{{org_field_logo}}
{{org_field_name}}
Registration Number: {{org_field_registration_no}}
Cyber Bullying Policy
1. Purpose
The purpose of this policy is to establish a zero-tolerance approach to cyber bullying within {{org_field_name}}, ensuring the safety, dignity, and well-being of staff, people we support, and other stakeholders. This policy outlines preventative measures, reporting procedures, and disciplinary actions to address cyber bullying effectively while complying with Care Inspectorate Scotland regulations and other relevant laws.
2. Scope
This policy applies to:
- All employees, management, and board members of {{org_field_name}}.
- People we support, their families, and visitors who interact with our services.
- Third-party providers and external agencies associated with our organisation.
- Any digital communication tools and platforms used for work-related activities, including emails, instant messaging, social media, and online forums.
3. Legal and Regulatory Requirements
This policy must be read and applied in accordance with the legal and regulatory requirements relevant to registered care-at-home services in Scotland, including:
- the Public Services Reform (Scotland) Act 2010;
- the Social Care and Social Work Improvement Scotland (Requirements for Care Services) Regulations 2011 (SSI 2011/210);
- the Health and Social Care Standards: My support, my life;
- the Scottish Social Services Council (SSSC) Codes of Practice for Social Service Workers and Employers, 2024;
- the Equality Act 2010;
- the Worker Protection (Amendment of Equality Act 2010) Act 2023;
- the Employment Rights Act 1996, including the provisions relating to protected disclosures;
- the Health and Safety at Work etc. Act 1974;
- the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018;
- the Protection from Harassment Act 1997, so far as applicable in Scotland;
- the Criminal Justice and Licensing (Scotland) Act 2010, including section 38 relating to threatening or abusive behaviour; and
- the Adult Support and Protection (Scotland) Act 2007 where conduct raises concerns that an adult may be at risk of harm.
{{org_field_name}} will also comply with current Care Inspectorate notification, record-keeping and reporting requirements applicable to the service.
Cyber bullying may amount to unlawful harassment, discrimination, victimisation, threatening or abusive behaviour, a safeguarding or adult protection concern, or other unlawful conduct depending upon the circumstances.
Under the Equality Act 2010, harassment may arise where unwanted conduct related to a relevant protected characteristic has the purpose or effect of violating a person’s dignity or creating an intimidating, hostile, degrading, humiliating or offensive environment. Sexual harassment includes unwanted conduct of a sexual nature which has that purpose or effect.
{{org_field_name}}, as an employer, will take reasonable steps to prevent sexual harassment of its employees in the course of their employment, including sexual harassment occurring through electronic communications, social media or other digital means.
Nothing in this policy will be interpreted or applied in a manner that prevents or penalises a worker for making a protected disclosure, raising a genuine safeguarding concern, reporting unsafe or unlawful practice, making a complaint, cooperating with a regulator or other competent authority, or exercising any other legally protected right.
4. Definition of Cyber Bullying
For the purposes of this policy, cyber bullying means unwanted, inappropriate, abusive, intimidating, humiliating, threatening, discriminatory or otherwise harmful behaviour carried out wholly or partly through digital or electronic means.
Cyber bullying may be intentional or unintentional. When deciding whether behaviour falls within this policy, {{org_field_name}} will consider the nature of the behaviour, its context, its impact, whether it forms part of a pattern of behaviour and any relevant legal definition. A person stating that they did not intend to cause harm does not, by itself, mean that the behaviour cannot amount to bullying or harassment.
Cyber bullying may involve a single serious incident or repeated behaviour and may occur through work or personal devices, accounts or platforms where there is a connection with work, the care service, a person receiving care or support, or another individual associated with the service.
Examples include, but are not limited to:
- sending abusive, threatening, intimidating, humiliating, offensive or malicious messages;
- posting, sharing or forwarding humiliating, abusive, discriminatory, sexual or otherwise inappropriate comments, photographs, recordings, videos or other material;
- unwanted conduct related to a protected characteristic which violates a person’s dignity or creates an intimidating, hostile, degrading, humiliating or offensive environment;
- unwanted conduct of a sexual nature carried out through messages, photographs, videos, social media, messaging applications or other electronic means;
- repeatedly contacting an individual electronically in a manner that amounts to harassment;
- deliberately excluding or isolating an individual from work-related electronic communications where this is intended to, or has the effect of, bullying, humiliating or undermining the individual;
- impersonating another person or creating false accounts or profiles for the purpose of bullying, harassing, humiliating, threatening or deceiving them;
- accessing another person’s account without authority for the purpose of bullying, harassment or other improper conduct;
- disclosing or sharing personal, confidential or sensitive information without lawful authority, including so-called “outing” or “doxxing”;
- knowingly spreading malicious or fabricated allegations about an individual;
- using digital communications to threaten violence, abuse or other harm; and
- encouraging, assisting or participating in cyber bullying carried out by another person.
Legitimate management action, appropriately expressed constructive feedback, reasonable instructions, lawful performance management, the raising of a grievance or complaint, reporting a safeguarding concern, reporting unsafe practice, raising concerns with the Care Inspectorate or SSSC, cooperating with an investigation, or making a protected disclosure will not be treated as cyber bullying merely because another person disagrees with, is embarrassed by or is unhappy about what has been raised.
Nothing in this policy prevents any worker from making a protected disclosure in accordance with the Employment Rights Act 1996 or the organisation’s Whistleblowing Policy.
5. Responsibilities
- Registered Manager: Ensures that all cyber bullying incidents are investigated and handled appropriately.
- IT Team: Implement security controls to prevent cyber bullying and support affected individuals.
- All Employees and Stakeholders: Maintain a professional and respectful online presence.
- Supervisors and Team Leaders: Act as the first point of contact for reporting concerns.
- People We Support & Families: Encouraged to report concerns regarding cyber bullying.
6. Preventative Measures
6.1 Awareness and Training
- Mandatory cyber bullying awareness training for all employees annually.
- Workshops and discussions on online professionalism and respectful communication.
- Training for supervisors on how to handle cyber bullying reports.
6.2 IT, Digital Communications and Monitoring
{{org_field_name}} will maintain appropriate technical and organisational measures to protect information systems, work-related digital communications and personal information.
These measures will include, where appropriate:
- appropriate access controls for organisational email accounts, electronic care systems, cloud services, messaging systems and other digital platforms;
- appropriate security and privacy controls designed to protect staff and people receiving care and support from unauthorised access, misuse, disclosure or online abuse;
- controls governing the acceptable use of organisational systems, devices, email, messaging applications and social media; and
- proportionate measures for preserving relevant electronic evidence where a cyber bullying allegation is reported.
Any monitoring of staff communications, devices, accounts or online activity undertaken by {{org_field_name}} will be lawful, necessary and proportionate and will be carried out in accordance with the UK GDPR, the Data Protection Act 2018 and the organisation’s privacy and information governance arrangements.
Workers will be provided with appropriate information about monitoring that may take place, including its purpose and the circumstances in which information may be accessed, reviewed, retained or disclosed.
Covert or excessive monitoring will not be undertaken merely for the purposes of this policy. Where exceptional circumstances may justify covert monitoring, this must be separately authorised at an appropriate senior level and undertaken only where there is a lawful basis and the action is necessary and proportionate.
Information obtained during an investigation will be accessed only by those who require it for a legitimate purpose and will be stored, shared, retained and disposed of in accordance with applicable data protection law and organisational retention requirements.
6.3 Workplace Culture and Well-being
- Open-door policy where staff feel safe to discuss cyber bullying concerns.
- Encouraging a supportive workplace culture where mutual respect and inclusivity are promoted.
- Zero tolerance messaging in policies, handbooks, and digital communication tools.
7. Reporting Procedures
7.1 How to Report Cyber Bullying
Any worker who experiences, witnesses, receives information about or reasonably suspects cyber bullying connected with {{org_field_name}} must raise the matter promptly.
A concern may be reported:
- verbally or in writing to the worker’s line manager;
- to the Registered Manager;
- to the organisation’s designated safeguarding or Adult Support and Protection lead, where applicable;
- by email to: {{org_field_registered_manager_email}};
- by telephone to: {{org_field_phone_no}};
- using the out-of-hours contact number: {{out_of_hours}}; or
- through any other confidential reporting or whistleblowing route made available by {{org_field_name}}.
Where the concern relates to the worker’s line manager or Registered Manager, or where the worker reasonably believes that it would be inappropriate to report through the normal management route, the concern may be raised through the organisation’s senior management, safeguarding, grievance or whistleblowing arrangements as appropriate.
People receiving care and support, their representatives, relatives, carers and visitors may raise concerns directly with the service and must also be informed of their right to use the organisation’s complaints procedure and to contact the Care Inspectorate directly where the concern relates to the registered care service.
No person will be subjected to victimisation or retaliation for raising a concern in good faith, making a complaint, reporting a safeguarding concern, making a protected disclosure or cooperating with an investigation.
Where there is an immediate risk of harm, a threat of violence or another emergency, the priority is to protect the person from immediate danger. Emergency services must be contacted where necessary.
7.2 Initial Response, Preservation of Evidence and Investigation
All reports will be taken seriously and assessed promptly.
The manager receiving the concern must first determine whether immediate protective action is required and whether the matter is:
- an employment bullying, harassment, disciplinary or grievance matter;
- a complaint about the registered care service;
- a safeguarding or Adult Support and Protection concern;
- a possible criminal matter;
- a data protection or confidentiality breach;
- a potential SSSC or other professional fitness-to-practise matter; or
- an incident requiring notification or reporting to the Care Inspectorate or another authority.
More than one procedure may apply to the same incident.
Relevant evidence should be preserved where it is safe and lawful to do so. This may include emails, messages, screenshots, electronic records, dates, times, URLs, account details and witness information. Evidence must not be obtained by unlawfully accessing another person’s private account, device or communications.
Information will be handled confidentially so far as reasonably possible. Absolute confidentiality cannot be guaranteed where information must be shared to safeguard an individual, investigate an allegation, comply with the law, make a regulatory or professional referral, or allow a person who is the subject of an allegation a fair opportunity to respond.
An internal investigation must not interfere with, prejudice or unnecessarily duplicate an Adult Support and Protection, police, Care Inspectorate, SSSC or other statutory investigation. Where another authority is leading an investigation, {{org_field_name}} will cooperate with that authority and will seek or follow appropriate instructions before conducting interviews or taking investigative steps that could compromise the external investigation.
The person who is the subject of an allegation will be treated fairly and no conclusion will be reached before relevant evidence has been considered. Precautionary measures may be introduced where necessary to protect people or preserve the integrity of an investigation. Such measures do not amount to a finding of wrongdoing.
Where the report constitutes a complaint about the care service, it will also be handled in accordance with the organisation’s formal complaints procedure and the Social Care and Social Work Improvement Scotland (Requirements for Care Services) Regulations 2011.
7.3 Safeguarding, Regulatory and External Reporting
Where cyber bullying involves a person receiving care and support, the Registered Manager must consider immediately whether the information indicates actual, suspected or potential abuse, harm, exploitation, neglect, discriminatory abuse or another Adult Support and Protection concern.
Where such a concern exists:
- immediate action must be taken to protect the person from further harm;
- the organisation’s Adult Support and Protection procedure and the relevant local multi-agency Adult Support and Protection arrangements must be followed without unnecessary delay;
- the relevant local authority Adult Support and Protection service and/or Police Scotland must be contacted where required by the nature and seriousness of the concern;
- the incident, decisions made, referrals, protective actions and outcomes must be accurately recorded;
- the Care Inspectorate must be notified where the incident falls within a current Care Inspectorate notification requirement;
- where the conduct of an SSSC-registered worker raises a concern about their fitness to practise, the Registered Manager or provider must consider and, where required, make a referral to the SSSC in accordance with current SSSC referral guidance; and
- any other required referral or notification to a professional regulator, commissioning authority or statutory body must be made within the applicable timescale.
A decision not to make an Adult Support and Protection, Care Inspectorate, SSSC, police or other external referral where one has been considered must be supported by a clear recorded rationale.
8. Outcomes and Action Following Cyber Bullying
Where an allegation of cyber bullying is substantiated, {{org_field_name}} will take action that is appropriate and proportionate to the circumstances and in accordance with the relevant organisational procedure.
For employees, misconduct will be addressed under the organisation’s disciplinary procedure. Depending on the facts and seriousness of the case, disciplinary action may include a formal warning or dismissal, including dismissal for gross misconduct where justified.
No disciplinary sanction will be imposed solely because an allegation has been made. The person concerned will be informed of the allegations against them and given a reasonable opportunity to respond before a disciplinary decision is reached, subject to any necessary safeguarding or external-investigation arrangements.
Suspension from work, removal from particular duties, increased supervision, changes to working arrangements or restrictions on access to systems may be considered as precautionary measures where reasonably necessary to protect people, preserve evidence or enable a fair investigation. A precautionary suspension is not, in itself, a disciplinary sanction or a finding of wrongdoing.
Where the person responsible is not an employee, {{org_field_name}} will take appropriate action within its authority. This may include restricting access to organisational systems or premises, ending an inappropriate communication channel, contacting an employer, contractor or commissioning organisation, or taking steps to protect the person affected.
Where conduct may constitute a criminal offence, {{org_field_name}} may refer the matter to Police Scotland and will do so where this is necessary to protect a person or comply with safeguarding or other legal obligations.
Where the conduct of a registered social service worker raises a question about their fitness to practise, {{org_field_name}} will consider its responsibility to make a referral to the SSSC. Any referral will be considered separately from the internal disciplinary process and will not be delayed solely because internal proceedings remain ongoing.
Where required, {{org_field_name}} will also make notifications or referrals to the Care Inspectorate or another relevant professional, regulatory, safeguarding or statutory body.
All decisions, actions and reasons for those decisions will be appropriately recorded.
9. Support and Protection for Affected Individuals
{{org_field_name}} will take reasonable steps to support individuals affected by cyber bullying and to protect them from further harm or retaliation.
Support will be considered according to the person’s individual circumstances and may include:
- access to appropriate wellbeing or counselling support;
- advice about preserving evidence and protecting digital accounts;
- temporary or longer-term adjustments to working arrangements where appropriate;
- support through supervision or management arrangements;
- assistance to access safeguarding, advocacy, police or other relevant services where required; and
- reasonable measures to prevent further unwanted contact or behaviour.
Mediation will not be used where it would be unsafe, inappropriate or inconsistent with safeguarding requirements, particularly where there is an allegation of abuse, serious harassment, sexual harassment, violence, coercion or a significant imbalance of power.
No employee will be subjected to dismissal, disciplinary action, disadvantage, intimidation, victimisation or other retaliation because they have, in good faith, raised a concern, made a complaint, reported a safeguarding matter, cooperated with an investigation or made a protected disclosure. This does not prevent appropriate action where an allegation is established to have been deliberately fabricated or made maliciously.
Any allegation of retaliation or victimisation following a report under this policy must itself be taken seriously, recorded and investigated.
10. Related Policies
- Workplace Harassment and Bullying Policy
- Social Media and Online Conduct Policy
- IT Equipment Security Policy
- Data Protection and GDPR Compliance Policy
11. Policy Review
This policy will be reviewed annually or immediately after any major cyber bullying incident. {{org_field_name}} is committed to creating a safe and respectful online environment for all employees and people we support.
Responsible Person: {{org_field_registered_manager_first_name}} {{org_field_registered_manager_last_name}}
Reviewed on: {{last_update_date}}
Next Review Date: {{next_review_date}}
Copyright © {{current_year}} – {{org_field_name}}. All rights reserved.