ComplyChat Start free

Guide · Data protection

Privacy notice for care home residents

A care home must give residents, and the relatives whose details it holds, privacy information under Articles 13 and 14 of the UK GDPR – who the home is, why it uses their information and on what lawful basis, who it shares it with, how long it keeps it and their rights, including since June 2026 the right to complain to the home itself – in clear and plain language a resident can actually follow.

By ComplyChatPublished 15 minute read

In the small library corner of a care home, a deputy manager reads a short printed notice aloud to an older man with sight loss, his white cane resting against the arm of his chair

Most care homes have a notice; fewer have one a resident living with dementia could follow, or one that mentions the camera in the corridor. This guide covers what is specific to care: who the notice must reach, the lawful basis and sharing a template misses, residents who may lack capacity, attorneys and deputies, the national data opt-out, CCTV, and the 2026 changes. For the full checklist that applies to any organisation, see our charity privacy notice guide.

01

The rule: the right to be informed, as amended in 2026

A care home’s duty to give privacy information comes from Articles 12 to 14 of the UK GDPR. Article 13 applies when the home collects personal data from the person themselves, and the information is due “at the time when personal data are obtained”. Article 14 applies when the data comes from someone else – a hospital discharge summary, a local authority referral, a relative’s details given by the resident – and the information is due “within a reasonable period after obtaining the personal data, but at the latest within one month”, at the first communication with the person if that is sooner, or at the latest when the data is first disclosed to another recipient.

Article 12(1) sets the standard for both: the information must be given “in a concise, transparent, intelligible and easily accessible form, using clear and plain language”, in writing or by other means, and when the person asks it may be given orally, provided their identity is proven by other means. In a care home that standard is the hard part.

The Data (Use and Access) Act 2025 changed the list three times in 2026. On 5 February the wording on international transfers and automated decision-making changed. Since 19 June, Article 13(2)(ca) requires the notice to include “the right to make a complaint to the controller under section 164A of the 2018 Act”, with the same in Article 14(2)(da); section 164A of the Data Protection Act 2018 requires the home to acknowledge a complaint “within the period of 30 days beginning when the complaint is received”. And since 30 September, Article 13(2)(d) reads “the right to make a complaint to the Commission under section 165 of the 2018 Act”, because under SI 2026/1015 the Information Commission replaced the Information Commissioner. The regulator is still known as the ICO, but a notice that still names the Information Commissioner’s Office should be updated to name the Information Commission.

A notice written before 2026 therefore needs checking line by line. Take the list from the revised text of Articles 13 and 14, not from an older template: the ICO’s right to be informed guidance is under review following the Act, and at 8 October 2026 its right to be informed checklists still list no right to complain to the controller.

02

Who a care home’s notice has to reach

List every group whose personal data the home holds before drafting, because each needs words it can use:

  • Residents, from the pre-admission assessment onwards: health and care records, medicines, capacity assessments, finances where the home manages them, photographs, and what other professionals send about them.
  • Relatives, next of kin and representatives: their own names, phone numbers, email addresses and what they tell staff. The resident usually gives these details, so Article 14 applies: the information is due within a reasonable period and at the latest within one month, or the first time the home contacts them if that is sooner.
  • Attorneys and deputies: the home holds a copy of the lasting power of attorney or court order and their contact details.
  • Visitors: the signing-in record, and any recordings if the home uses cameras.
  • Staff, bank and agency workers: a separate notice, usually in the recruitment and induction pack.

The usual answer is layered: a short notice for each group at the point its data is collected, each linking to one full notice. The ICO’s guidance on the right to be informed says “It is often most effective to provide privacy information to people using a combination of different techniques including layering, dashboards, and just-in-time notices.” For a care provider completing the Data Security and Protection Toolkit, evidence item 1.1.3 in the DSPT 2026-27 assertions and evidence items asks: “Does your organisation maintain an up-to-date privacy notice that clearly explains how information is used?” The same applies to home care and supported living services.

03

What a resident’s notice must say that a template misses

The lawful basis for the care record is not consent. Article 13(1)(c) requires “the purposes of the processing … as well as the legal basis for the processing”. Residents’ health information is special category data, and the condition for it is usually Article 9(2)(h), given effect by paragraph 2 of Schedule 1 to the Data Protection Act 2018: “This condition is met if the processing is necessary for health or social care purposes”, which include “the provision of social care”. Section 11(1) sets out the safeguard that goes with it: processing by or under the responsibility of a health or social work professional, or by another person who owes a duty of confidentiality. Say so in the notice. A form asking residents to “consent to GDPR” for their own care record misstates the law; consent is for extras such as a photograph on the home’s social media. Our care home data protection guide explains the Article 6 lawful basis that sits alongside this condition.

Who the home shares information with, by name or category: the GP, pharmacy, hospitals, district nurses and therapists, the local authority and any NHS commissioner, CQC, and the processors that hold the records, such as the digital care planning and electronic medicines record suppliers.

How the home keeps personal information secure, and how long records are kept, by reference to the home’s retention schedule rather than a vague “as long as necessary”. Article 13(2)(a) asks for “the period for which the personal data will be stored, or if that is not possible, the criteria used to determine that period”. Our guide to care records retention covers the periods.

Rights, and who can use them on a resident’s behalf. The ICO’s guidance on how to recognise a subject access request says “You should clearly explain in your privacy information what authority you require from a third party acting on someone’s behalf.” It says “it’s reasonable to assume that an attorney with authority to manage someone’s property and affairs has the appropriate authority to make a SAR on their behalf”, the same applies to a deputy appointed by the Court of Protection, and the home must “check the type and circumstances of the particular power of attorney”. Being next of kin is not that authority in itself: without evidence that a relative is authorised to act, the ICO says “you cannot comply with the SAR until you receive the appropriate authority”.

The national data opt-out. Evidence item 1.2.4’s tooltip says “You should check that your policies, procedures, and privacy notice cover the opt out.” The underlying information standard, DCB3058 Compliance with National Data Opt-outs, “applies to any health or adult social care organisation in England that handles confidential patient information”. NHS England’s Understanding the national data opt-out says it “does not apply where information is being used or shared for an individual patient’s care” and “only applies to use or disclosure of data for purposes beyond individual care such as research and planning”. So the notice should explain the opt-out without suggesting it stops the home sharing with a resident’s GP.

Both complaint routes: to the home first, with a named contact and a form that can be completed electronically and on paper, and to the Information Commission.

The rest of the Article 13 list – the controller’s identity, any data protection officer, recipients, transfers, rights, and whether the data is a statutory or contractual requirement – applies to a care home as to anyone, and our charity privacy notice guide works through it item by item.

04

Residents who may lack capacity, and their families

The UK GDPR does not list a resident’s lack of capacity among its exceptions to the right to be informed, and the Mental Capacity Act 2005, section 1 points the same way: “A person must be assumed to have capacity unless it is established that he lacks capacity”, and “A person is not to be treated as unable to make a decision unless all practicable steps to help him to do so have been taken without success.” A notice the resident cannot follow is not one they have been given.

In practice that means:

  • Explain it in person at the pre-admission assessment or the first days after admission, with the short version in large print or easy read. The ICO’s page on methods for providing privacy information lists “Orally - face to face or when you speak to someone on the telephone (it’s a good idea to document this)”, so note in the care record when and how it was explained.
  • Go back to it. Capacity fluctuates, and a resident who could not take it in on admission day may follow it a fortnight later. The ICO says “You must regularly review, and where necessary, update your privacy information.”
  • Give it to the attorney or deputy as well, as the person who may exercise rights for the resident, without treating that as a substitute for telling the resident.
  • Give relatives their own short notice when the home first contacts them, covering their own details: why the home holds them, who it might pass them to (for example the hospital, in an emergency) and their own rights.
  • Tell people before anything new starts. The ICO’s right to be informed guidance says “You must bring any new uses of an individual’s personal data to their attention before you start the processing.”

Families ask what they are entitled to see, and the notice is the place to answer before the question becomes a dispute. In September 2025 the ICO announced that a care home director was found guilty of blocking, erasing or concealing records requested by a resident’s daughter, who “had the authority to request this information on her father’s behalf due to a lasting power of attorney”; he was fined £1,100 with £5,440 costs under section 173 of the Data Protection Act 2018. The records requested “included incident reports, copies of CCTV footage and notes relating to her father’s care”. Our subject access request policy guide covers the response.

A small dome camera on the ceiling of a care home corridor above a wooden handrail, with a resident using a walking frame passing out of focus below
05

CCTV, sensors and photographs

Cameras and listening devices need their own section in the notice, and everyone they affect needs to be told about them. CQC’s guidance Using surveillance in your care service says that where a provider uses them openly “You will need to tell everyone it affects. You can do this by talking to them before you start using surveillance or by putting up clear notices. In some circumstances, you may need their consent.” It treats recording used to keep people safe as part of their care, and adds that “any recordings you make of people also count as information about them”, regulated by the ICO. Hidden recording “is only likely to be appropriate in rare circumstances, if you have a pressing reason and only plan to use it for a short time”, and the same page notes that CQC cannot itself authorise hidden recording in residential areas under the Regulation of Investigatory Powers Act 2000.

CQC’s companion page, Consult people before using surveillance, says “Talking to people is the best way to understand their concerns about privacy. You must do this wherever it’s practical”, that it is best to keep a record of the consultation and the responses, and that privacy concerns should be considered “as part of your DPIA”. Privacy is also a fundamental standard: Regulation 10 of the Health and Social Care Act 2008 (Regulated Activities) Regulations 2014 requires “ensuring the privacy of the service user”, which bears directly on any camera near a bedroom or bathroom.

The CCTV part of the notice should say where the cameras or sensors are, what they are for, whether they record sound, who can view recordings, how long recordings are kept (the home’s own period, from its retention schedule), and how to ask for a copy. As the 2025 case shows, footage is personal data and families do ask.

Photographs follow the same logic as everything else outside care itself: a photograph in the care record for identification sits under the care basis, while one on the home’s website or social media needs consent, and the notice should say which is which.

06

The route the notice leaves out

Read a typical care home privacy notice and residents’ information travels to the GP, the pharmacy, the hospital, the local authority and the care planning supplier. Ask the staff and two more routes appear. The staff group chat, where the night senior posts that a resident had a fall and a carer replies with her blood pressure. And the texts between the deputy manager’s personal phone and a resident’s son about his mother’s chest infection.

Each carries residents’ health information along a route the notice does not name, on devices the home does not control, kept for as long as each person keeps their phone. The notice’s retention period means nothing for messages that stay on a former carer’s phone. And when an attorney asks for everything the home holds about their father, the ICO’s guidance on finding and retrieving the information says staff who keep it on their own devices “may be holding it on your behalf”, so those messages may be within scope, and the home can only ask each person to search their own phone. An end-to-end-encrypted consumer app is designed to keep the content on the handsets and away from the organisation, so no setting fixes this.

ComplyChat gives those conversations a channel the home holds. Everyone added is told the channel is on the record and can object or leave; messages are recorded on the server as they are sent, and are stored and processed in the UK; and a mobile number verified by SMS is the identity, so bank staff, a visiting therapist or a relative the resident wants involved can take part without a work account. On paid plans the lasting record files into the provider’s own Microsoft 365 once the tenant is connected, under its own retention rules, so the notice can describe the route truthfully and a subject access request can reach it. ComplyChat is not a care record system or a family portal, and it does not write the privacy notice.

A question for the next managers’ meeting: does our privacy notice describe the way we actually message families and each other?

07

Questions people ask

What does a privacy notice include?

Under Article 13 of the UK GDPR a privacy notice must include the controller’s identity and contact details, any data protection officer’s details, the purposes and lawful basis, recipients, transfers outside the UK, how long data is kept, people’s rights, the right to complain to the controller and to the Information Commission, and whether providing the data is a statutory or contractual requirement. Article 14 adds the categories of data and their source where the data did not come from the person.

What is privacy and dignity in care?

Privacy and dignity in care is a CQC fundamental standard: Regulation 10 of the Health and Social Care Act 2008 (Regulated Activities) Regulations 2014 says “Service users must be treated with dignity and respect”, which includes “ensuring the privacy of the service user”. It is wider than a privacy notice, which is the data protection duty to tell residents how their information is used.

What is the difference between privacy and confidentiality?

In a care home, privacy is the resident’s right under Regulation 10 to be treated with dignity, including privacy in their room and care, and under data protection law to be told how their information is used. Confidentiality is the duty not to disclose what a resident or family tells staff in confidence except where the law or an overriding interest allows, which the National Data Guardian’s Caldicott principles apply across health and social care; principle 8 is “Inform patients and service users about how their confidential information is used”.

What are the GDPR changes in 2026?

For privacy notices, the headline changes are that since 19 June 2026 Articles 13(2)(ca) and 14(2)(da) of the UK GDPR require the notice to tell people of their right to complain to the controller, and since 30 September 2026 the regulator they can complain to is the Information Commission, still known as the ICO. Earlier, on 5 February 2026, the Data (Use and Access) Act 2025 also changed the Article 13 and 14 wording on international transfers and automated decision-making, so a pre-2026 template needs checking line by line.

Can a family member see a care home resident’s records?

A relative can make a subject access request for a resident only with authority to act for them: the ICO says it is reasonable to assume an attorney with authority over the person’s property and affairs, or a deputy appointed by the Court of Protection, can make one, but the type and circumstances of the power must be checked, and the home should say in its privacy information what authority it needs. In 2025 a care home director was convicted and fined after blocking, erasing or concealing records requested by a daughter holding a lasting power of attorney.

Does a care home need consent to keep residents’ records?

No. A care home relies on a lawful basis other than consent for care records, with the Article 9(2)(h) condition for health or social care given effect by paragraph 2 of Schedule 1 to the Data Protection Act 2018, which covers “the provision of social care”; the privacy notice must say which basis applies. Consent is for things outside care itself, such as photographs on social media.

08

Official guidance and your next step

The primary sources are Articles 13 and 14 of the UK GDPR as revised, with Article 12 and section 164A of the Data Protection Act 2018; the ICO’s guidance on the right to be informed and its small-organisation page on how to write a privacy notice, both under review following the Data (Use and Access) Act, so check them against the Articles; CQC’s guidance Using surveillance in your care service; NHS England’s national data opt-out compliance guidance; and the 2026-27 DSPT evidence items. Quotations are from those pages as published on 8 October 2026.

This guide is a practical summary for care providers in England, not legal advice. UK GDPR and the Data Protection Act 2018 apply across the UK; CQC, the national data opt-out and the DSPT are England only, and Wales, Scotland and Northern Ireland have their own regulators. Where a resident lacks capacity and family members disagree about access, take professional advice.

Then do one thing: read the home’s current notice against four lines – the right to complain to the home, the Information Commission named as the regulator, the national data opt-out, and what authority a relative needs to act for a resident – and then ask one resident and one relative to read the short version and tell you what it means.

Why we publish this

We build ComplyChat for the work conversations organisations need to keep. In a care home the route residents’ information most often takes without appearing in the privacy notice is staff and family messaging, and a notice can only be true about places the home can see. The organisational record described here is on paid plans; Free is personal messaging with one private group, direct messages and three calendar months of recent history, and it is not a way to meet a retention duty.

Explore Free · How it works · Compare plans

Sources

Every document this guide quotes or links to, in the order it first cites them.

  1. Article 13 legislation.gov.uk
  2. Article 14 legislation.gov.uk
  3. Article 12(1) legislation.gov.uk
  4. Section 164A of the Data Protection Act 2018 legislation.gov.uk
  5. SI 2026/1015 legislation.gov.uk
  6. Right to be informed guidance ico.org.uk
  7. Right to be informed checklists ico.org.uk
  8. DSPT 2026-27 assertions and evidence items dsptoolkit.nhs.uk
  9. Paragraph 2 of Schedule 1 to the Data Protection Act 2018 legislation.gov.uk
  10. Section 11(1) legislation.gov.uk
  11. How to recognise a subject access request ico.org.uk
  12. DCB3058 Compliance with National Data Opt-outs standards.nhs.uk
  13. Understanding the national data opt-out digital.nhs.uk
  14. Mental Capacity Act 2005, section 1 legislation.gov.uk
  15. Methods for providing privacy information ico.org.uk
  16. A care home director was found guilty ico.org.uk
  17. Using surveillance in your care service cqc.org.uk
  18. Consult people before using surveillance cqc.org.uk
  19. Regulation 10 of the Health and Social Care Act 2008 (Regulated Activities) Regulations 2014 legislation.gov.uk
  20. Finding and retrieving the information ico.org.uk
  21. Caldicott principles gov.uk
  22. How to write a privacy notice ico.org.uk
  23. National data opt-out compliance guidance digital.nhs.uk
  24. 2026-27 DSPT evidence items dsptoolkit.nhs.uk