GDPR training for care staff is a yearly refresher that teaches everyone in your service how to handle personal information lawfully, keep it confidential, share it safely and spot a data breach before it grows. In adult social care, that information is mostly health and care data, which UK GDPR treats as special category data needing extra protection.
The Data Security and Protection Toolkit expects staff to complete data security training every year, so a short annual course is the simplest way to keep your team current and your evidence ready, and the best news, our course is structured around the care sector.
Why does GDPR training for care staff matter so much?
Care workers handle more sensitive information in a single shift than many office workers see in a month. Care plans, medication records, safeguarding concerns and family details pass through their hands on paper, on phones and in conversation.
Most data protection problems in care are not dramatic hacks. They are everyday slips:
A handover sheet left on a lounge table where visitors can read it.
A photo of a resident taken on a personal phone and shared in a staff group chat.
An email with a care plan attached sent to the wrong family member.
A relative given details over the phone without checking who they are or whether the person has agreed.
A worker clicking a convincing link in a fake email and handing over their login.
Each of these is preventable when staff know what to do. That is the purpose of the training: practical habits, not legal theory.
What law does data protection training need to cover?
In the UK, personal information is governed by the UK GDPR and the Data Protection Act 2018, which was amended by the Data (Use and Access) Act 2025. Your staff do not need to quote articles, but they do need to understand the principles the Information Commissioner's Office (ICO) sets out.
Personal data must be:
Processed lawfully, fairly and in a transparent way.
Collected for specific purposes and not used for something unrelated.
Adequate, relevant and limited to what is needed.
Accurate and kept up to date.
Kept no longer than necessary.
Kept secure.
There is also an accountability principle: as the provider, you must be able to show you comply. Training records are a large part of that proof.
Alongside the law sit the Caldicott Principles, which guide how health and care information that identifies a person is used and shared. They ask staff to justify why information is needed, use only the minimum necessary, give access on a strict need-to-know basis, understand their responsibilities, and remember that the duty to share information can be as important as the duty to protect it. The eighth principle asks services to inform people about how their information is used, so there are no surprises.
What should GDPR and data protection training include for a care service?
Good GDPR and data protection training for care should mirror the real decisions your staff make. At a minimum, it should help them answer these questions with confidence.
Who can I share this with?
Staff often worry that data protection stops them sharing anything. It does not. Sharing information with a GP, district nurse or pharmacist for the person's direct care is normal and expected. Sharing to protect someone from abuse or serious harm is supported by the law. The skill is knowing when sharing is appropriate, sharing only what is needed, checking the identity of the person asking, and recording what was shared and why.
CareStream turns your policies into role-based training with tracking and certificates. See the plans and get started.
See training plansWhat rights do the people we support have?
People have the right to be informed about how their data is used, the right to see a copy of it, the right to have mistakes corrected and, in some cases, the right to object or to have data erased. A request to see records does not have to be in writing or use any particular words. Staff need to recognise a subject access request when a resident or relative makes one verbally, and pass it to the right person straight away so your service can respond within the legal time limit, which is normally one month.
How should I record and store information?
Records should be factual, respectful, written as soon as possible and kept where only authorised people can see them. That applies to digital records, paper files and office whiteboards alike. Disposal matters too: confidential waste goes in the confidential bin or shredder, never in general waste.
How do I keep devices and accounts safe?
Most care services now run on digital care planning, eMAR and rostering apps. Staff need to lock screens, never share logins, use only approved apps and devices, keep personal messaging apps away from care information, and report a lost phone or tablet immediately.
How does data security and protection toolkit training fit in?
The Data Security and Protection Toolkit (DSPT) is the online self-assessment from NHS England that lets organisations show they meet the National Data Guardian's data security standards. Many care providers complete it because they have NHS contracts or access NHS systems and information, such as shared care records or NHSmail.
One of the Toolkit's expectations is that staff complete appropriate data security and protection training every year, and that you can show how many have done so. That is why data security and protection toolkit training is usually treated as an annual requirement rather than a one-off induction topic. A course that covers confidentiality, sharing, cyber security and breach reporting, with dated completion records for each person, gives you what you need for that part of your submission.
Why is cyber security now part of data protection training?
Care providers hold valuable personal information and staff are busy, which makes them targets for phishing emails, fake invoices and calls asking a worker to "confirm" a password.
Your staff are your best defence. Training should help them pause before clicking, check the sender, never give out passwords or one-time codes, and report anything suspicious even if they think they might have made a mistake. A culture where people report quickly, without fear of blame, limits the damage.
What counts as a data breach and what should staff do?
A personal data breach is any security incident that leads to personal data being lost, destroyed, altered, disclosed or accessed without authorisation. It does not have to be deliberate. A misdirected email or a lost unlocked phone can both be breaches.
Staff do not decide whether a breach is reportable. Their job is to tell their manager or data protection lead immediately. Where a breach is likely to result in a risk to people's rights and freedoms, the organisation must report it to the ICO within 72 hours of becoming aware of it, and in some cases must also tell the people affected. That clock is why speed matters. A worker who waits until the end of their shift, or the next day, can make it much harder for you to meet your legal duty.
Assign, track and evidence staff training in minutes. Explore the plans and roll it out this week.
See training plansWhat does the CQC look for in data protection?
The CQC expects records to be accurate, complete, kept securely and available to the right people when needed. This sits under Regulation 17 of the Health and Social Care Act 2008 (Regulated Activities) Regulations 2014, good governance. Regulation 18, staffing, requires staff to receive the training they need to carry out their role.
In practice, inspectors may notice:
Whether care records are left open or visible in communal areas.
Whether staff can explain how they keep information safe and what they would do if something went wrong.
Whether your training matrix shows data protection training is up to date for every member of staff, including bank and night workers.
How often do care staff need data protection training?
The Skills for Care statutory and mandatory training guide lists information governance and data protection among the topics care staff should be trained in, and the DSPT expects yearly staff training. For most providers, that means every member of staff completes a refresher every 12 months, and new starters complete it during induction before they handle records unsupervised.
The CareStream GDPR / Data Protection CPD Certified course
Our GDPR / Data Protection course is a CPD Certified Course, certified by The CPD Certification Service and worth 1 CPD hour. It was built for adult social care on UK GDPR, the Data Protection Act 2018 as amended in 2025, ICO guidance and the Caldicott Principles. It has eight lessons:
CareStream is a registered CPD Provider (No. 50224). You can check our membership and see every CPD Certified course we offer on our page on The CPD Certification Service website.
Data protection law and principles
Confidentiality and the Caldicott Principles
People's rights over their information
Sharing information safely
Recording, storing and disposing of information
Fraud, scams and cyber security
Devices, apps and paper records
Data breaches
Each lesson uses care scenarios and interactive activities, followed by a 32-question knowledge assessment with an 80% pass mark. It takes about an hour, runs online on any phone or computer, and learners work at their own pace. If someone gets an answer wrong, a short follow-up lesson revisits that point. Staff can take the course in over 60 languages, which helps everyone understand the details.
Each learner who passes receives a named, dated certificate carrying the CPD mark. The certificate evidences completion of CPD Certified training and a pass in our knowledge assessment; it is not a qualification. Managers allocate licences and track who has finished, and their scores, from one dashboard, which makes your DSPT and CQC evidence easy to pull together. The course is an annual refresher, team prices start from 10 licences, and any licence not yet started can be refunded within 14 days.
Getting data protection right in your service
Data protection in care is about respect. The people you support trust your staff with the most personal details of their lives, and good GDPR training for care staff turns that trust into everyday habits: locked screens, careful conversations, sensible sharing and fast reporting. Make it part of induction, refresh it every year, keep clear records, and your team will protect the people in your care and your service at the same time.
Sources
- ICO: a guide to the data protection principles · ico.org.uk
- ICO: personal data breaches · ico.org.uk
- ICO: right of access · ico.org.uk
- NHS England: Data Security and Protection Toolkit · dsptoolkit.nhs.uk
- GOV.UK: the Caldicott Principles · gov.uk
- legislation.gov.uk: Data Protection Act 2018 · legislation.gov.uk
- CQC: Regulation 17, good governance · cqc.org.uk
- CQC: Regulation 18, staffing · cqc.org.uk
- Skills for Care: statutory and mandatory training guide · skillsforcare.org.uk
Frequently asked
Is GDPR training mandatory for care staff?
There is no single law that names a course, but UK GDPR requires you to keep personal data secure and show you comply, Regulation 18 requires staff to be trained for their role, and the Data Security and Protection Toolkit expects yearly staff training. In practice, every care provider should treat it as essential training for all staff.
How often should care staff complete data protection training?
Most providers refresh data protection training every 12 months, in line with the Data Security and Protection Toolkit expectation of annual staff training. New starters should complete it during induction, before they handle records unsupervised.
What is the Data Security and Protection Toolkit?
It is an online self assessment from NHS England that lets organisations show they meet the National Data Guardian's data security standards. Many care providers complete it because they have NHS contracts or access NHS systems and information.
What should a care worker do if they think there has been a data breach?
Tell their manager or data protection lead straight away, even if they are not sure. Where a breach is likely to put people's rights and freedoms at risk, the organisation must report it to the ICO within 72 hours of becoming aware of it, so speed matters.
Does data protection stop care staff sharing information with GPs or families?
No. Sharing information with other professionals for a person's direct care is normal and expected, and sharing to protect someone from harm is supported by the law. Staff should share only what is needed, check who they are speaking to and record what they shared and why.
Written by












