{{org_field_logo}}

{{org_field_name}}

Registration Number: {{org_field_registration_no}}


Confidentiality and Information Sharing Policy

1. Purpose

The purpose of this policy is to explain how {{org_field_name}} protects confidential information and shares information lawfully, fairly, securely and only where there is a clear need to do so.

{{org_field_name}} is committed to complying with all applicable data protection, confidentiality, employment and safeguarding requirements relevant to a temporary staffing agency operating in England, including the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and other applicable legislation and guidance in force from time to time. Where relevant to the services provided, this policy also supports compliance with the Employment Agencies Act 1973, the Conduct of Employment Agencies and Employment Businesses Regulations 2003, safeguarding obligations, right to work requirements, equality obligations and lawful information sharing duties.

This policy applies to all personal data and confidential information processed by {{org_field_name}} in relation to applicants, candidates, temporary workers, employees, contractors, former staff, client organisations, client contacts, referees, complainants, witnesses and other individuals whose information {{org_field_name}} handles in the course of its business.

Where {{org_field_name}} supplies workers into health or social care environments, this policy also requires staff to have regard to sector-specific confidentiality expectations, including the Caldicott Principles where relevant to health and care information sharing. However, this policy does not assume that {{org_field_name}} is itself a regulated care provider unless expressly stated elsewhere in the organisation’s governance documents.

2. Scope

This policy applies to:

3. Principles of Confidentiality and Data Protection

{{org_field_name}} will process personal data and confidential information in accordance with the following principles:

4. Types of Confidential Information

Confidential information processed by {{org_field_name}} may include, but is not limited to:

5. Responsibilities

Directors and Senior Management: are responsible for ensuring that {{org_field_name}} has appropriate governance, resources, systems, contracts, training, supervision and assurance arrangements in place to comply with confidentiality and data protection requirements.

Data Protection Lead / Data Protection Officer: is responsible for oversight of data protection compliance, advice, breach handling and support with data subject rights.

Managers: must ensure that staff only access information on a strict need-to-know basis, follow this policy, escalate concerns promptly and maintain appropriate local controls.

Employees, Agency Workers and Contractors: must keep information confidential, follow all policies and training, use information only for authorised purposes, report incidents immediately and never access or disclose information without a legitimate business reason.

IT and Systems Administrators / Service Providers: must maintain appropriate security, access management, backup, resilience, monitoring and secure disposal arrangements for systems and devices used by {{org_field_name}}.

6. Information Sharing Guidelines

{{org_field_name}} will only share personal data or confidential information where there is a clear and documented lawful basis, where the sharing is necessary and proportionate, and where appropriate safeguards are in place.

Information may be shared, as appropriate, in the following circumstances:

{{org_field_name}} will not rely on consent where another more appropriate lawful basis applies, particularly in employment or recruitment relationships where consent may not be freely given.

Before sharing information, staff must consider:

  1. what information is necessary;
  2. who needs to receive it;
  3. the lawful basis and, where relevant, special category or criminal offence condition;
  4. whether the disclosure is proportionate;
  5. whether the individual should be informed;
  6. whether there is any immediate safeguarding or serious harm issue; and
  7. how the decision and rationale will be recorded.

7. Lawful Bases and Conditions for Processing

Depending on the circumstances, {{org_field_name}} may rely on one or more of the following lawful bases under Article 6 UK GDPR: contract, legal obligation, legitimate interests, vital interests, consent, or another lawful basis permitted by law.

Where {{org_field_name}} processes special category data, it will identify an additional condition under Article 9 UK GDPR and, where required, a condition under Schedule 1 to the Data Protection Act 2018. These may include employment, social security and social protection obligations, occupational medicine or assessment of working capacity, safeguarding, substantial public interest, legal claims, or explicit consent where appropriate.

Where {{org_field_name}} processes criminal offence data, including DBS-related information, it will do so only where authorised by law, necessary for the relevant role, and handled with additional confidentiality and access controls.

8. Secure Handling of Information

{{org_field_name}} will implement appropriate technical and organisational measures to protect personal data and confidential information. These measures include, where appropriate:

9. Data Subject Rights

Individuals whose personal data is processed by {{org_field_name}} have rights under data protection law, subject to legal exemptions and limitations. These rights may include the right to:

10. Personal Data Breaches and Reporting

A personal data breach means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.

All data breaches must be assessed promptly and recorded in the organisation’s breach log, whether or not they are reportable to the ICO.

Where a personal data breach is likely to result in a risk to the rights and freedoms of individuals, {{org_field_name}} will notify the ICO without undue delay and, where feasible, within 72 hours of becoming aware of the breach. Where the breach is likely to result in a high risk to the rights and freedoms of individuals, {{org_field_name}} will also inform affected individuals without undue delay unless a lawful exception applies.

{{org_field_name}} will investigate the cause of each breach, take remedial action, document lessons learned and, where necessary, update systems, controls, contracts or training.

11. Retention and Disposal

{{org_field_name}} will retain personal data and confidential information only for as long as necessary for the purpose for which it was collected, taking account of legal, regulatory, contractual, safeguarding, tax, employment, limitation and insurance requirements.

Retention periods will be set out in a separate retention schedule or records management procedure. At the end of the retention period, records will be securely deleted, anonymised or destroyed, unless there is a lawful reason to retain them for longer.

Staff must not keep duplicate, excessive or unofficial records outside approved systems.

12. Controller, Processor and Third-Party Sharing

{{org_field_name}} will identify whether it is acting as a controller, joint controller or processor in relation to each category of personal data it handles.

In most cases, {{org_field_name}} will act as controller for recruitment, compliance, onboarding, assignment management, payroll-related administration under its control, incident management and internal HR data.

Where {{org_field_name}} uses third-party processors, including software providers, payroll providers, document storage providers, communication platforms, occupational health providers or other service providers, it will ensure that appropriate written contracts and security measures are in place.

Where personal data is shared with client organisations, the parties will clarify their respective responsibilities and only share the information necessary for lawful recruitment, placement, supervision, payment, safeguarding, regulatory compliance or related legitimate business purposes.

13. Right to Work, DBS and Safeguarding Information

{{org_field_name}} will process right to work, DBS, safeguarding and related compliance information only where necessary and permitted by law.

Right to work checks will be completed in line with current Home Office requirements and recorded in a way that supports the organisation’s statutory excuse where applicable.

DBS certificate information, barred list information and other criminal offence data will only be requested, used, shared and retained where the role is eligible and the processing is lawful, necessary and proportionate. Access to such information will be strictly limited to authorised personnel.

Where safeguarding concerns arise, information may be shared without consent where necessary to protect a child, young person or adult at risk, or where otherwise justified by law. Such decisions must be documented clearly, including the reason for sharing, the recipient, the information shared and the lawful basis relied upon.

14. Disciplinary Actions for Breaches of Confidentiality

Failure to comply with this policy may result in disciplinary action, removal from duties or assignments, termination of engagement, referral to professional or regulatory bodies, reporting to clients, reporting to the ICO or other authorities, and where appropriate civil or criminal action.

The action taken will depend on the seriousness of the breach, whether it was deliberate or negligent, the level of harm or risk caused, and any previous concerns regarding conduct or compliance.

15. Related Policies and Documents

This policy should be read together with, where applicable:

16. Policy Review

This policy will be reviewed at least annually and sooner where required by changes in law, ICO guidance, Home Office guidance, case law, regulatory expectations, business operations or lessons learned from incidents, complaints, audits or investigations.


Responsible Person: {{org_field_registered_manager_first_name}} {{org_field_registered_manager_last_name}}
Reviewed on:
{{last_update_date}}
Next Review Date:
{{next_review_date}}
Copyright © {{current_year}} – {{org_field_name}}. All rights reserved.

Leave a Reply

Your email address will not be published. Required fields are marked *