Many care providers start from a template written for an NHS trust or a GP surgery, which brings duties and job titles that do not fit a care home or a home care service. This guide covers the roles to name, the documents beneath the policy, what the 2026-27 toolkit asks for and how a management team shows it is in charge. For the data protection policy itself, the Caldicott principles and breach reporting, see our care home data protection guide.
The rule: information governance in health and social care
Information governance in health and social care is the set of rules for handling personal and confidential information – data protection law, confidentiality and the Caldicott principles, secure record keeping and information security – and the provider is accountable for all of it. Article 5(2) of the UK GDPR says “The controller shall be responsible for, and be able to demonstrate compliance with, paragraph 1 (‘accountability’)”, and Article 24(2) adds that, where proportionate, the controller’s measures “shall include the implementation of appropriate data protection policies”.
In a regulated care service the policy reaches further than data protection. Regulation 17 of the Health and Social Care Act 2008 (Regulated Activities) Regulations 2014 requires systems to “maintain securely an accurate, complete and contemporaneous record in respect of each service user” and to “evaluate and improve their practice” in processing that information. The National Data Guardian’s eight Caldicott principles govern confidential information about people who use services. And the ten data security standards in the Review of Data Security, Consent and Opt-Outs begin: “Leaders of all health and social care organisations should commit to the following data security standards.” The toolkit measures providers against them.
So an information governance policy is really an information governance framework, not a GDPR policy with a new title: it names who has which responsibilities, lists the documents that do the detailed work, and shows how the management team checks they are followed.
Be careful with NHS templates. A GP surgery’s policy usually cites the Freedom of Information Act 2000, which applies to public authorities as defined in section 3 of the Freedom of Information Act 2000 and its Schedule 1; a private or voluntary care provider is not one, although a care service run directly by a local authority is. NHS templates also name a Senior Information Risk Owner (SIRO), an NHS title the social care toolkit does not ask for.
The roles a care provider should name
The provider is the data controller and carries the legal responsibility. Within it, the tooltip to evidence item 1.1.5 in the DSPT 2026-27 assertions and evidence items (version 9, v1.1) says: “Whilst data security and data protection is everybody’s business, there must be a named person within your organisation who takes overall senior responsibility for data security and protection issues.” The responsibility “could form part of their job description, or be noted in the minutes of a management meeting, or be in an email from the appropriate director”. In a single care home that person is often the registered manager or nominated individual; in a group, a director.
The tooltip adds that an organisation “may also have additional specialised roles, for example a Data Protection Officer … or a Caldicott Guardian”. Decide on each and record the decision:
- Caldicott Guardian. The National Data Guardian’s guidance on the appointment of Caldicott Guardians is statutory guidance that the organisations it lists “must have regard to”, and it recommends that they “should appoint a Caldicott Guardian”. The list includes organisations providing publicly funded “adult social care, or adult carer support” under arrangements with a public body. The guidance says “A Caldicott Guardian in a small or medium-sized care home might be a social care professional or registered nurse”, that an organisation “may choose to share a Caldicott Guardian with one or more other organisations”, and that very small organisations might use the commissioning organisation’s. It is a recommendation to weigh, not a duty to appoint.
- Data protection officer. Article 37 of the UK GDPR requires one where core activities consist of processing special category data on a large scale. Our care home data protection guide sets out the test.
- An IT and cyber security lead, often an external supplier, with a named person inside the organisation who instructs and checks them.
Add the person who handles data protection complaints and subject access requests, and the person who keeps the information asset register. In a small service one person may hold several roles, provided the policy says so and the minutes show the roles were assigned.
The documents beneath the policy
The toolkit does not prescribe a number of policies and procedures. The 1.3.1 tooltip says “some will have one all-encompassing policy, whilst others may have multiple policies”, and sets the minimum: data protection and confidentiality, “how the organisation complies with UK GDPR and the Caldicott Principles, including data breach management, risk assessment, data subject rights, and data protection by design and default”; records management “from their creation to disposal”; cyber security, such as “password management, device and network security, backups”; and, if relevant, remote working and bring your own device.
In practice the framework is a short top-level policy and a set of documents beneath it, most of them matching an evidence item in the 2026-27 toolkit:
- The information governance policy, or a data protection and confidentiality policy, covering that minimum (1.3.1).
- A retention timetable: “Does your organisation have a timetable which sets out how long you retain records for?” (1.4.1). See our guide to care records retention.
- A cyber security policy (1.3.1).
- A bring your own device policy, with “evidence of how this policy is enforced” (1.3.11), and remote working rules where they are relevant (1.3.1).
- An information asset register and record of processing activities (1.1.2): “You can combine these into one register, but it is fine to have two separate documents.” See our guide to the record of processing activities.
- A privacy notice that “clearly explains how information is used” (1.1.3).
- A data protection impact assessment procedure (1.3.8), since Article 35 of the UK GDPR requires one before processing likely to result in a high risk.
- A supplier list and contracts of suppliers that process personal data on the provider’s behalf (10.1.2); the National Data Guardian’s standard 10 says “IT suppliers are held accountable via contracts for protecting the personal confidential data they process”.
- A breach reporting procedure (6.1.1) and a breach log.
- A joiners, movers and leavers procedure: “a reliable way of removing or amending people’s access to IT systems when they leave or change roles” (4.2.4).
- A data protection complaints procedure. Since 19 June 2026, section 164A of the Data Protection Act 2018 requires a controller to “facilitate the making of complaints … such as providing a complaint form which can be completed electronically and by other means”, and to acknowledge a complaint within 30 days.
- A national data opt-out procedure (1.2.4), covered under oversight below.
The Digital Care Hub, the sector’s support service for the toolkit, publishes free template policies for care providers. A template is a starting point: the register, the supplier list and the retention timetable can only be written by someone who knows where the service’s personal data actually goes.
What the 2026-27 DSPT asks of a care provider
The 2026-27 Data Security and Protection Toolkit is version 9. The DSPT release notes record that it was released on 1 September 2026, and NHS England’s news item on the 2026-27 assertions and evidence items, published with the v1.1 spreadsheet on 2 October 2026, says “The deadline for the Data Security and Protection Toolkit is 30th June 2027.” Work from that version, not last year’s.
Social care providers are category 3 and answer a list of prescriptive evidence items. NHS trusts, integrated care boards, commissioning support units and arm’s length bodies use a different interface based on the National Cyber Security Centre’s Cyber Assessment Framework (CAF); other organisations’ answers are mapped to a CAF profile “in the background”, and version 9 is aligned to CAF version 4.0. A CAF objectives-and-outcomes checklist handed to a care home answers the wrong toolkit.
Version 9 adds category 3a for providers in CQC’s Market Oversight scheme. Their items match category 3 with one addition, 9.4.6 “Submit a Cyber Assessment Framework Assessment”, not mandatory in 2026-27; its tooltip says “We do not expect you to have completed a full assessment this year”, but asks those providers to “prepare to complete a CAF assessment as a mandatory part of the DSPT in the future.”
Who must complete it depends on contracts and access, not size. The toolkit is an information standard (DAPB0086) published under section 250 of the Health and Social Care Act 2012. NHS England’s Adult Social Care Standards Directory entry for the DSPT lists “Social care providers that provide care through the NHS Standard Contract”, says “All organisations that have access to NHS patient data and systems must use this toolkit”, and warns of enforcement action for those who fail to comply. The full “Applies to” list is wider than those two lines – it also names “All organisations which have either direct or indirect access to national informatics services” – so read the whole list before deciding the toolkit does not apply.
Beyond the documents above, the category 3 items a framework has to answer include 1.1.1, the organisation’s ICO registration number; 1.1.5, the named senior person; 1.2.4, compliance with the national data opt-out; and 3.2.1: “Have at least 95% of staff, directors, trustees and volunteers in your organisation completed training on data security and protection, and cyber security, in the last twelve months?”
Item 1.1.1’s tooltip still says Information Commissioner’s Office. On 30 September 2026, under SI 2026/1015, the office of Information Commissioner was abolished and its functions transferred to the Information Commission, still known as the ICO; new policy wording should name the Information Commission. The toolkit’s publication levels are covered in our care home data protection guide.

Oversight: who approves what, and how often
For the framework documents themselves the toolkit sets two review clocks: policies “updated every three years as a minimum” (1.3.1), and the register “reviewed and approved by the management team at least once in the last twelve months” (1.1.2). Other mandatory category 3 items run on a yearly cycle too, among them spot checks that staff follow the policies, which “should be undertaken at least every year” (1.3.2), and a training needs analysis “completed in the last twelve months” (3.1.1). None of these is statutory, and a policy should change sooner when the law or the service does, as complaints law did in June 2026.
The National Data Guardian’s fifth standard adds an annual review of practice: “Processes are reviewed at least annually to identify and improve processes which have caused breaches or near misses, or which force staff to use workarounds which compromise data security.” With Regulation 17’s duty to evaluate and improve, that gives a management team an agenda it can minute:
- Roles: confirm the named senior person and the Caldicott Guardian and data protection officer decisions.
- The register: review and approve it, adding any new system, supplier or way of working.
- Breaches and near misses: read the log and record what changed as a result.
- Risks: agree the top information risks, who owns each and what is being done.
- Training: check the 95% figure, including bank staff, directors and volunteers; see our guide to data protection training records.
- Leavers: check that everyone who left lost access to every system on the day.
- Requests and complaints: check each was acknowledged and answered on time.
- The toolkit: agree who completes each section and a publication date before 30 June 2027.
The national data opt-out needs its own procedure. NHS England’s Understanding the national data opt-out says “All organisations providing or coordinating publicly-funded health or adult social care in England will need to comply with the opt-out”, including private and voluntary providers; children’s social care is out of scope. It applies only to confidential patient information used “for purposes beyond individual care such as research and planning”, not to sharing for a person’s own care, anonymised data, disclosures with explicit consent or disclosures the law requires. Its page on compliance with the national data opt-out says a provider with no such uses “must still put procedures in place to assess future uses or disclosures”.
This is what CQC reads under Regulation 17: signed policies with no minutes, no register review and no breach learning are not governance that works. Our guide to Regulation 17 good governance covers oversight more generally, and the Information Commission’s data protection audit framework suggests starting “with the Accountability toolkit” for a self-check; that page is under review following the Data (Use and Access) Act.
The workaround the register leaves out
Read the fifth standard again: processes “which force staff to use workarounds which compromise data security”. In most care services the commonest workaround is in plain sight. It is the staff group chat on personal phones, set up because the rota changes at short notice and the office phone does not reach the night shift. A team leader posts a photograph of a hospital discharge letter so the night shift knows what changed. A carer messages that a resident was unsettled and refused her tablets. A home care worker texts the office that a client was not answering the door.
Measured against the framework, that chat is an information asset holding residents’ health data, and it is on nobody’s register: no entry in the record of processing activities, no supplier contract, no retention period, no leavers procedure. The carer who left in March still has every message. Item 1.3.11 asks for evidence that the bring your own device policy is enforced, and a policy that bans residents’ details on personal phones while the rota group carries them every shift is what that item tests. An end-to-end-encrypted consumer app cannot be configured into compliance, because its design keeps the content on the handsets of the people in the group and away from the organisation.
ComplyChat replaces that group with channels the provider holds. Everyone added is told the channel is on the record and can object or leave; messages are recorded on the server as they are sent, and are stored and processed in the UK; a mobile number verified by SMS is the identity, so bank and agency staff without a work email can be included; and managers add someone in a click and remove them the moment they leave. On paid plans the lasting record files into the provider’s own Microsoft 365 once the tenant is connected, under the retention rules the provider already sets, so the channel can sit on the register as an asset the provider controls. ComplyChat is not a care record system, does not do care planning, rostering or medicines, and does not complete the toolkit or write the policy.
A question for the next management meeting: which of our information assets is the staff group chat, and is it on the register?
Questions people ask
Is information governance the same as GDPR?
No. In health and social care, information governance covers data protection under the UK GDPR and also confidentiality, including the Caldicott principles, records management and cyber security. The DSPT 2026-27 evidence items say a care provider’s policies should cover all four, with remote working and bring your own device where relevant.
What should an information governance policy include?
For a care provider, the DSPT says the policy or policies should cover, as a minimum, data protection and confidentiality (UK GDPR and the Caldicott principles, breach management, risk assessment, data subject rights, data protection by design and default), records management from creation to disposal, cyber security and, if relevant, remote working and personal devices, and should be updated every three years as a minimum. A good framework also names the senior person responsible and lists the documents beneath it.
Who is responsible for information governance in a care home?
The provider, as data controller, is responsible, and the DSPT says “there must be a named person within your organisation who takes overall senior responsibility for data security and protection issues”, with that responsibility formally assigned. A provider may also have a data protection officer, required where Article 37 of the UK GDPR applies, or a Caldicott Guardian, which the National Data Guardian recommends for publicly funded adult social care.
What are the 8 principles of information governance?
In health and social care, the recognised eight are the Caldicott principles, published in their current form by the National Data Guardian on 8 December 2020, which govern how confidential information about patients and service users is used and shared. Other sectors use different eight-item lists for records management. Our care home data protection guide lists the Caldicott principles and what each means in practice.
What are the GDPR changes in 2026?
Among the Data (Use and Access) Act 2025 changes, from 19 June 2026 every controller must make it easy for people to complain to it about its handling of their data, acknowledge a complaint within 30 days and respond without undue delay, under section 164A of the Data Protection Act 2018. On 30 September 2026 the Information Commission replaced the Information Commissioner, still known as the ICO. Our care home data protection guide covers the rest.
Official guidance and your next step
The primary sources are NHS England’s 2026-27 DSPT assertions and evidence items and the Data Security and Protection Toolkit; Article 24 of the UK GDPR and section 164A of the Data Protection Act 2018; the National Data Guardian’s Caldicott principles and Caldicott Guardian guidance; Regulation 17; and NHS England’s national data opt-out compliance guidance, with template policies from the Digital Care Hub. Quotations are from those pages as published on 8 October 2026.
This guide is a practical summary for adult social care providers in England, not legal advice. The DSPT, the National Data Guardian’s guidance and Regulation 17 apply in England; Wales, Scotland and Northern Ireland have their own regulators and standards, though the UK GDPR applies across the UK.
Then do one thing: at the next management meeting, put the twelve documents listed above on one page, write beside each its owner and the date it was last updated, and minute who holds overall senior responsibility for data security and protection.
We build ComplyChat for the work conversations organisations need to keep. In a care service the information asset most often missing from the register is the staff group chat, and a framework can only govern what it lists. The organisational record described here is on paid plans; Free is personal messaging with one private group, direct messages and three calendar months of recent history, and it is not a way to meet a retention duty.
Sources
Every document this guide quotes or links to, in the order it first cites them.
- Article 5(2) of the UK GDPR legislation.gov.uk
- Article 24(2) legislation.gov.uk
- Regulation 17 of the Health and Social Care Act 2008 (Regulated Activities) Regulations 2014 legislation.gov.uk
- Eight Caldicott principles gov.uk
- Review of Data Security, Consent and Opt-Outs gov.uk
- Section 3 of the Freedom of Information Act 2000 legislation.gov.uk
- DSPT 2026-27 assertions and evidence items (version 9, v1.1) dsptoolkit.nhs.uk
- Guidance on the appointment of Caldicott Guardians assets.publishing.service.gov.uk
- Article 37 of the UK GDPR legislation.gov.uk
- Article 35 of the UK GDPR legislation.gov.uk
- Section 164A of the Data Protection Act 2018 legislation.gov.uk
- Digital Care Hub digitalcarehub.co.uk
- DSPT release notes dsptoolkit.nhs.uk
- News item on the 2026-27 assertions and evidence items dsptoolkit.nhs.uk
- Adult Social Care Standards Directory entry for the DSPT adultsocialcare.standards.nhs.uk
- SI 2026/1015 legislation.gov.uk
- Understanding the national data opt-out digital.nhs.uk
- Compliance with the national data opt-out digital.nhs.uk
- Data protection audit framework ico.org.uk
- Data Security and Protection Toolkit dsptoolkit.nhs.uk




