Information Governance Policy£59 one-off·Delivered within 2 working days
Care Policies/Information Governance Policy
Personalised · Human-reviewed · Kept updated

A Information Governance Policy written for your service

  • Written for your organisation, not a template with your logo on it
  • Read and approved by a person before it carries your name
  • Verified against all 64 required elements of the legislation below
  • Kept updated when the law changes, so it never quietly goes stale
£59one-off, for your policy

No subscription needed. First year of updates included, £12 a year after that.

One-off, first year of updates included. Delivered within 2 working days of your details.

Build it now: 7 questions, three minutes

Trusted by UK care providers

Information Governance Policy

Let's build your Information Governance Policy

Answer 7 quick questions, about three minutes, and we'll write this policy for your service, in your name, with your people. You can skip anything and add it later.

Asked once, reused for every policy you buy

Built from the law, checked against the law

The legislation, CQC standards and guidance we analyse to write it.

Your Information Governance Policy is structured from these regulations, then verified against every required element of each one before a person signs it off. If the law changes, your policy is updated and you are told what changed and why.

01

Data Protection Act 2018

  • Policy document identifying the specific lawful basis (legal condition) used for processing different categories of personal data, including health and social care condition for care records, employment condition for DBS checks and payroll, and substantial public interest condition for safeguarding referrals
  • Appropriate policy document(s) required under Schedule 1 Part 2 for each substantial public interest condition relied upon (as required by Article 9(2)(g) and which the ICO may request to inspect)
  • Privacy notice written in plain language that residents can read and in an accessible format, explaining how personal data is used
  • Procedure for responding to subject access requests within one calendar month from receipt, free of charge, including process for redacting third-party information (residents, relatives, staff) that appears on shared pages in care records
  • Staff training and written warning that accessing resident files without legitimate work purpose, photographing care plans, or similar unauthorised processing constitutes a personal criminal offence under section 170 of the Act
  • Data breach notification procedure requiring reporting to the ICO within 72 hours of the organisation becoming aware (not when manager is informed) of breaches such as lost handover sheets, misdirected emails, stolen devices, or ransomware incidents
12 required elements verified in your policy
Data Protection Act 2018
02

Information governance (umbrella framework for lawful, secure and confidential information handling)

  • A data protection complaints procedure specifying acknowledgment within 30 days and response timescales without undue delay
  • An appropriate policy document for processing under health and social care conditions and substantial public interest conditions (as required when not relying on consent)
  • Privacy notices provided in formats accessible to residents in accordance with the Accessible Information Standard
  • Access controls ensuring staff can only view information for residents they are directly caring for (role-based access restrictions)
  • Procedures prohibiting removal of handover sheets and care documentation from the building and ensuring confidential information is not visible to visitors
  • A requirement that lawful basis for processing does not override common law duty of confidence, with public interest justifications recorded at the time for disclosures including safeguarding referrals
13 required elements verified in your policy
Information governance (umbrella framework for lawful, secure and confidential information handling)
03

Records Management Code of Practice for Health and Social Care 2021

  • Specifies retention periods for each type of record held by the home, including care records, staff records, occupational health records, controlled drugs registers, complaints records (including Freedom to Speak Up cases with minimum ten-year retention), safeguarding records, and incident reports, referencing the retention schedule in Appendix II of the Code
  • Requires that all staff complete records management training before being permitted to handle or access resident records
  • Establishes procedures for maintaining a destruction log that records what was destroyed, the date of destruction, who performed the destruction, and under what authority the destruction was carried out
  • Defines and implements a legal hold procedure that immediately stops routine destruction of records when an inquest, police investigation, safeguarding enquiry, claim, public inquiry or similar formal process is in prospect or underway
  • Specifies that any member of staff is authorised to trigger a legal hold and that such holds cannot be overridden without proper authority
  • Addresses records management procedures for system migrations, including verification that historical records remain readable, complete and accessible after migration to new care planning or record-keeping systems
11 required elements verified in your policy
Records Management Code of Practice for Health and Social Care 2021
04

The Caldicott Principles

  • States that personal information may only be used or shared where there is a clear, justified and lawful purpose
  • Requires that information is only accessed or shared when absolutely necessary and proportionate to the purpose
  • Requires use of the minimum amount of personal information necessary for the stated purpose
  • Restricts access to confidential information on a strict need-to-know basis according to staff role and responsibilities
  • Establishes accountability mechanisms for how personal information is handled and by whom
  • Requires all staff to be trained to understand their confidentiality responsibilities and how to apply the Caldicott Principles
15 required elements verified in your policy
The Caldicott Principles
05

UK General Data Protection Regulation (UK GDPR)

  • Identifies lawful basis for processing under Article 6 (legitimate interests or public task) and Article 9(2)(h) condition (health and social care provision) for resident personal and health data
  • Includes or references an appropriate policy document as required by Schedule 1 of the Data Protection Act 2018 for processing special category data
  • Specifies that information sharing for direct care, safeguarding, or vital interests is permitted and lawful, and that GDPR does not prevent such sharing
  • Defines unauthorised access to records (including looking up records without legitimate reason) as a criminal offence under section 170 of the Data Protection Act 2018
  • States that falsifying, altering or retrospectively amending care records is a criminal offence under section 173 of the Data Protection Act 2018
  • Establishes 72-hour breach notification timeline from awareness of breach and designate who can initiate breach reporting outside normal office hours when registered manager is unavailable
13 required elements verified in your policy
UK General Data Protection Regulation (UK GDPR)

Written for your service

What we ask you, so none of it is assumed.

Most policy packs are one document sold to everyone with a find and replace on the home name. Your Information Governance Policy is written from the legislation above and from your answers to the questions below. Where you have told us something, it says so. Where you have not, it sets out what must happen rather than claiming you already do it.

Before you pay7 quick questions

Your registered name, address, CQC numbers and who holds the key roles. About three minutes. Nothing else is asked before you buy.

After you buy9 about your service

Asked once in your own account and used across every policy you own, so a second policy never asks you the same thing twice.

Who is your data protection lead or DPO?A name, or "none appointed". Not every care service needs a formal DPO.
Do you use an electronic care planning system?If not, your policies will describe paper records instead.
How long do you keep care records after a resident leaves or dies?
Who is your Caldicott Guardian?A name, or "none appointed".
How is staff training delivered and recorded?For example an e-learning provider, in-house sessions, or a training matrix.
What is your ICO registration number?
Do staff use WhatsApp or similar messaging apps for anything about residents?An honest yes matters: those messages are health records in law.
What monitoring equipment is in use?CCTV in communal areas, acoustic monitoring, bedroom sensors, door sensors, body-worn cameras, or none.
What is your electronic care system called?Leave blank if you work on paper.

Why it matters. A policy that claims you assess your premises annually, when you never have, is not a harmless overstatement. It is a signed statement handed to your inspector. We would rather write what you must do than guess what you already do.

How it is made

From your details to a policy you can stand behind.

01You give us the details

The short questions above: who you are, your CQC registration, and the people this policy names.

02We write it from the law

One section per required element of the legislation, in your name, with your people.

03It is verified, then read

Automated checks against every required element, then a person reads it before it ships.

04It stays current

When legislation changes, your policy is updated and you are told what changed and why.

Common questions

What you are actually buying.

What exactly do I receive?

A complete Information Governance Policy written for your organisation, in your dashboard and as a print-ready PDF on your own letterhead. It names your service, your registration details and your leads, because you gave us them.

Is this a template?

No. Each policy is written for the organisation buying it, structured from the legislation itself, verified against 64 required regulatory elements, and read by a person before it carries your name.

How quickly will I get it?

Within 2 working days of you completing the short questions above. Most arrive sooner.

What happens when the law changes?

We monitor UK care legislation continuously. When something affecting this policy changes, your copy is updated and you are told what changed and why. The first year of updates is included, then £12 a year per policy.

Can I edit the policy myself?

No, and deliberately so: we stand behind every word we approve. If something needs changing, tell us and we amend and re-verify it, so it always remains a document we can both defend to an inspector.

What if I need more than one policy?

Most services do. The Statutory Starter Pack covers the twenty policies every CQC-registered service is expected to hold, and the Complete Policy Library covers all 66.

Why CareStream

Policies written the way an inspector expects to read them.

66 care policies, one platform
Written for your service, never a template
Verified against every required element of the law
Read by a person before it carries your name
Kept up to date with UK care regulations
Branded, print-ready PDF on your letterhead
Delivered within 2 working days of your details
Part of the full CareStream platform when you are ready

Before you buy

What the document actually looks like.

Every section it contains, and a page of the real thing. We show the structure and the personalisation rather than the wording, because the wording is what you are paying us to write for your service.

Contents of your Information Governance Policy

  1. Purpose and scopewho it covers
  2. Legal and regulatory frameworkcited in full
  3. Definitions used in this policy
  4. Roles and responsibilitiesyour people, named
  5. Procedure, step by step
  6. Recording, reporting and escalation
  7. Training and competency
  8. Monitoring, audit and review
  9. Related policies and documents
  10. Version control and approvalsigned and dated
Your service name hereApproved · Version 1.0

Section 4 · Roles and responsibilities

Who is accountable, by name

Overall accountability for this policy rests with your registered manager, supported by your nominated individual. Day to day responsibility sits with your named lead, who is the first point of contact for staff at your service address.

The remaining wording is written for the organisation buying it, so it is not shown here.

Fourteen day refundIf it is not right for your service, tell us within fourteen days and we refund it in full.
£12 a year after the firstYear one of updates is included. After that it is £12 a year to keep the policy current, and you can stop at any time.
A person reads itEvery policy is read and approved by a human before it carries your name. No exceptions.

“The inspector asked for evidence and I had it on screen before she finished the sentence.”

Registered Manager · 48-bed nursing home, West Sussex

Related policies

More policies your service may need.

More statutory and operational policies CareStream writes for your service, personalised, human-reviewed and kept updated, exactly like this one.

Data Protection and GDPR Policy

Data Protection and GDPR Policy

Lawful handling of personal and special category data under UK GDPR and the Data Protection Act 2018.

£69
See this policy in full →
Duty of Candour Policy

Duty of Candour Policy

Being open and honest when things go wrong, under Regulation 20.

£69
See this policy in full →
Clinical Governance Policy

Clinical Governance Policy

How clinical quality is led, measured, audited and improved.

£69
See this policy in full →
Statement of Purpose

Statement of Purpose

Your registered Statement of Purpose under the 2009 Registration Regulations, ready to file with CQC.

£69
See this policy in full →
Confidentiality Policy

Confidentiality Policy

Keeping personal information confidential, and when sharing is right.

£59
See this policy in full →
Business Continuity Policy

Business Continuity Policy

Keeping people safe through outages, staffing crises and emergencies, with your escalation contacts.

£59
See this policy in full →

Compared

The four ways care services get a policy.

We have compared what each approach does rather than naming competitors, because products change and the comparison should still be true next year.

CareStreamA policy packA consultantA free template
Questions asked at the point of purchase, so it is personalised rather than blank
Written for your service, naming your manager and your leads
Structured from the regulations, every required element checked before it is sent
A branded companion document setting out the law it was written against
Read and approved by a person before it carries your name
Prints on your own letterhead with a sign-off and version block
Named role holders update everywhere when the person changes
Kept current when the law changes, and you are told what changed
Turnaround stated before you buy
Your staff can ask it questions in their own language
What it costs£39 to £79 per policy, one-off£250 to £995 for the packA day rate, typically £400 upwardsNothing

Prices are the published rates of the common alternatives as at September 2026, for comparison only.

Training

Owning the policy is half of it

An inspector asks whether your staff understood it, not whether you hold it. Ninety eight modules written and kept current by us, to the same regulations, from £25.99 per staff member with no subscription.

Browse the training

Accreditations and compliance

  • Good Business Charter accredited
  • CPD Certification Service accredited provider
  • Registered with the Information Commissioner's Office
  • Disability Confident Committed
  • GDPR compliant

CPD Provider No. 50224 · ICO registration ZC221613