Information Governance PolicyA Information Governance Policy written for your service
- Written for your organisation, not a template with your logo on it
- Read and approved by a person before it carries your name
- Verified against all 64 required elements of the legislation below
- Kept updated when the law changes, so it never quietly goes stale
No subscription needed. First year of updates included, £12 a year after that.
One-off, first year of updates included. Delivered within 2 working days of your details.
Trusted by UK care providers

Let's build your Information Governance Policy
Answer 7 quick questions, about three minutes, and we'll write this policy for your service, in your name, with your people. You can skip anything and add it later.
Asked once, reused for every policy you buy
That's everything we need
0 of 7 answered. You can add the rest at any point before we write it.
- Registered company name
- Trading name (if different)
- Service address
- CQC provider ID
- CQC location ID
- Registered manager
- Nominated individual
Your answers are saved on this device and carried into your order.
Built from the law, checked against the law
The legislation, CQC standards and guidance we analyse to write it.
Your Information Governance Policy is structured from these regulations, then verified against every required element of each one before a person signs it off. If the law changes, your policy is updated and you are told what changed and why.
Data Protection Act 2018
- Policy document identifying the specific lawful basis (legal condition) used for processing different categories of personal data, including health and social care condition for care records, employment condition for DBS checks and payroll, and substantial public interest condition for safeguarding referrals
- Appropriate policy document(s) required under Schedule 1 Part 2 for each substantial public interest condition relied upon (as required by Article 9(2)(g) and which the ICO may request to inspect)
- Privacy notice written in plain language that residents can read and in an accessible format, explaining how personal data is used
- Procedure for responding to subject access requests within one calendar month from receipt, free of charge, including process for redacting third-party information (residents, relatives, staff) that appears on shared pages in care records
- Staff training and written warning that accessing resident files without legitimate work purpose, photographing care plans, or similar unauthorised processing constitutes a personal criminal offence under section 170 of the Act
- Data breach notification procedure requiring reporting to the ICO within 72 hours of the organisation becoming aware (not when manager is informed) of breaches such as lost handover sheets, misdirected emails, stolen devices, or ransomware incidents

Information governance (umbrella framework for lawful, secure and confidential information handling)
- A data protection complaints procedure specifying acknowledgment within 30 days and response timescales without undue delay
- An appropriate policy document for processing under health and social care conditions and substantial public interest conditions (as required when not relying on consent)
- Privacy notices provided in formats accessible to residents in accordance with the Accessible Information Standard
- Access controls ensuring staff can only view information for residents they are directly caring for (role-based access restrictions)
- Procedures prohibiting removal of handover sheets and care documentation from the building and ensuring confidential information is not visible to visitors
- A requirement that lawful basis for processing does not override common law duty of confidence, with public interest justifications recorded at the time for disclosures including safeguarding referrals

Records Management Code of Practice for Health and Social Care 2021
- Specifies retention periods for each type of record held by the home, including care records, staff records, occupational health records, controlled drugs registers, complaints records (including Freedom to Speak Up cases with minimum ten-year retention), safeguarding records, and incident reports, referencing the retention schedule in Appendix II of the Code
- Requires that all staff complete records management training before being permitted to handle or access resident records
- Establishes procedures for maintaining a destruction log that records what was destroyed, the date of destruction, who performed the destruction, and under what authority the destruction was carried out
- Defines and implements a legal hold procedure that immediately stops routine destruction of records when an inquest, police investigation, safeguarding enquiry, claim, public inquiry or similar formal process is in prospect or underway
- Specifies that any member of staff is authorised to trigger a legal hold and that such holds cannot be overridden without proper authority
- Addresses records management procedures for system migrations, including verification that historical records remain readable, complete and accessible after migration to new care planning or record-keeping systems

The Caldicott Principles
- States that personal information may only be used or shared where there is a clear, justified and lawful purpose
- Requires that information is only accessed or shared when absolutely necessary and proportionate to the purpose
- Requires use of the minimum amount of personal information necessary for the stated purpose
- Restricts access to confidential information on a strict need-to-know basis according to staff role and responsibilities
- Establishes accountability mechanisms for how personal information is handled and by whom
- Requires all staff to be trained to understand their confidentiality responsibilities and how to apply the Caldicott Principles

UK General Data Protection Regulation (UK GDPR)
- Identifies lawful basis for processing under Article 6 (legitimate interests or public task) and Article 9(2)(h) condition (health and social care provision) for resident personal and health data
- Includes or references an appropriate policy document as required by Schedule 1 of the Data Protection Act 2018 for processing special category data
- Specifies that information sharing for direct care, safeguarding, or vital interests is permitted and lawful, and that GDPR does not prevent such sharing
- Defines unauthorised access to records (including looking up records without legitimate reason) as a criminal offence under section 170 of the Data Protection Act 2018
- States that falsifying, altering or retrospectively amending care records is a criminal offence under section 173 of the Data Protection Act 2018
- Establishes 72-hour breach notification timeline from awareness of breach and designate who can initiate breach reporting outside normal office hours when registered manager is unavailable

Written for your service
What we ask you, so none of it is assumed.
Most policy packs are one document sold to everyone with a find and replace on the home name. Your Information Governance Policy is written from the legislation above and from your answers to the questions below. Where you have told us something, it says so. Where you have not, it sets out what must happen rather than claiming you already do it.
Your registered name, address, CQC numbers and who holds the key roles. About three minutes. Nothing else is asked before you buy.
Asked once in your own account and used across every policy you own, so a second policy never asks you the same thing twice.
Why it matters. A policy that claims you assess your premises annually, when you never have, is not a harmless overstatement. It is a signed statement handed to your inspector. We would rather write what you must do than guess what you already do.
How it is made
From your details to a policy you can stand behind.
The short questions above: who you are, your CQC registration, and the people this policy names.
One section per required element of the legislation, in your name, with your people.
Automated checks against every required element, then a person reads it before it ships.
When legislation changes, your policy is updated and you are told what changed and why.
Common questions
What you are actually buying.
What exactly do I receive?
A complete Information Governance Policy written for your organisation, in your dashboard and as a print-ready PDF on your own letterhead. It names your service, your registration details and your leads, because you gave us them.
Is this a template?
No. Each policy is written for the organisation buying it, structured from the legislation itself, verified against 64 required regulatory elements, and read by a person before it carries your name.
How quickly will I get it?
Within 2 working days of you completing the short questions above. Most arrive sooner.
What happens when the law changes?
We monitor UK care legislation continuously. When something affecting this policy changes, your copy is updated and you are told what changed and why. The first year of updates is included, then £12 a year per policy.
Can I edit the policy myself?
No, and deliberately so: we stand behind every word we approve. If something needs changing, tell us and we amend and re-verify it, so it always remains a document we can both defend to an inspector.
What if I need more than one policy?
Most services do. The Statutory Starter Pack covers the twenty policies every CQC-registered service is expected to hold, and the Complete Policy Library covers all 66.
Why CareStream
Policies written the way an inspector expects to read them.
Before you buy
What the document actually looks like.
Every section it contains, and a page of the real thing. We show the structure and the personalisation rather than the wording, because the wording is what you are paying us to write for your service.
Contents of your Information Governance Policy
- Purpose and scopewho it covers
- Legal and regulatory frameworkcited in full
- Definitions used in this policy
- Roles and responsibilitiesyour people, named
- Procedure, step by step
- Recording, reporting and escalation
- Training and competency
- Monitoring, audit and review
- Related policies and documents
- Version control and approvalsigned and dated
Section 4 · Roles and responsibilities
Who is accountable, by name
Overall accountability for this policy rests with your registered manager, supported by your nominated individual. Day to day responsibility sits with your named lead, who is the first point of contact for staff at your service address.
The remaining wording is written for the organisation buying it, so it is not shown here.
“The inspector asked for evidence and I had it on screen before she finished the sentence.”
Registered Manager · 48-bed nursing home, West SussexRelated policies
More policies your service may need.
More statutory and operational policies CareStream writes for your service, personalised, human-reviewed and kept updated, exactly like this one.

Data Protection and GDPR Policy
Lawful handling of personal and special category data under UK GDPR and the Data Protection Act 2018.

Duty of Candour Policy
Being open and honest when things go wrong, under Regulation 20.

Clinical Governance Policy
How clinical quality is led, measured, audited and improved.

Statement of Purpose
Your registered Statement of Purpose under the 2009 Registration Regulations, ready to file with CQC.

Confidentiality Policy
Keeping personal information confidential, and when sharing is right.

Business Continuity Policy
Keeping people safe through outages, staffing crises and emergencies, with your escalation contacts.
Compared
The four ways care services get a policy.
We have compared what each approach does rather than naming competitors, because products change and the comparison should still be true next year.
| CareStream | A policy pack | A consultant | A free template | |
|---|---|---|---|---|
| Questions asked at the point of purchase, so it is personalised rather than blank | ||||
| Written for your service, naming your manager and your leads | ||||
| Structured from the regulations, every required element checked before it is sent | ||||
| A branded companion document setting out the law it was written against | ||||
| Read and approved by a person before it carries your name | ||||
| Prints on your own letterhead with a sign-off and version block | ||||
| Named role holders update everywhere when the person changes | ||||
| Kept current when the law changes, and you are told what changed | ||||
| Turnaround stated before you buy | ||||
| Your staff can ask it questions in their own language | ||||
| What it costs | £39 to £79 per policy, one-off | £250 to £995 for the pack | A day rate, typically £400 upwards | Nothing |
Prices are the published rates of the common alternatives as at September 2026, for comparison only.
Training
Owning the policy is half of it
An inspector asks whether your staff understood it, not whether you hold it. Ninety eight modules written and kept current by us, to the same regulations, from £25.99 per staff member with no subscription.




