{{org_field_logo}}
{{org_field_name}}
Registration Number: {{org_field_registration_no}}
Using Social Media Platforms Policy
1. Purpose
The purpose of this policy is to provide clear guidance on the appropriate and responsible use of social media platforms by employees, people we support, and representatives of {{org_field_name}}. This policy ensures that social media is used in a way that:
- Protects the privacy, dignity, and rights of people we support.
- Maintains professional boundaries between staff and service users.
- Prevents any breach of confidentiality, safeguarding concerns, or reputational damage.
- Complies with CQC regulations, GDPR, and best practice guidance on social media use in health and social care settings.
2. Scope
This policy applies to all employees, agency and bank staff, volunteers, contractors, and people we support. It covers the use of:
- Personal and professional social media accounts on platforms such as Facebook, Instagram, Twitter, LinkedIn, TikTok, YouTube, and WhatsApp.
- Official organisation social media accounts managed by {{org_field_name}}.
- Internal and external online forums, blogs, and video-sharing sites.
3. Legal and Regulatory Compliance
This policy must be implemented in accordance with all applicable legislation and regulatory requirements, including:
- Health and Social Care Act 2008 (Regulated Activities) Regulations 2014, including, where applicable:
- Regulation 10 – Dignity and Respect: requiring people using the service to be treated with dignity and respect, including respect for their privacy, autonomy and independence.
- Regulation 11 – Need for Consent: requiring care and treatment to be provided with the consent of the relevant person and requiring the Mental Capacity Act 2005 to be followed where a person lacks capacity to make the relevant decision.
- Regulation 13 – Safeguarding Service Users from Abuse and Improper Treatment: requiring effective systems and processes to prevent, identify, investigate and respond to abuse and improper treatment, including abuse or exploitation facilitated through social media or other online platforms.
- Regulation 17 – Good Governance: requiring effective systems and processes for assessing and monitoring risks and for maintaining secure, accurate, complete and contemporaneous records, including records relating to decisions, consent, safeguarding and information governance.
- Regulation 20 – Duty of Candour: requiring the registered person to act in an open and transparent way with people receiving care and support and to comply with the specific statutory requirements where a notifiable safety incident occurs.
- Care Quality Commission (Registration) Regulations 2009, including the requirement to notify the Care Quality Commission of incidents where the statutory notification criteria are met.
- UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, as amended, including by the Data (Use and Access) Act 2025, governing the lawful, fair, transparent and secure processing of personal data.
- Mental Capacity Act 2005 and its Code of Practice, where a person may lack capacity to make a particular decision relating to their use of social media, sharing of information or support provided by staff.
- Care Act 2014, including the statutory adult safeguarding framework where an adult with care and support needs is experiencing, or is at risk of, abuse or neglect and is unable to protect themselves because of those needs.
- Equality Act 2010, including the requirement not to unlawfully discriminate against people because of a protected characteristic.
- Safeguarding Vulnerable Groups Act 2006, where applicable to safeguarding arrangements, regulated activity and barring requirements.
{{org_field_name}} will also have regard to current CQC guidance relating to dignity and respect, consent, safeguarding, good governance, duty of candour and statutory notifications.
4. Principles of Social Media Use
At {{org_field_name}}, we promote the safe and responsible use of social media by:
- Protecting the confidentiality of people we support.
- Ensuring all online interactions maintain professional boundaries.
- Preventing the misuse of social media for discriminatory, offensive, or harmful content.
- Using official organisation social media accounts professionally to promote positive engagement.
- Ensuring that social media use does not compromise safeguarding responsibilities.
5. Guidelines for Staff on Social Media Use
5.1 Personal Social Media Use
- Staff must never post confidential or identifying information about people we support.
- Staff must not accept friend requests or follow people we support on personal social media accounts.
- Staff must not share or comment on sensitive workplace information online.
- Any personal opinions posted must not bring the organisation into disrepute.
- Staff must not post photos or videos of people we support without explicit written consent.
5.2 Use of Official Social Media Accounts
- Only designated staff members may post on official {{org_field_name}} social media accounts.
- All content must be professional, accurate, and respectful.
- Consent must be obtained before posting any images, videos, or testimonials of people we support.
- Social media must not be used for disclosing internal complaints, disputes, or confidential information.
- Responses to public comments and messages must be managed professionally and in line with GDPR.
6. Safeguarding and Online Safety
6.1 Protecting People We Support Online
- Staff must remain alert to online abuse, exploitation, grooming, harassment, coercion, fraud, scams, cyberbullying, sexual exploitation and other forms of harm that may affect a person we support.
- Any allegation, suspicion or evidence of abuse or improper treatment connected with social media or other online activity must be acted upon without delay in accordance with the organisation’s Safeguarding Adults Policy and safeguarding procedures.
- Where the statutory safeguarding criteria are met, the concern must be referred to the relevant local authority adult safeguarding service in accordance with the organisation’s safeguarding procedures.
- People we support must, where appropriate, be offered accessible information and support to understand online risks, privacy settings, scams and ways of protecting their personal information.
- A person’s disability, diagnosis, age or use of supported living services must not in itself be treated as evidence that they lack capacity to use social media or make decisions about their online activity.
- Capacity must be presumed unless it is established otherwise in accordance with the Mental Capacity Act 2005.
- Where there is reason to doubt a person’s capacity to make a particular decision relating to social media or online activity, staff must first provide all practicable support to help the person make the decision themselves.
- Any capacity assessment must relate to the specific decision that needs to be made at the relevant time. A person must not be treated as lacking capacity merely because they make a decision that staff, relatives or professionals consider unwise.
- Where a person lacks capacity to make the specific decision, any decision made or action taken on their behalf must comply with the Mental Capacity Act 2005, including the best-interests requirements and the requirement to consider the least restrictive available option.
- Staff must not restrict, monitor, block or control a person’s use of social media solely because the activity involves risk. Any restriction imposed as part of the person’s care or support must have a lawful basis, be necessary and proportionate to the identified risk and be properly assessed, authorised where required, recorded and reviewed.
- Relevant assessments, decisions, consent, best-interests decisions, agreed support and identified risks must be recorded in the person’s care and support records where they relate to the regulated care or support being provided.
6.2 Reporting Online Abuse or Misuse
- Any online harassment, abuse, exploitation or other safeguarding concern involving a person we support must be reported immediately in accordance with the organisation’s safeguarding reporting procedure.
- Staff must take immediate action where necessary to protect the person from further harm while avoiding unnecessary or disproportionate restrictions on the person’s rights and freedoms.
- Where the concern meets the relevant adult safeguarding criteria, a referral must be made to the local authority adult safeguarding service in accordance with the Safeguarding Adults Policy.
- Where a crime is suspected, or immediate police assistance is required, the matter must be reported to the police in accordance with the organisation’s safeguarding and incident-reporting procedures.
- Harmful content, impersonation, fraudulent accounts or other misuse of a social media platform relating to the organisation or a person we support should also be reported to the relevant platform where appropriate.
- Evidence relevant to a safeguarding investigation must be preserved where lawful and necessary. Staff must not unnecessarily circulate, download or reproduce offensive, abusive, intimate or confidential material.
- Where the incident also constitutes a personal data breach, the requirements in Section 7 of this policy must be followed.
- Where the incident meets a statutory CQC notification requirement, the registered person must ensure that the appropriate notification is submitted to CQC without delay or within any other applicable statutory timescale.
7. Data Protection and Confidentiality
- All personal data processed in connection with social media or other online platforms must be handled in accordance with the UK GDPR, the Data Protection Act 2018, as amended, and the organisation’s data protection, confidentiality, records management and information-security policies.
- Personal information about people we support, staff or other individuals must not be posted, disclosed or discussed on social media unless the processing is lawful, necessary and authorised.
- Before personal data is published through an official social media account, {{org_field_name}} must identify and document an appropriate lawful basis for the processing. Where special category personal data is processed, an applicable condition for processing special category data must also be identified where required.
- Health information and other special category personal data must be afforded the additional protection required by data-protection law.
- Where {{org_field_name}} relies upon consent as its lawful basis for processing personal data, the consent must satisfy the applicable requirements of data-protection law. Consent must be freely given, specific, informed and indicated by an unambiguous affirmative action, and the person must be able to withdraw consent.
- Consent to receive care or support and consent to publish a person’s photograph, video, testimonial or other personal information are separate matters and must not be treated as interchangeable.
- Staff must not assume that a relative, friend or informal carer has legal authority to consent to the processing or publication of an adult’s personal information on the adult’s behalf.
- Personal data must be limited to what is necessary for the identified purpose and must not be retained, copied or circulated unnecessarily.
- Professional communication containing personal or confidential information must only take place using communication methods authorised by {{org_field_name}}. Staff must not use personal social media accounts, personal messaging applications or personal devices to communicate confidential service-user information unless their use has been specifically authorised and appropriate security measures are in place.
- Any actual or suspected unauthorised disclosure, loss, alteration, destruction, access to, or publication of personal data must be reported immediately through {{org_field_name}}’s personal data breach procedure.
- {{org_field_name}} must assess every personal data breach to determine the risk to the rights and freedoms of the affected person or people.
- Where a personal data breach is required to be notified to the Information Commissioner’s Office, the notification must be made without undue delay and, where feasible, no later than 72 hours after {{org_field_name}} becomes aware of the breach.
- Where a personal data breach is likely to result in a high risk to the rights and freedoms of an affected person, {{org_field_name}} must inform that person without undue delay unless a lawful exception applies.
- {{org_field_name}} must maintain an appropriate record of personal data breaches, including breaches that do not require notification to the Information Commissioner’s Office.
- Personal data breaches involving people we support must also be considered under the organisation’s safeguarding, incident-reporting, duty of candour and CQC notification procedures where applicable.
- A breach of confidentiality or data-protection requirements may result in disciplinary action in accordance with the organisation’s disciplinary procedure.
8. Managing Reputational Risks
- Staff must ensure that their online behaviour reflects the values and professionalism of {{org_field_name}}.
- Any negative comments, complaints, or disputes regarding the organisation must be handled internally rather than discussed on social media.
- If staff become aware of false information, negative reviews, or damaging social media content about the organisation, they must report it to senior management.
9. Training and Awareness
- All staff must complete mandatory training on social media use and online safety.
- Updates on GDPR, confidentiality, and safeguarding in social media contexts will be provided regularly.
- Staff will be supported in understanding how to safely use social media in a professional capacity.
10. Action Following Breaches of this Policy
Breaches of this policy must be assessed promptly and proportionately. {{org_field_name}} must take any immediate action required to protect people we support, preserve evidence, secure personal information and prevent further harm.
A breach of this policy may result in management or disciplinary action in accordance with the organisation’s disciplinary procedure. Serious breaches may constitute gross misconduct, depending on the circumstances and the applicable disciplinary procedure.
Examples of conduct that may result in disciplinary action include:
- Sharing confidential or identifying information about a person we support without lawful authority.
- Publishing photographs, recordings, videos or other personal information without the required authority or lawful basis.
- Posting discriminatory, abusive, degrading, threatening or offensive material relating to people we support, colleagues or others connected with the service.
- Engaging in online bullying, harassment, abuse, exploitation or inappropriate relationships with people we support.
- Deliberately circumventing the organisation’s information-security or communication requirements.
- Failing to report a safeguarding concern or personal data breach in accordance with organisational procedures.
- Using social media in a way that constitutes a serious breach of professional boundaries.
A breach must also be considered under the organisation’s safeguarding, incident-reporting, data-protection and information-governance procedures as applicable.
Where the circumstances meet the statutory criteria:
- A safeguarding referral must be made to the relevant local authority adult safeguarding service.
- Suspected criminal conduct must be reported to the police where appropriate.
- A personal data breach must be notified to the Information Commissioner’s Office where the legal notification threshold is met.
- The affected person must be informed of a personal data breach without undue delay where the breach is likely to result in a high risk to their rights and freedoms, unless a lawful exception applies.
- The registered person must make any notification to CQC required by the Care Quality Commission (Registration) Regulations 2009.
- {{org_field_name}} must comply with Regulation 20, Duty of Candour, where its requirements apply.
Reporting an incident to CQC, the local authority, the Information Commissioner’s Office or the police must not be described or treated as discretionary where the relevant statutory reporting requirement has been met.
11. Related Policies
- SL09 – Confidentiality and Data Protection Policy
- SL13 – Safeguarding Adults from Abuse Policy
- SL16 – Health and Safety at Work Policy
- SL30 – Equality, Diversity, and Inclusion Policy
- SL42 – Communication and Engagement with Service Users Policy
12. Policy Review
This policy will be reviewed annually, or earlier if:
- Legislation or best practices evolve.
- A serious online incident occurs that requires a policy update.
- Feedback from staff or people we support suggests improvements.
Responsible Person: {{org_field_registered_manager_first_name}} {{org_field_registered_manager_last_name}}
Reviewed on: {{last_update_date}}
Next Review Date: {{next_review_date}}
Copyright © {{current_year}} – {{org_field_name}}. All rights reserved.