{{org_field_logo}}
{{org_field_name}}
Registration Number: {{org_field_registration_no}}
Confidentiality and Data Protection (GDPR) – Service User Policy
1. Purpose
The purpose of this policy is to ensure that {{org_field_name}} complies with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and Care Inspectorate Wales (CIW) regulations when handling service user information. This policy outlines our approach to confidentiality, data security, and compliance with legal obligations while ensuring that all personal data is processed fairly, lawfully, and transparently.
Protecting the confidentiality of service users is fundamental to maintaining trust, ensuring dignity, and safeguarding personal rights. This policy applies to all staff, volunteers, contractors, and third parties who handle service user data in any capacity.
2. Scope
This policy applies to:
- All personal and sensitive data collected, stored, and processed by {{org_field_name}}.
- All staff members, volunteers, and external contractors handling service user information.
- Electronic, paper-based, and verbal data exchanges related to service users.
It covers:
- Confidentiality principles and legal compliance.
- Data collection, storage, and processing.
- Data sharing and access control.
- Service user rights under GDPR.
- Data breach procedures.
3. Legal and Regulatory Compliance
{{org_field_name}} will comply with all applicable data protection and social care legislation and guidance, including:
- UK GDPR and the Data Protection Act 2018, as amended from time to time.
- The Data (Use and Access) Act 2025, which makes changes to UK data protection and privacy law (including clarifying subject access request handling).
- The Regulation and Inspection of Social Care (Wales) Act 2016 and The Regulated Services (Service Providers and Responsible Individuals) (Wales) Regulations 2017 (as amended), including requirements to keep, maintain, secure and retain records.
- Welsh Government statutory guidance for care home and domiciliary suppliers (Version 3 – March 2024), which providers and Responsible Individuals must have regard to when meeting regulatory requirements.
- Relevant Care Inspectorate Wales (CIW) guidance and inspection expectations (including inspection Code of Practice).
4. Principles of Confidentiality and Data Protection
All data processing activities at {{org_field_name}} adhere to the following key principles:
4.1 Lawfulness, Fairness, and Transparency
- Service users must be informed about how their data is collected, used, and stored.
- We process personal data lawfully, fairly and transparently. We will identify and record a lawful basis for processing personal data and, where we process special category data (including health and care information), we will also identify and record an additional condition that permits this. Consent is not the only lawful basis and will be used only where appropriate; in many care situations we process information because it is necessary for care delivery, safeguarding, contractual and/or legal obligations.
- Privacy notices will be provided in accessible formats, explaining data processing activities.
4.2 Lawful basis and special category data
Most service user information we hold is special category personal data. We will only process it where we have both:
- a lawful basis under UK GDPR; and
- a valid condition for special category data.
We keep an internal record of the lawful basis/condition relied upon for our key processing activities (e.g., care planning, daily records, medicines support, incident management, safeguarding, invoicing and regulatory compliance).
4.3 Purpose Limitation
- Personal data will only be collected for specific, explicit, and legitimate purposes related to care provision.
- Information will not be used for purposes unrelated to care delivery, such as marketing.
4.4 Data Minimisation
- Only the minimum necessary data will be collected to fulfil care needs.
- Staff must not collect excessive or irrelevant information about service users.
4.5 Storage limitation and record retention
We retain personal data only for as long as necessary for safe care, safeguarding, legal and regulatory purposes.
In line with regulatory record requirements, we will:
- retain records relating to adults for at least 3 years from the date of the last entry;
- retain records relating to children for at least 15 years from the date of the last entry (unless the records must be returned to the placing authority as required).
Records will be disposed of securely (or anonymised where appropriate) when the retention period ends.
If the service closes, we will make secure arrangements for records to continue to be kept securely and remain retrievable for lawful requests, including regulatory requests.
4.6 Storage Limitation
- Personal data will be retained only for as long as necessary for care provision and regulatory compliance.
- Records will be securely deleted or anonymised when no longer needed.
4.7 Integrity and Confidentiality
- Personal data will be stored securely, using encryption and access controls.
- Staff must follow confidentiality agreements and secure communication protocols.
5. Data Collection, Storage, and Processing
5.1 Data Collection
- Personal data is collected during initial assessments, care planning, and ongoing service provision.
- Data collected includes:
- Basic identification details (e.g., name, address, date of birth).
- Health and medical history relevant to care provision.
- Emergency contact and next of kin details.
- Care preferences and risk assessments.
5.2 Data Storage and Security
- Electronic records are stored securely using encrypted care management systems.
- Paper records are kept in locked cabinets with restricted staff access.
- Staff must use password-protected devices when accessing personal data.
- Unauthorised access or data sharing is strictly prohibited.
Where records are stored electronically, access will be controlled by unique user accounts and permissions so that an audit trail shows who has accessed, created or amended records, and when.
5.3 Data Processing
- Personal data is processed to deliver safe and effective care.
- Data is only accessed by authorised staff members who require it for their role.
- Processing activities are monitored for compliance with GDPR and CIW regulations.
6. Data Sharing and Access Control
6.1 Who Can Access Service User Data?
- Only authorised employees who require access to perform their duties.
- Care professionals involved in service user support, such as GPs or social workers.
- Regulatory bodies (CIW, local authorities) if required by law.
6.2 Sharing Data with Third Parties
- Data will only be shared when necessary for care provision, safeguarding, or legal compliance.
- A formal Data Processing Agreement is required before engaging third-party providers.
We will seek to involve the service user in information-sharing decisions wherever possible. However, information may be shared without consent where there is a lawful basis and it is necessary, for example, to protect the person or others (vital interests), for safeguarding, to comply with a legal obligation, or for the prevention/detection of crime. Where we share information without consent, we will record the decision, the rationale, what was shared, and with whom.
6.3 Service User Access to Their Own Data
Service users (or authorised representatives) have the right to request access to personal information we hold about them.
- Requests will normally be answered within one month. Where requests are complex or numerous, the response time may be extended in line with data protection law.
- We may need to verify identity and/or ask for clarification to locate the correct information. Where we require further information to respond, we will apply the lawful “stop the clock” approach so time pauses until we receive what we reasonably need.
- We will carry out reasonable and proportionate searches for information relevant to the request.
Service users may also request correction of inaccurate data and may raise concerns or objections as set out in data protection law.
6.4 Data protection complaints
Service users can raise a data protection concern or complaint with {{org_field_name}} verbally, in writing, or via an electronic method. We will acknowledge and investigate concerns promptly and will explain the outcome to the individual. This is in addition to the individual’s right to raise concerns with the Information Commissioner’s Office (ICO).
7. Data Breach Procedures
7.1 Identifying a Data Breach
A data breach includes:
- Unauthorised access or disclosure of personal data.
- Loss or theft of records or devices containing personal data.
- Cybersecurity breaches affecting data security.
7.2 Reporting and Responding to a Data Breach
- All breaches must be reported immediately to the Data Protection Officer: {{org_field_data_protection_officer_first_name}} {{org_field_data_protection_officer_last_name}}.
- A breach assessment will be conducted to determine the level of risk.
- Serious breaches must be reported to the Information Commissioner’s Office (ICO) within 72 hours.
Where we are required to notify the ICO, we will do so within 72 hours where feasible. If notification is made later than 72 hours, we will record and provide the reasons for delay. We will also keep an internal breach log of all incidents (including near misses), outcomes and learning actions.
7.3 Actions to Mitigate Risk
- Contain and investigate the breach to prevent further data loss.
- Notify affected individuals if there is a high risk to their rights and freedoms.
- Implement corrective measures to prevent recurrence.
8. Staff Responsibilities and Training
8.1 Staff Responsibilities
- All staff must follow data protection policies and maintain service user confidentiality.
- Personal data should only be accessed when necessary for service delivery.
- Any suspected data breaches must be reported immediately.
8.2 Mandatory Data Protection Training
- All employees must complete GDPR and confidentiality training during induction.
- Refresher training is conducted annually.
- Training covers:
- GDPR compliance and legal responsibilities.
- Secure data handling and storage.
- Identifying and responding to data breaches.
- Information security and the actions to be taken where personal information is compromised.
9. Monitoring and Compliance
- The Data Protection Officer conducts regular audits to ensure GDPR compliance.
- CIW may review how we protect confidentiality, manage and retain records, and uphold people’s rights as part of assessing our compliance with the Regulations and statutory guidance (including record-keeping expectations).
- Service user feedback is used to monitor data protection effectiveness.
10. Related Policies
This policy should be read in conjunction with:
- Whistleblowing (Speaking Up) Policy (DCW29)
- Staff Conduct and Code of Ethics Policy (DCW28)
- Safeguarding Adults from Abuse and Improper Treatment Policy (DCW13)
- Complaints Handling Policy (DCW14)
11. Policy Review
This policy will be reviewed annually or sooner if required by legislative changes, CIW guidance, or operational needs. Staff will be informed of any updates, and additional training will be provided as necessary.
Responsible Person: {{org_field_registered_manager_first_name}} {{org_field_registered_manager_last_name}}
Reviewed on: {{last_update_date}}
Next Review Date: {{next_review_date}}
Copyright © {{current_year}} – {{org_field_name}}. All rights reserved.