{{org_field_logo}}

{{org_field_name}}

Registration Number: {{org_field_registration_no}}


Sharing Information with Third Party Organisations Policy

1. Purpose

The purpose of this policy is to ensure that {{org_field_name}} shares personal information with third party organisations lawfully, fairly, transparently, securely and only where there is an identified and documented need to do so.

This policy supports compliance with the Regulation and Inspection of Social Care (Wales) Act 2016; the Regulated Services (Service Providers and Responsible Individuals) (Wales) Regulations 2017, as amended; the Social Services and Well-being (Wales) Act 2014; the UK General Data Protection Regulation (UK GDPR); the Data Protection Act 2018; the Data (Use and Access) Act 2025; the Mental Capacity Act 2005; applicable human rights and equality legislation; and relevant statutory guidance and requirements issued by the Welsh Government, Care Inspectorate Wales and the Information Commissioner’s Office.

{{org_field_name}} recognises each individual’s right to privacy, dignity and confidentiality. Information will nevertheless be shared where this is necessary and lawful to provide safe and effective care and support, protect an individual or another person from abuse, neglect or harm, comply with a legal or regulatory obligation, support legitimate health or social care purposes, or otherwise fulfil a lawful purpose.

Only information that is necessary, relevant, adequate and proportionate for the identified purpose will be shared. Decisions about information sharing will take account of the individual’s rights, wishes and circumstances and will be documented where appropriate.

2. Scope

This policy applies to all staff at {{org_field_name}}, including permanent, temporary, and agency workers, as well as any volunteers or contractors who may have access to confidential information. It covers the sharing of personal and sensitive information with any external organisations or individuals, including:

3. Related Policies

This policy should be read in conjunction with:

4. Policy Statement and Implementation

4.1 Legal and Regulatory Framework

{{org_field_name}} will process and share personal information in accordance with applicable data-protection legislation, including the UK GDPR, the Data Protection Act 2018 and the Data (Use and Access) Act 2025.

As a provider of a regulated care home service in Wales, {{org_field_name}} will also comply with the Regulation and Inspection of Social Care (Wales) Act 2016 and the Regulated Services (Service Providers and Responsible Individuals) (Wales) Regulations 2017, as amended.

In particular, the service will ensure that:

Where personal information is to be shared, the service will consider both the requirements of data-protection legislation and any separate statutory, common-law, professional or regulatory obligations affecting the disclosure.

Lawful Basis for Sharing Information

Personal information must not be shared merely because sharing would be convenient or because another organisation has requested it. Before personal information is shared, {{org_field_name}} must identify and document an appropriate lawful basis under Article 6 of the UK GDPR.

Depending upon the circumstances, a lawful basis may include:

Consent will not be used as the lawful basis where the processing would continue regardless of whether consent was given or withdrawn.

4.2 Special Category Personal Data

Information concerning an individual’s health, racial or ethnic origin, religious or philosophical beliefs, genetic information, biometric information used for identification, sex life or sexual orientation is special category personal data.

Where special category personal data is shared, {{org_field_name}} must identify:

Depending upon the circumstances, relevant Article 9 conditions may include:

Where reliance is placed upon a condition requiring an additional condition under Schedule 1 of the Data Protection Act 2018, that Schedule 1 condition must also be identified and any requirement for an Appropriate Policy Document must be met.

For safeguarding disclosures, this may include an applicable substantial public interest condition under the Data Protection Act 2018 relating to safeguarding children or individuals at risk, where the statutory criteria are satisfied.

Data Protection Principles

Before sharing information, staff must ensure that:

Individuals will be provided with appropriate privacy information explaining how and why their personal information may be shared, with whom it may be shared or the categories of recipients, unless a lawful exemption applies.

Complex, unusual or high-risk disclosures must be referred to the Registered Manager and, where applicable, the Data Protection Officer or other person responsible for data protection before information is released.

4.3 Consent and Capacity

{{org_field_name}} will involve individuals in decisions about the use and sharing of their personal information wherever this is practicable and appropriate.

Where consent is relied upon as the lawful basis for processing, consent must meet the requirements of data-protection legislation. It must be freely given, specific, informed and unambiguous, and the service must be able to demonstrate that valid consent was obtained. Where explicit consent is required for the processing of special category personal data, the record must clearly demonstrate the individual’s express agreement.

An individual may withdraw consent where consent is the lawful basis relied upon. Withdrawal of consent will not affect the lawfulness of processing already carried out before consent was withdrawn.

Consent is not required in every case. Information may be shared without consent where another lawful basis and, where applicable, an Article 9 condition permits the disclosure. Examples may include safeguarding, protection of vital interests, provision or management of health or social care, compliance with a legal obligation or another lawful statutory purpose.

Where an adult may lack capacity to make a particular decision about the use or disclosure of information, staff must apply the Mental Capacity Act 2005. Capacity must be considered in relation to the specific decision at the relevant time and must not be assumed solely because of a person’s diagnosis, age, disability, behaviour or communication needs.

Where a person lacks capacity to make the relevant decision:

A best-interests decision under the Mental Capacity Act 2005 does not, by itself, constitute a lawful basis for processing personal information under the UK GDPR.

Where information is shared without the individual’s consent, the reason, lawful basis, information disclosed and recipient must be recorded where appropriate. The individual should normally be informed about the disclosure unless doing so would be unlawful, would prejudice a safeguarding or criminal investigation, would create a risk of harm, or another lawful exemption applies.

4.4 Information Sharing Arrangements and Contracts

Before routinely sharing personal information with another organisation, {{org_field_name}} will establish the role of each party under data-protection legislation and determine whether the organisations are acting as independent controllers, joint controllers or as controller and processor.

Processors

Where another organisation processes personal information on behalf of {{org_field_name}}, a written contract or other binding legal act meeting the requirements of Article 28 of the UK GDPR must be in place before the processor undertakes the processing.

The arrangement must address, as applicable:

Joint Controllers

Where {{org_field_name}} and another organisation jointly determine the purposes and means of processing, the parties must have an arrangement that transparently sets out their respective responsibilities for compliance with data-protection legislation, including arrangements relating to individual rights and privacy information.

Independent Controllers

Where personal information is shared between independent controllers, {{org_field_name}} will determine and document the lawful basis for the disclosure and ensure that the disclosure complies with the data-protection principles.

Where routine, systematic or higher-risk controller-to-controller sharing takes place, an appropriate written information-sharing arrangement will be used where necessary to clearly document the purpose of the sharing, responsibilities of the parties, information to be shared, lawful bases, security arrangements, retention, individual rights and management of incidents.

A separate information-sharing agreement is not required merely because information is being lawfully disclosed to a statutory regulator, safeguarding authority, police service, health professional or other body that is independently entitled to receive the information. However, staff must still confirm the identity and authority of the recipient and ensure that the disclosure itself is lawful, necessary and proportionate.

4.5 Secure Methods of Sharing

Staff are trained to use only secure, approved methods for sending or receiving confidential information, including:

Under no circumstances should personal data be shared via personal email accounts, social media, or unapproved messaging services.

4.6 Recording and Documentation

Whenever information is shared, it must be clearly documented in the person’s file and in the communication log. This includes:

This level of documentation provides transparency for audits and CIW inspections and helps us to track decisions over time.

4.7 Responding to Requests for Information

Requests from third parties for personal information must be considered on their individual circumstances. Staff must not disclose personal information solely because the requesting person identifies themselves as a relative, representative, solicitor, police officer, health professional or other professional.

Unless routine disclosure has already been authorised under an established procedure, requests must be referred to the Registered Manager and, where appropriate, the Data Protection Officer or other person responsible for data protection.

Before information is released, the service must establish:

Subject Access Requests

A request by an individual for access to their own personal information is a Subject Access Request and may be made verbally or in writing.

Subject Access Requests must be referred promptly to the person responsible for data protection and handled in accordance with current data-protection legislation.

{{org_field_name}} must respond without undue delay and normally no later than one month after the applicable statutory time period begins.

Where permitted by law:

Information disclosed in response to a Subject Access Request must be reviewed for information concerning other people, legal restrictions and applicable exemptions before it is released and must be provided securely.

4.8 Data Protection Complaints

{{org_field_name}} will maintain an accessible process through which individuals may raise complaints about the way their personal information has been collected, used, recorded, retained, disclosed, shared, secured or otherwise processed.

A data protection complaint may be made verbally or in writing and must be referred promptly to the person responsible for data protection.

{{org_field_name}} must:

The investigation and outcome must take account of the individual’s rights under data-protection legislation and any actions required to correct or improve the service’s processing of personal information.

Appropriate records of data protection complaints, investigations, outcomes and actions taken will be maintained in accordance with applicable retention requirements.

Individuals will be informed of their right to raise concerns with the Information Commissioner’s Office where applicable.

Where a complaint also concerns the provision of care, safeguarding, confidentiality or another regulated-service matter, the complaint must additionally be considered under the relevant service policy and regulatory procedure.

4.9 Training and Accountability

All staff at {{org_field_name}} receive mandatory training on data protection, confidentiality, and safe information sharing. This is refreshed annually or as required. The Registered Manager and Data Protection Officer are responsible for ensuring staff understand their responsibilities and feel confident in applying this policy.

Supervision sessions are used to reflect on real cases, reinforce good practice, and identify training needs.

4.10 Breaches and Concerns

Any actual or suspected personal data breach must be reported immediately through {{org_field_name}}’s internal data-breach reporting procedure to the Registered Manager and the Data Protection Officer or other person responsible for data protection.

A personal data breach includes a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal information transmitted, stored or otherwise processed.

Following notification, {{org_field_name}} will without undue delay:

Where a personal data breach is likely to result in a risk to the rights and freedoms of individuals, {{org_field_name}} must notify the Information Commissioner’s Office without undue delay and, where feasible, no later than 72 hours after becoming aware of the breach. Where notification is made after 72 hours, the reasons for the delay must be provided where required.

Where the personal data breach is likely to result in a high risk to an individual’s rights and freedoms, the affected individual must also be informed without undue delay unless a statutory exception applies.

{{org_field_name}} will document all personal data breaches, including breaches which do not meet the threshold for notification to the Information Commissioner’s Office. The record will include the circumstances of the breach, its effects, the risk assessment undertaken, decisions about notification and remedial action taken.

Lessons identified through personal data breaches will be incorporated into governance, staff training, information-security arrangements and service improvement.

4.11 Safeguarding and the Duty to Share

Where there is a safeguarding concern, the safety and wellbeing of the individual take priority. In such cases, staff have a duty to share relevant information with {{org_field_local_authority_authority_name}} or other safeguarding partners, even without consent, if there is a risk of abuse, neglect, or harm. This aligns with both CIW and Wales Safeguarding Procedures expectations​.

4.12 Safeguarding and Information Sharing

Where there is an allegation, evidence or reasonable concern that an individual may be experiencing or at risk of abuse, neglect, improper treatment or other harm, staff must act in accordance with {{org_field_name}}’s safeguarding policy, the Wales Safeguarding Procedures and applicable statutory safeguarding requirements.

Staff must not delay necessary safeguarding action solely because consent to share information has not been obtained.

Where practicable and consistent with the individual’s safety and well-being, the individual should be involved in the decision and their wishes and feelings should be established and taken into account.

Information may be shared without consent where this is necessary and lawful, including where:

Before making a safeguarding disclosure, staff must share only information that is relevant, necessary and proportionate to the safeguarding purpose.

Safeguarding disclosures must be made promptly to the appropriate safeguarding authority or other relevant agency in accordance with local and national safeguarding arrangements.

The service will record, as appropriate:

Information sharing for safeguarding purposes must remain consistent with the service’s duty to protect individuals’ confidentiality, dignity and human rights while taking necessary action to protect people from abuse, neglect and harm.

5. Policy Review

This policy will be reviewed annually, or sooner if required due to changes in legislation, guidance from CIW, or emerging best practice. Feedback from staff, service users, or external audits may also prompt interim review. The next scheduled review will take place 12 months from the date of the current version.


Responsible Person: {{org_field_registered_manager_first_name}} {{org_field_registered_manager_last_name}}
Reviewed on:
{{last_update_date}}
Next Review Date:
{{next_review_date}}
Copyright © {{current_year}} – {{org_field_name}}. All rights reserved.

Leave a Reply

Your email address will not be published. Required fields are marked *