{{org_field_logo}}
{{org_field_name}}
Registration Number: {{org_field_registration_no}}
Caldicott Principles and Service user Information Policy
1. Purpose
The purpose of this policy is to ensure that {{org_field_name}} upholds the highest standards of confidentiality, integrity, and lawful processing of service user information in line with the Caldicott Principles, UK GDPR, and Care Inspectorate Wales (CIW) regulations. This policy sets out clear procedures for handling service user data securely, maintaining confidentiality, and ensuring that information is shared appropriately to protect service users’ rights and privacy.
This policy ensures compliance with:
- UK GDPR and the Data Protection Act 2018 (lawful processing, security, individual rights).
- The Regulation and Inspection of Social Care (Wales) Act 2016 and The Regulated Services (Service Providers and Responsible Individuals) (Wales) Regulations 2017 (as amended), and the Welsh Government statutory guidance for care home and domiciliary support service providers and responsible individuals (last updated 27 March 2024).
- Social Services and Well-being (Wales) Act 2014 (person-centred practice, well-being and rights-based approaches).
- Social Care Wales Codes of Professional Practice and Employer Code (confidentiality, record keeping, and professional duty of candour where applicable).
- CIW inspection frameworks / lines of enquiry (including expectations on record keeping, confidentiality, and staff understanding of policies).
2. Scope
This policy applies to:
- All employees, including care staff, managers, and administrative personnel.
- External contractors, volunteers, and agency staff handling service user information.
- Service user-identifiable data in electronic, paper, or verbal format.
It covers:
- Understanding the Caldicott Principles.
- Staff responsibilities in handling service user information.
- How and when service user data can be shared.
- Ensuring compliance with GDPR and legal requirements.
- Data security measures and breach reporting.
- Training and competency requirements.
This policy also applies to information handled during domiciliary care delivery, including records kept in an individual’s home (e.g., daily notes / MAR or visit logs), information carried on paper between visits, and information accessed or recorded using mobile devices or remote systems. It includes verbal information shared in the individual’s home and information exchanged with families/representatives and partner professionals.
3. The Caldicott Principles
The Caldicott Principles provide a framework for managing service user information securely and ethically. {{org_field_name}} ensures that all staff understand and apply these principles:
Principle 1: Justify the Purpose for Using Confidential Information
- Service user information should only be used when necessary and for a clear purpose, such as care provision or safeguarding.
- All data requests must be assessed to determine if disclosure is appropriate.
Principle 2: Use Confidential Information Only When Absolutely Necessary
- Staff must only access service user data that is relevant to their role.
- Non-identifiable information should be used whenever possible (e.g., anonymised case studies).
Principle 3: Use the Minimum Necessary Confidential Information
- Only the essential details should be shared (e.g., for GP referrals, medication changes).
- Excessive data collection is prohibited under GDPR regulations.
Principle 4: Access to Confidential Information Should Be on a Strict Need-to-Know Basis
- Staff must not access service user records unless required for their duties.
- Access permissions are role-specific, limiting unnecessary exposure to sensitive information.
Principle 5: Everyone Must Understand Their Responsibilities
- All staff must sign a confidentiality agreement as part of their contract.
- Staff must complete mandatory Caldicott and GDPR training annually.
Principle 6: Comply with the Law
- All data processing activities must comply with UK GDPR and the Data Protection Act 2018.
- Any breach of confidentiality is reportable to the Information Commissioner’s Office (ICO) if required.
Principle 7: The Duty to Share Information Can Be as Important as the Duty to Protect It
- In some cases, sharing information is necessary for safeguarding, medical care, or legal requirements.
- Staff must follow the Safeguarding Adults from Abuse and Improper Treatment Policy (DCW13) when reporting concerns.
Principle 8: Inform Service users About How Their Information Is Used
- Service users must be informed about how their data is collected, used, and stored.
- Privacy notices must be provided in accessible formats.
4. Responsibilities of Staff in Handling Service user Information
4.1 Responsibilities of the Service Provider and Responsible Individual (RI)
The Service Provider and Responsible Individual are accountable for ensuring effective information governance arrangements are in place. This includes:
- ensuring up-to-date policies and procedures exist for confidentiality, record keeping and data protection and are accessible to staff;
- ensuring staff read and understand these policies during induction and that understanding is reviewed through supervision and performance processes;
- ensuring there are effective systems for secure record keeping, audit, and action taken where issues are identified; and
- ensuring any significant information governance risks or incidents are escalated and managed in line with organisational processes and regulatory expectations.
4.2 Responsibilities of the Registered Manager
- Ensure compliance with Caldicott, GDPR, and CIW regulations.
- Monitor staff training and confidentiality agreements.
- Oversee data security audits and ensure secure storage of records.
4.3 Responsibilities of Care Staff
- Follow confidentiality and data protection procedures at all times.
- Only access service user information relevant to care delivery.
- Report any suspected data breaches or unauthorised access.
4.4 Responsibilities of the Data Protection Officer (DPO)
- Data Protection Officer: {{org_field_data_protection_officer_first_name}} {{org_field_data_protection_officer_last_name}}.
- Oversee compliance with data security policies.
- Investigate data breaches and manage ICO reporting.
5. Sharing Service user Information Safely
5.1 When Can Service user Information Be Shared?
Service user-identifiable data can only be shared:
- With the service user’s consent for care coordination.
- For safeguarding concerns (following CIW and local authority procedures).
- When legally required by regulatory bodies or law enforcement.
5.2 Secure Methods of Sharing Data
- Encrypted emails must be used when sharing service user information electronically.
- Telephone discussions should be conducted in private settings.
- Paper records must be transported securely and never left unattended.
5.3 Documenting Data Sharing
- Any disclosure of service user information must be recorded, including who requested it, why, and how it was shared.
- Service users should be informed when their information is shared unless legally exempt.
6. Individuals’ information rights and access to records
{{org_field_name}} will support individuals (and where appropriate their authorised representatives) to understand and exercise their rights under UK GDPR and the Data Protection Act 2018. This includes the right to: access a copy of their personal data, request correction of inaccurate data, request deletion where applicable, restrict processing, object to certain processing, and complain to the Information Commissioner’s Office (ICO).
Subject Access Requests (SARs): Any request (verbal or written) from an individual/representative to see or obtain copies of records must be treated as a SAR and forwarded to the Data Protection Officer immediately. Identity and authority will be verified before disclosure. Responses will be issued within statutory timescales and disclosures will be recorded.
Transparency: Privacy notices must be provided in accessible formats and explained in a way the individual can understand, including what data is collected, why, who it may be shared with, and how long it is retained.
7. Records management, retention and disposal
Records must be accurate, complete, contemporaneous and attributable, and stored in a way that maintains confidentiality and integrity. Records include (but are not limited to) assessments, personal plans, visit notes, risk assessments, medication records, incident records, safeguarding records, staff records and data-sharing logs.
Retention: Records will be retained for periods defined in {{org_field_name}}’s Record Retention Schedule, aligned to legal, regulatory and best-practice requirements for health and social care records.
Secure disposal: At the end of the retention period, paper records must be cross-shredded or disposed of via an approved confidential waste contractor. Electronic records must be securely deleted in line with IT procedures, ensuring data cannot be reconstructed. Disposal actions must be logged where required.
8. Data Security and Breach Reporting
8.1 How Data is Stored
- Electronic records are stored in secure, password-protected systems.
- Paper records must be kept in locked filing cabinets.
- Staff must log out of systems when not in use to prevent unauthorised access.
- Mobile working and devices: Service user information must not be stored on personal devices unless formally authorised and protected by approved security controls (e.g., device encryption, strong passcodes/biometrics, auto-lock, remote wipe capability). Staff must not use personal email accounts or unapproved messaging applications to share identifiable information.
- In an individual’s home: Paper records (including daily visit notes) must be kept in a secure place agreed with the individual, not accessible to visitors, and not left open or unattended. Staff must take reasonable steps to prevent others from overhearing confidential conversations.
- Images/photographs: Staff must not photograph records or screens containing identifiable information unless explicitly authorised for a legitimate purpose and using approved secure systems.
8.2 What Constitutes a Data Breach?
A data breach includes:
- Loss of service user files or unauthorised disclosure.
- Hacking or cyber-attacks on electronic records.
- Sending confidential information to the wrong recipient.
8.3 Reporting a Data Breach
- Report the breach immediately to the Data Protection Officer.
- The DPO assesses the impact and determines if ICO notification is required.
- The breach is documented, and corrective action is taken to prevent recurrence.
9. Staff Training and Compliance
- All staff must complete Caldicott and GDPR training upon induction.
- Annual refresher training is mandatory for all employees.
- Regular compliance audits ensure best practices are maintained.
10. Monitoring and Compliance
- The Registered Manager and DPO conduct regular audits to ensure compliance.
- Service user feedback is reviewed to assess transparency and consent management.
- CIW inspections and ratings assessments will consider how the service assures confidentiality, data protection and record keeping in practice, including whether staff have access to, understand and follow up-to-date policies, and whether governance/audit arrangements identify and address issues promptly.
As inspection outcomes contribute to published ratings, the service will maintain clear audit trails for training, access controls, breaches, and corrective actions relating to information governance.
11. Related Policies
This policy should be read in conjunction with:
- Confidentiality and Data Protection (GDPR) Policy (DCW34).
- Whistleblowing (Speaking Up) Policy (DCW29).
- Safeguarding Adults from Abuse and Improper Treatment Policy (DCW13).
- IT and Cybersecurity Policy (DCW40).
12. Policy Review
This policy will be reviewed annually or sooner if required by legislative changes, CIW regulations, or operational needs.
Responsible Person: {{org_field_registered_manager_first_name}} {{org_field_registered_manager_last_name}}
Reviewed on: {{last_update_date}}
Next Review Date: {{next_review_date}}
Copyright © {{current_year}} – {{org_field_name}}. All rights reserved.