Data Protection & Information Governance Policy

Legal & complianceAll services

How the service keeps personal information safe, accurate and lawful under UK GDPR and the Data Protection Act, for the people you support and your staff.

Pages

Description

What goes in a data protection policy for a care service?

A data protection policy explains how a care service keeps personal information safe, accurate and lawful. It covers what you hold about the people you support, their families, staff and visitors, whether on paper, on a device or shared by phone and email. This one is built on the UK GDPR, the Data Protection Act 2018 and the Data (Use and Access) Act 2025. It also meets regulation 17, which says each person's care record must be secure, accurate, complete and written at the time.

The template works for care homes, home care and supported living. Home care staff carry information between visits and keep documents and devices out of sight when travelling. Supported living services keep care records apart from the landlord's tenancy records.

The parts managers use most

The policy statement runs to 13 short sections. These are the ones that come up week to week:

  • lawful basis: recording why you use each type of data, with an extra condition for health data

  • DBS information: who can see a certificate, how it is stored and when it is destroyed

  • sharing information, including in safeguarding, where staff must not confuse confidentiality with secrecy

  • people's rights, such as the right to a copy of their own data

  • personal data breaches and the breach log

Time limits it sets out

A person who asks for a copy of their data should get it within one month. The service can extend that by two further months if the request is complex or there are many of them, and requests are usually free. When a breach needs reporting, the lead tells the Information Commission without undue delay, and within 72 hours where feasible. Complaints about data use get an acknowledgement within 30 days.

The Information Commission is the UK data protection regulator. It has replaced the Information Commissioner, so update any privacy notice that still names the old body.

What to add first

CQC will reject an application whose documents are out of date or not relevant. Add your service type, your data protection lead, your record systems and your retention periods, then delete the service lines that do not apply.

Note what you decide to keep from a DBS certificate on the DBS Check Record & Certificate, and keep right to work copies with the Right to Work Verification Record for the length of employment and 2 years after. When information has to be shared to keep someone safe, the Safeguarding Policy & Procedure explains how.

More legal & compliance templates

See all