{{org_field_logo}}

{{org_field_name}}

Registration Number: {{org_field_registration_no}}


Using Social Media Platforms Policy

1. Purpose

The purpose of this policy is to provide clear requirements for the safe, lawful and responsible use of social media, online communication platforms and messaging applications by staff, individuals receiving care and support, and other persons connected with {{org_field_name}}.

Social media and digital communication can support communication, participation, relationships and engagement. Their use can also create risks relating to confidentiality, data protection, safeguarding, professional boundaries, dignity, privacy and the safety and well-being of individuals.

{{org_field_name}} will ensure that the use of social media in connection with the service is consistent with applicable Welsh social care legislation, data protection legislation, safeguarding requirements, Care Inspectorate Wales requirements and the Codes of Professional Practice issued by Social Care Wales.

This policy is intended to ensure that:

2. Scope

This policy applies to:

This policy covers all social media platforms, including but not limited to:

3. Legal and Regulatory Framework

This policy must be implemented in accordance with applicable legislation, statutory guidance and regulatory requirements, including:

This policy must be read together with the organisation’s safeguarding, confidentiality and data protection, professional boundaries, disciplinary, whistleblowing and incident-reporting procedures.

4. Social Media Management in the Care Home

4.1 Official Social Media Accounts

4.2 Personal Use of Social Media by Staff

Staff must ensure that their use of personal social media accounts and other online platforms complies with their professional responsibilities, this policy, applicable confidentiality and safeguarding requirements and the current Code of Professional Practice for Social Care Workers.

Staff must not, through a personal or professional account:

Staff must maintain appropriate professional boundaries online as well as in person. Unless contact is expressly authorised as part of the person’s role and is consistent with organisational policy, staff must not initiate or accept personal social media connections, friend requests, follows, private messages or similar personal online relationships with individuals whom they support or with their family members.

Where an individual or family member attempts to establish personal online contact with a member of staff, the member of staff must maintain professional boundaries and seek advice from their line manager where necessary.

Staff remain responsible for their online conduct outside working hours. Personal online activity may be considered under the organisation’s disciplinary or capability procedures where there is a legitimate connection with the person’s employment, professional responsibilities, safeguarding obligations or suitability to work in social care.

Any member of staff who becomes aware through social media of information suggesting that an individual may be experiencing abuse, neglect, exploitation, improper treatment or other risk of harm must act immediately in accordance with the Safeguarding Policy and Wales Safeguarding Procedures.

4.3 Social Media Use by Individuals Receiving Care and Support

Individuals receiving care and support have the right, so far as reasonably practicable, to access and use social media, digital communication and the internet in accordance with their wishes and preferences.

Staff must support individuals to exercise choice and control over their online activity and must not impose restrictions merely because a person receives care and support, is older, has a disability, has a diagnosis or is considered vulnerable.

Where an individual’s social media or online activity presents an identifiable risk to their safety or well-being, or to the safety or rights of another person, an appropriate person-centred risk assessment must be undertaken. The assessment must:

Staff should provide proportionate support where required to help individuals understand matters such as:

A diagnosis of dementia, cognitive impairment, learning disability, mental disorder or other condition must not in itself be treated as evidence that an adult lacks capacity to make decisions about social media.

Where there is a reasonable doubt about an adult’s capacity to make a specific decision relating to social media, online communication or disclosure of personal information, staff must follow the Mental Capacity Act 2005 and the organisation’s Mental Capacity Policy.

Any assessment of capacity must relate to the specific decision that needs to be made at the relevant time. All practicable steps must first be taken to support the person to make their own decision.

Where a person lacks capacity in relation to the specific decision, any decision made or action taken on their behalf must comply with the Mental Capacity Act 2005, including the requirement to act in the person’s best interests and to consider the least restrictive option.

Any restriction on an individual’s access to social media or digital communication must have a lawful basis, be necessary and proportionate to the identified risk, and be documented and reviewed.

4.4 Privacy, Confidentiality and Data Protection

All use of personal information through social media must comply with the UK GDPR, the Data Protection Act 2018, the organisation’s Data Protection and Confidentiality Policy and any applicable privacy notice.

Staff must not disclose personal or confidential information obtained through their role unless there is a lawful and legitimate reason to do so.

Before personal information is processed for social media purposes, {{org_field_name}} must:

Photographs, video recordings, audio recordings and other material in which an individual is identifiable are personal data and must be handled accordingly.

Where consent is relied upon for social media publication:

For an adult, consent must normally be provided by the individual where they have capacity to make the particular decision.

A family member, next of kin or representative must not be treated as automatically having authority to provide consent on behalf of an adult. Where another person purports to make a decision on the individual’s behalf, staff must establish and record the legal authority under which that person is acting and seek appropriate advice where necessary.

Where there is doubt about an adult’s capacity to make the particular decision, the Mental Capacity Act 2005 and the organisation’s Mental Capacity Policy must be followed before any information is published.

Staff photographs, recordings or personal information must not be published without an appropriate lawful basis and compliance with applicable data protection requirements.

Confidentiality obligations continue after a member of staff leaves employment and after an individual ceases to receive a service.

4.5 Safeguarding and Online Protection

Online activity and social media may give rise to safeguarding concerns, including:

Where a member of staff becomes aware of an allegation, evidence or reasonable suspicion of abuse, neglect, exploitation or improper treatment arising through social media or other online activity, they must:

Staff must not promise confidentiality to a person making a safeguarding disclosure. Information must be shared on a lawful, necessary and proportionate basis with persons or agencies who need the information in order to protect the individual or another person.

Where safeguarding action involves sharing personal information, staff must follow data protection requirements; however, data protection legislation must not be used as a reason for failing to share information where sharing is necessary and lawful to protect a person from harm.

4.6 Professional Conduct and Professional Boundaries

Staff must maintain the standards of conduct required by their employment, their professional registration where applicable, the current Code of Professional Practice for Social Care Workers and the policies of {{org_field_name}}.

These responsibilities apply to relevant online conduct both during and outside working hours.

Staff must:

Staff must not:

Where online conduct raises a legitimate concern about safeguarding, confidentiality, fitness to practise, professional boundaries, the safety or well-being of individuals, or the employee’s suitability to undertake their role, the matter will be managed under the appropriate organisational procedure and, where required, reported to the relevant statutory or professional body.

4.7 Reporting and Managing Breaches

Any actual or suspected breach of this policy must be reported without delay to the Registered Manager or other person designated under the organisation’s reporting arrangements.

Examples include:

The Registered Manager or designated person must ensure that appropriate immediate action is taken to protect individuals, secure accounts or information, preserve relevant evidence and prevent further unauthorised disclosure or harm.

Where the matter constitutes or may constitute a safeguarding concern, the Safeguarding Policy and Wales Safeguarding Procedures must be followed.

Where the incident falls within an event which the service provider or Responsible Individual is required to notify to Care Inspectorate Wales under the Regulated Services (Service Providers and Responsible Individuals) (Wales) Regulations 2017, as amended, the appropriate CIW notification must be made without delay and in the form and manner required by CIW.

This includes, where applicable, abuse or an allegation of abuse involving the service provider, a member of staff or a volunteer, allegations of misconduct by a member of staff, incidents reported to the police and other events specified in the Regulations.

A safeguarding concern must not automatically be treated as requiring a CIW notification where it does not fall within a statutory notification category. The Registered Manager and Responsible Individual must determine and document whether a notification is required by reference to the applicable Regulations and current CIW requirements.

Where staff conduct is implicated, the matter must be considered under the organisation’s disciplinary procedure. Where appropriate, consideration must also be given to referral or notification to the Disclosure and Barring Service, Social Care Wales, the Nursing and Midwifery Council, another relevant professional regulator or the police.

All relevant decisions, actions, referrals and notifications must be recorded.

4.8 Personal Data Breaches

Any actual or suspected loss, unauthorised disclosure, alteration, destruction of, or unauthorised access to personal data through social media or another online platform must be treated as a potential personal data breach and reported immediately in accordance with the organisation’s Data Protection and Personal Data Breach Procedure.

Examples include:

On receiving a report, the organisation must take prompt action to:

Where the personal data breach is likely to result in a risk to the rights and freedoms of individuals, {{org_field_name}} must notify the Information Commissioner’s Office without undue delay and, where feasible, within 72 hours after becoming aware of the breach.

Where the breach is likely to result in a high risk to an individual’s rights and freedoms, the affected individual must also be informed without undue delay unless a relevant legal exception applies.

All personal data breaches must be recorded, including breaches which do not meet the threshold for notification to the Information Commissioner’s Office.

Where the same incident also gives rise to a safeguarding concern, police matter, professional regulatory issue or CIW-notifiable event, the relevant reporting procedure must be followed in parallel.

5. Staff Training and Awareness

All staff must receive information, instruction and training appropriate to their role so that they understand and can comply with this policy.

As part of induction and ongoing training, relevant staff must be made aware of:

Training and staff guidance must be reviewed and updated when relevant legislation, regulatory requirements, Social Care Wales Codes, safeguarding procedures, data protection requirements or organisational arrangements change.

Understanding and compliance with this policy must be reinforced through supervision, management oversight and, where relevant, appraisal.

{{org_field_name}} must maintain appropriate records of training provided to staff.

6. Record-Keeping and Documentation

Records created under this policy must be accurate, complete, secure, accessible only to authorised persons and retained in accordance with the organisation’s retention arrangements and applicable data protection requirements.

Records must include, where applicable:

Records containing personal information must not be retained for longer than necessary and must be disposed of securely when the applicable retention period expires.

7. Related Policies

This policy must be read in conjunction with, where applicable:

8. Policy Review

This policy will be reviewed annually or sooner if legislation, CIW regulations, or operational needs change. Updates will ensure continued compliance and best practices.


Responsible Person: {{org_field_registered_manager_first_name}} {{org_field_registered_manager_last_name}}
Reviewed on:
{{last_update_date}}
Next Review Date:
{{next_review_date}}
Copyright © {{current_year}} – {{org_field_name}}. All rights reserved.

Leave a Reply

Your email address will not be published. Required fields are marked *