ComplyChat Start free

Guide · Data protection

Care home data protection

A care home holds more sensitive information about more people than most organisations of its size: residents' health, medicines, capacity, family circumstances and last wishes, and staff records with DBS checks and sickness absence. Data protection in a care home is therefore not a paperwork exercise bolted onto care; it sits inside the duty to keep an accurate, complete and secure record of each person. This guide sets out the law a care home data protection policy rests on, the Caldicott principles and the Data Security and Protection Toolkit, what to do when something goes wrong, and the part of the information a service holds that its policy rarely reaches.

By ComplyChatPublished 15 minute read

A care home administrator at the reception desk turns her monitor away as a visiting family signs in at the counter, seen from the entrance lobby
01

The law a care home data protection policy rests on

Four layers of rules apply to personal information in a care home in England, and a good policy names all of them rather than just "GDPR".

  1. UK GDPR and the Data Protection Act 2018. The general data protection law, which applies to every organisation that handles personal data: residents, relatives, staff, applicants, visitors. It sets the seven data protection principles (lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability), the lawful bases for processing personal data, the rights of the data subject, and the duty to report breaches. The Data (Use and Access) Act 2025 has amended both, and the ICO, the data protection regulator, says all the Act's data protection provisions have been in force since 19 June 2026 and that it will continue updating its guidance over time, so check the date on any ICO page you rely on.
  2. The common law duty of confidentiality. Information given in confidence, as almost everything a resident or their family tells a carer is, may not normally be disclosed without consent unless the law requires it or there is an overriding public interest. It sits beside data protection law, not under it: a disclosure can be lawful under UK GDPR and still breach confidence.
  3. Regulation 17 of the Health and Social Care Act 2008 (Regulated Activities) Regulations 2014. The good governance regulation requires systems that enable the registered person to "maintain securely an accurate, complete and contemporaneous record in respect of each service user", and to "maintain securely" the records kept about staff and the management of the service. Security of information is a fundamental standard that the Care Quality Commission (CQC) assesses, not only a matter for the ICO.
  4. The health and care standards. The eight Caldicott principles, the National Data Guardian's ten data security standards, and the Data Security and Protection Toolkit through which a provider shows it meets them. CQC's guidance for providers points to all three.

The information that makes a care home different is special category data. Article 9 of UK GDPR prohibits the processing of "data concerning health", along with data about racial or ethnic origin, religious beliefs, sex life, sexual orientation, genetic and biometric data, unless one of its listed conditions applies, and only where there is also a lawful basis under Article 6. For a care home the Article 6 basis is usually a contract with the resident or their funder, a legal obligation such as the record Regulation 17 requires, or, for some processing about relatives and visitors, legitimate interests. For care, the condition is Article 9(2)(h), processing necessary for "the provision of health or social care or treatment", given effect in UK law by paragraph 2 of Schedule 1 to the Data Protection Act 2018, whose "health or social care purposes" include "the provision of social care". A care plan, a medication record, a falls log and a note of a resident's faith and funeral wishes are all special category data, and most of what a care home holds about residents is.

The practical consequence is that consent is not the usual basis for care records. A resident does not have to consent for the home to record their care; the home is required to record it. Consent matters for things outside care itself: a photograph on the home's social media, a quote in the newsletter, a place in a research study. A policy that asks residents to sign a GDPR consent form for their own care record has usually misunderstood the law, and a resident who withdraws that "consent" cannot stop the home keeping the record Regulation 17 requires.

02

What a care home data protection policy should cover

The policy is the document that tells staff what to do and tells an inspector or the ICO that the home has thought about it. It does not need to be long, but it does need to be specific to the service. In practice it covers:

  • Who is responsible. The provider is the data controller. Name the person who leads on data security and protection, and say whether the home has appointed a data protection officer. Article 37 of UK GDPR requires one where the core activities consist of processing special category data "on a large scale"; whether a single care home reaches that threshold is a judgement to take and record, and a group of homes is more likely to.
  • What the home holds and why. A record of processing activities: the categories of personal data (residents, relatives, staff, applicants, visitors), the purpose, the lawful basis and Article 9 condition, who it is shared with and how long it is kept.
  • Privacy information. What residents, families and staff are told about how their information is used, in a form a resident with dementia or a relative at an admission meeting can actually follow. Since 19 June 2026, Articles 13(2)(ca) and 14(2)(da) of UK GDPR also require that information to include "the right to make a complaint to the controller", so a privacy notice written before then needs that line and a pointer to the data protection complaints procedure below.
  • Sharing. With GPs, district nurses, pharmacies, hospitals, the local authority, commissioners and families, and the rule for a relative who asks how their mother is: who may be told what, and where the resident's own wishes are recorded.
  • Processors. The care planning software company, the eMAR supplier, the payroll bureau and the IT support firm all process personal data on the home's behalf. Article 28 of UK GDPR requires a written contract with each data processor setting out what they may do with it, and the home remains responsible for choosing processors that protect it.
  • Security. Access to the care record system on a need-to-know basis, locked storage for paper, passwords and multi-factor sign-in, shared devices on the floor, and what happens to a staff member's access the day they leave.
  • Staff and personal devices. Whether staff may use their own phones for work, what may never go on them, and which approved route replaces the staff group chat.
  • Rights requests. Subject access requests from residents, relatives acting under a lasting power of attorney, and staff, and requests for erasure or correction, with the one-month clock and who handles them, and the data protection complaints procedure every controller has needed since 19 June 2026, under which a complaint must be acknowledged within 30 days and answered without undue delay.
  • Retention and disposal. How long each type of record is kept and how it is destroyed, set out in a schedule rather than a paragraph.
  • Breaches. How staff report one, who assesses it, the breach log, and the 72-hour decision on telling the ICO.
  • Training. Data security training at induction and every year after, with records of who has completed it.

Two further items are specific to care. Where a new system or a significant change will process residents' health data, such as a digital care planning system, acoustic monitoring at night or a new messaging tool, a data protection impact assessment is likely to be required before it starts, because large-scale processing of health data is one of the cases Article 35 of UK GDPR names. And every care provider must pay the ICO's data protection fee unless it is exempt, and the exemptions apply only where personal data is processed solely for listed purposes, such as staff administration, accounts and records or not-for-profit purposes, or not on a computer at all. A service keeping residents' care records electronically is exempt only if all its processing fits those purposes, and the ICO says an organisation using CCTV for crime prevention must pay regardless; its fee self-assessment gives the answer for a particular service.

03

The Caldicott principles in a care home

The eight Caldicott principles, published in their current form by the National Data Guardian on 8 December 2020, apply to confidential information about patients and service users across health and social care. They are the most useful single test of whether a home's everyday habits with information are sound. In the National Data Guardian's words, they are:

  1. Justify the purpose(s) for using confidential information
  2. Use confidential information only when it is necessary
  3. Use the minimum necessary confidential information
  4. Access to confidential information should be on a strict need-to-know basis
  5. Everyone with access to confidential information should be aware of their responsibilities
  6. Comply with the law
  7. The duty to share information for individual care is as important as the duty to protect patient confidentiality
  8. Inform patients and service users about how their confidential information is used

In a care home these translate into ordinary questions. Does the handover sheet left on the nurses' station need every resident's diagnosis on it, or only what the next shift must act on (principles 2 and 3)? Can the kitchen assistant open the whole care record, or only the dietary requirements (principle 4)? Does the agency nurse on her first shift know what she may and may not share with a visiting relative (principle 5)?

Principle 7 is the one managers most often forget. It exists because professionals were withholding information that a person's care depended on, out of misplaced caution about data protection. Sharing a resident's allergy with the paramedic, their end-of-life wishes with the out-of-hours GP, or a safeguarding concern with the local authority is not a data protection risk; failing to share it can be a failure of care. For safeguarding in particular, paragraph 18 of Schedule 1 to the Data Protection Act 2018 provides a condition for processing special category data without consent where it is necessary to protect an adult at risk from neglect or harm and consent cannot be given, cannot reasonably be obtained, or would prejudice the protection. The policy should say so plainly, because a carer unsure whether she is allowed to pass something on is the most common way a concern stalls.

The principles also recommend involving a Caldicott Guardian where "a novel and/or difficult judgment or decision is required". Many smaller providers do not have one of their own; the practical equivalent is a named senior person who takes those decisions and records the reasoning.

04

The Data Security and Protection Toolkit

The Data Security and Protection Toolkit (DSPT) is a free online self-assessment, run by NHS England, against the National Data Guardian's standards and data protection law. The version for adult social care is written for care providers and covers paper records and conversations as well as computers. It is completed and published once a year; each year's version has its own deadline and question set, and the 2026-27 version was published in September 2026, so work from the current one.

CQC's guidance for providers is direct about who must use it: "All care providers who work under the NHS Standard Contract must register with the toolkit. The government recommends all other adult social care providers register too." A home with residents funded through NHS continuing healthcare is therefore under a contractual requirement, and local authority commissioners increasingly ask for it in their contracts. CQC's own guidance lists the National Data Guardian's standards the toolkit measures, among them regular data security training for staff, access to personal information only for those who need it for their job, a plan for what to do if data security is threatened, no unsupported software, and contracts that hold IT suppliers to account.

A published assessment is public, and anyone can search the toolkit to see a service's status. There are three levels. Approaching Standards is a stepping stone with an action plan. Standards Met is the level the Digital Care Hub, the sector's free support service, describes as "the level you really need to reach", and it is the level required to access NHS patient data or deliver services under an NHS contract. Standards Exceeded adds Cyber Essentials Plus. Standards Met also opens access to shared care records and GP systems, which is increasingly how a home learns about a resident's hospital stay.

Under CQC's single assessment framework, the well-led quality statement on governance, management and sustainability expects "robust arrangements for the availability, integrity and confidentiality of data, records and data management systems". The toolkit is the way most homes evidence that statement. Its questions on staff, policies, data security and devices make a sensible checklist for a data protection policy even for a home that has not yet registered.

Two carers in tunics talk quietly on the paved path outside a red-brick care home in morning drizzle, one holding a closed folder under her arm
05

A care home data breach: what to do and how quickly

A personal data breach is wider than a hack. UK GDPR defines it as a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. In care homes the common ones are ordinary: a care plan emailed to the wrong relative, a handover sheet left on a bus, a lost or stolen phone holding residents' details, a leaver whose access to the care system was never removed, a photograph of a resident posted where it should not have been, and a message about a resident sent to the wrong group.

Article 33 of UK GDPR sets the clock. Where a breach is likely to result in a risk to people's rights and freedoms, the controller must notify the ICO "without undue delay and, where feasible, not later than 72 hours after having become aware of it"; a later notification must give the reasons for the delay, and information can follow in phases. Article 34 adds that where the breach is likely to result in a high risk, the people affected must be told without undue delay, in clear and plain language. Because almost every breach in a care home involves health data about people who may be vulnerable, the risk threshold is met more often than in most organisations.

Health and care organisations can report through the toolkit. The DSPT includes an incident reporting tool which notifies the ICO, the Department of Health and Social Care and NHS England, and its guidance repeats the 72-hour rule. Other providers report through the ICO's report a breach service. A breach can also be a safeguarding matter, an incident for Regulation 17 purposes and, if the police are involved, a CQC notification, so the breach procedure should connect to the incident reporting route rather than run beside it.

The duty that is easiest to miss is Article 33(5): the controller "shall document any personal data breaches, comprising the facts relating to the personal data breach, its effects and the remedial action taken". That applies to every breach, including the ones judged not reportable. A breach log that records the event, when the home became aware, who assessed the risk, the decision on reporting and why, and what changed afterwards is the evidence that the home judged correctly. As with CQC notifications, an inspector or the ICO cannot tell a sound decision not to report from a breach nobody noticed unless the log shows it.

A breach log entry you can keep – fictional example

Ref B-014 · 11 September 2026, 21:40 · Carer's personal phone lost on the bus home; phone locked; no care records app on it; staff group chat on it named two residents and a hospital admission · Aware: 12 September 07:15, reported to manager by phone · Assessed by the registered manager 12 September 09:30: risk to individuals, not high (device locked, limited detail) · ICO: notified 12 September 15:10 via DSPT · Residents' families: not told (risk not high), reason recorded · Actions: group chat withdrawn from use, residents' details moved to the care record only, staff reminded of the devices policy 13 September.

06

The staff group chat the policy never reaches

Most care home data protection policies are written about the care record system and the filing cabinet. The information the policy does not reach is the information that moves fastest: the staff group chat on personal phones, where the night senior asks who can cover tomorrow's early, a carer posts that Room 4's daughter is upset about the laundry again, and someone shares a photo of the handover sheet because the printer is broken.

Measured against the rules above, that group fails most of them without anyone intending it to. It holds health data about residents on devices the provider does not control, outside the need-to-know basis the fourth Caldicott principle asks for, visible to everyone in the group whatever their role, and to the former colleague nobody removed. When a phone is lost, the home cannot say what was on it, so it cannot assess the breach, and the Article 33(5) log records a guess. When a relative makes a subject access request, the messages about their mother are within scope and held by a dozen people. And the conversation in which the night senior decided a resident was fine until morning is, under Regulation 17, part of the record of decisions taken about that person's care, held nowhere the provider can produce it.

An end-to-end-encrypted consumer app cannot fix this by being configured more carefully, because its design keeps the content on the handsets of the people in the group and away from the organisation. The fix is a route for work conversations that the provider holds. ComplyChat replaces the staff group with channels the service controls: everyone added is told the channel is on the record and can object or leave, messages are recorded on the server as they are sent, and a mobile number verified by SMS is an identity on it, so bank and agency staff without a work email can be included. On paid plans the lasting record files into the provider's own Microsoft 365 once the tenant is connected, under the retention rules the provider already sets. ComplyChat is not a care record system, it does not do care planning or medicines, and it does not replace the DSPT; it removes the place where residents' information was travelling outside all of them.

A question for the next managers' or board meeting: if a carer's phone were lost tonight, could the home say by tomorrow morning which residents' information was on it, and could it produce the staff conversations about any one resident if their family asked?

07

Official guidance and your next step

The primary sources are the Data Protection Act 2018 and UK GDPR, the ICO's UK GDPR guidance and resources (under review following the Data (Use and Access) Act, so check the date on the page), the National Data Guardian's Caldicott principles, and the Data Security and Protection Toolkit, with the Digital Care Hub's guidance and template policies written for care providers. For how long to keep each kind of record, our guide to CQC record keeping requirements covers the Records Management Code of Practice periods. Quotations here are from those sources as published on 25 September 2026.

This guide is a practical starting point for care providers in England, not legal advice about an individual breach, request or dispute. Wales, Scotland and Northern Ireland have their own care regulators and standards, though UK GDPR applies across the UK.

Then do one thing: search the toolkit for your own service's status, and if it is not Standards Met for the current year, put the date for publishing it in the next managers' meeting minutes.

Why we publish this

We build ComplyChat for the work conversations organisations need to keep. In a care home, residents' information travels in staff messages every shift, and those messages are usually the part of the data protection picture no policy reaches. Explore Free personal messaging, or compare the paid plans if your service needs a lasting Microsoft 365 archive.

Explore Free · How it works · Compare plans

Sources

Every document this guide quotes or links to, in the order it first cites them.

  1. Fee self-assessment ico.org.uk
  2. Eight Caldicott principles gov.uk
  3. Data Security and Protection Toolkit dsptoolkit.nhs.uk
  4. Digital Care Hub digitalcarehub.co.uk
  5. Report a breach ico.org.uk
  6. The Data Protection Act 2018 legislation.gov.uk
  7. UK GDPR guidance and resources ico.org.uk