What a confidentiality policy is, and the law behind it
A confidentiality policy sets out how an organisation meets its legal duties of confidence and data protection, and it draws on several sources of law rather than one statute. For a care provider or charity in England, four matter most.
- The common law duty of confidence. Section 2 of the Health and Social Care Information Centre's 2013 A guide to confidentiality in health and social care: references, now published by NHS England, explains that it is built up from case law, not an Act of Parliament: "A duty of confidence arises when one person discloses information to another in circumstances where it is reasonable to expect that the information will be held in confidence." Information given by service users to a health or social care service is generally accepted to be given in confidence, for as long as it can identify them.
- The UK GDPR and the Data Protection Act 2018. Article 5 of the UK GDPR requires personal data to be processed with appropriate security, which it calls "integrity and confidentiality". Information about a person's health is special category data under Article 9, and processing it is prohibited unless one of the listed conditions applies.
- The Human Rights Act 1998. Article 8 gives everyone "the right to respect for his private and family life, his home and his correspondence".
- The Caldicott principles. The National Data Guardian's eight Caldicott principles, published in December 2020, apply "to the use of confidential information within health and social care organisations and when such information is shared with other organisations and between individuals".
Is the policy itself a legal requirement? Not by that name. Article 24 of the UK GDPR requires a controller to implement appropriate measures to ensure, and be able to demonstrate, that its processing complies with the UK GDPR, and says that where proportionate those measures "shall include the implementation of appropriate data protection policies". For a provider registered with the Care Quality Commission, Regulation 17 of the Health and Social Care Act 2008 (Regulated Activities) Regulations 2014 requires records to be kept securely, and the CQC's Regulation 17 guidance says "Systems and processes must support the confidentiality of people using the service and not contravene the Data Protection Act 2018." A confidentiality policy is how most organisations show both.
Confidentiality and data protection overlap but are not the same duty, and a disclosure has to be lawful under both.
What should be included in a confidentiality policy
A confidentiality policy and procedure staff can use answers the questions they actually meet. Include:
- Who it applies to. Employees, bank and agency staff, trustees, volunteers and contractors.
- What counts as confidential. Personal information about service users, clients and their families, staff personal information and sensitive business information, with examples from your service.
- Need to know. Who may see which records; being on shift is not the same as needing to read everything.
- Consent and the right to object. How consent to share is sought and recorded, and what happens when a person says no.
- Families, carers and other third parties. What staff may tell a relative who phones, and who decides when the person lacks capacity.
- When confidentiality can be broken. Safeguarding, legal duties and the public interest, with the named person who decides (section 04).
- Secure handling, storage and disposal. Paper, screens, email and phones, and the retention schedule.
- Talking and messaging. Handovers, public places, social media and group chats (section 05).
- Breaches and data security. How to report one, who assesses it, and the ICO's clock.
- Roles and review. The Caldicott Guardian or senior lead, the data protection lead, and the review date.
Keep the service user's version short. People who use the service, and their families, should be able to read in plain words what is kept, who sees it and when it might be shared without their agreement. The ICO's guidance on the right to be informed says you must tell people "your purposes for processing their personal data, your retention periods for that personal data, and who it will be shared with", and that is the backbone of the version they read.
The Caldicott principles and the five confidentiality rules
In health and social care, two short lists matter. The first is the eight Caldicott principles:
- Justify the purpose(s) for using confidential information.
- Use confidential information only when it is necessary.
- Use the minimum necessary confidential information.
- Access to confidential information should be on a strict need-to-know basis.
- Everyone with access to confidential information should be aware of their responsibilities.
- Comply with the law.
- The duty to share information for individual care is as important as the duty to protect patient confidentiality.
- Inform patients and service users about how their confidential information is used.
Principle 1 says every proposed use or transfer of confidential information "should be clearly defined, scrutinised and documented". Principle 7 says professionals "should have the confidence to share confidential information in the best interests of patients and service users". A policy that only teaches caution fails the seventh as surely as a careless one fails the first.
The second list is the five confidentiality rules from the Health and Social Care Information Centre's A guide to confidentiality in health and social care, published on 1 September 2013, before the UK GDPR, and now hosted by NHS England: rely on it for the common law and these rules, not for data protection law. Its foreword expects it "to become part of the DNA for all staff in residential homes, providing care at home, working in wards and in communities".
- Confidential information about service users or patients should be treated confidentially and respectfully.
- Members of a care team should share confidential information when it is needed for the safe and effective care of an individual.
- Information that is shared for the benefit of the community should be anonymised.
- An individual's right to object to the sharing of confidential information about them should be respected.
- Organisations should put policies, procedures and systems in place to ensure the confidentiality rules are followed.
Rule 5 is the reason the policy exists. The guide asks for "a senior individual responsible for ensuring the confidentiality rules are followed", which should be the Caldicott Guardian or another senior member of staff responsible for information risk, and for compliance to be reviewed and policies updated "at least annually". The National Data Guardian's guidance on the appointment of Caldicott Guardians, published in August 2021, recommends that a Caldicott Guardian is appointed by public bodies exercising health service, adult social care or adult carer support functions in England, and by organisations providing publicly funded health services, adult social care or adult carer support under arrangements with those bodies, where they process confidential information about patients or service users. For an organisation that is not a public body, the duty to have regard to the guidance applies "only in relation to work that is publicly funded".
When confidentiality can lawfully be broken
Confidential information can lawfully be shared in three circumstances: with the person's consent, where the law requires or permits it, or where the public interest in sharing outweighs the duty of confidence. Section 2 of the 2013 guide's references sets out each one.
- Consent. "For consent to be legally valid, the individual must be informed, must have the capacity to make the decision in question and must give consent voluntarily." Within direct care it can be implied; outside the care team it needs to be explicit.
- A legal duty or permission. Some legislation requires disclosure, and some permits it. The guide's examples include the duty to notify certain infections, court orders, and bodies with legal power to obtain information, naming the Care Quality Commission.
- The public interest. The guide notes that judgments allowing confidentiality to be breached "in the public interest" have "centred on case-by-case consideration of exceptional circumstances".
For adult safeguarding, the Care and support statutory guidance under the Care Act 2014 is blunt. Paragraph 14.187 says agencies' common agreement on confidentiality should ensure that "confidentiality must not be confused with secrecy", that informed consent should be obtained "but, if this is not possible and other adults are at risk of abuse or neglect, it may be necessary to override the requirement", and that "it is inappropriate for agencies to give assurances of absolute confidentiality in cases where there are concerns about abuse". Paragraph 14.190 adds that confidentiality rules protecting an organisation's management interests "must never be allowed to conflict with the welfare of an adult".
Data protection law provides a matching condition. Schedule 1, paragraph 18 of the Data Protection Act 2018 allows special category data to be processed without consent where it is necessary to protect a child, or an adult at risk, from neglect or physical, mental or emotional harm, and consent cannot be given, cannot reasonably be obtained, or would prejudice that protection, and the processing is necessary for reasons of substantial public interest. The ICO's data sharing code of practice on urgent situations says that "In an emergency you should go ahead and share data as is necessary and proportionate", and lists "safeguarding vulnerable adults or children" among its examples.
Two consequences belong in the policy. Staff must never promise that something will stay between them, because they may not be able to keep that promise; the honest wording is that it will be shared only with those who need to know. And every decision to disclose without consent needs a short record: what, with whom, why, who decided, and whether the person was told.

Staff talk, messages and what counts as a breach
Most breaches of confidentiality are not a stolen laptop. They are a handover overheard in a corridor, a resident discussed at the bus stop, a relative told more than the resident agreed to, or a message sent to the wrong group.
Put the everyday rules in plain words:
- Handovers and phone calls about a person happen where others cannot overhear.
- Nobody discusses a person the service supports in public or on social media, even without a name, if they could be recognised.
- Information about service users travels only through the organisation's systems, never a photograph on a personal phone.
- Identity is checked before anything is said to a caller.
- A misdirected message is reported at once, not quietly deleted.
A breach of confidentiality that involves personal data is often also a personal data breach. The ICO's guide to personal data breaches defines one as "a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data", and says "You must report a notifiable breach to the ICO without undue delay, but not later than 72 hours after becoming aware of it." So staff should report a suspected breach the same day, including one they caused.
The conversation on the bus, and the group on a personal phone
Every care provider and charity has two kinds of confidential conversation it cannot see. One is spoken: colleagues on the bus home talking through a hard shift. The policy can only teach judgement there.
The other is written, and it is the larger risk. A staff WhatsApp group set up to swap shifts becomes the place where someone asks whether a resident's fall was reported, or raises a concern about a colleague at eleven at night. Each message is confidential information, processed on a personal phone, in a group the organisation did not create and cannot recover when a member leaves.
The ICO has already dealt with a close version of this pattern. In its reprimand to NHS Lanarkshire, a Scottish health board, issued under the UK GDPR on 31 July 2023, it found that a team's WhatsApp group, used "as a substitute for communications that would have taken place in the clinical office", held at least 533 entries including patient names between April 2020 and April 2022, and that someone had been added to it in error. The staff were using work-issued phones, not personal ones, and the reprimand still found infringements of Article 5(1)(f), Article 25(1) and Article 32(1) of the UK GDPR, recording that WhatsApp "was not approved by NHS Lanarkshire for processing personal data of patients".
The same conversation is also a record. If it holds the first sign of a safeguarding concern or a decision about someone's care, the organisation may need to produce it to the CQC, a subject access request or a safeguarding enquiry, and it sits on phones the organisation does not control.
ComplyChat gives those conversations a channel the organisation owns. Everyone added is told the channel is on the record, messages are recorded on the server as they are sent, and on paid plans the lasting record files into the organisation's own Microsoft 365 once the archive is connected. It does not reach or archive a personal WhatsApp group; it gives staff somewhere better to talk. It is not a care record system, it will not stop a conversation on a bus, and if your staff never need to message each other about the people you support, you do not need it. ComplyChat Free is a permanent personal tier (one private group, direct messages, up to 25 staff members, three calendar months of history and no Microsoft 365 archive): a way to get to know the product, not a record system.
A question for your next board or leadership meeting: if a resident's family asked what had been said about their mother in staff messages last month, where would we look, and could we show it?
Questions people ask
What is a confidentiality policy?
A confidentiality policy is an organisation's written rules for keeping information about the people it serves and its staff confidential: who may access it, how it is stored and shared, and when it may lawfully be disclosed.
When can we legally break confidentiality?
Confidentiality can lawfully be broken with the person's consent, where the law requires or permits disclosure, or where the public interest outweighs the duty of confidence, such as a risk of serious harm. For adults at risk, the Care and support statutory guidance says that where informed consent cannot be obtained and other adults are at risk of abuse or neglect, it may be necessary to override the requirement for consent.
What are the five confidentiality rules in health and social care?
The five rules come from A guide to confidentiality in health and social care (2013): treat confidential information confidentially and respectfully; share it within the care team when needed for safe and effective care; anonymise information shared for the benefit of the community; respect a person's right to object to sharing; and put policies, procedures and systems in place so the rules are followed.
Is it a legal requirement to have a privacy policy?
UK data protection law requires privacy information rather than a document with a particular name: the ICO says "You must provide privacy information to individuals at the time you collect their personal data from them". Article 24 of the UK GDPR requires appropriate data protection policies where proportionate.
What is classed as a breach of confidentiality?
A breach of confidentiality is the use or disclosure of confidential information without consent or another lawful basis. Where it involves a breach of security leading to the unauthorised disclosure of, or access to, personal data, it is also a personal data breach, and a notifiable one must be reported to the ICO without undue delay and within 72 hours of becoming aware of it.
Where to read the official guidance
Start with the National Data Guardian's eight Caldicott principles, chapter 14 of the Care and support statutory guidance and the CQC's Regulation 17 guidance. Quotations are from the linked documents as published on 28 September 2026.
This guide is a practical starting point for care providers and charities in England, not legal advice about a particular disclosure. Where a decision to share is difficult, involve your Caldicott Guardian or data protection lead.
We build ComplyChat for the work conversations organisations need to keep and be able to produce. A confidentiality policy is only as good as the places staff actually talk, and the gap in section 06 is where it most often fails. Explore Free personal messaging, or compare the paid plans if your organisation needs a lasting Microsoft 365 archive.
Sources
Every document this guide quotes or links to, in the order it first cites them.
- A guide to confidentiality in health and social care: references digital.nhs.uk
- Article 5 of the UK GDPR legislation.gov.uk
- Article 9 legislation.gov.uk
- Article 8 legislation.gov.uk
- Eight Caldicott principles gov.uk
- Article 24 of the UK GDPR legislation.gov.uk
- Regulation 17 of the Health and Social Care Act 2008 (Regulated Activities) Regulations 2014 legislation.gov.uk
- CQC's Regulation 17 guidance cqc.org.uk
- The right to be informed ico.org.uk
- A guide to confidentiality in health and social care digital.nhs.uk
- Guidance on the appointment of Caldicott Guardians gov.uk
- Care and support statutory guidance gov.uk
- Schedule 1, paragraph 18 of the Data Protection Act 2018 legislation.gov.uk
- Data sharing code of practice on urgent situations ico.org.uk
- Guide to personal data breaches ico.org.uk
- Reprimand to NHS Lanarkshire ico.org.uk


