Sample policy · Reg 17

Confidentiality, Information Governance and Data Protection Policy

Statutory anchor: UK GDPR, the Data Protection Act 2018 as amended by the Data (Use and Access) Act 2025, and the common law duty of confidentiality. This policy also engages Regulation 17 (good governance), Health and Social Care Act 2008 (Regulated Activities) Regulations 2014 (SI 2014/2936). · primary source

Download the PDF

The PDF version of this template is the same content, formatted for adaptation in your document control system. The disclaimer above is repeated on the PDF cover.

Verivius pack version v1.1, 2026-07-21

1. What the regulation says

The primary law for this policy is UK GDPR, the Data Protection Act 2018 as amended by the Data (Use and Access) Act 2025, and the common law duty of confidentiality, which sit outside the CQC Regulations. This policy also engages Regulation 17 (good governance), which requires the secure, accurate and contemporaneous records that information governance protects:

Systems or processes must be established and operated effectively to ensure compliance with the requirements in this Part. (Reg 17(1): the umbrella duty)

assess, monitor and improve the quality and safety of the services provided in the carrying on of the regulated activity (including the quality of the experience of service users in receiving those services) (Regulation 17(2)(a))

assess, monitor and mitigate the risks relating to the health, safety and welfare of service users and others who may be at risk which arise from the carrying on of the regulated activity (Regulation 17(2)(b))

maintain securely an accurate, complete and contemporaneous record in respect of each service user, including a record of the care and treatment provided to the service user and of decisions taken in relation to the care and treatment provided. (Reg 17(2)(c): accurate service-user record)

The full text of the regulation is at https://www.legislation.gov.uk/uksi/2014/2936/regulation/17. UK GDPR, the Data Protection Act 2018 and the Data (Use and Access) Act 2025 are at https://www.legislation.gov.uk/eur/2016/679, https://www.legislation.gov.uk/ukpga/2018/12 and https://www.legislation.gov.uk/ukpga/2025/18. Where this policy and the law or regulation diverge, the law or regulation wins.

2. Plain-English summary

You have to run effective systems and processes to comply with everything else in Part 3. The regulation lists six things those systems must enable in particular: quality assessment and improvement, risk management, accurate service-user records, accurate employment and management records, seeking and acting on feedback, and continually evaluating and improving how you process all this. If CQC requests a written report on quality and risk plus your improvement plans, you have 28 days from the day after the request. Confidentiality and data protection are how a service keeps those records secure, lawful and trusted: personal and confidential information must be handled only for a lawful work reason, kept accurate and secure, shared only where lawful and necessary, and any breach reported and managed straight away.

3. Purpose

The purpose of this policy is to make sure that [Service Name] protects confidential information, manages personal data lawfully, and uses information safely to support care, treatment and governance.

Health and care information is sensitive. Poor information governance can harm people, damage trust, breach confidentiality, compromise safeguarding, disrupt care and create regulatory risk.

This policy supports Regulation 17 good governance, confidentiality duties, UK GDPR, the Data Protection Act 2018, professional standards and the service's duty to maintain secure, accurate and appropriate records.

4. Policy warning

Staff must not access, share, copy, discuss, photograph, remove, disclose or use personal or confidential information unless they have a lawful work reason and are authorised to do so.

Curiosity access is prohibited.

Information must not be shared through personal email, personal messaging apps, personal devices or unauthorised systems unless explicitly approved through service policy and risk assessment.

A confidentiality or data protection breach must be reported immediately.

5. Scope

This policy applies to:

It applies to personal data, special category data, confidential information and business-sensitive information.

6. Principles

The service will process personal information according to the following principles:

Staff must understand that confidentiality and data protection support safe care; they do not prevent appropriate information sharing where sharing is lawful and necessary.

7. Responsibilities

The provider is responsible for ensuring that data protection and information governance arrangements are in place.

The Registered Manager is responsible for local implementation, breach escalation, staff compliance and governance review.

The information governance lead is responsible for supporting policy, training, audits, privacy information, data sharing and breach management.

All staff are responsible for protecting information, following this policy and reporting concerns immediately.

Contractors and processors must only handle information under approved arrangements.

7.1 Local adoption decisions

Before this policy is approved, the provider records:

7.2 Operational information-handling workflow

For any new collection, use, access, sharing, correction, export, retention or disposal of personal data, Staff follow this sequence:

  1. Confirm the work purpose, lawful basis and, for special category data, the additional condition.
  2. Use only the minimum information needed and an approved system or transfer route.
  3. Check identity, recipient, access rights and accuracy before information is viewed, changed, sent or disclosed.
  4. Record consent, professional judgement, information-sharing rationale or refusal where the decision affects care, rights or risk.
  5. Escalate uncertainty, a rights request, a complaint or a suspected breach to the information governance lead without delay.
  6. Record the decision, action, owner, deadline and outcome in the appropriate governance record.
  7. Review recurring failures through audit, the risk register and an improvement action.

8. Confidentiality

Staff must keep information confidential unless there is a lawful reason to share it.

Confidential information may include:

Staff must not discuss people in public areas, corridors, reception spaces, social settings or online.

9. Access to records

Staff may only access records where they need the information for their role.

Access must be limited to the minimum necessary.

Managers must ensure that system access is:

Shared logins must not be used unless there is a documented exceptional reason and appropriate controls.

10. Accurate and appropriate records

Records must be accurate, complete, current and relevant.

Staff must not enter information they know to be false or misleading.

Where a record is corrected, the change must be traceable and must not hide the original entry.

Information must be recorded in the correct system or record location.

11. Privacy information

The service must provide clear privacy information explaining how personal information is used.

Privacy information should explain:

Privacy information must be accessible and reviewed when processing changes.

12. Sharing information

Information may be shared where there is a lawful basis and it is necessary.

This may include sharing with:

The service must share enough information to support safety and lawful duties, but not more than is necessary.

13. Safeguarding and serious risk

Staff must not use confidentiality as a reason to delay safeguarding action.

Information may need to be shared without consent where this is necessary to protect a child, adult at risk or another person from harm, or where there is another lawful reason.

The reason for sharing without consent must be recorded.

14. Consent and confidentiality

Consent may be relevant to confidentiality and information sharing, but it is not the only lawful basis for using information.

Staff must not promise absolute secrecy.

People should be told, in a way they can understand, when information may need to be shared for safety, safeguarding, legal or regulatory reasons.

15. Communication security

Staff must use approved communication methods.

When sending information, staff must check:

Emails sent to the wrong person, wrong attachments, lost letters or insecure messages must be reported as potential data breaches.

16. Mobile devices and remote working

Where staff use mobile devices or work remotely, they must:

Remote working must not reduce confidentiality standards.

17. Paper records

Paper records must be:

Staff must not take paper records home unless authorised.

18. Images, audio and video

Images, audio or video involving people using the service must only be taken where there is a clear lawful reason and proper consent or other lawful basis.

Images must not be stored on personal devices.

The record must explain:

Intimate or sensitive images require additional controls.

19. Data subject rights

The service must have a process for responding to requests from people about their personal data.

This may include requests to:

Requests must be escalated to the Registered Manager or information governance lead immediately.

The service must respond within legal timescales.

19.1 Data-protection complaints

The service provides an electronic route for a person to complain about how their personal data has been handled. The complaint is acknowledged within 30 days and answered without undue delay after a proportionate investigation.

The complaint record should include the date received, person affected, issue raised, records and staff checked, investigator, findings, action taken, response date, outcome and any learning or improvement action. The response explains how the person can raise the matter with the ICO if they remain dissatisfied.

20. Data breaches

A data breach is a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data.

Examples include:

All suspected breaches must be reported immediately and managed under the Data Breach Policy.

The information governance lead records the facts known, data and people affected, likely consequences, containment, recovery, risk assessment, advice, decision maker, notification decision and times. Where a breach is likely to risk people's rights and freedoms, the service notifies the ICO without undue delay and, where feasible, within 72 hours of becoming aware of it. Where the risk is high, affected people are informed without undue delay unless a lawful exception applies.

21. Retention and disposal

Information must be kept only for as long as required by law, professional guidance, contract, safeguarding need, legal claim risk or service retention schedule.

Records must be disposed of securely when no longer required.

Disposal must be recorded where appropriate.

The service must not keep information indefinitely because it may be useful one day.

22. Processors and third-party systems

Where the service uses external systems or suppliers to process personal data, the provider must ensure there are suitable arrangements in place.

This may include:

The service must not upload confidential information to unapproved systems.

23. Training

Staff must receive information governance and confidentiality training during induction and at regular intervals.

Training must include:

Training must be recorded.

24. Audit and governance

The Registered Manager must audit information governance at least annually, and more often where risk requires.

The audit must check:

Findings must be added to the action plan or risk register where required.

25. Related policies in this pack

This policy should be read with:

26. Review

This policy will be reviewed annually, or sooner following a data breach, ICO concern, CQC finding, system change, new supplier, new processing activity, safeguarding concern, change in law or change in national guidance.

27. Sources and further reading

This template is based on CQC's guidance for providers and managers, the Health and Social Care Act 2008 (Regulated Activities) Regulations 2014, and other topic-specific legislation and guidance listed below. It is a starting point for adaptation, not a substitute for legal, clinical, HR, safeguarding or specialist professional advice.

28. When to seek further advice

Seek specialist advice where the issue involves serious harm, safeguarding, deprivation of liberty, restraint, children, professional misconduct, controlled drugs, radiation, termination of pregnancy, infection outbreak, water safety, employment dismissal, DBS barring referral, or regulatory enforcement.

29. Document control

Version Date Author Changes
v1.1 2026-07-21 Verivius (sample) Added local adoption decisions, an operational handling workflow, current data-protection complaint duties and a decision-ready breach record.
v1 2026-06-10 Verivius (sample) Initial sample template, conformed to the Verivius policy standard.

This sample policy template was issued by Verivius. It is a template, not a substitute for legal advice or the provider's own policy-development process. Where this template and live law or regulator guidance diverge, the live source wins.

What good looks like here

Written from an ex-CQC inspector's chair, but the point is safe, well-led care your team can stand behind. Each row shows what strong evidence looks like, what thin evidence looks like, and where the expectation comes from.

Confidentiality is the policy where the same mistake runs in two opposite directions and both of them land on the person. Share too much and you hand someone a diagnosis, an address a person has fled to, or a safeguarding concern, and the person quietly stops telling you the things that keep them safe. Share too little, or hide behind confidentiality when a child or adult at risk is in danger, and a concern sits in a file while the harm carries on. Neither failure announces itself. The over-share is found out by the person it exposed, and the under-share only once somebody has been hurt. These calls get made in seconds by whoever is holding the phone or the email, often out of hours with no manager to ask, so the reason written down at the point of decision is the only thing that shows whether the service is getting them right. That written reason also protects the member of staff who made a defensible call under pressure, which is what makes people willing to make it again rather than freeze.

  1. Record access is genuinely role-based and approved, and is actually removed when a person leaves or changes role, not a leaver who still holds a live login or staff reading records with no work reason, which the policy prohibits as curiosity access.

    Strong evidence: The access list and approval records, the leaver checklist and access review, and the exception record for any shared login, tested against the policy's rule that access is removed promptly and shared logins are used only by documented exception (Section 9; checklist section 4).

    Weak evidence: An access list exported once when the system went live and never reconciled against the current staff list, so a bank worker who left in the spring still holds an active login and a carer promoted to a senior role six months ago still carries the access from the job before it. Curiosity access is invisible because nobody has ever opened the audit log to look, and the two shared reception logins have no documented exceptional reason behind them beyond the fact that it has always been that way.

    A legal duty. This comes from legislation that applies to your service, so meeting it is not optional. The exact provision is cited beneath the badge.

    UK GDPR Article 5(1)(f) and Article 32(1)(b), (4); Data Protection Act 2018 s.170

  2. Confidentiality and data-protection breaches, a wrong-recipient email, a wrong attachment, a lost record or a stolen device, are reported immediately and managed, with the decision on whether to notify the Information Commissioner's Office (ICO), and the separate decision on whether to tell the affected person, recorded, not a mis-sent email quietly forgotten.

    Strong evidence: The breach log and incident records, and the breach decision note recording any ICO, CQC, commissioner or person-notification decision, against the policy's requirement that every suspected breach be reported immediately and managed under the Data Breach Policy (Sections 15, 20; checklist section 6).

    Weak evidence: A breach log with three entries, all of them lost paperwork, while staff describe a mis-sent email as something you simply recall and apologise for. Where a breach is logged, the outcome reads "dealt with" with no note of who assessed the risk to the person, why the Information Commissioner's Office (ICO) was or was not notified, and whether the affected person was told.

    A legal duty. This comes from legislation that applies to your service, so meeting it is not optional. The exact provision is cited beneath the badge.

    UK GDPR Article 33(1) and 33(5), and Article 34(1)

  3. Information shared outside the service rests on a recorded lawful basis and is limited to the minimum necessary, and staff check recipient and content before sending, not routine over-sharing or unchecked emails.

    Strong evidence: The data-sharing sample and disclosure notes, and the communication audit of recipient checks and minimum-necessary content, against the policy's rule to share enough for safety and lawful duties but no more (Sections 12, 15; checklist section 4).

    Weak evidence: Disclosure notes that record what was sent but not why it was lawful to send it, so the file shows an entire care record emailed to a solicitor when one dated entry was what had been asked for. Staff describe the recipient check as just looking at the address, and nobody can point to a case where they decided to send less than the whole record.

    A legal duty. This comes from legislation that applies to your service, so meeting it is not optional. The exact provision is cited beneath the badge.

    UK GDPR Article 5(1)(c) and 5(2), Article 6(1) and Article 9(2), and Article 32

  4. Confidentiality is never used to delay safeguarding action. The failure that harms someone is a disclosure withheld when sharing without consent was necessary to protect a child or adult at risk, and the reason for sharing without consent is recorded when it does happen.

    Strong evidence: The safeguarding disclosure notes recording the rationale for sharing without consent, against the policy's rule that confidentiality must not delay safeguarding and the reason for sharing without consent must be recorded (Section 13; checklist section 3).

    Weak evidence: A safeguarding file where the chronology jumps from the staff member's concern to a referral several days later, with a line about wanting to speak to the family first. Elsewhere the referral was made properly but nothing anywhere records why information was shared without consent, so the decision reads as an accident rather than a judgement someone made, weighed and owned.

    The recognised standard from a professional or clinical body, such as NICE or a royal college. Not a legal duty, but the accepted mark of safe practice, and a departure needs a documented reason.
  5. Service-user records are accurate and contemporaneous, and corrections preserve the original entry, not an amended record that hides what was first written or an entry known to be false or misleading.

    Strong evidence: A record sample and the system audit log for corrections, against the policy's requirement that changes stay traceable and must not hide the original entry, which underpins the accurate, complete and contemporaneous record duty quoted at Regulation 17(2)(c) (Section 10; checklist section 2).

    Weak evidence: Care notes written up at the end of a shift covering events across the whole day, so timings are approximate and the sequence of a deterioration cannot be reconstructed afterwards. Corrections appear as a clean overwrite with the original wording gone, or as paper entries with correction fluid over them, so nobody can tell what the record actually said at the moment the clinical decision was taken.

    A legal duty. This comes from legislation that applies to your service, so meeting it is not optional. The exact provision is cited beneath the badge.

    Health and Social Care Act 2008 (Regulated Activities) Regulations 2014, reg 17(2)(c); UK GDPR Article 5(1)(d)

  6. Requests from people about their own data are escalated and answered within the legal timescale, confidential data sits only on approved supplier systems under a data-processing agreement, and the annual information-governance audit is actually completed and feeds the action plan.

    Strong evidence: The subject-access process and response records (Section 19), the supplier due-diligence and data-processing agreements (Section 22), and the completed annual information-governance audit whose findings carry to the action plan or risk register (Section 24; checklist sections 5, 6).

    Weak evidence: A request from a person for their own data sits in a manager's inbox while people work out who owns it, with no log of when it arrived or when the response went out, so the service cannot show it met the statutory response time under the UK General Data Protection Regulation (UK GDPR). Rotas or handover notes live in a free messaging app or a personal cloud drive that never went through due diligence and has no written data-processing agreement behind it. The information-governance audit, which Verivius recommends at least annually as a default rather than a statutory interval, exists as a blank template or as a completed form whose findings never reached the action plan.

    Our recommended baseline. Not a legal or regulatory requirement, but a sensible standard we suggest where the rules leave the detail to you. Adapt it to your service.

Last verified 20 July 2026

Audit this policy

Record keeping and confidentiality procedure checklist

A policy is the intent; the evidence is what a CQC inspector actually asks to see. This matching checklist turns the policy above into the records to keep, the audit to run, and the places small services most often fall short.

Open the Record keeping and confidentiality procedure checklist

Spotted something to improve?

These are sample templates, not the last word. If you would change a wording, or want to help us confirm a detail, tell us and we will look at it.

Related Verivius content

Want help adapting this to your service?

A Verivius consultant can read your adapted policy against the live regulation and your service shape. The work fits inside a Mock Inspection engagement or a shorter consulting brief. A 20-minute conversation is the fastest way to find out whether the fit is right.

Get started free

Free to start, no card. A 14-day trial when you subscribe.

Last reviewed 21 July 2026