{{org_field_logo}}

{{org_field_name}}

Registration Number: {{org_field_registration_no}}


Confidentiality and Data Protection (GDPR) – Service User Policy

1. Purpose

The purpose of this policy is to ensure that {{org_field_name}} complies with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and Care Inspectorate Wales (CIW) regulations when handling service user information. This policy outlines our approach to confidentiality, data security, and compliance with legal obligations while ensuring that all personal data is processed fairly, lawfully, and transparently.

Protecting the confidentiality of service users is fundamental to maintaining trust, ensuring dignity, and safeguarding personal rights. This policy applies to all staff, volunteers, contractors, and third parties who handle service user data in any capacity.

2. Scope

This policy applies to:

It covers:

3. Legal and Regulatory Compliance

{{org_field_name}} will comply with all applicable data protection and social care legislation and guidance, including:

4. Principles of Confidentiality and Data Protection

All data processing activities at {{org_field_name}} adhere to the following key principles:

4.1 Lawfulness, Fairness, and Transparency

4.2 Lawful basis and special category data

Most service user information we hold is special category personal data. We will only process it where we have both:

We keep an internal record of the lawful basis/condition relied upon for our key processing activities (e.g., care planning, daily records, medicines support, incident management, safeguarding, invoicing and regulatory compliance).

4.3 Purpose Limitation

4.4 Data Minimisation

4.5 Storage limitation and record retention

We retain personal data only for as long as necessary for safe care, safeguarding, legal and regulatory purposes.

In line with regulatory record requirements, we will:

Records will be disposed of securely (or anonymised where appropriate) when the retention period ends.

If the service closes, we will make secure arrangements for records to continue to be kept securely and remain retrievable for lawful requests, including regulatory requests.

4.6 Storage Limitation

4.7 Integrity and Confidentiality

5. Data Collection, Storage, and Processing

5.1 Data Collection

5.2 Data Storage and Security

Where records are stored electronically, access will be controlled by unique user accounts and permissions so that an audit trail shows who has accessed, created or amended records, and when.

5.3 Data Processing

6. Data Sharing and Access Control

6.1 Who Can Access Service User Data?

6.2 Sharing Data with Third Parties

We will seek to involve the service user in information-sharing decisions wherever possible. However, information may be shared without consent where there is a lawful basis and it is necessary, for example, to protect the person or others (vital interests), for safeguarding, to comply with a legal obligation, or for the prevention/detection of crime. Where we share information without consent, we will record the decision, the rationale, what was shared, and with whom.

6.3 Service User Access to Their Own Data

Service users (or authorised representatives) have the right to request access to personal information we hold about them.

Service users may also request correction of inaccurate data and may raise concerns or objections as set out in data protection law.

6.4 Data protection complaints

Service users can raise a data protection concern or complaint with {{org_field_name}} verbally, in writing, or via an electronic method. We will acknowledge and investigate concerns promptly and will explain the outcome to the individual. This is in addition to the individual’s right to raise concerns with the Information Commissioner’s Office (ICO).

7. Data Breach Procedures

7.1 Identifying a Data Breach

A data breach includes:

7.2 Reporting and Responding to a Data Breach

Where we are required to notify the ICO, we will do so within 72 hours where feasible. If notification is made later than 72 hours, we will record and provide the reasons for delay. We will also keep an internal breach log of all incidents (including near misses), outcomes and learning actions.

7.3 Actions to Mitigate Risk

8. Staff Responsibilities and Training

8.1 Staff Responsibilities

8.2 Mandatory Data Protection Training

9. Monitoring and Compliance

10. Related Policies

This policy should be read in conjunction with:

11. Policy Review

This policy will be reviewed annually or sooner if required by legislative changes, CIW guidance, or operational needs. Staff will be informed of any updates, and additional training will be provided as necessary.


Responsible Person: {{org_field_registered_manager_first_name}} {{org_field_registered_manager_last_name}}
Reviewed on:
{{last_update_date}}
Next Review Date:
{{next_review_date}}
Copyright © {{current_year}} – {{org_field_name}}. All rights reserved.

Leave a Reply

Your email address will not be published. Required fields are marked *