observed; and
- the organisation can demonstrate why the disclosure was lawful and necessary.
Individuals will be provided with appropriate privacy information explaining how and why their personal information may be shared, with whom it may be shared or the categories of recipients, unless a lawful exemption applies.
Complex, unusual or high-risk disclosures must be referred to the Registered Manager and, where applicable, the Data Protection Officer or other person responsible for data protection before information is released.
4.3 Consent and Capacity
{{org_field_name}} will involve individuals in decisions about the use and sharing of their personal information wherever this is practicable and appropriate.
Where consent is relied upon as the lawful basis for processing, consent must meet the requirements of data-protection legislation. It must be freely given, specific, informed and unambiguous, and the service must be able to demonstrate that valid consent was obtained. Where explicit consent is required for the processing of special category personal data, the record must clearly demonstrate the individual’s express agreement.
An individual may withdraw consent where consent is the lawful basis relied upon. Withdrawal of consent will not affect the lawfulness of processing already carried out before consent was withdrawn.
Consent is not required in every case. Information may be shared without consent where another lawful basis and, where applicable, an Article 9 condition permits the disclosure. Examples may include safeguarding, protection of vital interests, provision or management of health or social care, compliance with a legal obligation or another lawful statutory purpose.
Where an adult may lack capacity to make a particular decision about the use or disclosure of information, staff must apply the Mental Capacity Act 2005. Capacity must be considered in relation to the specific decision at the relevant time and must not be assumed solely because of a person’s diagnosis, age, disability, behaviour or communication needs.
Where a person lacks capacity to make the relevant decision:
- the service must establish whether another person has lawful authority to make the relevant decision on their behalf;
- any decision made under the Mental Capacity Act 2005 must comply with its statutory principles and best-interests requirements; and
- the service must separately ensure that there is an appropriate lawful basis under data-protection legislation for processing or sharing the personal information.
A best-interests decision under the Mental Capacity Act 2005 does not, by itself, constitute a lawful basis for processing personal information under the UK GDPR.
Where information is shared without the individual’s consent, the reason, lawful basis, information disclosed and recipient must be recorded where appropriate. The individual should normally be informed about the disclosure unless doing so would be unlawful, would prejudice a safeguarding or criminal investigation, would create a risk of harm, or another lawful exemption applies.
4.4 Information Sharing Arrangements and Contracts
Before routinely sharing personal information with another organisation, {{org_field_name}} will establish the role of each party under data-protection legislation and determine whether the organisations are acting as independent controllers, joint controllers or as controller and processor.
Processors
Where another organisation processes personal information on behalf of {{org_field_name}}, a written contract or other binding legal act meeting the requirements of Article 28 of the UK GDPR must be in place before the processor undertakes the processing.
The arrangement must address, as applicable:
- the subject matter and duration of the processing;
- the nature and purpose of processing;
- the types of personal information involved;
- the categories of individuals concerned;
- confidentiality;
- information security;
- use of sub-processors;
- assistance with individual rights and data breaches;
- return or deletion of information at the end of the arrangement; and
- audit and compliance requirements.
Joint Controllers
Where {{org_field_name}} and another organisation jointly determine the purposes and means of processing, the parties must have an arrangement that transparently sets out their respective responsibilities for compliance with data-protection legislation, including arrangements relating to individual rights and privacy information.
Independent Controllers
Where personal information is shared between independent controllers, {{org_field_name}} will determine and document the lawful basis for the disclosure and ensure that the disclosure complies with the data-protection principles.
Where routine, systematic or higher-risk controller-to-controller sharing takes place, an appropriate written information-sharing arrangement will be used where necessary to clearly document the purpose of the sharing, responsibilities of the parties, information to be shared, lawful bases, security arrangements, retention, individual rights and management of incidents.
A separate information-sharing agreement is not required merely because information is being lawfully disclosed to a statutory regulator, safeguarding authority, police service, health professional or other body that is independently entitled to receive the information. However, staff must still confirm the identity and authority of the recipient and ensure that the disclosure itself is lawful, necessary and proportionate.
4.5 Secure Methods of Sharing
Staff are trained to use only secure, approved methods for sending or receiving confidential information, including:
- Encrypted emails
- Secure file transfer protocols (e.g. password-protected PDFs)
- Direct NHS mail or approved portals
- Telephone calls in private settings, confirming recipient identity
- Face-to-face meetings in confidential spaces
Under no circumstances should personal data be shared via personal email accounts, social media, or unapproved messaging services.
4.6 Recording and Documentation
Whenever information is shared, it must be clearly documented in the person’s file and in the communication log. This includes:
- The date and time
- What was shared
- Who it was shared with and their role
- The method of sharing
- The reason for sharing
- Whether consent was obtained or if an alternative lawful basis was used
This level of documentation provides transparency for audits and CIW inspections and helps us to track decisions over time.
4.7 Responding to Requests for Information
Requests from third parties for personal information must be considered on their individual circumstances. Staff must not disclose personal information solely because the requesting person identifies themselves as a relative, representative, solicitor, police officer, health professional or other professional.
Unless routine disclosure has already been authorised under an established procedure, requests must be referred to the Registered Manager and, where appropriate, the Data Protection Officer or other person responsible for data protection.
Before information is released, the service must establish:
- the identity of the requester;
- the requester’s authority or legal entitlement to receive the information;
- the purpose for which the information is requested;
- the applicable lawful basis for disclosure;
- any applicable Article 9 condition for special category personal data;
- whether consent or other lawful authority is required;
- whether an exemption, restriction or duty of confidentiality applies; and
- the minimum information necessary to satisfy the lawful purpose.
Subject Access Requests
A request by an individual for access to their own personal information is a Subject Access Request and may be made verbally or in writing.
Subject Access Requests must be referred promptly to the person responsible for data protection and handled in accordance with current data-protection legislation.
{{org_field_name}} must respond without undue delay and normally no later than one month after the applicable statutory time period begins.
Where permitted by law:
- the response period may be extended by up to a further two months because of the complexity or number of requests, provided the individual is informed within the initial one-month period and given the reason for the extension;
- reasonable and proportionate searches must be undertaken for the requested personal information;
- proportionate proof of identity or evidence of a representative’s authority may be requested where necessary;
- clarification may be requested where this is reasonably required to identify the personal information being sought, and the statutory response period may be paused where current legislation permits; and
- a request may only be refused or a fee charged where a statutory ground permits this.
Information disclosed in response to a Subject Access Request must be reviewed for information concerning other people, legal restrictions and applicable exemptions before it is released and must be provided securely.
4.8 Data Protection Complaints
{{org_field_name}} will maintain an accessible process through which individuals may raise complaints about the way their personal information has been collected, used, recorded, retained, disclosed, shared, secured or otherwise processed.
A data protection complaint may be made verbally or in writing and must be referred promptly to the person responsible for data protection.
{{org_field_name}} must:
- provide individuals with a clear means of making a data protection complaint;
- acknowledge receipt of a data protection complaint within 30 days of receiving it;
- take appropriate steps to investigate and respond to the complaint without undue delay;
- make appropriate enquiries having regard to the circumstances of the complaint;
- keep the complainant appropriately informed about the progress of the investigation without undue delay; and
- notify the complainant of the outcome without undue delay once the investigation is completed.
The investigation and outcome must take account of the individual’s rights under data-protection legislation and any actions required to correct or improve the service’s processing of personal information.
Appropriate records of data protection complaints, investigations, outcomes and actions taken will be maintained in accordance with applicable retention requirements.
Individuals will be informed of their right to raise concerns with the Information Commissioner’s Office where applicable.
Where a complaint also concerns the provision of care, safeguarding, confidentiality or another regulated-service matter, the complaint must additionally be considered under the relevant service policy and regulatory procedure.
4.9 Training and Accountability
All staff at {{org_field_name}} receive mandatory training on data protection, confidentiality, and safe information sharing. This is refreshed annually or as required. The Registered Manager and Data Protection Officer are responsible for ensuring staff understand their responsibilities and feel confident in applying this policy.
Supervision sessions are used to reflect on real cases, reinforce good practice, and identify training needs.
4.10 Breaches and Concerns
Any actual or suspected personal data breach must be reported immediately through {{org_field_name}}’s internal data-breach reporting procedure to the Registered Manager and the Data Protection Officer or other person responsible for data protection.
A personal data breach includes a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal information transmitted, stored or otherwise processed.
Following notification, {{org_field_name}} will without undue delay:
- take reasonable steps to contain the breach;
- establish the nature and circumstances of the incident;
- assess the actual and potential consequences for affected individuals;
- assess the likelihood and severity of risks to individuals’ rights and freedoms;
- take appropriate remedial action; and
- determine whether notification to the Information Commissioner’s Office or affected individuals is legally required.
Where a personal data breach is likely to result in a risk to the rights and freedoms of individuals, {{org_field_name}} must notify the Information Commissioner’s Office without undue delay and, where feasible, no later than 72 hours after becoming aware of the breach. Where notification is made after 72 hours, the reasons for the delay must be provided where required.
Where the personal data breach is likely to result in a high risk to an individual’s rights and freedoms, the affected individual must also be informed without undue delay unless a statutory exception applies.
{{org_field_name}} will document all personal data breaches, including breaches which do not meet the threshold for notification to the Information Commissioner’s Office. The record will include the circumstances of the breach, its effects, the risk assessment undertaken, decisions about notification and remedial action taken.
Lessons identified through personal data breaches will be incorporated into governance, staff training, information-security arrangements and service improvement.
4.11 Safeguarding and the Duty to Share
Where there is a safeguarding concern, the safety and wellbeing of the individual take priority. In such cases, staff have a duty to share relevant information with {{org_field_local_authority_authority_name}} or other safeguarding partners, even without consent, if there is a risk of abuse, neglect, or harm. This aligns with both CIW and Wales Safeguarding Procedures expectations.
4.12 Safeguarding and Information Sharing
Where there is an allegation, evidence or reasonable concern that an individual may be experiencing or at risk of abuse, neglect, improper treatment or other harm, staff must act in accordance with {{org_field_name}}’s safeguarding policy, the Wales Safeguarding Procedures and applicable statutory safeguarding requirements.
Staff must not delay necessary safeguarding action solely because consent to share information has not been obtained.
Where practicable and consistent with the individual’s safety and well-being, the individual should be involved in the decision and their wishes and feelings should be established and taken into account.
Information may be shared without consent where this is necessary and lawful, including where:
- seeking consent would place the individual or another person at increased risk of harm;
- the circumstances indicate a risk to another individual or to the wider public;
- the individual lacks capacity to make the relevant decision and disclosure is otherwise lawful;
- there is a statutory or legal requirement to disclose the information;
- disclosure is necessary to protect vital interests; or
- another applicable lawful basis and, where required, a condition for processing special category personal data permits the disclosure.
Before making a safeguarding disclosure, staff must share only information that is relevant, necessary and proportionate to the safeguarding purpose.
Safeguarding disclosures must be made promptly to the appropriate safeguarding authority or other relevant agency in accordance with local and national safeguarding arrangements.
The service will record, as appropriate:
- the safeguarding concern;
- whether the individual’s views or consent were sought;
- the individual’s wishes and feelings;
- where consent was not sought or was overridden, the reason for doing so;
- the lawful basis for sharing;
- the special category condition relied upon where applicable;
- what information was shared;
- the person or organisation with whom it was shared;
- when it was shared; and
- any resulting safeguarding action.
Information sharing for safeguarding purposes must remain consistent with the service’s duty to protect individuals’ confidentiality, dignity and human rights while taking necessary action to protect people from abuse, neglect and harm.
5. Policy Review
This policy will be reviewed annually, or sooner if required due to changes in legislation, guidance from CIW, or emerging best practice. Feedback from staff, service users, or external audits may also prompt interim review. The next scheduled review will take place 12 months from the date of the current version.
Responsible Person: {{org_field_registered_manager_first_name}} {{org_field_registered_manager_last_name}}
Reviewed on: {{last_update_date}}
Next Review Date: {{next_review_date}}
Copyright © {{current_year}} – {{org_field_name}}. All rights reserved.