{{org_field_logo}}

{{org_field_name}}

Registration Number: {{org_field_registration_no}}


Internet Access for Staff Policy

1. Purpose

The purpose of this policy is to establish clear requirements for the safe, lawful and appropriate use of internet access by staff at {{org_field_name}}. Internet access and digital systems are important resources for supporting the delivery of safe and effective care, staff learning and development, communication, access to professional information and the maintenance of electronic records.

{{org_field_name}} recognises that inappropriate or insecure use of internet-connected systems may create risks to individuals, staff and the organisation, including unauthorised access to personal information, loss or disclosure of confidential information, cyber incidents and disruption to the provision of care and support.

This policy supports compliance with the Regulation and Inspection of Social Care (Wales) Act 2016, the Regulated Services (Service Providers and Responsible Individuals) (Wales) Regulations 2017, as amended, and associated statutory guidance. In particular, it supports the requirements for policies and procedures to be kept up to date, for staff to understand confidentiality and data protection requirements, and for records, including electronic records, to be maintained securely.

Personal information must be processed in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and applicable amendments made by the Data (Use and Access) Act 2025. Staff must also comply with the organisation’s Confidentiality and Data Protection Policy and any related information security procedures.

All staff are responsible for using the organisation’s internet access, devices, systems and electronic information in a lawful, secure and responsible manner and for protecting the confidentiality, integrity and availability of information relating to individuals receiving care and support.

2. Scope

This policy applies to all employees, agency staff, contractors, and volunteers who access the internet using the organisation’s network, computers, tablets, or mobile devices. It covers internet browsing, email usage, social media access, downloading or sharing files, and communication conducted via online platforms. The policy applies to all workstations, whether wired or wireless, and extends to any use of the organisation’s network both on and off-site when using company devices.

3. Management of Internet Access

3.1 Providing Secure and Efficient Internet Access

{{org_field_name}} provides staff with internet access to facilitate the effective performance of their duties, support training and development, and enable communication with external health professionals, regulatory bodies, and service user representatives. The organisation maintains a secure network infrastructure with appropriate firewalls, antivirus software, and encryption measures to prevent unauthorised access, data leaks, and cyber threats. Staff must use the internet responsibly, ensuring it does not compromise the security or efficiency of the network. IT systems are regularly reviewed to ensure they meet security standards, and staff are encouraged to report any technical issues immediately to the designated IT support team.

3.2 Appropriate Use of the Internet

Internet access provided by {{org_field_name}} is primarily intended to support legitimate work-related activities. Appropriate professional use may include:

Limited personal use may be permitted during authorised breaks where this does not interfere with an employee’s duties, the provision of care and support, the security or performance of the organisation’s systems, or any other organisational policy.

Staff must not use internet access in a way that compromises the confidentiality, integrity or availability of personal information or organisational information, places individuals receiving care and support at risk, interferes with the proper performance of their duties, or is otherwise unlawful.

Where {{org_field_name}} monitors the use of its internet, network or information systems, such monitoring will only be undertaken for specified and legitimate purposes and in accordance with applicable data protection and privacy legislation. Monitoring must be necessary and proportionate to the identified purpose and must not be excessive.

Staff will be provided with appropriate privacy information explaining the nature, purpose and extent of monitoring, the categories of information collected, the lawful basis relied upon, how the information may be used, how long it will be retained and with whom it may be shared. Covert monitoring will not be undertaken routinely and may only be considered in exceptional circumstances where it is lawful, necessary and proportionate.

Information obtained through lawful monitoring may be used to investigate suspected breaches of this policy, information security incidents, safeguarding concerns, unlawful activity or other misconduct. Any disciplinary action arising from such information will be dealt with in accordance with the organisation’s disciplinary procedures.

3.3 Restrictions and Prohibited Activities

To maintain a professional and secure environment, the following internet activities are strictly prohibited: accessing or sharing explicit, extremist, discriminatory, or offensive material; engaging in online harassment, cyberbullying, or making defamatory statements about colleagues, service users, or the organisation; using the organisation’s internet for personal business ventures, unauthorised financial transactions, or gambling; downloading unauthorised software, applications, or files that may pose cybersecurity risks; attempting to bypass security controls, including the use of VPNs or proxy servers to access blocked content. Any violation of these restrictions will be investigated and may result in access restrictions, formal disciplinary action, or legal consequences if required.

3.4 Use of Social Media

Staff must use social media in a manner that protects the privacy, dignity, confidentiality and rights of individuals receiving care and support, colleagues and other persons associated with {{org_field_name}}.

Staff must comply with the Confidentiality and Data Protection Policy (CHW34), Staff Conduct and Code of Ethics Policy (CHW28), Safeguarding Adults from Abuse and Improper Treatment Policy (CHW13) and Whistleblowing (Speaking Up) Policy (CHW29).

Staff must not post, disclose, photograph, record, transmit or otherwise share confidential or personal information relating to an individual receiving care and support, their relatives or representatives, colleagues or the organisation unless there is a lawful and authorised reason for doing so. This applies to public posts, private messages, closed groups and any other online communication.

Staff must not publish defamatory, discriminatory, threatening, harassing or otherwise unlawful material relating to individuals receiving care and support, colleagues or the organisation.

Personal social media accounts must not be used to access, store, send or discuss confidential care records or other personal information obtained through employment unless specifically authorised through an approved organisational system.

Nothing in this policy prevents or restricts a worker from:

Where staff use social media personally, they must maintain appropriate professional boundaries and must not represent personal views as being those of {{org_field_name}} unless authorised to speak on behalf of the organisation.

Suspected misuse of social media in connection with employment will be considered in accordance with the organisation’s relevant investigation and disciplinary procedures.

3.5 Data Protection and Cybersecurity

{{org_field_name}} must protect personal information and confidential organisational information against unauthorised or unlawful access, use, alteration, disclosure, loss, destruction or damage.

Personal information must be processed in accordance with the UK GDPR, the Data Protection Act 2018, the Data (Use and Access) Act 2025 insofar as it amends applicable data protection legislation, and the organisation’s Confidentiality and Data Protection Policy.

Appropriate technical and organisational security measures must be maintained having regard to the nature, scope, context and purpose of the processing and the risks to individuals. These measures must include appropriate controls governing access to electronic systems and records.

Staff must:

Electronic systems used to maintain care or other regulated records must be appropriately secured. Individual staff access credentials must enable a clear audit trail to identify, where applicable, who has accessed, entered or amended information.

Access rights must be appropriate to the person’s role and must be removed or amended promptly when they are no longer required, including when a member of staff changes role or leaves the organisation.

Where personal information is stored or transmitted electronically, {{org_field_name}} will implement encryption and other security measures where appropriate to the identified risk and in accordance with its information security arrangements. Encryption does not replace the requirement to check that information is being sent to the correct authorised recipient.

Any member of staff who becomes aware of an actual or suspected loss, unauthorised disclosure, inappropriate access, cyber incident, phishing incident, malware infection or other potential personal data breach must report it immediately to the manager and the organisation’s Data Protection Officer or designated data protection lead, as applicable. Staff must not attempt to conceal, delete or independently investigate evidence relating to a suspected breach unless authorised to do so.

The organisation will assess reported personal data breaches promptly and will make any notification required by applicable data protection legislation to the Information Commissioner’s Office and, where legally required, to affected individuals.

Staff must receive appropriate information security and data protection training relevant to their duties and must comply with the organisation’s information security and data protection requirements.

3.6 Monitoring of Internet and Information Systems

{{org_field_name}} may monitor the use of its internet connection, network, devices, accounts and information systems where there is a specified and legitimate organisational purpose for doing so.

Any monitoring of workers must be undertaken in accordance with applicable data protection and privacy legislation. Before monitoring is introduced, the organisation must identify and document:

Monitoring must be proportionate to its stated purpose and must not collect more personal information than is necessary.

Staff must be provided with clear privacy information about monitoring before routine monitoring takes place. This information must explain the nature, purpose and extent of monitoring and how information obtained through monitoring will be processed. Relevant privacy information must be kept up to date where monitoring arrangements change.

Monitoring may, where necessary and proportionate, include system and security logs, internet connection records, access records, attempted access to restricted resources, downloads or other information necessary to protect the organisation’s systems, investigate suspected misuse or meet legal and regulatory obligations.

Where monitoring would involve accessing or monitoring the content of workers’ emails, messages or other communications, {{org_field_name}} must complete a Data Protection Impact Assessment where required by data protection law and must ensure that the monitoring is necessary and proportionate. Content must not routinely be accessed where less intrusive information, such as network or system metadata, is sufficient for the identified purpose.

Covert monitoring must not be used routinely. It may only be considered in exceptional circumstances where there are grounds to suspect serious misconduct or unlawful activity, the monitoring is strictly necessary and proportionate, less intrusive methods would not reasonably achieve the purpose, and all applicable legal and data protection requirements have been considered and documented.

Information obtained through monitoring must be kept secure and access restricted to persons who require it for an authorised purpose. It must not be retained for longer than is necessary for the purpose for which it was collected.

Where monitoring identifies suspected misconduct, the matter will be considered under the appropriate organisational procedure. The existence of monitoring does not remove the requirement for a fair investigation or for the organisation to follow its disciplinary procedures.

Nothing in the organisation’s monitoring arrangements will prevent or improperly interfere with a member of staff making a protected disclosure, raising a safeguarding concern or communicating lawfully with a regulator, statutory authority, trade union representative or other person where the communication is protected by law.

3.7 Access to Electronic Care Records and Other Regulated Records

Where staff access electronic care records or other electronic records required for the operation of the regulated service, access must be restricted to authorised persons and appropriate to their role.

Each member of staff must use their own individual access credentials. Shared user accounts must not be used for creating, amending or approving care records where doing so would prevent the organisation from identifying the person responsible for an entry or amendment.

Electronic record systems must, where applicable, provide a clear audit trail showing who has made entries or amendments. Staff must not use another person’s credentials, permit another person to use their credentials, or deliberately circumvent an electronic audit trail.

Staff must ensure that entries made in electronic care records are accurate, contemporaneous and attributable to the person making the entry. Records must not be altered, deleted or overwritten in a way that improperly obscures the original record or prevents the history of an amendment from being identified where the system is required to retain that information.

Access to electronic records must be withdrawn or amended promptly when it is no longer required.

Any suspected unauthorised access to, alteration of or disclosure from an electronic care-record system must be reported immediately in accordance with the organisation’s information security, incident reporting and data breach procedures.

4. Related Policies

This policy must be read and applied alongside the organisation’s other relevant policies and procedures, including:

Where a member of staff identifies a safeguarding concern, suspected unlawful activity, information security incident or personal data breach while using an internet-connected system, the relevant safeguarding, whistleblowing, incident reporting or data protection procedure must be followed without delay.

Nothing in this Internet Access for Staff Policy overrides a member of staff’s legal right or professional responsibility to raise a safeguarding concern, make a protected disclosure or communicate lawfully with Care Inspectorate Wales or another appropriate regulatory or statutory body.

5. Policy Review

This policy will be reviewed at least annually and sooner where necessary following:

The Responsible Individual must ensure that suitable arrangements are in place for this policy to be kept up to date in accordance with the applicable requirements of the Regulated Services (Service Providers and Responsible Individuals) (Wales) Regulations 2017, as amended.

Relevant changes must be communicated to staff and volunteers. Where a change affects the processing of staff personal information, including the introduction or material alteration of monitoring, associated privacy information must also be reviewed and updated.

Staff must have access to the current version of this policy and must be made aware of the requirements relevant to their role. Understanding of applicable confidentiality, data protection and information-security requirements must be addressed through induction, training, supervision or other appropriate management arrangements.


Responsible Person: {{org_field_registered_manager_first_name}} {{org_field_registered_manager_last_name}}
Reviewed on:
{{last_update_date}}
Next Review Date:
{{next_review_date}}
Copyright © {{current_year}} – {{org_field_name}}. All rights reserved.

Leave a Reply

Your email address will not be published. Required fields are marked *