Audit template
Information Governance / GDPR
Checks data protection practice, records security, retention and subject rights handling. This template runs annual in MyCareCompliance and carries 8 mapped checks across 4 CQC quality statements.
Last reviewed: September 2026. This guidance reflects CQC information available at the date above — always refer to cqc.org.uk for current regulatory requirements.
What the audit covers
Every question in the Information Governance / GDPR is mapped to a CQC quality statement and the underlying regulation, so a failed check tells you exactly which part of the single assessment framework is at risk. This is an optional template you can switch on when it applies to your service.
- Runs annual — optional template
- Part of the Safety & governance audit category
- Maps to 3 regulations: Regulation 17 — Good governance, Regulation 18 — Staffing, Regulation 9 — Person-centred care
- Failed checks become tracked improvement actions with an owner, due date and evidence
The 8 checks
Learning culture
Safe — 1 check- Regulation 17 — Good governanceInformation Governance / GDPR
Is there a robust system for logging, investigating, and reporting data breaches and near misses?
What we look for: Review the breach log. Good looks like all minor incidents (e.g., email sent to wrong person) are logged, investigated, and learning is shared. Fail: no log exists or failure to notify the ICO when required.
Evidence: Data breach log, incident reports, ICO notification records, post-incident reviews
Safe and effective staffing
Safe — 1 check- Regulation 18 — StaffingInformation Governance / GDPR
Do all staff receive comprehensive training on data protection, confidentiality, and GDPR upon induction and annually?
What we look for: Sample the training matrix for 5-10 staff. Good looks like 100% compliance with annual IG/GDPR refreshers, plus checks during supervision. Fail: staff handling sensitive data without valid training.
Evidence: Training matrix, GDPR training certificates, induction checklists, spot check records
Providing information
Responsive — 1 check- Regulation 9 — Person-centred careInformation Governance / GDPR
Are people who use the service provided with accessible privacy notices explaining how their data is used?
What we look for: Review the welcome pack. Good looks like clear, easy-to-read privacy notices explaining data sharing (e.g., with GPs/LAs) and individuals' rights. Fail: no privacy notice or heavily jargon-filled text.
Evidence: Service user guide, Privacy Notice, Consent forms, introductory packs
Governance, management and sustainability
Well-led — 5 checks- Regulation 17 — Good governanceInformation Governance / GDPR
Are comprehensive Information Governance and GDPR policies in place and reviewed annually?
What we look for: Review the core IG policies. Good looks like policies that are tailored to domiciliary care, up-to-date with current legislation, and accessible to staff. Fail: generic, out-of-date policies.
Evidence: Data Protection Policy, GDPR Policy, Subject Access Request Procedure, Information Sharing Policy
- Regulation 17 — Good governanceInformation Governance / GDPR
Has the provider successfully completed and published an annual Data Security and Protection Toolkit (DSPT)?
What we look for: Check the DSPT status online or ask for the certificate. Good looks like 'Standards Met' or higher within the last 12 months. Fail: unpublished DSPT or missing action plans for unmet standards.
Evidence: DSPT publication certificate, DSPT action plan, DSPT submission confirmation
- Regulation 17 — Good governanceInformation Governance / GDPR
Are physical records (e.g., paper care plans, staff files) stored securely to prevent unauthorized access?
What we look for: Walk around the office. Good looks like locked cabinets for staff/client files and a clear desk policy. Ensure care plans left in clients' homes are kept respectfully. Fail: loose files left out.
Evidence: Office security walkaround, locked filing cabinets, clear desk policy, archived record storage
- Regulation 17 — Good governanceInformation Governance / GDPR
Are digital care records, mobile devices, and systems protected by robust access controls and passwords?
What we look for: Check how digital systems are accessed. Good looks like unique logins (no sharing), complex passwords, and remote wipe capabilities for staff phones. Fail: shared generic logins or unlocked PCs.
Evidence: IT security policy, mobile device management (MDM) software evidence, password policy, staff leaver checklist
- Regulation 17 — Good governanceInformation Governance / GDPR
Are records retained for appropriate legal timeframes and destroyed securely when no longer needed?
What we look for: Review the retention schedule and disposal methods. Good looks like clear timelines (e.g., care records kept for 3 years post-discharge) and use of cross-cut shredders or secure waste contractors. Fail: hoarding old files indefinitely.
Evidence: Data Retention Schedule, confidential waste bins, certificates of secure destruction
See it running for your service
Book a free demonstration and we will run the Information Governance / GDPR against scenarios from a service like yours, or start your 7-day trial and try it yourself.
See it with your own service
Book a free demonstration and we will walk through the platform using scenarios from a service like yours.
