RQF Level 3 Diploma in Adult Care
L/616/8396: Promote effective handling of information in
care settings.
CANDIDIATE’S NAME:
1.1 Identify legislation and codes of practice that relate to handling information in adult care.
Relevant legislation relating to the recording, storage and sharing of information in adult care, e.g.
relating to data protection, confidentiality are:
The Data Protection Act 1998 is a United Kingdom Act of Parliament which defines UK law on the
processing of data on identifiable living people. In practice it provides a way for individuals to
control information about themselves. Most of the Act does not apply to domestic use, for example
keeping a personal address book. Anyone holding personal data for other purposes is legally
obliged to comply with this Act, subject to some exemptions. Thereafter, General Data Protection
Regulation (GDPR) became law in 2018 and share many of Data protection Act 1998. GDPR
places more emphasis on how organisation share people’s personal information.
The Freedom of Information Act says that most public authorities have a legal obligation to
provide information through an approved publication scheme and in response to requests for
information. If I work for a local authority, my employer will have one or more specialists
responsible for requests made under this Act. I will need to find out who this is and what
procedures I should follow if a request for information is made direct to me.
The Care Quality Commission (CQC) is the independent regulator of health and adult social care
services in England. they Ire established by the Adult.
Care Act 2008 and replaced the former Commission for Adult Care Inspection, Healthcare
Commission and Mental Health Act Commission.
1.2 Summaries the main points of legal requirements and codes of practice for handling
information in adult care
Legal and ethical protections apply both to any disclosure of service user information and to any
use of it. Legal obligations to protect the privacy of service users stem from three main sources:
Common law of confidentiality, Human rights law and Data protection law. The requirements
of the legal standards may differ. It is important to note that meeting the obligations of one source
does not guarantee that the obligations under the others are being met. For example, the consent
of a service user for a particular use may not be required by data protection law but may be a
common law requirement.
Common law of confidentiality: The key principles of the law of confidentiality are contained in
the common law, that is, in the decisions of judges in particular cases. In this case if the health
worker comes into confidential information then she or he should not disclose it. In the event of a
breach of this duty of Confidence, legal action may follow, including claims for an injunction and/or
damages. However, the user of adult care services can consent to the disclosure of information.
Data Protection Act lists the data protection principles in the following terms:
1. Personal data shall be processed fairly and lawfully and, in particular, shall not be processed
unless – requires that processing (use) is necessary for the exercise of functions of a public
nature in the public interest by any person. Or it requires that processing is with the consent
of the data subject, or that ‘the processing is necessary for medical purposes and is
undertaken by a health professional (or a person owing a duty of confidentiality equivalent to
that oId by a health professional)’.
2. Personal data shall be obtained only for one or more specified and lawful purposes, and
shall not be further processed in any manner incompatible with that purpose or those
purposes.
3. Personal data shall be adequate, relevant and not excessive in relation to the purpose or
purposes for which they are processed.
4. Personal data shall be accurate and, where necessary, kept up to date.
5. Personal data processed for any purpose or purposes shall not be kept for longer than is
necessary for that purpose or those purposes.
6. Personal data shall be processed in accordance with the rights of data subjects under this
Act.
7. Appropriate technical and organizational measures shall be taken against unauthorised or
unlawful processing of personal data and against accidental loss or destruction of, or
damage to, personal data.
8. Personal data shall not be transferred to a country or territory outside the European
Economic Area unless that country or territory ensures an adequate level of protection for
the rights and freedoms of data subjects in relation to the processing of personal data.
Human Rights Act 1998: The Human Rights Act 1998 incorporates the main Articles of the
European Convention on Human Rights into the domestic law of all parts of the United Kingdom.
The European Convention states that: ‘Everyone has the right to respect for his private and family
life, his home and his correspondence.’ To date this provision has not been interpreted by judges in
the United Kingdom as imposing a general right to privacy, but it has certainly been used to
strengthen the right to confidentiality.
2.1 Describe features of manual and electronic information storage systems that help
ensure security
Manual information storage systems
Manual information includes: Paper or card health records, case notes, care plans, assessment
records, staff records, registers, reports, computer print-outs and administrative records such as
letters, invoices and minutes from meetings. Imaging records such as X-rays, CCTV film,
photographs and slides.
Audio recordings such as telephone calls and tape recordings. Manual information should be held
in named folders to make filing and access easy.
To help insure security of the manual storage systems, information should:
If possible, be copied, and copies stored in a separate, secure location,
An authorised person or the designated ‘data owner’ should take responsibility.
Be annotated with its level of security and confidential information must identify who is
authorised to have access.
There are three levels of information security:
1. Low security - can be accessed by the public, for example policies and procedures and an
organization’s Website.
2. Medium security - is not readily accessible but may be disclosed in certain circumstances,
for example basic personal information such as class lists.
3. High security - contains personal and sensitive identifiable information and access is on a
‘need-to-know’ basis only.
Storage facilities for medium and high risk information, such as filing cabinets, cupboards and
stores should be:
Kept under lock and key, and keys and keypad number sequences held by the designated
data owner or a named key holder.
Access to information should be given on a need-to-know basis and a tracking record
maintained of who has had access, when and why.
If information is removed from storage a record should be made of when it was returned.
Tracking systems can be either paper-based or electronic, such as when records are
scanned in and out of storage.
When manual information is no longer needed it should be dealt with as appropriate:
Closed or inactive files may have to be retained for some time, in which case appropriate
storage facilities will be required.
Some information will need to be permanently preserved by archiving some retained for
review, and some destroyed.
Low security information should be recycled; medium and high-risk information should be
shredded, pulped or incinerated.
Electronic information storage systems
Information can also be stored (saved) electronically on a computer’s hard disk drive, an external
hard drive, USB memory stick, CD or DVD, using programmes such as Word, PowerPoint and
Outlook., equivalent to the manual folders stored in filing cabinets and cupboards, the documents
produced using the following programmes are put into folders electronically:
the template for creating documents such as:
Word documents, for example letters and reports
Spreadsheets, for example to record and monitor physiological measurements
Presentations, for example, for training
Email, for sharing information.
Electronic information storage systems just like manual storage system has to ensure that folders
containing documents that are personal and sensitive need to be stored securely. The Data
Protection Act requires organisations that use portable electronic information storage systems,
such as laptops, handheld computers and USB memory sticks,
To encrypt (change it to unintelligible format that seems to be useless) personal and
sensitive information and regularly review and update the encryption to make sure it remains
effective.
The Act also requires that organisations have policies regarding the use and security of
portable systems and to ensure their staff are properly trained in these.
If computer equipment has to go off-site for service, repair or recycling,
All information should be backed-up, for example, on a USB memory stick, and then
removed using data destruction software overwrites everything.
The same applies to when computer equipment has to be discarded – remove all sensitive
data first; alternatively, physically destroy.
Computer viruses cause severe loss and destruction of information.
Anti-viral software is highly recommended.
Firewalls help prevent attacks against computers while connected to the Internet.
Never open files attached to emails from people I don’t know. If I do know the sender but
have even the slightest doubt, check to confirm that they have sent it.
Have a secure username and password. Used correctly. Keep my username secret. And
don’t have the computer save it, particularly if I share the computer with other people.
Keep my password secret. If I think someone might have watched me keying it in, change it
immediately. Do not be obvious in my choice of password, for example don’t use my name,
birthday or anything else that someone might guess. Change it frequently and if I have to
write it down, disguise it. Use a different password for every computer username allocated to
me.
Candidate Signature: Date:
Assessor’s Signature: Date:
IQA’s Signature [if sampled] Date: