{{org_field_logo}}

{{org_field_name}}

Registration Number: {{org_field_registration_no}}


Confidentiality and Data Protection (GDPR) – Staff Policy

1. Purpose

The purpose of this policy is to ensure that {{org_field_name}} complies with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 when handling staff information. It sets out clear guidelines for the confidentiality, security, and lawful processing of employee data, ensuring that personal and sensitive information is managed responsibly and ethically.

This policy ensures compliance with:

2. Scope

This policy applies to:

It covers:

3. Principles of Confidentiality and Data Protection

{{org_field_name}} follows the seven key principles of the UK GDPR. Personal data must be:

  1. processed lawfully, fairly and transparently;
  2. collected for specified, explicit and legitimate purposes;
  3. adequate, relevant and limited to what is necessary (data minimisation);
  4. accurate and, where necessary, kept up to date;
  5. kept for no longer than necessary (storage limitation);
  6. processed securely to ensure integrity and confidentiality (security); and
  7. accountable – we must be able to demonstrate compliance (including having appropriate records, controls and training).

4. Staff Responsibilities

All staff are responsible for ensuring that confidentiality and data security are upheld at all times. This includes:

5. Collection, Processing, and Storage of Staff Data

5.1 What Personal Data We Collect

{{org_field_name}} collects and processes staff information necessary for employment, payroll, and compliance. This includes:

5.2 How Staff Data is Processed

Special category data (for example health information) will only be processed where we have:

We will document the lawful basis/condition before processing begins. Explicit consent will only be relied upon where it is appropriate and can be freely given in an employment context.

5.3 How Staff Data is Stored

5.4 Retention and secure disposal

We keep staff records only for as long as necessary for employment, legal, regulatory and safeguarding purposes, and in line with our retention schedule. Staff records are disposed of securely at end of retention (for example cross-shredding or approved confidential waste; secure deletion for electronic records).
HR will ensure staff files include and retain the information required by the Regulated Services Regulations/statutory guidance (for example key identity/DBS/employment/disciplinary records) for the appropriate period and store them securely with access controls.

6. Access Control and Data Security

6.1 Who Has Access to Staff Data?

6.2 Secure Access Procedures

7. Staff Rights Under GDPR

Employees have the following rights regarding their personal data (subject to legal limitations): the right to be informed, the right of access, rectification, erasure, restriction, data portability, the right to object, and rights relating to automated decision-making and profiling.

7.1 Right to Access (Subject Access Requests – SARs)

Staff may request access to their personal data by submitting a SAR to the Data Protection Officer (or Data Protection Lead). We will normally respond within one month.

Under the Data (Use and Access) Act 2025, where we reasonably need further information to confirm identity or clarify the request, we may pause the response timeframe (“stop the clock”) until that information is received. We will carry out reasonable and proportionate searches when responding.

Where requests are complex or numerous, the response time may be extended in line with UK GDPR requirements, and we will explain the reason for any extension.

7.2 Right to Rectification

7.3 Right to Erasure (Right to Be Forgotten)

7.4 Right to Restrict Processing

7.5 Right to Data Portability

8. Data Breaches and Reporting Procedures

8.1 What Constitutes a Data Breach?

A data breach occurs when unauthorised access, loss, or disclosure of personal data occurs. This includes:

8.2 Reporting a Data Breach

  1. Report the breach immediately to the Data Protection Officer.
  2. The Data Protection Officer will assess severity, contain the incident, and take remedial action.
  3. Where required, we will notify the ICO within 72 hours of becoming aware of a notifiable breach.
  4. If the breach is likely to result in a high risk to individuals’ rights and freedoms, we will also inform affected individuals without undue delay, including advice on protective steps they can take.
  5. We will keep an internal record of all personal data breaches (including facts, effects and remedial action), even where the breach is not reported to the ICO.

8.3 CIW notification and service-impact escalation

Where a breach involves service user information, affects continuity/safety of the service, or is otherwise a significant incident, the Registered Manager/Responsible Individual will consider whether the incident must also be notified to Care Inspectorate Wales (CIW) via CIW Online in line with CIW notification requirements and the service’s incident/notification procedures

9. Staff Training and Awareness

10. Data protection complaints

Staff who are concerned that their personal data has been handled in a way that breaches data protection law can raise a complaint to the Data Protection Officer (or Data Protection Lead).

We will:

Staff may also raise concerns with the Information Commissioner’s Office (ICO) at any time.

11. Monitoring and Compliance

Managers will ensure staff have access to up-to-date policies and will assess ongoing understanding through supervision and performance reviews, taking action where gaps are identified.

12. Related Policies

This policy should be read in conjunction with:

13. Policy Review

This policy will be reviewed annually or sooner if required by legislative changes, CIW regulations, or operational needs.


Responsible Person: {{org_field_registered_manager_first_name}} {{org_field_registered_manager_last_name}}
Reviewed on:
{{last_update_date}}
Next Review Date:
{{next_review_date}}
Copyright © {{current_year}} – {{org_field_name}}. All rights reserved.

Leave a Reply

Your email address will not be published. Required fields are marked *