{{org_field_logo}}
{{org_field_name}}
Registration Number: {{org_field_registration_no}}
Information Sharing with Third-Party Organisations Policy
1. Purpose
The purpose of this policy is to set out how {{org_field_name}} will share personal information lawfully, fairly, transparently, securely and proportionately with third-party organisations in connection with the provision, commissioning, regulation and oversight of domiciliary support services in Wales.
This policy supports compliance with the UK General Data Protection Regulation, the Data Protection Act 2018 as amended, the Data (Use and Access) Act 2025, the Regulation and Inspection of Social Care (Wales) Act 2016, the Regulated Services (Service Providers and Responsible Individuals) (Wales) Regulations 2017 as amended, the Social Services and Well-being (Wales) Act 2014, the common law duty of confidentiality and other applicable legal and professional duties.
The policy is intended to ensure that information is shared when it is necessary to protect an individual, provide safe and effective care and support, meet a legal or regulatory duty, support multi-agency working or fulfil another lawful purpose. It also ensures that information is not shared unnecessarily, excessively, inaccurately or with a person who is not authorised to receive it.
Information sharing is essential for effective service delivery, safeguarding, and multi-agency collaboration, but it must be managed in a way that protects service user confidentiality, ensures legal compliance, and maintains trust. This policy outlines when, how, and why information may be shared and how we ensure safe, lawful, and efficient handling of data.
This policy does not prevent necessary and proportionate information sharing. Data protection law must not be used as a reason to withhold information where sharing is necessary to protect an individual from abuse, neglect, improper treatment or serious harm, or where another lawful requirement applies. Staff must nevertheless record the reason for sharing, the information shared, the recipient and the lawful authority relied upon.
2. Scope
This policy applies to:
- All employees, workers, agency workers, bank staff, volunteers, students, contractors, consultants, the registered manager, the responsible individual and any other person acting on behalf of {{org_field_name}}.
- Third-party organisations and persons, including local authorities, Local Health Boards, NHS trusts, general practitioners, pharmacies, hospitals, emergency services, safeguarding authorities, commissioners, CIW, Social Care Wales, the Information Commissioner’s Office, police forces, courts, advocacy providers, legal representatives, insurers, auditors, professional advisers, IT suppliers and other health and social care providers.
- Personal data, special category personal data and, where relevant, criminal offence data relating to individuals receiving care and support, relatives, representatives, staff, applicants, contractors and other persons.
This policy applies to all formats of data, including written, verbal, electronic, and digital communications.
This policy applies to one-off disclosures, regular or systematic data-sharing arrangements, joint working arrangements, statutory notifications, referrals, telephone discussions, meetings, electronic communications, paper records, photographs, video or audio recordings and access to electronic care-record systems.
This policy applies whether {{org_field_name}} is acting as a controller, joint controller or processor. The organisation’s role must be established before any new regular or significant data-sharing arrangement begins.
Anonymised information that cannot reasonably identify an individual is not personal data. Pseudonymised information remains personal data where the individual can be re-identified using additional information.
3. Legal and Regulatory Framework
Information sharing by {{org_field_name}} will be undertaken in accordance with all applicable legislation, statutory guidance, regulatory requirements and professional standards, including:
- UK General Data Protection Regulation, including the data protection principles, lawful bases for processing, special category data requirements, security requirements, accountability obligations and individual rights.
- Data Protection Act 2018, as amended, including relevant conditions for processing special category personal data and criminal offence data.
- Data (Use and Access) Act 2025, which amends parts of the UK data protection framework and introduces additional requirements, including requirements concerning the handling of data protection complaints.
- Regulation and Inspection of Social Care (Wales) Act 2016.
- Regulated Services (Service Providers and Responsible Individuals) (Wales) Regulations 2017, as amended, particularly requirements relating to policies and procedures, safeguarding, personal plans, records, notifications, complaints, staff information, confidentiality and effective governance.
- Welsh Government statutory guidance for service providers and responsible individuals on meeting the service standard regulations, as amended.
- Social Services and Well-being (Wales) Act 2014, including safeguarding, assessment, care and support and multi-agency duties.
- Wales Safeguarding Procedures.
- Mental Capacity Act 2005 and its Code of Practice.
- Human Rights Act 1998, including respect for private and family life under Article 8 of the European Convention on Human Rights.
- Equality Act 2010.
- Common law duty of confidentiality.
- Crime and Disorder Act 1998, where applicable.
- Safeguarding Vulnerable Groups Act 2006, where applicable.
- Public Interest Disclosure Act 1998, where applicable.
- Investigatory Powers Act 2016, where relevant to requests from law enforcement or other authorised bodies.
- ICO Data Sharing Code of Practice and current ICO guidance.
- Social Care Wales Codes of Professional Practice, where applicable.
Where another enactment, court order, regulatory requirement or professional duty requires or permits disclosure, the relevant authority must be identified and recorded before the disclosure is made, unless an emergency makes prior documentation impracticable.
4. Principles of Information Sharing
When sharing information with third-party organisations, {{org_field_name}} adheres to the following principles:
- Lawfulness, Fairness, and Transparency – We only share data where there is a legal basis and inform individuals where appropriate.
- Purpose Limitation – Data is shared only for legitimate and specified reasons.
- Data Minimisation – We only share the minimum necessary information required for the purpose.
- Accuracy – We ensure data is accurate and up to date before sharing.
- Storage Limitation – Personal data must not be kept for longer than is necessary for the purpose for which it was obtained or shared. Information-sharing records will be retained in accordance with the organisation’s retention schedule, contractual obligations, statutory requirements and CIW record-keeping requirements.
- Integrity, Confidentiality and Security – Personal data must be protected against unauthorised or unlawful processing and against accidental loss, destruction, alteration or damage through appropriate technical and organisational measures.
- Accountability – {{org_field_name}} must be able to demonstrate compliance. Decisions to share or withhold information must be documented where appropriate, including the purpose, lawful basis, Article 9 condition where applicable, recipient, categories of information, security method, date, decision-maker and any relevant consent, objection, capacity or best-interests decision.
- Necessity and Proportionality – Information will only be shared where the purpose cannot reasonably be achieved by less intrusive means, and the extent of the disclosure is proportionate to the purpose.
- Need-to-Know Access – Information will only be disclosed to persons whose role or legal authority requires access.
- Individual Involvement – Individuals will be told how their information is used and shared through clear privacy information, unless an applicable exemption or risk of harm makes this inappropriate.
- Respect for Confidentiality – A lawful basis under data protection legislation does not, by itself, remove the common law duty of confidentiality. Staff must also consider consent, another legal requirement, overriding public interest or another recognised justification for disclosing confidential information.
- Accessible Communication – Privacy and information-sharing explanations will be made available in an appropriate language, style and format, including Welsh, large print, easy read, audio or other communication support where required.
5. Categories of Information
Information shared under this policy may include:
- identification and contact information;
- care and support assessments, personal plans, risk assessments and daily care records;
- health, medication, disability, mental health and clinical information;
- communication, cultural, religious and language needs;
- safeguarding information;
- capacity assessments, best-interests decisions and details of any attorney, deputy, parent or lawful representative;
- financial information where this is relevant to care, safeguarding, commissioning or payment;
- complaints, incidents, accidents and regulatory notifications;
- staff employment, training, registration, disciplinary or safeguarding information;
- photographs, recordings or monitoring information where lawfully obtained;
- criminal offence information where there is a lawful and necessary reason to process or disclose it.
Health information, information concerning racial or ethnic origin, religious or philosophical beliefs, sexual life or sexual orientation, biometric data used for identification and certain other sensitive information are special category personal data and require both an Article 6 lawful basis and an Article 9 condition.
6. When Information May Be Shared
6.1 Safeguarding and Protection of Individuals
Information must be shared promptly with the relevant local authority safeguarding team, police, emergency service, CIW or other appropriate agency where this is necessary and proportionate to:
- protect an adult or child from abuse, neglect, exploitation or improper treatment;
- respond to a safeguarding concern, allegation or disclosure;
- prevent or detect serious harm or crime;
- enable an authorised safeguarding enquiry, strategy discussion, investigation or protection plan;
- meet a statutory or regulatory notification duty.
Consent is not required where another lawful basis applies and seeking consent would place a person at greater risk, prejudice an investigation, cause an unreasonable delay or prevent the organisation from fulfilling a legal or safeguarding duty.
Wherever it is safe and appropriate, the individual should be informed that information is being shared, the reason for sharing and the recipient. Any decision not to inform the individual must be recorded with reasons.
Staff must not promise absolute confidentiality where information indicates that an individual or another person may be at risk.
Safeguarding disclosures must be limited to relevant information, shared with an authorised person and recorded in accordance with the Safeguarding Policy and Wales Safeguarding Procedures.
6.2 Care Provision, Care Planning and Multi-Agency Working
Information may be shared with health and social care professionals, commissioners and other authorised partners where this is necessary to assess, plan, provide, review, coordinate or monitor the individual’s care and support.
This may include sharing with:
- general practitioners, community nurses and other healthcare professionals;
- pharmacists and medicines-management professionals;
- local authority social workers, commissioners and case managers;
- Local Health Boards and NHS trusts;
- physiotherapists, occupational therapists, speech and language therapists and mental health services;
- ambulance services and hospitals;
- advocacy services and lawful representatives;
- other providers involved in the person’s agreed care and support.
Before sharing, staff must identify the applicable Article 6 lawful basis. Where health or other special category information is involved, staff must also identify an appropriate Article 9 condition and, where required, a condition under the Data Protection Act 2018.
Consent will only be relied upon where it is the most appropriate lawful basis and can be freely given, specific, informed, unambiguous and capable of withdrawal. The provision of necessary care and support must not normally be made conditional upon consent to unrelated or unnecessary information sharing.
Individuals must, where practicable, be informed about routine care-related sharing through the organisation’s privacy notice, written guide, service agreement and discussions about their personal plan.
6.3 Regulatory, Contractual and Legal Requirements
Information may be shared where {{org_field_name}} is required or lawfully requested to provide it to:
- Care Inspectorate Wales;
- Social Care Wales;
- the Information Commissioner’s Office;
- a local authority or Local Health Board;
- a coroner;
- a court or tribunal;
- the police or another authorised law-enforcement body;
- the Disclosure and Barring Service;
- an insurer, auditor or professional adviser;
- another person or body exercising a lawful statutory function.
Staff must not assume that every request from an official body is automatically lawful. Unless the disclosure is an emergency or a clear statutory notification, the identity and authority of the requester, the purpose of the request, the legal power relied upon and the scope of the information requested must be verified.
Court orders, production orders, warrants, statutory notices and other compulsory requests must be referred immediately to the registered manager or Data Protection Lead. Legal advice must be obtained where the scope or validity of the request is unclear.
Statutory notifications to CIW must be submitted without delay, normally within 24 hours where required by the applicable regulations and guidance, through CIW Online and in the form required by CIW.
6.4 Emergencies and Vital Interests
In an emergency, relevant personal information may be shared without prior consent where this is necessary to protect the life, physical safety or vital interests of the individual or another person.
Staff must:
- share only the information reasonably required by the receiving professional or emergency service;
- verify the recipient where circumstances permit;
- record what was shared, with whom, when and why;
- inform the individual afterwards where it is safe and appropriate to do so;
- notify the registered manager as soon as practicable.
A best-interests decision under the Mental Capacity Act 2005 may be required where an individual lacks capacity to make the relevant decision. However, “best interests” is not itself a complete data protection lawful basis; the organisation must also identify the applicable data protection basis and confidentiality justification.
6.5 Research, Audit, Service Evaluation and Training
Wherever practicable, information used for research, audit, service evaluation or training will be anonymised so that individuals cannot be identified.
Pseudonymised information remains personal data and must be protected accordingly.
Identifiable information may only be used where:
- there is a clearly defined and documented purpose;
- an appropriate lawful basis and, where relevant, Article 9 condition have been identified;
- the common law duty of confidentiality has been addressed;
- the information is necessary and proportionate;
- appropriate ethical, contractual and governance approvals have been obtained;
- a Data Protection Impact Assessment has been completed where required;
- individuals have been given appropriate privacy information unless a lawful exemption applies.
Explicit consent is not the only possible legal basis for research or audit. The correct basis must be determined according to the nature and purpose of the activity.
6.6 Requests from the Police and Other Law-Enforcement Bodies
A request from the police does not automatically require disclosure. Staff must obtain a written request wherever practicable and confirm:
- the identity and contact details of the requesting officer;
- the police force or body concerned;
- the specific information required;
- the purpose of the request;
- the statutory power or legal basis relied upon;
- whether informing the individual would prejudice the purpose of the request.
Requests must be referred to the registered manager or Data Protection Lead unless an immediate disclosure is necessary to prevent serious harm or respond to an emergency.
All disclosures and refusals must be documented.
6.7 Complaints, Investigations and Legal Claims
Information may be shared where necessary to investigate or respond to a complaint, concern, claim, disciplinary matter, safeguarding allegation, insurance matter or legal proceeding.
Wherever practicable, individuals will be informed where details of their complaint need to be disclosed to another person or organisation. Confidentiality must be maintained unless disclosure is necessary for a fair investigation, safeguarding, legal compliance or another overriding lawful purpose.
7. Consent, Capacity and Representatives
Consent is only one of several lawful bases for processing and sharing personal information. Staff must not seek consent where the organisation is relying on a legal obligation, safeguarding duty, vital interests, contractual necessity, public task, recognised legitimate interest, legitimate interest or another lawful basis.
Where consent is relied upon, it must be:
- freely given;
- specific;
- informed;
- unambiguous;
- demonstrated through a clear affirmative action;
- recorded;
- capable of being withdrawn as easily as it was given.
The consent record must include:
- the name of the person giving consent;
- the information they were provided;
- the specific information to be shared;
- the purpose of sharing;
- the recipient or category of recipient;
- the date and method of consent;
- any time limit or review date;
- any withdrawal or variation of consent.
Where a person lacks capacity to make the relevant decision, staff must follow the Mental Capacity Act 2005. Capacity is decision-specific and must not be assumed solely because of a diagnosis, disability, communication difficulty or age.
A relative, friend or informal carer does not automatically have authority to consent to information sharing on behalf of an adult. Authority must be confirmed, for example through a valid health and welfare lasting power of attorney, court-appointed deputyship, other legal authority or a best-interests decision made in accordance with the Mental Capacity Act 2005.
For children, staff must consider the child’s age, understanding and competence, parental responsibility, safeguarding needs and any applicable court order. The child’s views must be sought and respected where appropriate.
Where an individual objects to sharing and consent is not the lawful basis, the objection must be considered and recorded. Information may still be shared where another lawful and overriding basis applies.
8. Lawful Basis and Decision-Making
Before personal data is shared, the person authorising the disclosure must identify and record at least one applicable lawful basis under Article 6 of the UK GDPR.
Depending on the circumstances, this may include:
- consent;
- performance of a contract;
- compliance with a legal obligation;
- protection of vital interests;
- performance of a task in the public interest, where applicable;
- recognised legitimate interests;
- legitimate interests, following an appropriate assessment.
Where special category personal data is shared, an Article 9 condition must also be identified. Conditions commonly relevant to domiciliary support services may include:
- explicit consent;
- protection of vital interests;
- substantial public interest, where supported by law;
- provision or management of health or social care;
- establishment, exercise or defence of legal claims;
- public health, where applicable.
Where criminal offence information is involved, staff must also confirm that processing is authorised under Article 10 of the UK GDPR and the Data Protection Act 2018.
The lawful basis and relevant condition must be recorded before sharing, unless an emergency makes this impracticable. In an emergency, the record must be completed as soon as possible afterwards.
9. Secure Methods of Sharing Information
Personal information must be shared using a method appropriate to the sensitivity, volume, urgency and risk of the information.
Staff must:
- confirm the identity, role and authority of the recipient;
- check email addresses, postal addresses and telephone numbers before disclosure;
- use organisation-approved systems and devices;
- use encrypted email, secure portals or approved file-transfer systems where appropriate;
- use password protection or other access controls for attachments where appropriate, sending passwords separately;
- avoid using personal email accounts, unapproved messaging applications, personal cloud storage or removable media;
- ensure telephone conversations cannot be overheard;
- verify callers using independently held contact details rather than details provided during the call;
- use sealed, correctly addressed envelopes for paper information;
- use tracked, secure or hand-delivery arrangements according to risk;
- record receipt or obtain confirmation where appropriate;
- avoid leaving records in vehicles or unattended locations;
- immediately retrieve or securely delete information where sent to an incorrect recipient, where possible.
Information must not automatically be sent using an “NHS-approved” or local-authority system unless {{org_field_name}} is authorised to use that system. The organisation must specify the actual approved systems in its operational procedures.
Any disclosure involving a large volume of records, highly sensitive information, a new technology, systematic monitoring or a new regular sharing arrangement must be referred to the Data Protection Lead for consideration of a Data Protection Impact Assessment.
10. Data-Sharing Agreements and Third-Party Due Diligence
Regular, systematic, large-scale or high-risk information sharing must be governed by a written data-sharing agreement, information-sharing protocol, joint-controller arrangement or processor contract, as appropriate.
The agreement must address:
- the parties and their roles;
- the purpose and lawful basis;
- the categories of individuals and information;
- Article 9 or Article 10 conditions where applicable;
- information provided to individuals;
- security and access controls;
- accuracy and correction procedures;
- retention and secure deletion;
- handling individual rights requests;
- breach reporting and cooperation;
- restrictions on onward disclosure;
- audit, monitoring and review;
- termination arrangements;
- international transfers, where applicable.
Before appointing an organisation to process personal data on behalf of {{org_field_name}}, proportionate due diligence must be completed concerning its security, confidentiality, resilience, staff controls, breach arrangements, sub-processors, data location and ability to comply with data protection obligations.
Data-sharing agreements must be reviewed periodically and whenever the purpose, data, participants, technology or risk changes.
11. Managing Requests and Disclosures
All requests for personal information from third parties must be assessed before information is disclosed.
The member of staff receiving the request must record:
- the date and time of the request;
- the requester’s name, role, organisation and verified contact details;
- the identity of the individual concerned;
- the information requested;
- the purpose of the request;
- the lawful authority or basis relied upon;
- the urgency;
- whether the individual has been or should be informed.
Requests involving safeguarding, law enforcement, litigation, regulatory investigations, large volumes of records, staff information, confidential complaints or uncertainty about legal authority must be referred to the registered manager or Data Protection Lead.
Approval must be based on the risk and nature of the disclosure, not merely on whether the information is described as “sensitive”.
The organisation must keep a disclosure record showing:
- what was disclosed;
- what was withheld;
- the recipient;
- the date and method of disclosure;
- the purpose;
- the lawful basis and relevant condition;
- the name or role of the person authorising the decision;
- any follow-up action.
12. Individual Rights and Data Protection Complaints
Individuals may exercise rights provided by data protection legislation, including the rights of access, rectification, erasure, restriction, objection and data portability where applicable.
Any request concerning an individual’s personal data must be sent immediately to the Data Protection Lead and handled under the Data Subject Rights Procedure. Staff must not delay a request because the individual has not used a particular form or referred to data protection legislation.
Requests from representatives must be supported by appropriate evidence of authority. Information about another person must not be disclosed unless disclosure is lawful and appropriate.
{{org_field_name}} will maintain a documented data protection complaints process. A person may make a complaint verbally or in writing about how their personal information has been used, shared, secured or handled.
The organisation will:
- acknowledge the complaint within 30 days;
- take appropriate steps to investigate it without undue delay;
- keep the complainant informed of progress;
- provide a written outcome without undue delay;
- explain any action taken or reasons for taking no action;
- inform the complainant of their right to raise the matter with the Information Commissioner’s Office.
Records of data protection complaints, investigations, outcomes and remedial action will be retained and reviewed to identify patterns and improvements.
13. Personal Data Breaches
A personal data breach includes accidental or unlawful destruction, loss, alteration, unauthorised disclosure of or access to personal data. It includes information sent to the wrong recipient, lost records, unauthorised system access, insecure disposal, malware, theft, verbal disclosure and loss of availability.
All suspected or confirmed personal data breaches must be reported immediately to the registered manager and Data Protection Lead using the organisation’s breach-reporting process. Staff must not investigate the matter independently, conceal an error or contact affected individuals without authorisation.
Immediate action must be taken to:
- contain the breach;
- recover or secure the information where possible;
- preserve relevant evidence;
- identify affected individuals and information;
- assess risks to rights, freedoms, safety, dignity and well-being;
- consider whether safeguarding, CIW, commissioner, police, insurer or other notifications are also required.
The Data Protection Lead will determine whether the breach must be reported to the Information Commissioner’s Office. Where notification is required, it must be made without undue delay and, where feasible, within 72 hours of becoming aware of the breach.
Where the breach is likely to result in a high risk to affected individuals, those individuals must be informed without undue delay unless a lawful exception applies.
All breaches must be entered in the breach register, including breaches that are not reported to the Information Commissioner’s Office. The record must include the facts, effects, risk assessment, decision, notifications, containment and corrective action.
A personal data breach must also be considered under the organisation’s safeguarding, incident-reporting, duty of candour, complaints and CIW notification procedures.
14. Accuracy, Retention and Disposal
Before information is shared, reasonable steps must be taken to ensure it is accurate, current, relevant and not misleading.
Where information is disputed, this must be clearly identified and the recipient informed where appropriate.
Information received from another organisation must be attributed to its source and must not be presented as verified fact where it has not been verified.
Information-sharing records and copies of disclosures must be retained in accordance with the organisation’s retention schedule and the record-retention requirements applicable to regulated services in Wales.
Personal information must be securely deleted, destroyed or returned when it is no longer required. Disposal methods must prevent reconstruction or unauthorised access.
Where an external provider destroys information on behalf of {{org_field_name}}, appropriate evidence or certification of secure destruction must be obtained.
15. International Transfers and Cloud Services
Personal data must not be transferred or made remotely accessible outside the United Kingdom unless the Data Protection Lead has confirmed that the transfer complies with applicable data protection requirements.
Before using a cloud, software, communications or storage provider, {{org_field_name}} must establish:
- where personal data will be stored, backed up and accessed;
- whether support personnel outside the United Kingdom can access the information;
- whether an adequacy regulation or appropriate safeguard applies;
- whether a transfer risk assessment is required;
- whether the contract contains the necessary data protection terms.
Staff must not independently subscribe to online systems or applications for storing or sharing personal information.
16. Roles, Responsibilities and Training
16.1 Service Provider
The service provider is responsible for ensuring that appropriate governance, resources, policies, systems, contracts and monitoring arrangements are in place.
16.2 Responsible Individual
The responsible individual must maintain oversight of compliance, ensure identified concerns are addressed and consider information-governance risks within quality monitoring and service oversight.
16.3 Registered Manager
The registered manager is responsible for implementing this policy, ensuring staff compliance, escalating serious incidents, approving higher-risk disclosures and ensuring required safeguarding, contractual and regulatory notifications are made.
16.4 Data Protection Lead or Data Protection Officer
The Data Protection Lead or Data Protection Officer will:
- advise on lawful bases, special category conditions and confidentiality;
- maintain relevant information-governance records;
- advise on Data Protection Impact Assessments;
- review data-sharing agreements and processor arrangements;
- manage data breaches, individual rights requests and data protection complaints;
- monitor compliance and report significant concerns to senior management.
The organisation must use the title “Data Protection Officer” only where a person has been formally appointed to that statutory role. Otherwise, the policy should use “Data Protection Lead”.
16.5 All Staff
All staff must:
- follow this policy and related procedures;
- access information only where required for their role;
- verify recipients before disclosure;
- use approved systems;
- maintain accurate records;
- report concerns, errors and breaches immediately;
- complete required training;
- seek advice where the legal basis or authority to share is unclear.
Staff must not:
- browse records out of curiosity;
- disclose passwords or permit another person to use their account;
- photograph records on personal devices;
- use personal email or unapproved messaging applications;
- share information with relatives or friends without verified authority;
- discuss individuals in public or where conversations may be overheard.
16.6 Training
Staff will receive information-governance and confidentiality training during induction and refresher training at least annually. Additional role-specific training will be provided to managers, safeguarding leads, care planners, administrators and staff authorised to respond to requests or make disclosures.
Understanding and compliance will be assessed through supervision, competency checks, audits, incident reviews and appraisal.
17. Monitoring and Audit
Compliance with this policy will be monitored through:
- audits of disclosure records;
- reviews of data-sharing agreements and processor contracts;
- reviews of breaches, complaints and information requests;
- sampling of staff practice and electronic access logs;
- supervision and competency assessments;
- review of safeguarding and CIW notifications;
- review of actions arising from incidents, complaints or regulatory feedback.
Findings, trends and improvement actions will be reported to the registered manager, responsible individual and service provider through the organisation’s governance and quality-review arrangements.
Serious or repeated non-compliance will be addressed through additional training, supervision, capability or disciplinary procedures and, where appropriate, referral to CIW, Social Care Wales, the Information Commissioner’s Office, the police or another relevant body.
18. Related Policies and Documents
This policy should be read alongside:
- Confidentiality and Data Protection Policy (DCW34)
- Safeguarding Adults from Abuse and Improper Treatment Policy (DCW13)
- Staff Conduct and Code of Ethics Policy (DCW28)
- Disciplinary and Grievance Policy (DCW31)
- Privacy Notice
- Data Protection and Confidentiality Policy
- Data Subject Rights and Subject Access Request Procedure
- Data Protection Complaints Procedure
- Personal Data Breach Management Procedure
- Records Management, Retention and Disposal Policy
- Information Security and Cyber Security Policy
- Acceptable Use of IT, Email and Communications Policy
- Safeguarding Children Policy, where applicable
- Mental Capacity and Best-Interests Policy
- Complaints Policy
- Duty of Candour Policy
- Incident Reporting and CIW Notifications Procedure
- Whistleblowing Policy
- CCTV, Surveillance and Monitoring Policy, where applicable
- Business Continuity and Disaster Recovery Plan
- Data-Sharing Agreement template
- Data Protection Impact Assessment procedure
- Privacy Notice for Individuals Receiving Care and Support
- Staff Privacy Notice
19. Policy Governance and Review
This policy will be reviewed at least annually and sooner where:
- legislation, statutory guidance, CIW requirements or ICO guidance changes;
- the service’s statement of purpose changes;
- a serious information incident or personal data breach occurs;
- an audit, complaint, safeguarding enquiry or inspection identifies a weakness;
- new technology, a new supplier or a significant data-sharing arrangement is introduced;
- organisational roles or responsibilities change.
The registered manager will ensure that revisions are approved, version controlled and communicated to relevant staff. Staff will be required to confirm that they have read and understood material changes.
Responsible Person: {{org_field_registered_manager_first_name}} {{org_field_registered_manager_last_name}}
Reviewed on: {{last_update_date}}
Next Review Date: {{next_review_date}}
Copyright © {{current_year}} – {{org_field_name}}. All rights reserved.