Skip to content

Guide

Data protection guide for care providers

Care providers handle health data about people using the service and employment data about staff. This guide summarises the main UK GDPR and Data Protection Act 2018 duties. It is general guidance, not legal advice.

Know your lawful bases

Personal data needs a lawful basis under Article 6, and health data needs an additional condition under Article 9 — usually the provision of health or social care, or a substantial public interest condition such as safeguarding. Consent is rarely the right basis for care records.

Records of processing and DPIAs

Maintain a record of processing activities covering what you hold, why, who it is shared with and how long it is kept. Complete a data protection impact assessment before introducing new systems or high-risk processing.

Retention that is actually applied

Set retention periods for care records, staff files, CCTV, rotas and correspondence, and apply them. Keeping everything indefinitely is a breach of the storage limitation principle and increases the impact of any incident.

Individual rights and deadlines

Respond to subject access, rectification, erasure, restriction, objection and portability requests within one month, extendable by two months for complex requests. Keep a register of requests, dates and outcomes.

Breach response

Report a notifiable personal data breach to the ICO within 72 hours of becoming aware, and inform affected individuals where there is a high risk to them. Log every incident, including those you decide not to report, with your reasoning.

Sharing and processors

Share with local authorities, the NHS, safeguarding boards and CQC on a lawful basis and record it. Where a supplier processes data for you, put a written processor agreement in place and check their security arrangements.

See it with your own service

Book a free demonstration and we will walk through the platform using scenarios from a service like yours.