1. Governance
1.1. This is the Confidentiality and Data Protection (UK GDPR) Policy and Procedure for The Good Place Home Care Services Limited.
1.2. The Good Place Home Care Services Limited will be referred to in this document as "The Good Place Home Care Services Limited","The Good Place","We","Us", or "Our".
1.3. Our registered address is: 186 Wetmore Road, Burton-on-Trent, Staffordshire, DE14 1QZ.
1.4. We can be contacted by:-
- a. Telephone: 01283 296 337
- b. Email: [protected:ahello][protected:athegoodplace.care]
- c. Post: The Good Place, 186 Wetmore Road, Burton-on-Trent, Staffordshire, DE14 1QZ
1.5. Words importing one gender include all genders, and words in the singular include the plural and vice versa, unless the context requires otherwise.
1.6. Document control sheet:-
| Metadata | Value |
|---|---|
| Document fingerprint | IG-2094-V1 |
| Document owner | Dean Hill (Nominated Individual) |
| Document version | 1 |
| Document status | Approved on 18/03/2026 by the Dean Hill (Nominated Individual) |
| Document review cycle | Annually or sooner if legislation or guidance changes. Next review planned for March 2027 |
2. Purpose
2.1. To define the types of personal data we collect and process.
2.2. To explain how we use, store, and protect personal data.
2.3. To inform service users and staff of their rights regarding their personal data.
2.4. To outline how The Good Place ensures the confidentiality and protection of personal data in accordance with the General Data Protection Regulation (GDPR) and the Data Protection Act 2018.
2.5. To ensure compliance with applicable data protection legislation.
2.6. To ensure that we fulfil the legal and regulatory responsibilities.
2.7. To support us to meet, and be able to evidence compliance with, the following CQC Single Assessment Framework quality statements:-
| Safe | |
|---|---|
Safe systems, pathways and transitions | We work with people and our partners to establish and maintain safe systems of care, in which safety is managed, monitored and assured. We ensure continuity of care, including when people move between different services. |
Safeguarding | We work with people to understand what being safe means to them as well as with our partners on the best way to achieve this. We concentrate on improving people’s lives while protecting their right to live in safety, free from bullying, harassment, abuse, discrimination, avoidable harm and neglect. We make sure we share concerns quickly and appropriately. |
| Effective | |
Consent to care and treatment | We tell people about their rights around consent and respect these when we deliver person-centred care and treatment. |
| Caring | |
Independence, choice and control | We promote people’s independence, so they know their rights and have choice and control over their own care, treatment and wellbeing. |
| Responsive | |
Providing information | We provide appropriate, accurate and up-to-date information in formats that we tailor to individual needs. |
| Well-led | |
Freedom to speak up | We foster a positive culture where people feel that they can speak up and that their voice will be heard. |
Governance, management and sustainability | We have clear responsibilities, roles, systems of accountability and good governance. We use these to manage and deliver good quality, sustainable care, treatment and support. We act on the best information about risk, performance and outcomes, and we share this securely with others when appropriate. |
3. Scope
3.1. This policy covers all personal data relating to service users, staff, and other stakeholders, whether held electronically, on paper, or through other means. It ensures that data is processed lawfully, fairly, and securely to protect individuals' rights and uphold the integrity of our care services.
3.2. This policy applies to all staff, including permanent, temporary, agency and volunteer workers, and to any external organisations acting as data processors on behalf of The Good Place. Compliance with this policy is a condition of engagement and forms part of staff terms and conditions and contractor agreements.
4. Policy Statement
4.1. At The Good Place, we are committed to safeguarding the privacy and personal data of our service users, staff and stakeholders. This policy outlines our approach to managing personal information in compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. We aim to handle all personal data lawfully, fairly, and transparently, ensuring the rights and freedoms of our service users are respected.
4.2. The Good Place is committed to:-
- a. Protecting the confidentiality of all personal and sensitive information.
- b. Ensuring data processing aligns with the principles of the UK GDPR and the Data Protection Act 2018.
- c. Promoting a culture of respect for privacy.
- d. Implementing robust systems for data management and security.
- e. Providing staff with clear guidance and training on data protection.
4.3. We believe that safeguarding confidentiality is essential for building trust with service users and maintaining high-quality care standards.
4.4. Website Privacy Statement
4.4.1. The Good Place maintains a separate Website Privacy Statement which explains how personal data is collected and used when individuals interact with our website, including via contact forms, cookies and similar technologies, and analytics tools, and sets out the lawful bases we rely on for this processing.
4.4.2. This Confidentiality and Data Protection (UK GDPR) Policy and Procedure should be read alongside the Website Privacy Statement.
4.4.3. The Website Privacy Statement reflects the same principles, lawful bases, and data protection standards outlined in this policy but is presented in a format suitable for public users.
5. Legal & Regulatory Framework
5.1. This policy is guided by:-
- a. UK General Data Protection Regulation (UK GDPR), as retained in UK law by the European Union (Withdrawal) Act 2018.
- b. Guidance and statutory codes of practice issued by the Information Commissioner’s Office (ICO) – including guidance on UK GDPR, data sharing, subject access requests, and data security.
- c. Health and Social Care Act 2008 and the Health and Social Care Act 2008 (Regulated Activities) Regulations 2014 – Including the fundamental standards and Regulation 17 (Good governance), which require robust information systems, accurate records and effective management of confidential personal information.
- d. Health and Social Care Act 2012 – Mandates the proper handling and use of patient data within health and social care settings.
- e. The Caldicott Principles – Ethical principles that govern the use and sharing of patient-identifiable information to uphold confidentiality.
- f. National Data Guardian’s 10 Data Security Standards and, where applicable, the NHS Data Security and Protection Toolkit (DSPT) – national data security standards which The Good Place implements and, where required by commissioners or contracts, self-assesses against each year.
- g. National Data Opt-Out Policy – where applicable, we respect people’s choices about the use of their confidential information for purposes beyond their individual care, in line with NHS England and ICO guidance.
- h. The Freedom of Information Act 2000 – establishes public rights of access to non-personal information held by public authorities while maintaining people’s privacy. This applies directly where The Good Place is a public authority for FOIA purposes, and indirectly where we support public authorities in meeting their FOIA duties.
- i. NHS Code of Confidentiality (where relevant to our work with NHS partners) – informs how patient information is handled with care and only disclosed when necessary and lawful.
- j. Common Law Duty of Confidentiality – Requires that patient information is kept confidential unless there is a lawful and justifiable reason to disclose it.
5.2. The Good Place is fully committed to meeting the requirements of the Accessible Information Standard (AIS), as set out by NHS England. This means we will ensure that people with a disability, impairment, or sensory loss receive information and communication support that they can understand and use effectively. This may include large print, easy-read versions, audio formats, or the use of interpreters and communication aids. See our Accessible Information Standard (AIS) Policy and Procedure for further details.
5.3. We also comply with the Equality Act 2010 and are fully committed to promoting diversity, and human rights in all aspects of our service provision and employment practices. We are dedicated to ensuring that all individuals, including staff, service users, and stakeholders, are treated fairly, with dignity and respect, and without discrimination. We will also make reasonable adjustments so that no individual is treated less favourably when using our service. This includes supporting people with protected characteristics such as age, disability, gender reassignment, marriage and civil partnership, pregnancy and maternity, race, religion or belief, sex, and sexual orientation. See our Equality, Diversity and Human Rights Policy and Procedure for further details.
6. Roles & Responsibilities
6.1. Data Controller: The Good Place acts as the Data Controller for personal data it processes in the United Kingdom, determining the purposes and means of processing in accordance with the UK GDPR and the Data Protection Act 2018.
6.2. Data Protection Officer: The Good Place has appointed Dean Hill as its Data Protection Officer. This appointment is made on a voluntary basis to strengthen oversight of data protection and information governance. The DPO role is independent and reports to the highest management level. The DPO oversees data protection practices, advises on compliance, supports data protection impact assessments, and coordinates the response to data breaches and rights requests.
6.3. Staff Members: All staff must:-
- a. Handle personal data confidentially and only for legitimate work purposes.
- b. Complete mandatory information governance, UK GDPR and data security training at induction and at least annually.
- c. Maintain confidentiality and respect people’s privacy at all times, including when working in people’s own homes and in the community.
- d. Follow this policy and all related procedures, including records management, data sharing, and home-working/remote-working procedures.
- e. Use only authorised systems, devices and applications to create, access, store or transmit personal data.
- f. Report any concerns, near misses or actual data breaches immediately through the agreed incident-reporting process.
- g. Cooperate with audits, investigations and improvement actions relating to data protection and information security.
- h. Understand that their duty of confidentiality continues after their employment or engagement with The Good Place ends, and that unauthorised use or disclosure of personal data after leaving may be unlawful and may result in legal action.
7. Definitions
7.1. Personal Data – Any information relating to an identified or identifiable living individual, such as name, address, contact details, identification numbers, location data, online identifiers, and information about a person’s physical or mental health, social care needs, or other personal circumstances.
7.2. Special Category Data (sometimes referred to as sensitive personal data) – personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data for the purpose of uniquely identifying a person, data concerning health, or data concerning a person’s sex life or sexual orientation.
7.3. Data Subject - An individual whose personal data is processed.
7.4. Data Controller - The organisation responsible for determining how personal data is processed.
7.5. Data Processor - An individual or entity that processes data on behalf of the Data Controller.
7.6. Processing - Any action performed on data, including collection, storage, sharing, or deletion.
8. GDPR Principles
8.1. We adhere to the seven key principles of the UK GDPR when processing personal data:-
- a. Lawfulness, Fairness, and Transparency: Data is processed lawfully, fairly, and openly.
- b. Purpose Limitation: Data is collected for specified, legitimate purposes.
- c. Data Minimisation: Only necessary data is collected and processed.
- d. Accuracy: Personal data is kept accurate and up to date.
- e. Storage Limitation: Data is retained only as long as necessary.
- f. Integrity and Confidentiality: Data is protected against unauthorised access and loss.
- g. Accountability: We are responsible for, and must be able to demonstrate, compliance with all of these data protection principles, including through appropriate policies, procedures, training, records and audits.
9. Data Protection Impact Assessments (DPIAs)
9.1. For any processing that is likely to result in a high risk to individuals’ rights and freedoms – for example, the introduction of new electronic care planning systems, monitoring or surveillance technologies in people’s homes, large-scale processing of special category data, or new data-sharing arrangements – we will complete a documented Data Protection Impact Assessment. The DPIA will identify risks to privacy, security and individuals’ rights, and set out measures to mitigate those risks before the processing starts. The Data Protection Officer will advise on, and where appropriate review, DPIAs.
10. The Caldicott Principles
10.1. The Good Place rigorously follows the eight Caldicott Principles to ensure patient information is used and shared responsibly:-
- a. Justify the purpose – Every instance of using patient-identifiable information must have a clear, documented justification that is reviewed regularly.
- b. Only use it when necessary – We ensure patient information is used only where absolutely required to deliver care, research, or operational functions.
- c. Use the minimum necessary information – The Good Place limits the amount of identifiable data processed to only what is needed to complete a task.
- d. Access on a strict need-to-know basis – Access controls are implemented so only authorised personnel can access specific patient information.
- e. Everyone with access must understand their responsibilities – We provide continuous education and training to all employees regarding their responsibility to handle patient data appropriately.
- f. Comply with the law – All handling, storage and sharing of patient information aligns with relevant legislation and regulatory requirements.
- g. The duty to share information can be as important as the duty to protect confidentiality – Patient data is shared, where necessary and lawful, in the best interests of the individual and for safeguarding, public protection and other permitted purposes.
- h. Inform patients and service users about how their confidential information is used – The Good Place is open and transparent about how information is collected, used, shared and retained, and provides clear privacy information and opportunities for questions and feedback.
11. Data Collection
11.1. We collect personal data necessary for providing domiciliary care services, which may include:-
- a. Personal Identification Information: Name, date of birth, address, telephone number, and email address.
- b. Health Information: Medical history, medication details, care plans, and records of care provided.
- c. Next of Kin and Emergency Contact Details: Names and contact information of designated individuals.
- d. Financial Information: Billing details and payment information.
11.2. We collect personal data for:-
- a. Delivering safe and effective care.
- b. Managing staff records.
- c. Complying with regulatory requirements.
11.3. Data is collected through care assessments, care plans, consent forms where appropriate, employment documents, contracts, and digital platforms. Staff must:-
- a. Explain to people, in a way they can understand, why we need their information, how it will be used, and who it may be shared with.
- b. Ensure that there is a valid lawful basis for processing before collecting personal data – this may be consent in some circumstances, but more commonly will be contractual necessity, legal obligation, the provision of health or social care, or vital interests.
- c. Obtain and record consent where consent is the appropriate lawful basis (for example, certain types of marketing, or optional information sharing), and respect people’s right to withdraw consent.
- d. Avoid collecting more data than is necessary for the stated purposes (data minimisation).
- e. Provide or signpost clear privacy information (privacy notices) to people in a format they can understand, explaining our purposes, lawful bases, retention periods and their rights.
12. Lawful Basis for Processing
12.1. Our processing of personal data is based on the following lawful grounds:-
- a. Consent: Where explicit consent has been obtained from the service user or their legal representative.
- b. Contractual Necessity: To fulfil our obligations under the care service agreement.
- c. Legal Obligation: To comply with applicable laws and regulations governing health and social care.
- d. Vital Interests: To protect the life or health of the service user in emergency situations.
- e. Legitimate Interests: Where processing is necessary for our legitimate interests or those of a third party, provided these interests are not overridden by the service user's rights.
12.2. Where we process special category data (for example health and care information) we also ensure that a separate condition for processing under Article 9 UK GDPR and the Data Protection Act 2018 is met. For the provision of domiciliary care services, this will usually be because processing is necessary for the purposes of the provision of health or social care or treatment or the management of health or social care systems and services.
12.3. Where a person may lack capacity to make decisions about the use or sharing of their personal data, we follow the Mental Capacity Act 2005 and its Code of Practice. We assess capacity in relation to the specific decision, and where the person lacks capacity, we make best interests decisions in consultation with those involved in their care, and we record the decision-making process in the care record.
12.4. The Good Place does not undertake high-volume direct marketing. Where we send information that is not directly related to a person’s care or to our contract with them (for example, newsletters, general promotional information or satisfaction surveys sent to former service users), we will ensure there is a valid lawful basis and, where required by law, we will obtain prior consent (for example, for some electronic marketing). Individuals can opt out of such communications at any time, and we will record and respect their preferences.
13. Use of Personal Data
13.1. We use personal data to:-
- a. Develop and implement personalised care plans.
- b. Communicate effectively with service users, their families, and healthcare professionals.
- c. Manage and deliver care services safely and effectively.
- d. Maintain accurate records for legal, regulatory, and quality assurance purposes.
- e. Process billing and financial transactions.
14. Confidentiality in Practice
14.1. To maintain confidentiality, staff must:-
- a. Keep paper records in locked cabinets.
- b. Use password-protected systems for electronic data.
- c. Avoid discussing confidential matters in public areas.
- d. Share information on a need-to-know basis only.
- e. Take extra care when handling records or discussing care in people’s homes, ensuring conversations cannot be overheard inappropriately and that paper records, mobile devices and care plans are not left where visitors or other household members can access them without permission.
15. Data Sharing
15.1. We may share personal data with:-
- a. Healthcare professionals involved in the service user's care.
- b. Regulatory bodies, as required by law.
- c. Emergency services, when necessary to protect the service user's vital interests.
- d. Third-party service providers who support our operations, under strict confidentiality agreements.
15.2. We ensure that any third parties with whom we share personal data are compliant with data protection laws and uphold the same standards of confidentiality and security.
15.3. Data Sharing and Third-Party Access
15.3.1. There are circumstances where patient information must be shared securely and lawfully, including:-
- a. For direct care – Patient information is shared with authorised healthcare providers involved in their treatment.
- b. For legal obligations – Information is disclosed to regulatory bodies such as the Care Quality Commission (CQC) where required by law.
- c. For safeguarding purposes – Where necessary, information is shared to protect individuals from harm or abuse, following appropriate legal protocols.
- d. With third-party providers – Contractors and service providers must comply with data-sharing agreements, ensuring confidentiality and compliance with regulations.
15.3.2. Before any information is shared, a risk assessment is conducted to ensure that the sharing aligns with legal, ethical, and organisational policies.
15.3.3. All data sharing with external organisations, including commissioners, partner agencies and service providers, is supported by appropriate contracts or data-sharing agreements which set out roles and responsibilities, legal bases for sharing, security requirements and retention arrangements. Where possible, information is pseudonymised or anonymised before being shared.
15.3.4. Situations Requiring Information-Sharing
15.3.4.1. Information-sharing with third-party organisations is essential in situations such as:-
- a. Healthcare coordination, including referrals to GPs, hospitals, and allied healthcare providers.
- b. Safeguarding concerns, ensuring service users are protected from harm.
- c. Legal compliance, including CQC inspections, audits, and investigations.
- d. Financial and funding arrangements, such as local authority funding assessments.
- e. Emergency situations, where timely information exchange is necessary for safety.
- f. Service improvement and partnership working, ensuring better care outcomes.
15.3.5. Consent, Confidentiality, and Safeguarding
15.3.5.1. We share information only where there is a lawful basis to do so. Where consent is the appropriate lawful basis, we obtain and record the person’s informed consent. In many care and safeguarding situations, information may instead be shared on the basis of legal obligation, vital interests, public task, legitimate interests, or the provision of health or social care, without relying on consent.
15.3.5.2. We follow the Mental Capacity Act 2005 and its Code of Practice when a person may lack capacity to provide consent to information sharing, including assessing capacity for the specific decision, making and recording best interests decisions, and involving advocates or those close to the person where appropriate.
15.3.5.3. Information is only shared on a need-to-know basis, ensuring data minimisation.
15.3.5.4. All shared information must be accurate, up-to-date, and relevant to its purpose.
15.3.5.5. Safeguarding concerns override confidentiality when a person is at risk of harm. In such cases we share relevant information promptly with the local authority and other safeguarding partners in line with our Safeguarding Adults Policy and local multi-agency safeguarding procedures.
15.3.6. International transfers
15.3.6.1. Where we use systems or service providers that store or access personal data outside the UK, we will ensure that appropriate safeguards are in place in accordance with the UK GDPR and the Data Protection Act 2018. This may include use of UK adequacy regulations, International Data Transfer Agreements (IDTAs) or Addendums, and documented risk assessments.
16. Data Security
16.1. We implement appropriate technical and organisational measures to protect personal data against unauthorised access, loss, or damage. These measures include:-
- a. Access controls: restricting access to personal data to authorised personnel only, using unique user IDs, strong passwords and, where feasible, multi-factor authentication.
- b. Data encryption: using encryption technologies to protect data during storage and transmission, especially on laptops, tablets and mobile phones used in the community.
- c. Physical security: locked filing cabinets, clean-desk practices, and restricted access to offices and storage areas where records are held.
- d. Secure mobile and remote working: clear rules for staff using portable devices and paper records in people’s homes, including not leaving records unattended or visible, storing records securely when travelling, and ensuring devices are locked when not in use.
- e. System security: maintaining up-to-date anti-malware, firewalls, software updates and secure configurations on all devices used to access personal data.
- f. Regular audits and monitoring: periodic checks and audits of access logs, user permissions and compliance with this policy.
- g. Training and awareness: providing regular training to staff on data protection, confidentiality, phishing awareness and incident reporting.
- h. Business continuity and backup: secure backups and tested recovery arrangements to maintain the availability and integrity of critical care records.
17. Data Retention and Disposal
17.1. The Good Place ensures that records relating to people who use the service and to the management of the regulated activity are:-
- a. Accurate, complete and contemporaneous, reflecting the care and support provided.
- b. Legible and attributable, so that entries can be linked to the person who made them and the date and time of entry.
- c. Stored securely, with appropriate technical and organisational measures in place to prevent loss, damage, unauthorised access or alteration.
- d. Retained only for as long as necessary in line with legal, regulatory and contractual requirements and any applicable health and social care records retention schedules.
- e. Disposed of securely, for example through cross-cut shredding or approved confidential waste services for paper records, and secure deletion for electronic records.
17.2. Staff must follow The Good Place’s records management and archiving procedures and must not create, store or dispose of patient information outside authorised systems or locations.
17.3. Data is retained only as long as necessary for care delivery, legal obligations, contractual requirements, commissioning requirements and quality assurance, in line with relevant health and social care records retention schedules (for example, the NHS Records Management Code of Practice, where applicable) and The Good Place’s own Records Retention Schedule. Typical retention periods include:-
- a. Service user care records: normally at least 8 years after the end of care, or longer where required by law, contract or guidance.
- b. Staff employment records: normally 6 years after employment ends, or longer where required by law (for example, records relating to safeguarding or serious incidents).
- c. Incident and safeguarding reports: normally at least 10 years, or longer where required by law, insurance or safeguarding guidance.
17.4. Secure disposal methods include shredding paper records and permanent deletion of electronic files.
18. Rights of Service Users, Staff, and Stakeholders
18.1. Everyone has the following rights regarding their personal data:-
- a. Right to Access: To obtain a copy of their personal data and information about how it is processed.
- b. Right to Rectification: To request correction of inaccurate or incomplete data.
- c. Right to Erasure: To request deletion of personal data, subject to certain conditions.
- d. Right to Restrict Processing: To request a limitation on the processing of their data.
- e. Right to Data Portability: To receive their data in a structured, commonly used format and transfer it to another controller.
- f. Right to Object: To object to the processing of their data based on legitimate interests.
18.2. To exercise these rights, service users or their representatives should contact the Data Protection Officer (Dean Hill):-
- a. Email: [protected:adean][protected:athegoodplace.care]
- b. Telephone: 01283 296 337
18.3. If a person is unhappy with how we have handled their personal data, we encourage them to contact us in the first instance so we can try to resolve the concern quickly. If they remain dissatisfied, they have the right to complain to the Information Commissioner’s Office (ICO) at:-
- a. Telephone: 0303 123 1113
- b. Online: www.ico.org.uk
- c. Post: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF.
18.4. We will respond to requests to exercise data protection rights without undue delay and in any event within one month of receipt. Where a request is complex or we receive a large number of requests, we may extend this period by up to a further two months, and we will inform the person within the first month if we need to do this, explaining why. We will verify the identity of the person making the request before disclosing any personal data, which may include asking for additional information where necessary to confirm identity. In line with the UK GDPR, we will normally respond free of charge, but we may charge a reasonable fee or refuse to act on requests that are manifestly unfounded or excessive, explaining our reasons.
19. Managing Data Breaches
19.1. In the event of a data breach, The Good Place follows a strict incident management process:-
- a. Immediate containment – The breach is assessed, and immediate actions are taken to minimise further risk.
- b. Impact assessment – The severity and potential impact of the breach on individuals and the organisation are evaluated.
- c. Reporting internally – The Data Protection Officer (DPO) and Registered Manager are notified immediately.
- d. Notification of affected individuals – If necessary, affected individuals will be informed about the breach and any remedial actions taken.
- e. Regulatory reporting – Where a personal data breach is likely to result in a risk to the rights and freedoms of individuals, we will notify the Information Commissioner’s Office (ICO) without undue delay and, where feasible, within 72 hours of becoming aware of it, in line with ICO guidance.
- f. Corrective actions – Preventative measures are implemented to avoid similar breaches in the future.
- g. Recording and learning – All actual and suspected data breaches and near misses are recorded in our incident reporting system, investigated to identify root causes, and result in learning and improvement actions which are monitored for completion.
20. Whistleblowing and Reporting Concerns
20.1. Staff are encouraged to report concerns about data protection breaches through our Raising Concerns, Freedom to Speak Up and Whistleblowing Policy and Procedure. Reports can be made to the Data Protection Officer, Registered Manager, or external authorities.
21. Third-Party Data Processors
21.1. When outsourcing data processing, we ensure that third parties (data processors):-
- a. Are subject to a written contract that includes all mandatory clauses required by Article 28 UK GDPR, including processing only on our documented instructions, confidentiality obligations, security measures, assistance with data subject rights and breaches, and deletion or return of data at the end of the contract.
- b. Can demonstrate appropriate technical and organisational measures to protect personal data, including where data is processed or stored outside the UK.
- c. Do not appoint sub-processors without our prior written authorisation and equivalent contractual safeguards.
- d. Are monitored and reviewed periodically to ensure ongoing compliance with data protection requirements.
22. Staff Training and Awareness
22.1. All staff receive GDPR training during induction and annual refreshers. Training covers:-
- a. Recognising personal and sensitive data.
- b. Proper handling and storage of data.
- c. Identifying and reporting data breaches.
- d. Understanding individuals’ data protection rights and how to recognise and respond to requests, concerns or complaints about privacy.
22.2. Training is recorded so that we can evidence compliance with CQC’s Single Assessment Framework and demonstrate a culture of safety, openness and accountability.
23. Compliance and Monitoring
23.1. To ensure continuous compliance and assurance to senior leaders, The Good Place employs the following monitoring methods:-
- a. Regular internal audits to assess adherence to data protection standards.
- b. Random checks and system access reviews to detect any potential misuse of patient data.
- c. Feedback mechanisms where staff and service users can report concerns related to information security.
23.2. Regular policy reviews and updates to align with changes in legislation, ICO guidance, CQC requirements (including the Single Assessment Framework) and emerging data security threats. Findings from audits, incidents and feedback are used to drive improvements in our information governance arrangements.





