{{org_field_logo}}
{{org_field_name}}
Registration Number: {{org_field_registration_no}}
Technology-Enabled Care and Telecare Policy
1. Purpose
The purpose of this policy is to set out how our domiciliary care service utilises Technology-Enabled Care (TEC) and Telecare solutions to enhance service user safety, independence, and quality of life. As technology continues to evolve, our organisation recognises the importance of digital tools in providing efficient, responsive, and personalised care.
This policy supports compliance with the Regulation and Inspection of Social Care (Wales) Act 2016, the Social Services and Well-being (Wales) Act 2014, the Regulated Services (Service Providers and Responsible Individuals) (Wales) Regulations 2017, as amended, the Mental Capacity Act 2005, the Human Rights Act 1998, the Equality Act 2010, the UK General Data Protection Regulation and the Data Protection Act 2018. The service will also have regard to statutory guidance issued by the Welsh Ministers under section 29 of the Regulation and Inspection of Social Care (Wales) Act 2016 and relevant guidance issued by Care Inspectorate Wales.
Our organisation efficiently manages Technology-Enabled Care by:
- Integrating digital solutions into our care plans.
- Providing staff training on using and monitoring TEC devices.
- Ensuring service users and families understand and consent to the use of technology in their care.
- Maintaining robust data protection and cybersecurity measures to protect service users’ information.
2. Scope
This policy applies to:
- All staff, including care workers, supervisors, and managers who support service users in using TEC and Telecare systems.
- Service users and their families who benefit from TEC solutions.
- Third-party technology providers and assistive technology suppliers.
- Healthcare professionals, social workers, and local authorities involved in implementing TEC.
It covers:
- Types of TEC and Telecare solutions used in home care.
- Assessment, installation, and maintenance procedures.
- Data security, privacy, and ethical considerations.
- Emergency response procedures for technology failures.
- Staff training and competency in using TEC solutions.
3. Definition and Types of Technology-Enabled Care
Technology-Enabled Care (TEC) refers to the use of digital and electronic devices to support service user wellbeing, health monitoring, and independent living. This includes:
3.1 Telecare Solutions (Remote Monitoring and Alerts)
- Personal Alarms and Emergency Call Systems – worn as a pendant or wristband, allowing users to call for help in emergencies.
- Fall Detection Sensors – automatically alert carers if a service user falls.
- Door and Window Sensors – alert staff or family members if a service user with dementia wanders out of their home.
- Bed and Chair Sensors – detect movement and can alert carers if a service user has not returned to bed or has been inactive for too long.
3.2 Telehealth and Remote Health Monitoring
- Blood Pressure and Heart Rate Monitors – allowing real-time health tracking for individuals with cardiovascular conditions.
- Blood Glucose Monitoring Devices – enabling service users with diabetes to manage their condition more effectively.
- Medication Dispensers with Alerts – ensuring medication compliance by reminding service users when to take their medicines.
3.3 Smart Home Technology to Promote Independence
- Voice-activated Assistants (e.g., Alexa, Google Home) – enabling service users to control lights, thermostats, and reminders using voice commands.
- Smart Doorbells and CCTV – providing additional security and monitoring for vulnerable individuals.
- Automated Lighting and Environmental Controls – reducing fall risks by automatically adjusting lighting at night.
4. Implementation and Management of TEC in Home Care
4.1 Assessing Service User Needs for TEC
Before introducing TEC solutions, our organisation ensures that each service user undergoes a thorough assessment to determine:
- The specific risks and challenges they face in daily living.
- Their ability to use and interact with technology.
- Any accessibility or disability considerations.
- Their consent and willingness to have TEC integrated into their care.
The assessment must be person-centred and must identify the purpose of the proposed technology, the personal outcome it is intended to support, the risks it is intended to reduce, any new risks created by its use, less intrusive alternatives, the person’s communication and accessibility needs, and the arrangements for responding to alerts, faults and emergencies.
The assessment must also consider whether the technology could restrict the person’s freedom of movement, monitor the person continuously, influence decisions about when they may leave their home, or otherwise amount to control, restraint or a deprivation of liberty.
Where the service is responsible for using, monitoring or responding to the technology, the agreed arrangements must be recorded in the person’s provider assessment and personal plan. The personal plan must state:
- the purpose of the technology;
- the device or system being used;
- who owns and supplies it;
- who is responsible for installation, maintenance and testing;
- who receives and responds to alerts;
- expected response times;
- what staff must do when an alert is received;
- what staff must do if the equipment fails;
- the person’s wishes and preferences;
- the lawful decision-making arrangements;
- identified risks and control measures;
- any restrictions arising from its use; and
- when the arrangements must be reviewed.
Capacity must not be assumed or rejected solely because of the person’s diagnosis, disability, age, behaviour or communication needs. Where there is reason to doubt capacity, the service must complete or obtain a decision-specific assessment of the person’s capacity to decide about the particular technology, the monitoring involved and the sharing of information. All practicable steps must first be taken to support the person to make the decision themselves.
Assessments will be conducted in collaboration with:
- Service users and their families.
- Social workers and occupational therapists.
- TEC providers and healthcare professionals.
4.2 Installation and Maintenance of TEC Devices
Once a TEC solution is identified, we ensure:
- Proper installation by trained professionals.
- A clear demonstration and training for service users and staff on how to use the devices.
- Regular maintenance checks to ensure devices are working correctly.
- A clear protocol for reporting malfunctions to the appropriate team.
Checks, servicing, calibration, software and security updates, battery replacement and maintenance must be completed at the frequency required by the manufacturer, supplier, clinical professional or assessed level of risk. The service must keep a record of:
- the equipment identifier and location;
- the date of each check or test;
- the person completing the check;
- the outcome;
- any fault identified;
- action taken;
- escalation to the supplier or commissioner;
- the date the equipment was repaired or replaced; and
- any interim safety arrangements.
Equipment must not be used where it is known or suspected to be unsafe, inaccurate, damaged, unsupported or unsuitable for the person’s assessed needs.
The person and, where appropriate, their representative must be provided with information explaining how the technology operates, its benefits, limitations, risks, monitoring functions, data use, alert arrangements and fault-reporting process. Information must be provided in the person’s preferred language and in an accessible style, presentation and format that reflects their communication needs, level of understanding and any sensory or cognitive impairment. Appropriate support must be provided to help the person understand and use the information. Reasonable steps must be taken to meet Welsh-language needs and to provide the service through the medium of Welsh where this is the person’s language of need or choice.
4.3 Emergency Response to TEC Malfunctions
To prevent harm or disruption in care, we implement:
- Regular system checks to identify any faults before they cause issues.
- A 24/7 emergency response protocol if a critical device (e.g., fall detector, emergency alarm) stops working.
- A backup plan for continued care if TEC solutions fail.
- Liaison with telecare providers to ensure prompt repairs and replacements.
The backup arrangement must be specific to the person and proportionate to the risk. It must identify how the person will continue to receive safe care and support during loss of electricity, telephone service, mobile signal, internet access, monitoring-centre availability, cloud service, battery power or device functionality.
Where a fault removes or materially reduces an essential safety control, staff must not assume that the person remains safe because a technical report has been made. The manager must arrange an immediate risk assessment and implement alternative measures, which may include additional welfare calls, revised visit arrangements, direct contact with the person or representative, manual observations, replacement equipment or emergency-service involvement.
Staff must record the malfunction, action taken, people notified, interim safeguards, outcome and any effect on the person.
Staff are trained to identify signs of TEC failure, reassure service users, and contact technical support or emergency responders when necessary.
The Registered Manager and Responsible Individual must consider whether a failure, cyber incident or interruption involving TEC is notifiable to Care Inspectorate Wales. CIW must be notified where the event prevents, or could prevent, the provider from continuing to provide the service safely, or where another notification requirement in the Regulations applies. Notification to CIW does not replace safeguarding, police, commissioner, healthcare, Information Commissioner’s Office or other statutory reporting requirements.
5. Data Security, Privacy, and Ethical Considerations
5.1 Consent, Mental Capacity and Lawful Decision-Making
The person must be involved in decisions about TEC and must be given clear, accessible information about:
- why the technology is proposed;
- what it does and does not do;
- what information it collects;
- whether it records sound, images, movement, location or health information;
- who will receive or view information and alerts;
- how long information will be retained;
- the possible benefits and disadvantages;
- available alternatives;
- what will happen if the person refuses or later changes their mind; and
- how to raise a concern or exercise their information rights.
Consent to care or to the installation and use of equipment must be voluntary, informed, specific to the proposed arrangements and obtained from a person who has capacity to make that particular decision. Consent must be kept under review and the person may withdraw consent at any time. Withdrawal of consent must result in a prompt review of the care arrangements and risks.
Consent to care must not be treated automatically as the lawful basis for processing personal data. The organisation must separately identify and document the appropriate lawful basis under Article 6 of the UK GDPR and, where health, biometric or other special-category data is processed, a condition under Article 9 and any applicable requirement under the Data Protection Act 2018.
Where there is reason to doubt the person’s capacity, a decision-specific capacity assessment must be completed or obtained in accordance with the Mental Capacity Act 2005. The person must be supported to participate in the decision using their preferred communication method and any necessary aids, interpretation, advocacy or additional time.
Where the person lacks capacity to decide about the particular TEC arrangement, the decision must be made in accordance with the Mental Capacity Act 2005. The decision-maker must:
- identify the specific decision to be made;
- consider the person’s past and present wishes, feelings, beliefs and values;
- consult relevant family members, representatives and professionals where appropriate;
- involve any attorney or deputy who has authority to make the decision;
- involve an Independent Mental Capacity Advocate where the statutory criteria are met;
- consider less restrictive alternatives;
- determine whether the arrangement is necessary and proportionate;
- record the capacity assessment, consultation, options considered, best-interests decision and review arrangements; and
- ensure that any act or decision is within the legal authority of the person making it.
A family member must not be asked to provide consent on behalf of an adult unless that person has lawful authority, for example as an attorney under a registered lasting power of attorney for health and welfare or as a Court of Protection deputy with relevant powers.
For a child, decisions must take account of the child’s age, understanding, competence, wishes and feelings and the lawful authority of the person providing consent. Where the child is looked after or subject to statutory arrangements, the service must confirm the respective decision-making authority of those with parental responsibility and the placing authority.
5.2 Restrictive Practice and Deprivation of Liberty
TEC must not be used to control or restrain a person unless the intervention is necessary to prevent a risk of harm and is a proportionate response to that risk. Technology must not be used for staff convenience, as a substitute for necessary staffing or visits, as a punishment, or to impose restrictions that are not contained in the person’s lawful care arrangements.
Examples requiring specific consideration include:
- door-exit sensors used to prevent or delay a person leaving;
- continuous location tracking;
- remote locking systems;
- systems that enable another person to control doors, appliances or movement;
- continuous audio or visual monitoring;
- monitoring combined with instructions that the person must not leave;
- technology used as part of continuous supervision and control; and
- arrangements under which the person is not free to leave.
Where the arrangements may amount to a deprivation of liberty, the service must obtain appropriate legal and professional advice and must not implement or continue the arrangements without lawful authority.
Deprivation of Liberty Safeguards authorisations apply to hospitals and care homes. Where a person is living in their own home or another community setting and the arrangements amount to a deprivation of liberty, the matter must be referred to the relevant commissioning body and legal authorisation must be obtained through the Court of Protection or another applicable lawful route.
The service must immediately escalate any concern that TEC is being used unlawfully to restrict a person’s liberty, including where equipment has been installed or controlled by a relative, representative, commissioner or other organisation.
5.3 UK GDPR lawful bases and accountability
TEC may collect personal data and special-category data, including information about health, disability, movement, behaviour, location, routines, medication and emergency events. The organisation must process this information in accordance with the UK GDPR and the Data Protection Act 2018.
Before processing begins, the organisation must:
- identify and document an Article 6 lawful basis;
- identify and document an Article 9 condition where special-category data is processed;
- establish and document the purpose of processing;
- ensure that the processing is necessary and proportionate;
- collect only information that is adequate, relevant and limited to what is necessary;
- provide an appropriate privacy notice;
- define access controls and authorised users;
- establish retention and secure-deletion periods;
- ensure the information is accurate and corrected where necessary;
- establish arrangements for responding to data-subject rights;
- document whether the organisation, commissioner, technology provider or another party is acting as controller, joint controller or processor; and
- record the processing in the organisation’s data-processing records where required.
Health information, alerts, recordings and monitoring data must not be made available to family members, representatives, staff, commissioners or other organisations merely because access would be convenient. Access and disclosure must have a lawful basis, be necessary for a defined purpose and be limited to the minimum information required.
Staff must access TEC information only where required for their role. Access must be removed promptly when no longer required. Shared accounts must not be used where individual user accounts and audit trails are available.
Information must be protected through security measures appropriate to the risk, including, where applicable:
- encryption in transit and at rest;
- secure authentication;
- role-based access;
- audit logging;
- supported software and security updates;
- secure configuration;
- backup and recovery arrangements;
- protection against unauthorised remote access;
- secure disposal or return of equipment; and
- procedures for lost, stolen, compromised or obsolete devices.
The organisation’s privacy notice must explain the TEC processing in clear language, including the type of information collected, purpose, lawful basis, recipients, retention period, rights, complaint arrangements and any automated decision-making or overseas transfer.
5.4 Data Protection Impact Assessments
Before introducing or materially changing TEC processing that is likely to result in a high risk to people’s rights and freedoms, the organisation must complete a Data Protection Impact Assessment.
A DPIA screening assessment must be completed where the proposed system involves one or more of the following:
- systematic monitoring;
- monitoring of vulnerable people;
- health or other highly personal information;
- location tracking;
- video or audio monitoring;
- innovative or intrusive technology;
- large-scale processing;
- matching or combining information from different sources;
- automated decision-making with significant effects; or
- processing that could prevent the person exercising a right or receiving a service.
The DPIA must describe the processing, assess necessity and proportionality, identify risks to individuals, document measures to reduce those risks and record approval by the appropriate person. Where residual high risk cannot be reduced, the Data Protection Officer must be consulted and prior consultation with the Information Commissioner’s Office must be considered in accordance with the UK GDPR.
5.5 Technology Suppliers, Processors and Sub-processors
Before appointing a TEC supplier that will process personal data on behalf of the organisation, the organisation must complete proportionate due diligence to establish that the supplier provides sufficient guarantees regarding data protection, confidentiality, information security, service continuity, incident management and compliance.
Where the supplier acts as a processor, a written contract meeting Article 28 of the UK GDPR must be in place before processing begins. The contract must address:
- the subject matter and duration of processing;
- the nature and purpose of processing;
- the types of personal data and categories of individuals;
- documented instructions;
- confidentiality;
- appropriate security;
- use of sub-processors;
- assistance with individual rights;
- assistance with breaches, DPIAs and regulatory consultation;
- deletion or return of information at the end of the contract; and
- audit and inspection rights.
The organisation must establish where data will be stored and accessed. Personal data must not be transferred outside the United Kingdom unless the transfer complies with the UK GDPR and appropriate transfer arrangements and safeguards are in place.
Supplier contracts must include arrangements for faults, emergency support, system availability, cyber incidents, notification of breaches, software support, security updates, return of information, equipment removal and safe termination of the service.
5.6 CCTV, Smart Doorbells, Video and Audio Recording
CCTV, smart doorbells, cameras, microphones and other recording or live-monitoring systems must not be installed, activated, viewed or accessed by the service unless there is a clearly defined lawful purpose and the processing is necessary and proportionate.
Before the service installs, commissions, controls or routinely accesses such a system, it must:
- identify the controller or joint controllers;
- document the Article 6 lawful basis and any applicable Article 9 condition;
- complete a DPIA where required;
- consider less intrusive alternatives;
- define the areas, times and persons monitored;
- prevent monitoring of areas where there is a heightened expectation of privacy, except where exceptional lawful justification has been documented;
- inform the person, staff, visitors and other affected individuals;
- provide appropriate signage where required;
- establish who may access live images or recordings;
- establish retention and deletion periods;
- ensure recordings are securely stored and disclosed only where lawful and necessary; and
- review the continued necessity and proportionality of monitoring.
Audio recording is more intrusive than video-only monitoring and must be disabled unless the organisation has documented a specific lawful and proportionate need for it.
Where a camera, smart doorbell or recording system belongs to the person or a family member, the service must assess the effect on staff and other people entering the home. Staff must not interfere with privately owned equipment, but concerns about covert, excessive, unlawful or safeguarding-related monitoring must be reported to the Registered Manager and managed under the relevant safeguarding, employment and data-protection procedures.
Recorded material must not be copied, downloaded, shared through personal messaging applications or stored on personal devices.
5.7 Personal-Data Breaches and Cyber Incidents
Any actual or suspected loss, unauthorised access, disclosure, alteration, destruction or unavailability of TEC-related personal data must be reported immediately through the organisation’s data-breach procedure and to the Data Protection Officer or designated data-protection lead.
The organisation must:
- contain the breach;
- protect the person from further harm;
- preserve relevant evidence and system logs;
- determine what information and individuals are affected;
- assess the likely risk to rights and freedoms;
- document the breach, assessment, decision and action taken;
- notify the Information Commissioner’s Office without undue delay and, where feasible, within 72 hours where the legal reporting threshold is met; and
- inform affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms.
A data breach must also be considered under the safeguarding, incident-reporting, commissioner-notification and CIW-notification procedures where applicable.
6. Staff Training and Competency in Using TEC
To ensure TEC is effectively integrated into care, staff must:
- Complete TEC awareness and competency training as part of their induction.
- Receive ongoing refresher training on new digital health solutions.
- Understand how to troubleshoot and assist service users with TEC devices.
- Follow confidentiality and data protection protocols when accessing TEC-related information.
Staff must not install, configure, test, monitor or respond to TEC unless they have received training appropriate to their responsibilities and have been assessed as competent where the activity could affect the person’s safety.
Training and competency assessment must cover, as applicable:
- the purpose and limitations of the equipment;
- the person’s personal plan and risk assessment;
- correct operation and testing;
- recognition of faults, false alerts and loss of connectivity;
- response and escalation arrangements;
- emergency and contingency procedures;
- consent and the Mental Capacity Act 2005;
- restrictive practice and deprivation of liberty;
- privacy, confidentiality and data protection;
- CCTV, recording and monitoring;
- safeguarding concerns associated with misuse of technology;
- accurate record keeping; and
- safe charging, cleaning, storage and disposal.
The service must maintain records of training, competency assessments, refresher training and any restrictions placed on a staff member’s use of equipment. Competency must be reassessed following a significant incident, material equipment change, identified practice concern or extended period without using the equipment.
Failure to adhere to this policy may result in disciplinary action, in accordance with the Disciplinary and Grievance Policy (DCW31).
7. Monitoring and Review of TEC Effectiveness
Our organisation is committed to continuous improvement in TEC implementation. We will:
- Gather feedback from service users, families, and staff to refine our approach.
- Work closely with local authorities, telecare providers, and NHS Wales to stay updated on advancements in TEC.
- Ensure compliance with CIW inspection requirements regarding technology use in care.
- Review each person’s TEC arrangements as part of their personal-plan review at least every three months and sooner where:
- their needs, capacity, wishes, risks or personal outcomes change;
- the technology is no longer effective or suitable;
- consent is withdrawn;
- a fault, missed alert, false alert, cyber incident or other significant incident occurs;
- the person’s home, support arrangements or responsible contacts change;
- monitoring becomes more intrusive or restrictive;
- the supplier materially changes the system or its data processing; or
- staff, the person, their representative or another professional raises a concern.
The Registered Manager must provide relevant TEC information to the Responsible Individual for inclusion in the service’s quality-monitoring arrangements. The Responsible Individual’s six-monthly quality-of-care review must consider, where relevant:
- feedback from individuals and representatives;
- faults, missed alerts and response performance;
- incidents, safeguarding concerns and complaints;
- personal-data breaches and cyber incidents;
- maintenance and equipment-check records;
- staff training and competency;
- supplier performance;
- whether technology continues to support personal outcomes;
- whether any system has created an inappropriate restriction or reduced necessary human contact; and
- actions required to improve the quality and safety of the service.
Actions arising from monitoring must be recorded, allocated to a responsible person and followed through to completion.
8. Related Policies
This policy should be read alongside:
- Confidentiality and Data Protection (GDPR) Policy (DCW34).
- Safeguarding Adults from Abuse and Improper Treatment Policy (DCW13).
- Risk Management and Assessment Policy (DCW18).
- Emergency and Business Continuity Plan (DCW19).
- Consent and Mental Capacity Policy.
- Control, Restraint and Restrictive Practice Policy.
- Records Management and Retention Policy.
- Incident Reporting and CIW Notification Policy.
- Information Security and Cybersecurity Policy.
- CCTV, Surveillance and Recording Policy.
- Equality, Diversity, Human Rights and Welsh Language Policy.
- Staff Training, Supervision and Competency Policy.
- Complaints Policy.
- Whistleblowing Policy.
9. Policy Review
This policy will be reviewed annually or sooner if there are significant updates in TEC regulations, best practice guidelines, or technological advancements. The Registered Manager is responsible for overseeing its implementation.
Responsible Person: {{org_field_registered_manager_first_name}} {{org_field_registered_manager_last_name}}
Reviewed on: {{last_update_date}}
Next Review Date: {{next_review_date}}
Copyright © {{current_year}} – {{org_field_name}}. All rights reserved.