Last reviewed: September 2026. Policy owner: the Registered Manager, Prestige Care Connect.

This policy sets out how Prestige Care Connect (a trading name of Ola Prestige Care Services Ltd) meets its duties under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. It applies to everyone who works for us, including employed carers, bank staff, volunteers and contractors. Our Privacy Policy explains in plain terms what we do with your information.

Our commitment

People who use our services share sensitive information about their health and home life. We treat that information as confidential, use it only for the purposes it was given for, and keep it no longer than necessary.

The principles we work to

Roles and responsibilities

The Registered Manager is accountable for data protection within the service and is the point of contact for data protection questions, subject access requests and breaches. Every member of staff is responsible for following this policy, completing data protection and confidentiality training, and reporting any concern or breach immediately.

Lawful basis and special category data

Most of the information we hold about the people we support is special category health data. We rely on Article 6(1)(b) or 6(1)(c) UK GDPR together with Article 9(2)(h) — the provision of health and social care — and, where safeguarding is involved, Article 9(2)(b) and the substantial public interest condition for safeguarding in the Data Protection Act 2018.

Consent and capacity

Where we rely on consent, it is recorded, specific and can be withdrawn at any time. Where a person may lack capacity to make a decision about their information, we follow the Mental Capacity Act 2005, involve those with legal authority (for example a registered Lasting Power of Attorney) and act in the person’s best interests.

Keeping information secure

Data breaches

Any actual or suspected breach must be reported to the Registered Manager immediately and is recorded in our breach log. We assess the risk, take action to contain it, notify the Information Commissioner’s Office within 72 hours where the breach is likely to result in a risk to people’s rights, and inform the people affected where the risk is high. Where a breach involves the safety of someone we support, we also notify the CQC and the local authority as required.

Subject access and other rights

Requests can be made verbally or in writing to the Registered Manager. We confirm identity, respond within one calendar month, and provide the information free of charge in most cases. We record every request and the action taken.

Records retention

We follow the Records Management Code of Practice for health and social care. Care records are normally retained for eight years after our involvement ends; staff records for six years after employment ends; and enquiry records for up to two years. Records are destroyed securely.

Sharing with others

We share information only where there is a lawful reason: to deliver care safely, to meet a legal or regulatory duty, to protect someone at risk, or with the person’s consent. Suppliers who process information for us do so under a written contract that requires the same standards.

Training and review

All staff complete data protection and confidentiality training at induction and annually. This policy is reviewed at least once a year, and after any significant incident or change in the law.

Contact

Data protection queries, subject access requests and breach reports: 073 993 15159 or info@olaprestigecareservices.co.uk, or write to Prestige Care Connect, Regus House, Victory Way, Crossways Business Park, Dartford, Kent, DA2 6QD. You may also complain to the Information Commissioner’s Office at ico.org.uk or on 0303 123 1113.