{{org_field_logo}}

{{org_field_name}}

Registration Number: {{org_field_registration_no}}


Data Sharing and Individual Data Rights Policy

1. Purpose

The purpose of this policy is to set out how {{org_field_name}} protects confidential and personal information, manages the sharing of information and enables individuals to exercise their data-protection rights.

The NHS National Data Opt-Out applies to confidential patient information relating to health and adult social care provided in England. It does not apply to health or social care information generated or processed in Wales merely because that information is held by a care home service in Wales. {{org_field_name}} will therefore not describe a resident’s consent preference, objection to processing or other data-protection request as a National Data Opt-Out unless the information concerned is genuinely subject to the NHS England National Data Opt-Out arrangements.

Where {{org_field_name}} receives or processes information originating from the health or adult social care system in England which is subject to National Data Opt-Out requirements, the organisation will comply with any applicable requirements governing that information and with instructions or arrangements lawfully established by the relevant controller or health and care organisation.

For information processed by {{org_field_name}} as a care home service in Wales, the organisation will comply with applicable data-protection and confidentiality requirements, including the UK General Data Protection Regulation, the Data Protection Act 2018 as amended, including amendments made by the Data (Use and Access) Act 2025, and applicable duties of confidentiality.

The organisation will also comply with the Regulation and Inspection of Social Care (Wales) Act 2016 and the Regulated Services (Service Providers and Responsible Individuals) (Wales) Regulations 2017, as amended, including requirements relating to confidentiality, the security and accuracy of records, staff understanding of confidentiality and data protection, and effective governance of the service.

{{org_field_name}} is committed to ensuring that personal information is used lawfully, fairly, transparently and securely and that individuals are provided with appropriate information about how their personal information is used and about the rights available to them.

2. Scope

This policy applies to all employees, contractors, volunteers, and agency staff at {{org_field_name}} who have access to personal and confidential information. It applies to all residents using our services, their families or representatives, and to external partners who may receive or request data from us.

3. Related Policies

This policy should be read in conjunction with the following:

4. Policy Details

4.1 National Data Opt-Out and its Application in Wales

The NHS National Data Opt-Out is an arrangement applying to confidential patient information relating to health and adult social care provided in England. It allows eligible individuals to express a preference about the use of certain confidential patient information for purposes beyond their individual care, subject to the rules and exemptions applying to that scheme.

The National Data Opt-Out does not apply merely because {{org_field_name}} processes health or social care information about a resident in Wales. Information generated or processed as part of care provided in Wales is governed by the applicable data-protection, confidentiality and social-care requirements rather than by a Welsh equivalent of the NHS England National Data Opt-Out.

Accordingly:

Staff who are uncertain whether the NHS England National Data Opt-Out applies to particular information must seek advice from the Data Protection Officer before the information is used or disclosed for a purpose beyond the individual’s care.

4.2 Legal and Ethical Framework

{{org_field_name}} will process personal information in accordance with the UK General Data Protection Regulation, the Data Protection Act 2018 as amended, including amendments made by the Data (Use and Access) Act 2025, and applicable confidentiality requirements.

For every processing activity, {{org_field_name}} will identify and document an appropriate lawful basis under the UK GDPR. Where the information is special category personal data, including information concerning a person’s health, racial or ethnic origin, religious or philosophical beliefs, sexual orientation or other special category information, an appropriate condition for processing under Article 9 of the UK GDPR must also be identified.

Consent will only be relied upon as the data-protection lawful basis where it is appropriate to do so and where the requirements for valid consent can be met. Consent will not be treated as the automatic or default lawful basis for information processing simply because health or social care information is involved.

Information required for the provision, management or coordination of health or social care may be processed under another appropriate lawful basis and Article 9 condition. Information may also be processed or shared without consent where another lawful basis and, where required, an Article 9 condition applies, including where processing is necessary to meet a legal obligation, protect vital interests, perform an appropriate public task, provide or manage health or social care, meet safeguarding responsibilities or for another purpose permitted by law.

Where confidential information is disclosed, {{org_field_name}} will additionally consider the applicable duty of confidentiality and ensure that there is an appropriate justification or lawful authority for the disclosure.

Information will only be collected, used and shared for specified and legitimate purposes. The organisation will ensure that the information used is adequate, relevant and limited to what is necessary for the purpose, is kept accurate and up to date, is retained only for the required period and is protected by appropriate technical and organisational security measures.

These arrangements support the requirements of the Regulated Services (Service Providers and Responsible Individuals) (Wales) Regulations 2017, as amended, including the requirement to respect individuals’ confidentiality and to maintain secure, accurate and up-to-date records.

4.3 Individual Rights and Informed Choice

Residents will be provided with clear and accessible privacy information explaining how {{org_field_name}} collects, uses, stores and shares their personal information. The information provided will identify, as applicable, the purposes for which information is processed, the lawful basis relied upon, relevant recipients or categories of recipients, retention arrangements, the individual’s data-protection rights and how the individual may raise a data-protection concern or complaint.

Individuals have rights under data-protection legislation which may include, depending upon the circumstances:

These rights are not all absolute. A request will be considered according to the circumstances, the lawful basis for the processing and any applicable statutory exemptions or obligations. A resident cannot require {{org_field_name}} to stop processing information which the organisation is legally required or otherwise lawfully entitled to process merely by describing the request as an opt-out.

Where processing genuinely relies upon consent, residents will be informed that they may withdraw that consent without detriment. Withdrawal of consent will not affect the lawfulness of processing carried out before consent was withdrawn and will not prevent processing that is permitted or required under another lawful basis.

Residents will receive appropriate support to understand information about the use of their personal data and to exercise their rights.

A resident may authorise another person to assist them or act on their behalf. Staff must establish the authority of a representative before disclosing personal information or accepting instructions on the resident’s behalf.

Where an adult lacks capacity to make a particular decision concerning their information, staff will act in accordance with the Mental Capacity Act 2005 and any applicable legal authority. An attorney, deputy or other person may act only within the scope of their lawful authority. The involvement of an advocate does not, by itself, give that advocate legal authority to consent to processing, withdraw consent or exercise the individual’s data-protection rights on their behalf.

4.4 Managing Data-Sharing Preferences and Individual Rights Requests

When an individual asks {{org_field_name}} to stop, restrict or change the way their personal information is being used or shared, staff must establish the nature of the request rather than automatically recording it as an opt-out.

The request must be referred promptly to the Data Protection Officer or other person authorised to manage data-protection requests.

The organisation will establish whether the request is:

Where consent is the lawful basis and valid consent is withdrawn, the processing based on that consent will stop unless another lawful basis properly applies to future processing.

Where an individual objects to processing or asks for processing to be restricted or stopped, {{org_field_name}} will consider the request in accordance with data-protection legislation. Information will not automatically be withheld from a health professional, local authority, safeguarding body, regulator, law-enforcement agency or other recipient where disclosure remains necessary and lawful.

All requests and the decisions made in response will be documented appropriately. Relevant records and systems will be updated where required and staff who need to know about an approved restriction or change will be informed.

Residents may change a consent preference or make a further rights request at any time. No person will receive poorer care or treatment because they have exercised a data-protection right. However, staff will explain where a requested restriction cannot legally be followed or where it could affect the ability to provide a particular optional service that genuinely depends upon the processing concerned.

4.5 Communication and Transparency

{{org_field_name}} will provide residents with clear, accessible and accurate information explaining how their personal information is processed.

Privacy information will be made available at an appropriate stage, including when personal information is collected directly from the individual and, where information is obtained from another source, within the timescales required by data-protection legislation.

Information provided to residents will not describe the NHS National Data Opt-Out as applying to personal information generated through a care home service in Wales.

Residents will instead be informed about:

Information will be provided in a manner which is concise, transparent, intelligible and accessible.

Where a resident has additional communication requirements, appropriate support and alternative formats will be provided. This may include Easy Read information, large print, translated information, interpretation, advocacy or appropriate communication aids.

Reasonable steps will be taken to meet an individual’s language and communication needs, including Welsh-language needs in accordance with the service’s applicable arrangements.

4.6 Staff Responsibilities and Training

All staff who have access to personal or confidential information will receive appropriate data-protection, confidentiality and information-security training as part of induction and through ongoing training appropriate to their role.

Training will include, where relevant:

Staff must not promise that information will never be shared or tell a resident that all sharing can be stopped if the organisation has a legal duty or another lawful basis requiring or permitting the processing.

Staff must not disclose confidential information to a family member, advocate or other representative solely because that person is involved in the resident’s care. The resident’s wishes, the representative’s authority, the individual’s capacity, applicable confidentiality requirements and the lawful basis for disclosure must be considered.

The Data Protection Officer, {{org_field_data_protection_officer_first_name}} {{org_field_data_protection_officer_last_name}}, is responsible for overseeing data-protection compliance and providing advice in relation to this policy.

Staff must promptly escalate uncertainty about data sharing, confidentiality, lawful bases, individual rights or personal data breaches to the Data Protection Officer.

Email: {{org_field_data_protection_officer_email}} | Tel: {{org_field_data_protection_officer_phone}}

4.7 Data Sharing Practices

Personal information will only be shared where {{org_field_name}} has established that the sharing is necessary, proportionate and lawful.

Before identifiable personal information is routinely shared with another organisation, {{org_field_name}} will establish:

Pseudonymised information remains personal information where an individual can be re-identified using additional information and must therefore continue to be handled in accordance with applicable data-protection requirements.

Where information has been effectively anonymised so that individuals are no longer identifiable by reasonably available means, it will not normally constitute personal information for the purposes of the UK GDPR.

Explicit consent is not the only lawful mechanism by which identifiable information may be processed or shared. Information may be shared without consent where an appropriate lawful basis and, for special category information, an appropriate Article 9 condition applies and any relevant confidentiality requirements have been satisfied.

Where processing or disclosure is based upon consent, the consent must meet the applicable legal requirements and must be capable of being demonstrated.

Where the organisation is legally required to provide information, or where sharing is necessary and lawful for safeguarding, health or social care, vital interests, regulatory, law-enforcement or other permitted purposes, an individual’s objection or preference will be considered but will not automatically prevent the disclosure.

4.8 Monitoring, Audit and Personal Data Breaches

{{org_field_name}} will maintain effective arrangements for monitoring compliance with this policy and with its wider confidentiality, records-management, information-security and data-protection responsibilities.

Audits will include, where appropriate:

Records relating to individuals must be accurate and up to date and must be stored securely in accordance with the Regulated Services (Service Providers and Responsible Individuals) (Wales) Regulations 2017, as amended, and applicable data-protection legislation.

Any member of staff who becomes aware of an actual or suspected loss, unauthorised disclosure, unauthorised access, alteration, destruction or other personal data breach must report it immediately in accordance with the organisation’s data-breach procedure.

All personal data breaches will be documented, including the facts relating to the breach, its effects and the remedial action taken.

Where a personal data breach is likely to result in a risk to the rights and freedoms of individuals, {{org_field_name}}, as controller where applicable, will notify the Information Commissioner’s Office without undue delay and, where feasible, no later than 72 hours after becoming aware of the breach, unless an applicable exemption applies.

Where a personal data breach is likely to result in a high risk to the rights and freedoms of an affected individual, the individual will also be informed without undue delay unless a statutory exception to that requirement applies.

Notification to Care Inspectorate Wales is a separate regulatory consideration. A personal data breach will be notified to CIW where the circumstances of the incident also constitute an event which the service provider or Responsible Individual is required to notify under the Regulated Services (Service Providers and Responsible Individuals) (Wales) Regulations 2017, as amended. Any required CIW notification will be made without delay and in the manner and form required by the service regulator.

Findings from audits, complaints, breaches and investigations will be used to identify necessary corrective action and improvements to the service.

4.9 Managing Data-Protection Complaints and Concerns

A resident or other data subject has the right to complain to {{org_field_name}} if they consider that the organisation has infringed data-protection legislation in connection with personal information relating to them.

{{org_field_name}} will facilitate the making of data-protection complaints and will provide clear and accessible means by which a complaint may be submitted, including an electronic method and other appropriate means for individuals who cannot reasonably use an electronic route.

A data-protection complaint may be made directly to the Data Protection Officer or through the organisation’s complaints arrangements.

When a data-protection complaint is received, {{org_field_name}} will:

Where a complaint also concerns the quality or provision of the regulated care service, the relevant elements will additionally be managed under CHW14 – Receiving and Acting on Complaints Policy and any applicable CIW complaints arrangements.

Individuals will be informed that they may raise a concern with the Information Commissioner’s Office if they are dissatisfied with the organisation’s handling of their personal information or its response to a data-protection complaint.

Nothing in the organisation’s internal complaints process will prevent an individual from exercising any right available to them under data-protection legislation or from contacting the Information Commissioner’s Office.

5. Policy Review

This policy is reviewed annually or sooner if:


Responsible Person: {{org_field_registered_manager_first_name}} {{org_field_registered_manager_last_name}}
Reviewed on:
{{last_update_date}}
Next Review Date:
{{next_review_date}}
Copyright © {{current_year}} – {{org_field_name}}. All rights reserved.

Leave a Reply

Your email address will not be published. Required fields are marked *