Information Security Policy
Policy Name Module: Information Security
Module: Human Resources
Statement of purpose
The security of personal data is a top priority for Silomarg Ltd. We are committed to safeguarding the confidentiality, integrity, and availability of all personal data we hold, particularly data relating to the health, care, and well-being of our service users. This policy outlines how we manage and protect personal data in line with applicable UK legislation, including the General Data Protection Regulation (GDPR) and the Data Protection Act 2018.
This Information Security Policy applies to all employees, contractors, and third parties who have access to personal data processed by Silomarg Ltd. It covers all data processing activities, whether carried out in our offices, remotely, or in clients’ homes, and applies to electronic and physical data.
This policy ensures compliance with the following legislation:
UK General Data Protection Regulation (UK GDPR)
Data Protection Act 2018
Privacy and Electronic Communications Regulations (PECR)
Care Quality Commission (CQC) Regulations
The objectives of this Information Security Policy are:
To protect personal data from unauthorised access, loss, or damage.
To ensure compliance with GDPR and Data Protection Act requirements.
To provide employees and contractors with clear guidance on how to handle personal data securely.
To reduce the risk of data breaches and other security incidents.
It is the overall responsibility of the Registered Manager, Leah Margolis to ensure that all Staff have read and signed (as understood) this policy for Silomarg Ltd, and that it is implemented consistently in daily practice. It is the overall responsibility of every staff member to follow this policy and procedure. Failure to do so may lead to disciplinary action.
A current copy of the policy will be available electronically and in the Office.
This policy will be reviewed at least annually, or more frequently if significant changes occur.
The person accountable for this Policy/Procedure is Leah Margolis.
The Nominated Individual for Silomarg Ltd is Leah Margolis.
This Policy / Procedure was last updated on 20/07/2026.
This Policy / Procedure is due to be reviewed on 19/07/2027.
Policy Responsibilities
Data Protection Officer (DPO): The DPO is responsible for overseeing data protection strategy and implementation to ensure compliance with GDPR and other relevant regulations.
Management: Silomarg Ltd’s management team is responsible for ensuring that appropriate technical and organisational measures are in place to protect personal data.
Employees: All employees must follow this policy and any related procedures to protect personal data.
Data Security Principles
Silomarg Ltd adhere to the following key data protection principles outlined in Article 5 of the GDPR:
Lawfulness, fairness, and transparency: Data must be processed lawfully, fairly, and in a transparent manner.
Purpose limitation: Data must be collected for specified, explicit, and legitimate purposes.
Data minimisation: Data must be adequate, relevant, and limited to what is necessary.
Accuracy: Data must be accurate and kept up to date.
Storage limitation: Data must be kept only for as long as necessary.
Integrity and confidentiality: Data must be processed in a manner that ensures appropriate security, including protection against unauthorized or unlawful access.
Data Handling Procedures
Data Collection
Personal data should be collected only for legitimate business or care-related purposes and with the explicit consent of the data subject, unless another lawful basis for processing applies (e.g., the provision of care services).
Data Access Control
Access to personal data will be restricted to authorised employees only and on a need-to-know basis.
Role-based access controls (RBAC) will be implemented to ensure that employees can only access the information necessary for their role.
Strong passwords and multi-factor authentication (MFA) will be required for accessing any sensitive data.
Data Storage
Personal data should be stored securely using encryption and password protection on all devices and storage media.
Physical files should be locked in secure storage when not in use, and access should be restricted to authorised personnel.
Data Sharing
Personal data will only be shared with third parties where a lawful basis exists (e.g., with healthcare providers) and where a data sharing agreement is in place.
When sharing data electronically, encryption or secure file transfer methods (e.g., NHS secure email) must be used.
Data Retention
Personal data will be retained for no longer than is necessary, in line with legal and regulatory obligations. The agency will implement a data retention schedule based on the Care Quality Commission (CQC) and GDPR requirements.
Data Subject Rights
All data subjects have the following rights, which the agency will honour:
Right of access: To obtain a copy of their personal data.
Right to rectification: To correct any inaccuracies in their data.
Right to erasure (right to be forgotten): To request the deletion of their data, subject to legal constraints.
Right to restrict processing: To limit the way their data is used.
Right to data portability: To receive their data in a machine-readable format.
Right to object: To object to certain types of data processing.
Requests from data subjects will be handled promptly, and within the statutory 30-day period where applicable.
Data Breach Response
In the event of a data breach:
All breaches, whether actual or suspected, must be reported immediately to the Data Protection Officer (DPO).
The DPO will assess the breach and, if necessary, notify the Information Commissioner’s Office (ICO) within 72 hours of becoming aware of the breach.
Affected data subjects will be informed where required by law.
The agency will take immediate action to mitigate the impact of the breach and prevent future incidents.
Training and Awareness
All employees must receive regular data protection and information security training, including GDPR awareness, secure handling of personal data, and best practices for using agency systems and devices.
The agency will promote a culture of data security and ensure that all personnel are aware of their responsibilities under this policy.
Third-Party Suppliers
All third-party suppliers who process personal data on behalf of the agency must adhere to the same standards of data protection and security.
Contracts with third-party processors must include specific provisions for data protection, including adherence to GDPR requirements.
Monitoring and Review
The Data Protection Officer (DPO) will regularly review the agency’s information security practices to ensure compliance with this policy and UK legislation.
This policy will be reviewed annually or after any significant change in legislation, operational processes, or following a data breach.
Consequences of Non-Compliance
Failure to comply with this policy may result in disciplinary action, up to and including termination of employment, and may also result in personal liability under UK data protection laws.
Contact Information
For any questions or concerns regarding this policy or data protection practices, employees and data subjects should contact the agency’s Data Protection Officer:
Name: Leah Margolis
Email: leah.margolis@silomarg.co.uk
Phone: 07454 232181, 07445502088
Relevant Legislation
http://www.legislation.gov.uk/ukpga/2018/12/contents/enacted
Data Protection 2018
http://www.legislation.gov.uk/ukpga/2000/36/contents
Freedom of information Act 2000
http://www.legislation.gov.uk/ukpga/2014/23/contents/enacted
The Care Act 2014
http://www.legislation.gov.uk/ukpga/1998/42/contents
Human Rights Act 1998
http://www.legislation.gov.uk/ukpga/2005/9/contents
Mental Capacity Act 2005
http://www.legislation.gov.uk/ukpga/1990/18/contents
The Computer Misuse Act 1990
http://www.legislation.gov.uk/ukpga/1998/23/contents
Public Interest Disclosure Act 1998
http://www.legislation.gov.uk/ukpga/2015/28/contents/enacted
Health and Social Care (Safety & Quality) Act 2015
Relevant Regulations
https://ico.org.uk/
Information Commissioner’s Office
https://www.scie.org.uk/publications/adultsafeguardinglondon/informationsharing/legalframework.asp
Common Law Duty of Confidentiality
https://www.gov.uk/government/publications/guide-to-the-general-data-protection-regulation
General Data Protection Regulation 2018 (GDPR)
https://www.legislation.gov.uk/uksi/2014/2936/contents/made
The Health and Social Care Act 2008 (Regulated Activities) Regulations 2014
http://static.ukcgc.uk/docs/code.pdf
NHS Digital (formally HSCIC) Code of Practice on Confidential Information 2014
https://digital.nhs.uk/data-and-information/looking-after-information/data-security-and-information-governance/codes-of-practice-for-handling-information-in-health-and-care/a-guide-to-confidentiality-in-health-and-social-care
NHS Digital (formally HSCIC) Guide to confidentiality 2013
https://digital.nhs.uk/data-and-information/looking-after-information/data-security-and-information-governance/codes-of-practice-for-handling-information-in-health-and-care/records-management-code-of-practice-for-health-and-social-care-2016
Records Management Code of Practice for Health and Social Care 2016
https://www.cqc.org.uk/sites/default/files/20150324_guidance_providers_meeting_regulations_01.pdf
Regulation 9: Person-centred care
Regulation 10: Dignity and respect
Regulation 11: Need for consent
Regulation 17: Good governance
Regulation 20: Duty of candour
https://www.skillsforcare.org.uk/Documents/Topics/Digital-working/Information-sharing-for-social-care-employers.pdf
Information Sharing for Social Care Employers/ Skills For Care
https://www.legislation.gov.uk/uksi/2000/2699/contents/made
Telecommunications (Lawful Business Practice) (Interception of Communications) Regulations 2000
Quality Statements
• We maximise the effectiveness of people’s care and treatment by assessing and reviewing their health, care, wellbeing and communication needs with them.
• We plan and deliver people’s care and treatment with them, including what is important and matters to them. We do this in line with legislation and current evidence-based good practice and standards.
• We work effectively across teams and services to support people. We make sure they only need to tell their story once by sharing their assessment of needs when they move between different services.
• We support people to manage their health and wellbeing so they can maximise their independence, choice and control. We support them to live healthier lives and where possible, reduce their future needs for care and support.
• We work with people to understand what being safe means to them as well as with our partners on the best way to achieve this. We concentrate on improving people’s lives while protecting their right to live in safety, free from bullying, harassment, abuse, discrimination, avoidable harm and neglect. We make sure we share concerns quickly and appropriately.
• We work with people to understand and manage risks by thinking holistically so that care meets their needs in a way that is safe and supportive and enables them to do the things that matter to them.
• We have a proactive and positive culture of safety based on openness and honesty, in which concerns about safety are listened to, safety events are investigated and reported thoroughly, and lessons are learned to continually identify and embed good practices.
• We work with people and our partners to establish and maintain safe systems of care, in which safety is managed, monitored and assured. We ensure continuity of care, including when people move between different services.
• We detect and control potential risks in the care environment. We make sure that the equipment, facilities and technology support the delivery of safe care.
• We assess and manage the risk of infection. We detect and control the risk of it spreading and share any concerns with appropriate agencies promptly.
Key Lines of Enquiry KLOE
SAFE: How do systems, processes and practices keep people safe and safeguarded from abuse?
• Do staff have all the information they need to deliver safe care and treatment to people?
Effective: How are people’s care and treatment outcomes monitored and how do they compare with other similar services?
• Is consent to care and treatment always sought in line with legislation and guidance?
• How well do staff, teams and services work together within and across organisations to deliver effective care and treatment?
Caring: How are people’s privacy, dignity and independence respected and promoted?
Well-led: Are there clear responsibilities, roles and systems of accountability to support good governance and management?
• Are there clear and effective processes for managing risks, issues and performance?
• Is appropriate and accurate information being effectively processed, challenged and acted on?
• Are there robust systems and processes for learning, continuous improvement and innovation?