Policy collection

Data Protection Policies for CQC Registered Care Services

Data protection policies tell an inspector, a commissioner and your own staff exactly how your service handles personal information, and ours are written for your setting rather than a generic one. This collection brings together the data protection policies a regulated service in England is expected to hold, from confidentiality and records management through to subject access requests and breach reporting. Every document names your registered company, your trading name, your Care Quality Commission provider and location identifiers, your registered manager and the person accountable for information governance, so nothing arrives with a blank waiting to be filled in. We write against the UK General Data Protection Regulation, the Data Protection Act 2018 and Regulation 17 of the Health and Social Care Act 2008 (Regulated Activities) Regulations 2014, so a person reads the document before it reaches you. You can buy one policy for £39 to £79, a themed pack from £295, or the twenty statutory documents for £495. One-time purchase, no subscription, and your policy arrives within two working days, print-ready on your own letterhead with a sign-off block. 

6 in this collectionWritten for your service, not a templateChecked against the law before it carries your name
Data Protection and GDPR Policy

Lawful handling of personal and special category data under UK GDPR and the Data Protection Act 2018.

£693 regulations
Confidentiality Policy

Keeping personal information confidential, and when sharing is right.

£594 regulations
Caldicott and Information Sharing Policy

The Caldicott principles applied to your service, and who decides when data is shared.

£594 regulations
Records Management Policy

Creating, storing, retaining and destroying records, aligned to the Records Management Code.

£593 regulations
Information Governance Policy

The framework over your data policies: accountability, training, breaches and DSPT alignment.

£595 regulations
CQC Notifications Policy

Which events must be notified to CQC, by whom, and how fast.

£592 regulations

Documents that name your service, your people and the law that applies to you

A policy only does its job when it describes what actually happens in your service. An inspector reading your information governance arrangements is looking for four things: that the document names the service and the legal entity behind it, that it identifies the people accountable by role and by name, that it reflects current law rather than the law as it stood in 2018, and that staff can show they understood it and followed it. Data protection policies written for somebody else fail on all four counts, however long they run. Everything in this collection is written around your setting, your systems and the people you support, so the document in the folder matches the practice on the floor. 

What a data protection policy for a care service has to contain

A data protection policy sets out how your service collects, records, stores, shares and destroys personal information about the people you support, their families, your staff and your visitors. It should identify the data controller by registered company name, state your Information Commissioner's Office registration reference, and name the person who leads on information governance. It should explain your lawful bases under Article 6 of the UK General Data Protection Regulation and your condition for processing special category data under Article 9, because health and care information about the people you support is special category data in almost every case. It should cover your record of processing activities, how you carry out a data protection impact assessment before you introduce a new care planning system or install cameras, how staff report a suspected breach and how quickly, how you handle a subject access request from a resident or a relative, and how long you keep records before you destroy them. It should also say what staff may not do, which in practice means personal phones, photographs, group chats and handover notes taken home in a pocket.

Which care settings have to hold these documents, and why

Every provider registered with the Care Quality Commission processes personal data, so every provider is a data controller under the Data Protection Act 2018 and the UK General Data Protection Regulation. That includes residential care homes, nursing homes, domiciliary care agencies, supported living services, extra care and live-in care providers, hospices, shared lives schemes, substance misuse services, independent hospitals, GP practices and dental practices. Regulation 17 of the Health and Social Care Act 2008 (Regulated Activities) Regulations 2014, the good governance regulation, requires you to maintain accurate, complete and contemporaneous records for each person using the service and to keep them securely. Under the Single Assessment Framework, evidence about how you handle information sits within the quality statements on governance, management and sustainability, and on treating people as individuals. A domiciliary care agency carries the same duties as a care home and a few extra ones, because records travel in cars, notes are written in people's own homes and staff work alone on their own devices.

Who these policies are perfect for

These documents are made for the registered manager, owner or nominated individual of a small CQC registered service who has been asked for something specific and does not have a compliance department to ask. They suit a new registration application where the provider needs to show the arrangements are in place before the interview. They suit a service that has just had an inspection, or has one booked, and knows the information governance file has not been opened since the previous manager left. They suit a provider bidding for a local authority or integrated care board contract where the tender asks for a named policy with a review date and a sign-off. They suit a manager who has just had a breach, a lost handover sheet or a photograph posted to a family group, and wants the written procedure in place before anyone asks how it was handled. And they suit anyone who has downloaded a free template, opened it, and found it still says insert name of organisation here on page one.

Compare what you get, check the price and order today

Every policy in this collection is written by CareStream for the service named on the front page. A single policy costs £39 to £79 depending on length and complexity. A themed pack, which bundles the data protection and confidentiality policy with records management, breach reporting, subject access and information security, starts at £295. The twenty statutory documents every registered provider is expected to hold cost £495. It is a one-time purchase with no subscription, no contract and no minimum term, so there is nothing to cancel later. The price is on the page, so there is no quote needed and nobody to talk to before you get started. Secure checkout takes a couple of minutes; we ask for the details we merge into the document, and the finished policy is available within two working days as a print-ready file with your letterhead, a version number, a review date and a sign-off block for the responsible person.

Why our data protection policies stand up to being read closely

Anyone can send you a file. The value sits in what happens between your order and your download, and in whether the document survives being read by someone looking for a reason to mark you down.

Why our policies are better than a free template or a generic pack

A free template is written for nobody, which means it is written for no regulation, no setting and no named person. It will tell you to report breaches to the data protection officer without saying whether you need one. It will reference the Data Protection Act 1998 or the European General Data Protection Regulation in a footnote nobody updated after 2021. A nine hundred pound policy pack has the opposite problem: it arrives complete, contradicts itself in three places, and nobody in the building has read it. A CareStream policy is personalised before it is sent. Your registered company name, trading name and address, your provider and location identifiers, your registered manager, your nominated individual and the named information governance lead are merged into the text rather than left as blanks. Every document is checked against the regulations that apply to your setting, and every one is hand-checked and human-reviewed by a person who knows the sector before it reaches your inbox.

How each policy is written, checked and delivered

You tell us the service, the setting and the roles, and we write the document around them. We work from the current UK General Data Protection Regulation, the Data Protection Act 2018, including the Schedule 1 conditions that cover criminal offence data from your recruitment checks, the Records Management Code of Practice for Health and Social Care, the Caldicott principles and the guidance published by the Information Commissioner's Office. Where a document has to identify someone accountable, we name them. Where it has to set a retention period, we set one rather than saying as appropriate. A person reads every policy before it is sent, which is why we quote two working days rather than pretending a document like this appears the moment you pay. You receive a print-ready file that prints on your own letterhead, with version control, an issue date, a review date and a sign-off block. Policies are updated when the law changes.

How these documents connect to your wider policy set and training

Data protection rarely arrives on its own. Services that buy a confidentiality policy usually need records management, breach reporting and information security alongside it, which is why they sit together in one pack. Safeguarding and information sharing overlap constantly, because the seven golden rules for information sharing are the bridge between the two, so those policies are written to agree with each other rather than contradict each other. If you are building a full folder rather than filling one gap, start with the complete range of care policies and procedures we write for regulated services. A policy only counts as evidence if staff have understood it, so most services pair the written document with GDPR and data protection training for care staff. And if you already hold a folder and cannot tell what is missing, you can have your existing policy set checked for gaps against current regulation before you buy anything at all. A single policy bought here is the same document, written the same way, as the ones held by services using the wider CareStream platform to manage version control, approvals and staff questions.

What happens after you buy

Nothing renews by itself, because there is no subscription to renew. You own the document. When the law changes in a way that affects what your policy says, we update the wording and tell you what changed, so the version in your folder does not quietly date. Most services review their information governance documents annually, or sooner if they change care planning systems, install cameras, take on a new contract or change the person who leads on information governance, and the review date printed on the document is there to prompt exactly that. If something in your policy does not match how your service actually works, tell us, and we will rewrite it. Our return policy for personalised documents is set out in full at checkout, and it is written in plain English rather than in a way designed to be unreadable.

Data Protection Policies for CQC Registered Care Services FAQs

What are data protection policies in a care service?

They are the written documents that set out how your service handles personal information about the people you support, their families and your staff. In practice, that means how information is recorded, where it is stored, who can see it, how it is shared with a GP, a local authority or an integrated care board, how long it is kept and how it is destroyed. They also explain what staff must do when something goes wrong. They exist because the UK General Data Protection Regulation and the Data Protection Act 2018 require a controller to demonstrate how it meets its duties, and because Regulation 17 of the Health and Social Care Act 2008 (Regulated Activities) Regulations 2014 requires you to keep accurate records securely.

What are the three main data protection policies a service should hold?

If you only hold three, hold these. First, a data protection and confidentiality policy, which sets out your lawful bases, your accountability arrangements and the rules staff follow every day. Second, a records management and retention policy, which sets out what you keep, where, for how long and how you destroy it. Third, a data breach and incident reporting procedure, which tells staff how to recognise a breach, who to tell and how fast. Most services add a subject access request procedure and an information security or acceptable use policy quite quickly, because those are the two an inspector or a commissioner asks about next.

What are the seven principles of the UK GDPR?

Lawfulness, fairness and transparency. Purpose limitation, meaning you only use information for the purpose you collected it for. Data minimisation, meaning you collect what you need and no more. Accuracy, meaning records are correct and kept up to date. Storage limitation, meaning you do not keep information longer than you need it. Integrity and confidentiality, meaning it is held securely. Accountability, meaning you can show how you meet the other six. That last one is the reason a written policy matters. A service that does everything correctly but cannot evidence it still has a problem when someone asks.

What rights do people have over their information?

Under the UK General Data Protection Regulation, there are eight: the right to be informed, the right of access, the right to rectification, the right to erasure, the right to restrict processing, the right to data portability, the right to object, and rights relating to automated decision-making and profiling. Not all of them apply equally in a care setting. The right to erasure, for example, is limited where you have a legal obligation to keep the record. The two you will meet most often are the right to be informed, which is why you need a privacy notice for residents and one for staff, and the right of access, which is the formal name for a subject access request.

What counts as personal data, and is an email address personal data?

Personal data is any information that identifies a living person or could identify them when combined with other information you hold. Five everyday examples in a care service: a person's name and room number, a care plan, a medication administration record, a staff rota with initials that can be matched to individuals, and a photograph. Yes, an email address is personal data where it identifies someone, and a work address in the format firstname.surname@provider.co.uk almost always does. Health information and information about someone's care needs are special category data, which carries a higher bar and is why your policy has to name an Article 9 condition as well as an Article 6 lawful basis.

Policies are one part of it.

CareStream is the compliance system underneath: your policies, your staff training, your audits and your evidence, kept current and ready for the day somebody asks to see them.

  • Policies written and kept updated for you
  • Staff training that records itself against the standard
  • Gap analysis showing what you are missing before an inspector does
  • Everything in one place, for one price

Accreditations and compliance

  • Good Business Charter accredited
  • CPD Certification Service accredited provider
  • Registered with the Information Commissioner's Office
  • Disability Confident Committed
  • GDPR compliant

CPD Provider No. 50224 · ICO registration ZC221613