{{org_field_logo}}

{{org_field_name}}

Registration Number: {{org_field_registration_no}}


Information Sharing with Third-Party Organisations Policy

1. Purpose

The purpose of this policy is to set out how {{org_field_name}} will share personal information lawfully, fairly, transparently, securely and proportionately with third-party organisations in connection with the provision, commissioning, regulation and oversight of domiciliary support services in Wales.

This policy supports compliance with the UK General Data Protection Regulation, the Data Protection Act 2018 as amended, the Data (Use and Access) Act 2025, the Regulation and Inspection of Social Care (Wales) Act 2016, the Regulated Services (Service Providers and Responsible Individuals) (Wales) Regulations 2017 as amended, the Social Services and Well-being (Wales) Act 2014, the common law duty of confidentiality and other applicable legal and professional duties.

The policy is intended to ensure that information is shared when it is necessary to protect an individual, provide safe and effective care and support, meet a legal or regulatory duty, support multi-agency working or fulfil another lawful purpose. It also ensures that information is not shared unnecessarily, excessively, inaccurately or with a person who is not authorised to receive it.

Information sharing is essential for effective service delivery, safeguarding, and multi-agency collaboration, but it must be managed in a way that protects service user confidentiality, ensures legal compliance, and maintains trust. This policy outlines when, how, and why information may be shared and how we ensure safe, lawful, and efficient handling of data.

This policy does not prevent necessary and proportionate information sharing. Data protection law must not be used as a reason to withhold information where sharing is necessary to protect an individual from abuse, neglect, improper treatment or serious harm, or where another lawful requirement applies. Staff must nevertheless record the reason for sharing, the information shared, the recipient and the lawful authority relied upon.

2. Scope

This policy applies to:

This policy applies to all formats of data, including written, verbal, electronic, and digital communications.

This policy applies to one-off disclosures, regular or systematic data-sharing arrangements, joint working arrangements, statutory notifications, referrals, telephone discussions, meetings, electronic communications, paper records, photographs, video or audio recordings and access to electronic care-record systems.

This policy applies whether {{org_field_name}} is acting as a controller, joint controller or processor. The organisation’s role must be established before any new regular or significant data-sharing arrangement begins.

Anonymised information that cannot reasonably identify an individual is not personal data. Pseudonymised information remains personal data where the individual can be re-identified using additional information.

3. Legal and Regulatory Framework

Information sharing by {{org_field_name}} will be undertaken in accordance with all applicable legislation, statutory guidance, regulatory requirements and professional standards, including:

Where another enactment, court order, regulatory requirement or professional duty requires or permits disclosure, the relevant authority must be identified and recorded before the disclosure is made, unless an emergency makes prior documentation impracticable.

4. Principles of Information Sharing

When sharing information with third-party organisations, {{org_field_name}} adheres to the following principles:

5. Categories of Information

Information shared under this policy may include:

Health information, information concerning racial or ethnic origin, religious or philosophical beliefs, sexual life or sexual orientation, biometric data used for identification and certain other sensitive information are special category personal data and require both an Article 6 lawful basis and an Article 9 condition.

6. When Information May Be Shared

6.1 Safeguarding and Protection of Individuals

Information must be shared promptly with the relevant local authority safeguarding team, police, emergency service, CIW or other appropriate agency where this is necessary and proportionate to:

Consent is not required where another lawful basis applies and seeking consent would place a person at greater risk, prejudice an investigation, cause an unreasonable delay or prevent the organisation from fulfilling a legal or safeguarding duty.

Wherever it is safe and appropriate, the individual should be informed that information is being shared, the reason for sharing and the recipient. Any decision not to inform the individual must be recorded with reasons.

Staff must not promise absolute confidentiality where information indicates that an individual or another person may be at risk.

Safeguarding disclosures must be limited to relevant information, shared with an authorised person and recorded in accordance with the Safeguarding Policy and Wales Safeguarding Procedures.

6.2 Care Provision, Care Planning and Multi-Agency Working

Information may be shared with health and social care professionals, commissioners and other authorised partners where this is necessary to assess, plan, provide, review, coordinate or monitor the individual’s care and support.

This may include sharing with:

Before sharing, staff must identify the applicable Article 6 lawful basis. Where health or other special category information is involved, staff must also identify an appropriate Article 9 condition and, where required, a condition under the Data Protection Act 2018.

Consent will only be relied upon where it is the most appropriate lawful basis and can be freely given, specific, informed, unambiguous and capable of withdrawal. The provision of necessary care and support must not normally be made conditional upon consent to unrelated or unnecessary information sharing.

Individuals must, where practicable, be informed about routine care-related sharing through the organisation’s privacy notice, written guide, service agreement and discussions about their personal plan.

6.3 Regulatory, Contractual and Legal Requirements

Information may be shared where {{org_field_name}} is required or lawfully requested to provide it to:

Staff must not assume that every request from an official body is automatically lawful. Unless the disclosure is an emergency or a clear statutory notification, the identity and authority of the requester, the purpose of the request, the legal power relied upon and the scope of the information requested must be verified.

Court orders, production orders, warrants, statutory notices and other compulsory requests must be referred immediately to the registered manager or Data Protection Lead. Legal advice must be obtained where the scope or validity of the request is unclear.

Statutory notifications to CIW must be submitted without delay, normally within 24 hours where required by the applicable regulations and guidance, through CIW Online and in the form required by CIW.

6.4 Emergencies and Vital Interests

In an emergency, relevant personal information may be shared without prior consent where this is necessary to protect the life, physical safety or vital interests of the individual or another person.

Staff must:

A best-interests decision under the Mental Capacity Act 2005 may be required where an individual lacks capacity to make the relevant decision. However, “best interests” is not itself a complete data protection lawful basis; the organisation must also identify the applicable data protection basis and confidentiality justification.

6.5 Research, Audit, Service Evaluation and Training

Wherever practicable, information used for research, audit, service evaluation or training will be anonymised so that individuals cannot be identified.

Pseudonymised information remains personal data and must be protected accordingly.

Identifiable information may only be used where:

Explicit consent is not the only possible legal basis for research or audit. The correct basis must be determined according to the nature and purpose of the activity.

6.6 Requests from the Police and Other Law-Enforcement Bodies

A request from the police does not automatically require disclosure. Staff must obtain a written request wherever practicable and confirm:

Requests must be referred to the registered manager or Data Protection Lead unless an immediate disclosure is necessary to prevent serious harm or respond to an emergency.

All disclosures and refusals must be documented.

6.7 Complaints, Investigations and Legal Claims

Information may be shared where necessary to investigate or respond to a complaint, concern, claim, disciplinary matter, safeguarding allegation, insurance matter or legal proceeding.

Wherever practicable, individuals will be informed where details of their complaint need to be disclosed to another person or organisation. Confidentiality must be maintained unless disclosure is necessary for a fair investigation, safeguarding, legal compliance or another overriding lawful purpose.

7. Consent, Capacity and Representatives

Consent is only one of several lawful bases for processing and sharing personal information. Staff must not seek consent where the organisation is relying on a legal obligation, safeguarding duty, vital interests, contractual necessity, public task, recognised legitimate interest, legitimate interest or another lawful basis.

Where consent is relied upon, it must be:

The consent record must include:

Where a person lacks capacity to make the relevant decision, staff must follow the Mental Capacity Act 2005. Capacity is decision-specific and must not be assumed solely because of a diagnosis, disability, communication difficulty or age.

A relative, friend or informal carer does not automatically have authority to consent to information sharing on behalf of an adult. Authority must be confirmed, for example through a valid health and welfare lasting power of attorney, court-appointed deputyship, other legal authority or a best-interests decision made in accordance with the Mental Capacity Act 2005.

For children, staff must consider the child’s age, understanding and competence, parental responsibility, safeguarding needs and any applicable court order. The child’s views must be sought and respected where appropriate.

Where an individual objects to sharing and consent is not the lawful basis, the objection must be considered and recorded. Information may still be shared where another lawful and overriding basis applies.

8. Lawful Basis and Decision-Making

Before personal data is shared, the person authorising the disclosure must identify and record at least one applicable lawful basis under Article 6 of the UK GDPR.

Depending on the circumstances, this may include:

Where special category personal data is shared, an Article 9 condition must also be identified. Conditions commonly relevant to domiciliary support services may include:

Where criminal offence information is involved, staff must also confirm that processing is authorised under Article 10 of the UK GDPR and the Data Protection Act 2018.

The lawful basis and relevant condition must be recorded before sharing, unless an emergency makes this impracticable. In an emergency, the record must be completed as soon as possible afterwards.

9. Secure Methods of Sharing Information

Personal information must be shared using a method appropriate to the sensitivity, volume, urgency and risk of the information.

Staff must:

Information must not automatically be sent using an “NHS-approved” or local-authority system unless {{org_field_name}} is authorised to use that system. The organisation must specify the actual approved systems in its operational procedures.

Any disclosure involving a large volume of records, highly sensitive information, a new technology, systematic monitoring or a new regular sharing arrangement must be referred to the Data Protection Lead for consideration of a Data Protection Impact Assessment.

10. Data-Sharing Agreements and Third-Party Due Diligence

Regular, systematic, large-scale or high-risk information sharing must be governed by a written data-sharing agreement, information-sharing protocol, joint-controller arrangement or processor contract, as appropriate.

The agreement must address:

Before appointing an organisation to process personal data on behalf of {{org_field_name}}, proportionate due diligence must be completed concerning its security, confidentiality, resilience, staff controls, breach arrangements, sub-processors, data location and ability to comply with data protection obligations.

Data-sharing agreements must be reviewed periodically and whenever the purpose, data, participants, technology or risk changes.

11. Managing Requests and Disclosures

All requests for personal information from third parties must be assessed before information is disclosed.

The member of staff receiving the request must record:

Requests involving safeguarding, law enforcement, litigation, regulatory investigations, large volumes of records, staff information, confidential complaints or uncertainty about legal authority must be referred to the registered manager or Data Protection Lead.

Approval must be based on the risk and nature of the disclosure, not merely on whether the information is described as “sensitive”.

The organisation must keep a disclosure record showing:

12. Individual Rights and Data Protection Complaints

Individuals may exercise rights provided by data protection legislation, including the rights of access, rectification, erasure, restriction, objection and data portability where applicable.

Any request concerning an individual’s personal data must be sent immediately to the Data Protection Lead and handled under the Data Subject Rights Procedure. Staff must not delay a request because the individual has not used a particular form or referred to data protection legislation.

Requests from representatives must be supported by appropriate evidence of authority. Information about another person must not be disclosed unless disclosure is lawful and appropriate.

{{org_field_name}} will maintain a documented data protection complaints process. A person may make a complaint verbally or in writing about how their personal information has been used, shared, secured or handled.

The organisation will:

Records of data protection complaints, investigations, outcomes and remedial action will be retained and reviewed to identify patterns and improvements.

13. Personal Data Breaches

A personal data breach includes accidental or unlawful destruction, loss, alteration, unauthorised disclosure of or access to personal data. It includes information sent to the wrong recipient, lost records, unauthorised system access, insecure disposal, malware, theft, verbal disclosure and loss of availability.

All suspected or confirmed personal data breaches must be reported immediately to the registered manager and Data Protection Lead using the organisation’s breach-reporting process. Staff must not investigate the matter independently, conceal an error or contact affected individuals without authorisation.

Immediate action must be taken to:

The Data Protection Lead will determine whether the breach must be reported to the Information Commissioner’s Office. Where notification is required, it must be made without undue delay and, where feasible, within 72 hours of becoming aware of the breach.

Where the breach is likely to result in a high risk to affected individuals, those individuals must be informed without undue delay unless a lawful exception applies.

All breaches must be entered in the breach register, including breaches that are not reported to the Information Commissioner’s Office. The record must include the facts, effects, risk assessment, decision, notifications, containment and corrective action.

A personal data breach must also be considered under the organisation’s safeguarding, incident-reporting, duty of candour, complaints and CIW notification procedures.

14. Accuracy, Retention and Disposal

Before information is shared, reasonable steps must be taken to ensure it is accurate, current, relevant and not misleading.

Where information is disputed, this must be clearly identified and the recipient informed where appropriate.

Information received from another organisation must be attributed to its source and must not be presented as verified fact where it has not been verified.

Information-sharing records and copies of disclosures must be retained in accordance with the organisation’s retention schedule and the record-retention requirements applicable to regulated services in Wales.

Personal information must be securely deleted, destroyed or returned when it is no longer required. Disposal methods must prevent reconstruction or unauthorised access.

Where an external provider destroys information on behalf of {{org_field_name}}, appropriate evidence or certification of secure destruction must be obtained.

15. International Transfers and Cloud Services

Personal data must not be transferred or made remotely accessible outside the United Kingdom unless the Data Protection Lead has confirmed that the transfer complies with applicable data protection requirements.

Before using a cloud, software, communications or storage provider, {{org_field_name}} must establish:

Staff must not independently subscribe to online systems or applications for storing or sharing personal information.

16. Roles, Responsibilities and Training

16.1 Service Provider

The service provider is responsible for ensuring that appropriate governance, resources, policies, systems, contracts and monitoring arrangements are in place.

16.2 Responsible Individual

The responsible individual must maintain oversight of compliance, ensure identified concerns are addressed and consider information-governance risks within quality monitoring and service oversight.

16.3 Registered Manager

The registered manager is responsible for implementing this policy, ensuring staff compliance, escalating serious incidents, approving higher-risk disclosures and ensuring required safeguarding, contractual and regulatory notifications are made.

16.4 Data Protection Lead or Data Protection Officer

The Data Protection Lead or Data Protection Officer will:

The organisation must use the title “Data Protection Officer” only where a person has been formally appointed to that statutory role. Otherwise, the policy should use “Data Protection Lead”.

16.5 All Staff

All staff must:

Staff must not:

16.6 Training

Staff will receive information-governance and confidentiality training during induction and refresher training at least annually. Additional role-specific training will be provided to managers, safeguarding leads, care planners, administrators and staff authorised to respond to requests or make disclosures.

Understanding and compliance will be assessed through supervision, competency checks, audits, incident reviews and appraisal.

17. Monitoring and Audit

Compliance with this policy will be monitored through:

Findings, trends and improvement actions will be reported to the registered manager, responsible individual and service provider through the organisation’s governance and quality-review arrangements.

Serious or repeated non-compliance will be addressed through additional training, supervision, capability or disciplinary procedures and, where appropriate, referral to CIW, Social Care Wales, the Information Commissioner’s Office, the police or another relevant body.

18. Related Policies and Documents

This policy should be read alongside:

19. Policy Governance and Review

This policy will be reviewed at least annually and sooner where:

The registered manager will ensure that revisions are approved, version controlled and communicated to relevant staff. Staff will be required to confirm that they have read and understood material changes.


Responsible Person: {{org_field_registered_manager_first_name}} {{org_field_registered_manager_last_name}}
Reviewed on:
{{last_update_date}}
Next Review Date:
{{next_review_date}}
Copyright © {{current_year}} – {{org_field_name}}. All rights reserved.

Leave a Reply

Your email address will not be published. Required fields are marked *