Most care home managers meet data protection twice: once during induction, when somebody says the words GDPR and confidentiality in the same sentence, and once in a panic, when a daughter asks for everything you hold about her mother or a care plan folder goes missing in a taxi. Neither moment is a good time to learn it.
This guide sets out what UK GDPR and the Data Protection Act 2018 actually require of a care home or supported living service in the UK, in the order the questions come up in real life. It covers the lawful basis for keeping care records (which is not consent, and getting that wrong causes a lot of trouble), special category data, how long to keep what, subject access requests, photographs and body maps, staff files, and what to do in the first hour after a breach.
The short answer
UK GDPR sits alongside the Data Protection Act 2018. Together they say you must have a lawful reason to hold information about people, keep it accurate, keep it secure, keep only what you need for as long as you need it, and let people see what you hold about them. For care records your lawful basis is legal obligation or public task under Article 6, with the health and social care condition under Article 9, plus vital interests in an emergency. It is not consent. You must answer a subject access request within one month. You must report a personal data breach to the Information Commissioner's Office within 72 hours if it is likely to cause a risk to the person, and tell the person themselves if that risk is high. Everything else in this guide is detail on those points.
GDPR meaning in care: what the words actually mean
GDPR stands for General Data Protection Regulation. Since 2021 the version that applies here is UK GDPR, which is the retained version of the EU regulation, amended for the UK. The Data Protection Act 2018 is the Act of Parliament that fills in the gaps UK GDPR leaves to member states, including most of the conditions that let health and social care organisations process sensitive information at all.
In care, GDPR meaning is usually simpler than people fear. It does not stop you sharing information to keep someone safe. It does not require a signed consent form before you can write a care plan. It does require you to know why you hold what you hold, to keep it locked up properly, and to be honest with people about it.
Who is the controller, and who is the processor
Your service is the data controller for the people you support and for your own staff. That means you decide what is collected and why, and you carry the legal responsibility. Your care records software supplier, your payroll bureau and your occupational health provider are usually data processors: they handle the data on your instructions.
This matters for two reasons. First, you cannot outsource responsibility. If a supplier loses your data, you are still the controller answering to the ICO and to families. Second, UK GDPR requires a written contract with every processor covering security, sub-processors, breach notification and what happens to the data when the contract ends. If you use cloud software and have never seen a data processing agreement from that supplier, ask for one. Our security page sets out the sort of detail you should expect to be given.
What counts as personal data in a care home
Personal data is any information that identifies a living person or could identify them when combined with other information you hold. In a care home that is far more than the care plan. It includes the daily notes, the MAR chart, body maps, incident forms, the fluid chart, the call bell log, the visitors book, the resident's bank details for personal allowance, the photograph on the bedroom door, the whiteboard in the office, the WhatsApp message a worker sent about a resident, and the handover sheet in somebody's back pocket at the end of a shift.
It also includes information about staff: application forms, DBS certificates, references, supervision notes, sickness records, disciplinary papers and rota data.
Special category data, which care records mostly are
UK GDPR gives extra protection to special category data: health, race or ethnic origin, religious or philosophical beliefs, sex life and sexual orientation, genetic and biometric data, trade union membership and political opinions. Criminal offence data is handled separately but with similar care.
Almost everything in a care record is special category data. A diagnosis, a body map, a mental health history, a note that someone attends mosque on Fridays, a note that someone's partner is the same sex, a medication record: all of it. That is why the security expectations for care records are closer to those for a GP surgery than to those for a shop's mailing list, and why a folder left on a passenger seat is a serious matter rather than an embarrassing one.
Lawful basis for care records: why it is not consent
This is the single most common mistake in adult social care. Services ask people to sign a consent form for their care records, then discover they have created a problem. Consent under UK GDPR must be freely given, specific, informed and unambiguous, and it must be as easy to withdraw as it was to give. If your basis for holding a care plan is consent, then when a resident withdraws consent you would have to stop holding the plan. You cannot, because you are legally required to keep it.
The correct answer is that you do not need consent for care records, because you have stronger and more honest bases available.
The lawful bases that actually apply
| What you are doing | Article 6 basis | Article 9 or DPA 2018 condition | Notes |
|---|---|---|---|
| Keeping care plans, risk assessments, daily notes, MAR charts | Legal obligation, Article 6(1)(c) | Health or social care purposes, Article 9(2)(h) with DPA 2018 Schedule 1 Part 1 paragraph 2 | Required by the Health and Social Care Act 2008 regulations and the Care Act 2014 |
| Delivering care commissioned by a local authority or the NHS | Public task, Article 6(1)(e) | Article 9(2)(h) | Common for local authority and CCG or ICB funded placements |
| Emergency treatment when the person cannot consent | Vital interests, Article 6(1)(d) | Vital interests, Article 9(2)(c) | Use for genuine emergencies, not as a routine basis |
| Fees and invoicing for a self-funding resident | Contract, Article 6(1)(b) | Not usually special category | Financial data still needs proper security |
| Safeguarding referrals and information sharing | Legal obligation or public task | Safeguarding condition, DPA 2018 Schedule 1 Part 2 paragraph 18 | You do not need the person's consent to make a safeguarding referral |
| Employing staff, DBS, payroll, sickness | Legal obligation or contract | Employment and social security, Article 9(2)(b); criminal records under DPA 2018 Schedule 1 | Separate retention rules apply |
| Photographs for marketing, newsletters or the website | Consent, Article 6(1)(a) | Consent, Article 9(2)(a) where health is revealed | This is one of the few places consent is right |
| CCTV in communal areas | Legitimate interests, Article 6(1)(f) | Depends on purpose; needs a documented assessment | Requires a data protection impact assessment |
Where consent still belongs
Consent is the right basis for things the person can genuinely say no to without affecting their care: a photograph on the website, a newsletter, a birthday mention on social media, an open day film, participation in research, sharing information with a friend who is not involved in care.
Keep those consents separate from the care record consent conversation, record them specifically, and make it easy to withdraw them. A single form headed consent to everything is worth nothing, and an inspector or the ICO will treat it as such.
Capacity, consent and the people who cannot sign
Where a person lacks capacity to decide about a photograph or an information sharing request, you cannot obtain valid consent from them and a relative cannot consent on their behalf unless they hold a lasting power of attorney that covers it. For anything optional, a best interests decision under the Mental Capacity Act 2005 is the route, recorded properly, taking account of the person's known wishes and the views of those close to them. For care records themselves the question does not arise, because your basis is legal obligation rather than consent.
The principles, translated into care home English
- Lawfulness, fairness and transparency: have a basis, do not be sneaky, tell people in a privacy notice.
- Purpose limitation: data collected to provide care is not data to be used for marketing.
- Data minimisation: record what is needed for care, not everything anybody said.
- Accuracy: wrong information in a care plan is both a care failure and a data breach waiting to happen.
- Storage limitation: have a retention schedule and follow it.
- Integrity and confidentiality: locks, logins, encryption, and staff who know not to text about residents.
- Accountability: be able to show all of the above, which means written policies and records rather than good intentions.
Data minimisation in daily notes
Minimisation is where good recording and good data protection meet. A daily note should record what happened and what it means for the person's care. It should not record the worker's opinion of the family, gossip about another resident, or the detail of someone else's business.
Two practical rules help. First, never name another resident in someone's record; use initials or a description such as another resident. Second, write every entry as though the person and their solicitor will read it, because one day they might. Our guide to daily care notes shows the difference in practice.
Accuracy, and the right to have things corrected
People have the right to have inaccurate personal data corrected. In care that usually means a factual error: the wrong date of birth, the wrong NHS number, a diagnosis recorded that the person does not have, a recorded allergy that is wrong.
Professional opinion is different. If a nurse recorded that a wound looked infected and a later swab was negative, the record is not inaccurate; it recorded a professional judgment at a point in time. The right response is to add the later information, not to delete the earlier entry. Never overwrite a record to make it look better. Every decent electronic system keeps an audit trail and shows exactly what was changed, when and by whom, which is a protection for staff as much as for residents.
How long to keep records
Retention in health and social care follows the Records Management Code of Practice published for the NHS and adult social care, together with employment and health and safety law. You should write your own schedule and follow it, rather than keeping everything forever, which is itself a breach of the storage limitation principle.
| Record | Typical retention | Where the rule comes from |
|---|---|---|
| Adult social care record, including care plans and daily notes | 8 years after the person leaves the service or after death | Records Management Code of Practice |
| Records for a person under 18 | Until their 25th birthday, or 26th if they turned 17 at the last entry | Records Management Code of Practice |
| MAR charts and medication records | Commonly 8 years, in line with the care record | Records Management Code of Practice and NICE guidance |
| Controlled drug register | 2 years from the date of the last entry, kept intact | Misuse of Drugs Regulations 2001 |
| Accident and incident records | 3 years minimum; longer where litigation is possible | RIDDOR and limitation periods |
| Safeguarding records | Usually retained with the care record; some authorities require longer | Local safeguarding board policy |
| Staff personnel file after leaving | 6 years after employment ends | Limitation Act 1980 and HMRC requirements |
| Recruitment records for unsuccessful candidates | 6 to 12 months | Equality Act 2010 tribunal time limits |
| DBS certificate details | Record the number and date; do not keep the certificate beyond 6 months | DBS code of practice |
| CCTV footage | Usually 30 days unless needed for an investigation | ICO video surveillance guidance |
Security: what the ICO expects of a care service
UK GDPR requires appropriate technical and organisational measures. For a care home that means, at a minimum: individual logins for every worker with no shared accounts, access limited to the people each worker supports, encryption on laptops and phones, locked offices and cabinets for anything on paper, a policy on removing records from the building, secure disposal by shredding or a confidential waste contractor, and a written record of who has keys and who has admin rights.
It also means leavers being removed from systems the day they leave. The most common finding in an information governance audit is a live login for somebody who left eight months ago.
Agency and bank staff
Agency workers need enough access to provide safe care and no more. The practical answer is access limited to the people they are supporting on the days they are working, with the account closed or suspended afterwards. A shared agency login that everybody uses is the worst of both worlds: nobody can tell who wrote what, and the audit trail that protects your staff disappears. Our article on agency staff in care homes covers the induction side of this.
Subject access requests: the basics
Any person can ask for a copy of the personal data you hold about them. There is no special form, no fee, and the request does not have to mention GDPR or the words subject access. An email saying I want to see everything you have about me is a valid request, and so is a verbal request to a care worker in the lounge, which is why staff need to know to pass it on the same day.
You have one calendar month from receipt, or from the day you receive the identification you reasonably asked for. You can extend by up to two further months for complex or multiple requests, but you must tell the person within the first month and explain why.
How to run a subject access request without losing your weekend
- Log it the day it arrives, with the date, who made it and what they asked for.
- Confirm identity proportionately. A resident you know does not need a passport.
- Clarify the scope if it is broad. You may ask what they are looking for, but you cannot insist on narrowing it.
- Search everywhere, including care records, emails, incident forms, complaints files, handover notes and any messages about the person.
- Redact third party information that identifies other people, unless they agree or it is reasonable to disclose.
- Provide it in a usable form, normally electronically if they asked electronically.
- Include the supporting information: purposes, categories, recipients, retention, and their rights to rectification, erasure and complaint to the ICO.
The hard part: other people in the record
Care records are full of other people. A daily note might name a relative, a staff member or another resident. You must not disclose information that identifies another individual unless that person consents or it is reasonable to disclose without consent.
In practice: staff names in a professional capacity are usually disclosable, because they were acting in their role. A relative's private disclosure, another resident's details, or an anonymous safeguarding referrer's identity usually are not. Redact carefully, keep an unredacted copy with a note of why each redaction was made, and if a request is genuinely difficult take advice before sending anything.
Requests from families, attorneys and after a death
A relative has no automatic right to see a person's records. Ask what authority they hold. A person with a registered lasting power of attorney for health and welfare, or a court appointed deputy, can make a request on the person's behalf within the scope of their authority. Where a person has capacity, the answer is simply to ask the person whether they want the information shared.
UK GDPR does not apply to the deceased. Access after death is governed by the Access to Health Records Act 1990, which gives rights to the personal representative of the estate and to anyone who may have a claim arising from the death. The practical answer to a grieving daughter is usually a conversation and an offer to meet, not a legalistic letter.
Photographs, films and social media
Photographs are a common weak point. The rules are straightforward. For care purposes such as a photograph on a MAR chart to confirm identity, or a picture in a communication passport, your normal care basis applies. For anything public, you need consent, and it must be specific about where the image will be used and for how long.
Never allow staff to use personal phones for photographs of residents. Once an image is in somebody's camera roll it is beyond your control, it will back up to their private cloud account, and you have no way of deleting it when they leave. If images are needed for care, they should be taken on a service device within the care system and stored inside the record.
Body maps, wound photographs and intimate images
Wound and injury photography is legitimate and often necessary, but it is the most sensitive data a care service holds. Set clear rules: take images only where they add something a written body map does not, use a service device, include the person's identifier and the date, explain what you are doing and seek agreement where the person can give it, avoid capturing more of the body than is needed, and store the image directly in the care record rather than in a phone gallery or a shared drive.
Where the person lacks capacity, record a short best interests rationale. Where the image is required for a safeguarding investigation, follow the local safeguarding board's guidance, which is covered in our safeguarding guide.
Sharing information with other professionals
Information sharing is where staff are most nervous and most likely to hide behind the word GDPR. The rule to teach is short: data protection law is not a barrier to sharing information where sharing is necessary and proportionate to keep someone safe or to provide their care.
You can share with the GP, the hospital, the district nurse, the pharmacy, the ambulance service, the local authority and the safeguarding team where it is needed for care or protection. You should tell the person what you are sharing and why unless doing so would increase risk. You should record what you shared, with whom, when and why. Refusing to give a paramedic a person's medication list because of GDPR is not compliance, it is a care failure with a legal excuse attached.
Data breaches: what actually counts
A personal data breach is any security incident leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. It is much broader than hacking. Real examples from care services include a handover sheet left on a bus, an email with a resident list sent to the wrong family, a care folder photographed and shared on WhatsApp, a laptop stolen from a car, a visitor reading the whiteboard in an unlocked office, records destroyed by a flood with no backup, and a worker looking up the records of a neighbour who is not on their unit.
The 72 hour rule, and what happens in hour one
If a breach is likely to result in a risk to people's rights and freedoms, you must report it to the ICO without undue delay and within 72 hours of becoming aware of it. The clock starts when you have a reasonable degree of certainty that a breach occurred, not when you have finished investigating. If it is likely to result in a high risk, you must also tell the affected people without undue delay, in clear language, explaining what happened and what they should do.
In the first hour: contain it (lock the account, recall the email, retrieve the paperwork), record the facts with times, assess who is affected and what harm could follow, and tell your registered manager and data protection lead. Then decide on reporting. If you decide not to report to the ICO, write down why. That reasoning is what you will be asked for later. Serious incidents may also require a CQC notification and, where a resident's safety or dignity is affected, a safeguarding referral.
A worked example
A team leader emails a spreadsheet of next of kin contacts to a family member by mistake, at 16:40 on a Friday. It contains names, phone numbers and the unit each resident lives on. She notices at 16:55 and tells the manager.
The manager records the time, asks the recipient by phone to delete it and confirm deletion in writing, and gets that confirmation at 17:30. She assesses the risk: nine residents identifiable, unit names reveal that some live in a dementia unit, which is health data. She reports to the ICO on Monday morning, within 72 hours, describing the containment and the confirmed deletion. She writes to the nine families explaining what happened. She then changes the process so that contact lists are never emailed, and adds a delayed send rule to outgoing mail. The ICO takes no further action, because she contained it, reported it and fixed the cause. That last part is what the regulator looks for.
Staff records and HR data
Staff have the same rights as residents. They can make a subject access request, which in practice usually arrives during a grievance or disciplinary process. Everything you write in a supervision note, an investigation report or an email about a worker is potentially disclosable to them. That is a good discipline: write about conduct and evidence, not about personalities.
Keep recruitment and employment data secure and separate, restrict access to managers who need it, hold DBS certificate numbers and dates rather than photocopies of certificates, and be careful with health information such as occupational health reports, which is special category data and should be held apart from the general file.
Privacy notices, records of processing and impact assessments
Three documents keep you honest. A privacy notice, written in plain English and given to people when they start with the service, saying what you collect, why, who you share it with, how long you keep it and what their rights are. An easy-read version should exist wherever you support people with a learning disability. A record of processing activities, which is a simple table of what data you hold, why, who it is shared with and how long it is kept. And a data protection impact assessment for anything high risk, which for a care service typically means CCTV, body worn cameras, acoustic monitoring, falls sensors, and any new system holding health data.
Your information governance policy should sit alongside these. Our policies and procedures list shows where it fits in the wider set.
Do you need a data protection officer?
A formal data protection officer is mandatory for public authorities and for organisations whose core activities involve large scale processing of special category data. A single home is not usually caught by this; a group operating many services may well be. Either way, you must have someone accountable. Most providers appoint a data protection lead, often the registered manager or a head office nominee, name them in the privacy notice, and make sure they have had proper training. Being named without training is worse than not being named at all.
Choosing software without inheriting somebody else's risk
If you are moving from paper to digital, data protection questions belong in the procurement conversation. Ask where the data is hosted, whether it stays in the UK, who at the supplier can see your records and under what controls, how access is logged, whether the audit trail is tamper-evident, how often backups are taken and tested, whether the supplier is independently assessed, what happens to your data if you leave, and how quickly they will tell you about a breach on their side.
Ask for the data processing agreement before you sign, not after. A supplier that cannot answer these questions in writing is not ready to hold special category data about vulnerable adults. Kiwi publishes its answers on the security page for exactly that reason, and you should expect the same from anyone you consider. Our guide to digital care records versus paper covers the wider comparison.
Training that actually changes behaviour
An annual e-learning module will not stop somebody photographing a body map on their own phone. What works is short, specific rules repeated often: no resident information on personal devices, no photographs on personal phones, no records leaving the building without authorisation, no shared logins, lock the screen when you walk away, and tell the manager the moment something goes wrong.
The last one is the most important. A culture where staff hide breaches is far more dangerous than the breaches themselves, because containment in the first hour is what limits the harm. Say clearly and often that reporting a mistake promptly is what you expect, and mean it when it happens.
A ten point self-audit
- Can you name your lawful basis for care records without looking it up?
- Is your privacy notice current, in plain English, and is there an easy-read version?
- Does every worker have their own login, and are leavers removed the day they leave?
- Do you have a written retention schedule, and has anything actually been destroyed under it in the last year?
- Do you have a signed data processing agreement with every software supplier?
- Would a subject access request arriving today be logged, and by whom?
- Does every worker know that photographs of residents on personal phones are forbidden?
- Do you have a breach log, and does it contain entries, including near misses?
- Has a data protection impact assessment been done for any CCTV or sensor technology?
- If your office flooded tonight, what would you lose that exists nowhere else?
Final conclusion
Data protection in care homes is not a paperwork exercise bolted onto care. It is the same discipline as good record keeping: know why you hold something, keep it right, keep it safe, keep it only as long as you need it, and be straight with people about it. Get the lawful basis right and stop asking for consent you do not need. Write the retention schedule and use it. Give every worker their own login. Teach staff that sharing to keep somebody safe is required, not forbidden. And rehearse the first hour of a breach before you need it, because that hour is the one the ICO will ask about.
Frequently asked
What is the lawful basis for keeping care records under UK GDPR?
For care records the usual basis is legal obligation under Article 6(1)(c), or public task under Article 6(1)(e) for local authority or NHS commissioned care, combined with the health and social care condition under Article 9(2)(h) and the associated condition in Schedule 1 of the Data Protection Act 2018. Vital interests can be used in a genuine emergency. It is not consent.
Do we need a resident's consent to keep a care plan?
No. Consent is the wrong basis because you could not stop holding the record if it were withdrawn, and you are legally required to keep it. Consent is still the right basis for optional things such as photographs for a website or newsletter, which the person can genuinely refuse without affecting their care.
How long do we keep care records after someone dies or leaves?
The Records Management Code of Practice sets 8 years after death or after the person leaves the service for adult social care records. Records about someone under 18 are kept until their 25th birthday. Controlled drug registers are kept for 2 years from the last entry, and staff files for 6 years after employment ends.
How long do we have to answer a subject access request?
One calendar month from receipt, or from the point you receive identification you reasonably asked for. You can extend by up to two further months for complex or multiple requests, but you must tell the person within the first month and explain why. There is no fee unless the request is manifestly unfounded or excessive.
Can a daughter ask to see her mother's care records?
Not automatically. If her mother has capacity, ask her mother whether she wants the information shared. If the daughter holds a registered lasting power of attorney for health and welfare or is a court appointed deputy, she can request within the scope of that authority. After death, access is dealt with under the Access to Health Records Act 1990 rather than UK GDPR.
When do we have to report a data breach to the ICO?
Within 72 hours of becoming aware of it, where the breach is likely to result in a risk to people's rights and freedoms. Where the risk is high you must also tell the affected people without undue delay, in plain language. If you decide not to report, record the reasoning behind that decision.
Does GDPR stop us sharing information with the GP or a safeguarding team?
No. Data protection law is not a barrier to sharing information that is necessary and proportionate to provide care or protect someone at risk. The Data Protection Act 2018 contains a specific safeguarding condition. Record what you shared, with whom, when and why, and tell the person unless doing so would increase risk.
Can staff take photographs of residents on their own phones?
No. Personal devices put special category data outside your control, back it up to private accounts and cannot be wiped when a worker leaves. Any image needed for care, such as a wound photograph, should be taken on a service device and stored directly in the care record, with a best interests record where the person cannot agree.
Sources
- Information Commissioner's Office: guide to UK GDPR
- Data Protection Act 2018
- UK General Data Protection Regulation
- Records Management Code of Practice for Health and Social Care
- Access to Health Records Act 1990
- Mental Capacity Act 2005
- Care Quality Commission: Regulation 17 good governance
- Information Commissioner's Office: personal data breach reporting and video surveillance guidance




