Information Governance and UK GDPR
Information governance is the practical framework used to ensure that information is collected, recorded, accessed, used, shared, stored and disposed of safely, accurately and appropriately.
The UK General Data Protection Regulation and Data Protection Act 2018 regulate how organisations use personal information. In care homes, this includes residents’ care records, health information, medication records, photographs, contact details, assessments, incident reports and conversations about care.
Health information is classed as special category personal data and requires additional protection. ICO: Special category data
For an HCA, information governance means:
Accessing information only for legitimate work purposes
Recording care accurately and promptly
Protecting confidential information
Sharing relevant information with authorised people
Using workplace systems and devices safely
Reporting errors, losses and suspected breaches immediately
Aim of the course
The course aims to give healthcare assistants and similar frontline care workers the practical knowledge needed to handle residents’ information safely, lawfully and respectfully during everyday work.
It helps learners understand that confidentiality does not mean never sharing information. Relevant information must sometimes be shared with authorised colleagues to provide safe care or protect someone from harm. The key is to share the right information, with the right person, for the right purpose and through an approved method.
Scope of the course
This course is suitable for:
- Healthcare assistants
- Care assistants
- Support workers
- Senior care assistants
- Nursing assistants
- Activity coordinators
- Agency and temporary care staff
- New employees and existing staff requiring refresher training
The course focuses on frontline activities such as:
- Reading and updating care records
- Completing daily notes and charts
- Participating in handovers
- Communicating with colleagues and relatives
- Using electronic care-record systems
- Handling paper documents
- Using work email, telephones and mobile devices
- Responding to information requests
- Recognising and reporting information-security incidents
The course supports awareness of:
- UK General Data Protection Regulation
- Data Protection Act 2018
- Common law duty of confidentiality
- Human Rights Act 1998, particularly Article 8
- Health and Social Care Act 2008 (Regulated Activities) Regulations 2014, particularly Regulations 10 and 17
- Caldicott Principles
- Relevant CQC expectations
- Local confidentiality, record-keeping, information-security and social-media policies
UK data protection legislation is formed principally by the UK GDPR and Data Protection Act 2018. GOV.UK: Data protection legislation
Limits of the course
This is a frontline awareness course. It does not train HCAs to:
- Select or approve an organisation’s lawful bases
- Write privacy notices
- Complete Data Protection Impact Assessments
- Negotiate data-processing contracts
- Set organisational retention schedules
- Manage subject access requests
- Investigate serious data breaches
- Make disclosures to the Information Commissioner’s Office
- Perform the duties of a Data Protection Officer or Caldicott Guardian
An HCA’s responsibility is to recognise issues, protect information and report requests or incidents promptly to the appropriate manager or information-governance lead.
Topics covered
- Meaning of information governance
- Purpose of the UK GDPR and Data Protection Act 2018
- Personal, confidential and special category information
- Examples of information used in care homes
- The seven data-protection principles
- Confidentiality and the Caldicott Principles
- Accessing records only for legitimate work purposes
- Keeping usernames, passwords and access cards secure
- Avoiding shared accounts and inappropriate record access
- Accurate, factual and timely care records
- Correcting recording errors appropriately
- Maintaining respectful and professional language
- Secure handovers and confidential conversations
- Sharing information for direct care
- Sharing only relevant and necessary information
- Verifying identity and authority before disclosure
- Communicating with relatives, friends and representatives
- Consent, mental capacity and information sharing
- Safeguarding and public-interest disclosures
- Secure use of electronic care systems
- Screen security and locking unattended devices
- Safe handling and storage of paper records
- Approved email, telephone and messaging methods
- Personal phones, photography, video and audio recording
- Social media and professional boundaries
- Working from home or away from the care home
- Printing, transporting and disposing of information
- Misdirected emails and messages
- Lost paperwork, devices and access cards
- Recognising phishing and suspicious requests
- Recognising personal data breaches
- Immediate reporting and preservation of evidence
- Responding appropriately to requests for copies or corrections
- Residents’ information rights and appropriate escalation
Learning outcomes
By the end of the course, learners should be able to:
- Define information governance and explain its relevance to care-home work.
- Identify personal data, confidential information and special category data.
- Give examples of information that HCAs handle during everyday care.
- Outline the seven UK GDPR data-protection principles.
- Explain why resident information must be accurate, relevant and secure.
- Access records only when required for their authorised duties.
- Keep usernames, passwords, access cards and devices secure.
- Produce clear, factual, respectful and timely care records.
- Correct documentation errors using approved workplace procedures.
- Maintain confidentiality during handovers and conversations.
- Explain why confidentiality does not prevent necessary information sharing for safe care.
- Share only information that is relevant and necessary.
- Verify a person’s identity and authority before disclosing information.
- Respond appropriately when relatives request information.
- Recognise when safeguarding concerns may require information to be shared.
- Use workplace email, telephones and electronic records safely.
- Explain why personal devices and social media must not be used to record or share resident information without proper authorisation.
- Protect screens, paperwork and records from unauthorised viewing.
- Recognise phishing, impersonation and suspicious information requests.
- Identify common personal data breaches in a care-home environment.
- Take immediate action following lost records, misdirected messages or unauthorised disclosure.
- Report suspected breaches through the correct workplace procedure.
- Recognise a resident’s information-rights request and pass it promptly to the responsible person.
- Work within the limits of the HCA role and seek advice when uncertain.
NHS England’s adult social care guidance makes clear that sharing relevant information for individual care is as important as protecting confidentiality; information should be necessary, relevant and transferred securely. NHS England: Information sharing in social care