{{org_field_logo}}
{{org_field_name}}
Registration Number: {{org_field_registration_no}}
Using Social Media Platforms Policy
1. Purpose
The purpose of this policy is to provide clear requirements for the safe, lawful and responsible use of social media, online communication platforms and messaging applications by staff, individuals receiving care and support, and other persons connected with {{org_field_name}}.
Social media and digital communication can support communication, participation, relationships and engagement. Their use can also create risks relating to confidentiality, data protection, safeguarding, professional boundaries, dignity, privacy and the safety and well-being of individuals.
{{org_field_name}} will ensure that the use of social media in connection with the service is consistent with applicable Welsh social care legislation, data protection legislation, safeguarding requirements, Care Inspectorate Wales requirements and the Codes of Professional Practice issued by Social Care Wales.
This policy is intended to ensure that:
- the privacy, dignity, confidentiality, rights and well-being of individuals receiving care and support are protected;
- personal information is processed lawfully, fairly, transparently and securely;
- individuals are supported to exercise choice, control and independence in relation to their use of social media, subject to proportionate and lawful safeguarding measures;
- staff maintain appropriate professional boundaries and standards of conduct when using social media or communicating online;
- actual or suspected abuse, neglect, improper treatment, exploitation or other safeguarding concerns arising through online activity are identified, reported and acted upon appropriately;
- personal data breaches are identified, contained, assessed, recorded and reported where legally required; and
- the service complies with the Regulation and Inspection of Social Care (Wales) Act 2016, the regulations made under that Act, applicable statutory guidance and relevant professional standards.
2. Scope
This policy applies to:
- All employees of {{org_field_name}}, including permanent, temporary, and agency staff.
- Service users and their families when using social media in connection with {{org_field_name}}.
- Visitors, contractors, and external professionals who interact with the care home online.
- Official social media accounts representing {{org_field_name}}.
This policy covers all social media platforms, including but not limited to:
- Facebook, Twitter, Instagram, LinkedIn, TikTok, YouTube, and WhatsApp.
- Online forums, blogs, and review websites.
- Messaging apps used for work-related communication.
3. Legal and Regulatory Framework
This policy must be implemented in accordance with applicable legislation, statutory guidance and regulatory requirements, including:
- The Regulation and Inspection of Social Care (Wales) Act 2016, as amended, which provides the principal statutory framework for the regulation and inspection of regulated care services in Wales.
- The Regulated Services (Service Providers and Responsible Individuals) (Wales) Regulations 2017, as amended, including requirements relating to the provision of the service, policies and procedures, dignity and confidentiality, safeguarding, staff conduct, staff information, record keeping and notifications to Care Inspectorate Wales.
- The Regulated Services (Service Providers and Responsible Individuals) (Wales) (Amendment) Regulations 2024, where applicable.
- Welsh Government statutory guidance for service providers and responsible individuals on meeting the service standard regulations for care home services, which must be taken into account when meeting the requirements of the Regulations.
- The Social Services and Well-being (Wales) Act 2014, including the duties and principles relating to well-being, voice and control, safeguarding and protection from abuse, neglect and harm.
- The Mental Capacity Act 2005 and its Code of Practice, where a question arises about an adult’s capacity to make a particular decision concerning social media, photographs, recordings, disclosure of information or other relevant matters.
- The UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, as amended, including requirements relating to lawful, fair and transparent processing; data minimisation; security; individuals’ information rights; special category personal data; accountability; and personal data breach management.
- The Equality Act 2010, where decisions or restrictions concerning social media use may affect an individual because of a protected characteristic or require reasonable adjustment.
- The Human Rights Act 1998, including the need to respect individuals’ rights to private and family life and freedom of expression, subject to lawful and proportionate restrictions where these are necessary to protect the rights and safety of others.
- The current Code of Professional Practice for Social Care Workers and the Code of Professional Practice for Social Care Employers issued by Social Care Wales, together with relevant current practice guidance.
- The Wales Safeguarding Procedures, which must be followed where social media or online activity gives rise to an allegation, evidence or suspicion of abuse, neglect, exploitation, improper treatment or other safeguarding concern.
- Relevant requirements, guidance and notification arrangements published by Care Inspectorate Wales (CIW).
This policy must be read together with the organisation’s safeguarding, confidentiality and data protection, professional boundaries, disciplinary, whistleblowing and incident-reporting procedures.
4. Social Media Management in the Care Home
4.1 Official Social Media Accounts
- All official social media accounts operated in the name of {{org_field_name}} must be authorised by the service provider or a person formally authorised by the service provider.
- Responsibility for administration, access, security, monitoring and publication of content must be clearly allocated.
- Access to official accounts must be restricted to authorised persons. Login credentials must be protected and must not be shared with unauthorised persons.
- Content published through an official account must be lawful, accurate, respectful and consistent with the values, statement of purpose and policies of {{org_field_name}}.
- Personal or confidential information relating to an individual receiving care and support, a member of staff or another identifiable person must not be published unless {{org_field_name}} has identified and documented an appropriate lawful basis for the processing and complied with all other applicable UK GDPR and Data Protection Act 2018 requirements.
- Where information constitutes special category personal data, {{org_field_name}} must also identify and document an applicable condition for processing that information before publication.
- Where {{org_field_name}} relies upon consent for the publication of photographs, recordings or other personal information, the consent must be freely given, specific, informed, unambiguous and capable of being withdrawn. Evidence of the consent and the information provided to the person at the time consent was obtained must be retained.
- Consent to publication must be separate from consent to receive care and support. An individual must not be disadvantaged or receive a different standard of care because they decline or withdraw consent for social media use.
- Before publishing photographs, video, audio or other information about an individual receiving care and support, staff must consider whether the proposed material could identify the person directly or indirectly, including through the setting, accompanying information or other contextual details.
- Publication must cease where consent relied upon as the lawful basis is withdrawn. Any request for removal of existing material must be acted upon promptly, subject to any legal limitations on removing information already copied, shared or otherwise disseminated by third parties.
- Social media must never be used to disclose confidential care records, health information, safeguarding information or other sensitive information unless disclosure is specifically required or permitted by law and the relevant organisational procedure has been followed.
4.2 Personal Use of Social Media by Staff
Staff must ensure that their use of personal social media accounts and other online platforms complies with their professional responsibilities, this policy, applicable confidentiality and safeguarding requirements and the current Code of Professional Practice for Social Care Workers.
Staff must not, through a personal or professional account:
- disclose confidential or personal information obtained through their employment unless the disclosure is lawfully authorised and required as part of their role;
- post, share, forward, comment upon or otherwise distribute photographs, video recordings, audio recordings or information relating to an individual receiving care and support unless this forms part of an authorised work activity and all relevant consent, data protection and organisational requirements have been met;
- discuss individual cases, care arrangements, safeguarding matters, incidents or other confidential matters on social media, including in apparently private or closed online groups;
- post content that constitutes abuse, harassment, discrimination, bullying or unlawful conduct;
- engage in online conduct which could reasonably raise concerns about their suitability to work in social care;
- use information gained through their professional role to locate, contact or monitor individuals receiving care and support or their families for personal purposes; or
- use personal social media accounts to establish inappropriate relationships with individuals receiving care and support or their families.
Staff must maintain appropriate professional boundaries online as well as in person. Unless contact is expressly authorised as part of the person’s role and is consistent with organisational policy, staff must not initiate or accept personal social media connections, friend requests, follows, private messages or similar personal online relationships with individuals whom they support or with their family members.
Where an individual or family member attempts to establish personal online contact with a member of staff, the member of staff must maintain professional boundaries and seek advice from their line manager where necessary.
Staff remain responsible for their online conduct outside working hours. Personal online activity may be considered under the organisation’s disciplinary or capability procedures where there is a legitimate connection with the person’s employment, professional responsibilities, safeguarding obligations or suitability to work in social care.
Any member of staff who becomes aware through social media of information suggesting that an individual may be experiencing abuse, neglect, exploitation, improper treatment or other risk of harm must act immediately in accordance with the Safeguarding Policy and Wales Safeguarding Procedures.
4.3 Social Media Use by Individuals Receiving Care and Support
Individuals receiving care and support have the right, so far as reasonably practicable, to access and use social media, digital communication and the internet in accordance with their wishes and preferences.
Staff must support individuals to exercise choice and control over their online activity and must not impose restrictions merely because a person receives care and support, is older, has a disability, has a diagnosis or is considered vulnerable.
Where an individual’s social media or online activity presents an identifiable risk to their safety or well-being, or to the safety or rights of another person, an appropriate person-centred risk assessment must be undertaken. The assessment must:
- involve the individual as far as possible;
- take account of the individual’s wishes, views, communication needs and personal outcomes;
- identify the nature and likelihood of the specific risk;
- consider less restrictive ways of reducing or managing the risk;
- support positive risk-taking and independence wherever reasonably possible;
- identify any safeguarding action required; and
- be recorded and reviewed when circumstances change.
Staff should provide proportionate support where required to help individuals understand matters such as:
- privacy and account-security settings;
- scams and financial exploitation;
- cyberbullying and harassment;
- inappropriate or unwanted contact;
- sharing personal information, photographs and location information;
- fraudulent links or messages; and
- how to report or block inappropriate contact.
A diagnosis of dementia, cognitive impairment, learning disability, mental disorder or other condition must not in itself be treated as evidence that an adult lacks capacity to make decisions about social media.
Where there is a reasonable doubt about an adult’s capacity to make a specific decision relating to social media, online communication or disclosure of personal information, staff must follow the Mental Capacity Act 2005 and the organisation’s Mental Capacity Policy.
Any assessment of capacity must relate to the specific decision that needs to be made at the relevant time. All practicable steps must first be taken to support the person to make their own decision.
Where a person lacks capacity in relation to the specific decision, any decision made or action taken on their behalf must comply with the Mental Capacity Act 2005, including the requirement to act in the person’s best interests and to consider the least restrictive option.
Any restriction on an individual’s access to social media or digital communication must have a lawful basis, be necessary and proportionate to the identified risk, and be documented and reviewed.
4.4 Privacy, Confidentiality and Data Protection
All use of personal information through social media must comply with the UK GDPR, the Data Protection Act 2018, the organisation’s Data Protection and Confidentiality Policy and any applicable privacy notice.
Staff must not disclose personal or confidential information obtained through their role unless there is a lawful and legitimate reason to do so.
Before personal information is processed for social media purposes, {{org_field_name}} must:
- identify the specific purpose for which the information will be used;
- identify and document an appropriate lawful basis under the UK GDPR;
- identify any additional condition required where special category personal data is involved;
- ensure the proposed use is necessary, proportionate and compatible with the purpose explained to the individual;
- provide the individual with appropriate privacy information;
- collect no more personal information than is necessary;
- ensure appropriate security arrangements are in place; and
- retain evidence demonstrating compliance.
Photographs, video recordings, audio recordings and other material in which an individual is identifiable are personal data and must be handled accordingly.
Where consent is relied upon for social media publication:
- consent must be obtained before publication;
- the individual must understand what information will be published, where it will be published, why it will be published and who may be able to view or share it;
- consent must be freely given, specific, informed and unambiguous;
- the person must be told that they may withdraw consent;
- refusal or withdrawal of consent must not affect the care and support provided to them; and
- a record of the consent must be retained.
For an adult, consent must normally be provided by the individual where they have capacity to make the particular decision.
A family member, next of kin or representative must not be treated as automatically having authority to provide consent on behalf of an adult. Where another person purports to make a decision on the individual’s behalf, staff must establish and record the legal authority under which that person is acting and seek appropriate advice where necessary.
Where there is doubt about an adult’s capacity to make the particular decision, the Mental Capacity Act 2005 and the organisation’s Mental Capacity Policy must be followed before any information is published.
Staff photographs, recordings or personal information must not be published without an appropriate lawful basis and compliance with applicable data protection requirements.
Confidentiality obligations continue after a member of staff leaves employment and after an individual ceases to receive a service.
4.5 Safeguarding and Online Protection
Online activity and social media may give rise to safeguarding concerns, including:
- cyberbullying, intimidation or harassment;
- grooming or sexual exploitation;
- financial abuse, fraud or scams;
- coercion or controlling behaviour;
- threats, hate crime or discriminatory abuse;
- inappropriate relationships or contact;
- sharing of intimate or exploitative images;
- impersonation or identity theft;
- disclosure of an individual’s location or other information that may place them at risk; and
- abuse, neglect or improper treatment disclosed or identified through messages, photographs, recordings or other online content.
Where a member of staff becomes aware of an allegation, evidence or reasonable suspicion of abuse, neglect, exploitation or improper treatment arising through social media or other online activity, they must:
- take any immediate and proportionate action necessary to protect the individual or other persons from immediate harm;
- report the concern without delay in accordance with the organisation’s Safeguarding Policy;
- preserve relevant information or evidence where it is safe and lawful to do so, without conducting their own safeguarding investigation;
- make or support the making of appropriate safeguarding referrals in accordance with the Wales Safeguarding Procedures and local safeguarding arrangements;
- involve the police or other emergency services where there is an immediate danger, suspected crime or other circumstance requiring their involvement;
- ensure that the substance of the allegation or evidence, action taken, decisions made and referrals made are accurately recorded; and
- ensure that any required notification to Care Inspectorate Wales is made in accordance with the applicable Regulations and CIW notification requirements.
Staff must not promise confidentiality to a person making a safeguarding disclosure. Information must be shared on a lawful, necessary and proportionate basis with persons or agencies who need the information in order to protect the individual or another person.
Where safeguarding action involves sharing personal information, staff must follow data protection requirements; however, data protection legislation must not be used as a reason for failing to share information where sharing is necessary and lawful to protect a person from harm.
4.6 Professional Conduct and Professional Boundaries
Staff must maintain the standards of conduct required by their employment, their professional registration where applicable, the current Code of Professional Practice for Social Care Workers and the policies of {{org_field_name}}.
These responsibilities apply to relevant online conduct both during and outside working hours.
Staff must:
- respect the dignity, privacy, confidentiality and rights of individuals receiving care and support;
- maintain appropriate professional boundaries with individuals and their families and carers;
- communicate respectfully and professionally;
- protect confidential information obtained through their work;
- avoid online conduct which could reasonably raise concerns about their suitability to work in social care; and
- report online safeguarding concerns in accordance with this policy and the Safeguarding Policy.
Staff must not:
- post abusive, discriminatory, threatening, humiliating, harassing or otherwise unlawful material relating to individuals, colleagues or other persons;
- disclose confidential information about individuals, colleagues or the operation of the service without lawful authority;
- use social media to bully, intimidate, exploit or harass another person;
- establish inappropriate personal or sexual relationships with individuals receiving care and support or exploit professional relationships through online contact;
- represent personal opinions as the official views of {{org_field_name}} unless authorised to do so; or
- make unauthorised statements on behalf of {{org_field_name}}.
Where online conduct raises a legitimate concern about safeguarding, confidentiality, fitness to practise, professional boundaries, the safety or well-being of individuals, or the employee’s suitability to undertake their role, the matter will be managed under the appropriate organisational procedure and, where required, reported to the relevant statutory or professional body.
4.7 Reporting and Managing Breaches
Any actual or suspected breach of this policy must be reported without delay to the Registered Manager or other person designated under the organisation’s reporting arrangements.
Examples include:
- unauthorised disclosure of personal or confidential information;
- publication of photographs, video or information without the required authority;
- inappropriate online contact or breach of professional boundaries;
- abusive, discriminatory, threatening or exploitative online conduct;
- unauthorised access to an official social media account;
- loss or compromise of account credentials;
- safeguarding concerns arising from social media;
- actual or suspected personal data breaches; and
- online conduct which raises concerns about a worker’s fitness to practise or suitability to work in social care.
The Registered Manager or designated person must ensure that appropriate immediate action is taken to protect individuals, secure accounts or information, preserve relevant evidence and prevent further unauthorised disclosure or harm.
Where the matter constitutes or may constitute a safeguarding concern, the Safeguarding Policy and Wales Safeguarding Procedures must be followed.
Where the incident falls within an event which the service provider or Responsible Individual is required to notify to Care Inspectorate Wales under the Regulated Services (Service Providers and Responsible Individuals) (Wales) Regulations 2017, as amended, the appropriate CIW notification must be made without delay and in the form and manner required by CIW.
This includes, where applicable, abuse or an allegation of abuse involving the service provider, a member of staff or a volunteer, allegations of misconduct by a member of staff, incidents reported to the police and other events specified in the Regulations.
A safeguarding concern must not automatically be treated as requiring a CIW notification where it does not fall within a statutory notification category. The Registered Manager and Responsible Individual must determine and document whether a notification is required by reference to the applicable Regulations and current CIW requirements.
Where staff conduct is implicated, the matter must be considered under the organisation’s disciplinary procedure. Where appropriate, consideration must also be given to referral or notification to the Disclosure and Barring Service, Social Care Wales, the Nursing and Midwifery Council, another relevant professional regulator or the police.
All relevant decisions, actions, referrals and notifications must be recorded.
4.8 Personal Data Breaches
Any actual or suspected loss, unauthorised disclosure, alteration, destruction of, or unauthorised access to personal data through social media or another online platform must be treated as a potential personal data breach and reported immediately in accordance with the organisation’s Data Protection and Personal Data Breach Procedure.
Examples include:
- posting information, photographs or recordings to the wrong account;
- publishing information about the wrong individual;
- accidental disclosure of confidential information in a post, comment or message;
- sending personal information to an unintended recipient;
- loss or compromise of a social media password;
- unauthorised access to an official account;
- hacking of an account containing personal information; and
- inappropriate sharing, copying or forwarding of personal information.
On receiving a report, the organisation must take prompt action to:
- contain the breach and prevent further disclosure where possible;
- establish what personal data is involved;
- identify the individuals affected;
- assess the likely consequences and level of risk to individuals’ rights and freedoms;
- document the circumstances of the breach, its effects and the remedial action taken; and
- determine whether notification to the Information Commissioner’s Office and/or affected individuals is legally required.
Where the personal data breach is likely to result in a risk to the rights and freedoms of individuals, {{org_field_name}} must notify the Information Commissioner’s Office without undue delay and, where feasible, within 72 hours after becoming aware of the breach.
Where the breach is likely to result in a high risk to an individual’s rights and freedoms, the affected individual must also be informed without undue delay unless a relevant legal exception applies.
All personal data breaches must be recorded, including breaches which do not meet the threshold for notification to the Information Commissioner’s Office.
Where the same incident also gives rise to a safeguarding concern, police matter, professional regulatory issue or CIW-notifiable event, the relevant reporting procedure must be followed in parallel.
5. Staff Training and Awareness
All staff must receive information, instruction and training appropriate to their role so that they understand and can comply with this policy.
As part of induction and ongoing training, relevant staff must be made aware of:
- confidentiality and data protection responsibilities;
- the safe and lawful use of personal information, photographs, video and audio recordings;
- the organisation’s arrangements for obtaining and recording consent where consent is relied upon;
- the Mental Capacity Act 2005 and the distinction between an individual’s capacity to make a specific decision and another person’s authority to act on their behalf, where relevant to the staff member’s role;
- safeguarding risks associated with social media and online communication;
- the action to take where online abuse, exploitation, grooming, fraud or other safeguarding concerns are identified;
- professional boundaries in online relationships;
- the organisation’s rules relating to personal and official social media use;
- how to identify and immediately report a suspected personal data breach;
- the circumstances in which information may need to be shared to safeguard an individual;
- the current Code of Professional Practice for Social Care Workers and relevant Social Care Wales practice guidance; and
- the consequences of breaching confidentiality, safeguarding obligations, professional boundaries or this policy.
Training and staff guidance must be reviewed and updated when relevant legislation, regulatory requirements, Social Care Wales Codes, safeguarding procedures, data protection requirements or organisational arrangements change.
Understanding and compliance with this policy must be reinforced through supervision, management oversight and, where relevant, appraisal.
{{org_field_name}} must maintain appropriate records of training provided to staff.
6. Record-Keeping and Documentation
Records created under this policy must be accurate, complete, secure, accessible only to authorised persons and retained in accordance with the organisation’s retention arrangements and applicable data protection requirements.
Records must include, where applicable:
- consent obtained for the publication of photographs, recordings or other personal information, including what the person agreed to, when consent was obtained and the information provided to them;
- withdrawal of consent and action taken following withdrawal;
- assessments or decisions concerning an individual’s capacity where these are relevant to a proposed social media activity;
- details of any legal authority relied upon where another person acts on behalf of an adult;
- relevant risk assessments concerning identified online or social media risks;
- safeguarding allegations, evidence or concerns arising through social media;
- immediate protective action taken following a safeguarding concern;
- safeguarding referrals and the outcome of those referrals where known;
- incidents and breaches of this policy;
- personal data breaches, including the facts relating to the breach, its effects, the risk assessment undertaken and remedial action taken;
- decisions as to whether a personal data breach required notification to the Information Commissioner’s Office or an affected individual;
- notifications made to Care Inspectorate Wales and the reason for the notification;
- decisions that a particular incident did not meet a statutory CIW notification requirement where recording the rationale is necessary;
- referrals or notifications made to the police, Disclosure and Barring Service, Social Care Wales or another professional regulator; and
- relevant staff training.
Records containing personal information must not be retained for longer than necessary and must be disposed of securely when the applicable retention period expires.
7. Related Policies
This policy must be read in conjunction with, where applicable:
- Confidentiality and Data Protection Policy;
- Personal Data Breach Procedure;
- Safeguarding Adults from Abuse, Neglect and Improper Treatment Policy;
- Mental Capacity Act and Deprivation of Liberty Safeguards Policy;
- Professional Boundaries Policy;
- Staff Conduct Policy;
- Whistleblowing Policy;
- Disciplinary Policy and Procedure;
- Complaints Policy and Procedure;
- Record Keeping and Information Governance Policy; and
- Incident Reporting and CIW Notification Procedure.
8. Policy Review
This policy will be reviewed annually or sooner if legislation, CIW regulations, or operational needs change. Updates will ensure continued compliance and best practices.
Responsible Person: {{org_field_registered_manager_first_name}} {{org_field_registered_manager_last_name}}
Reviewed on: {{last_update_date}}
Next Review Date: {{next_review_date}}
Copyright © {{current_year}} – {{org_field_name}}. All rights reserved.