Information Sharing Policy for Safeguarding Children, Young People and Vulnerable Adults
- Purpose
The purpose of this policy is to ensure that all staff understand their responsibilities regarding the sharing of information to safeguard and promote the welfare of children, young people and vulnerable adults.
The practice recognises that effective information sharing is essential for identifying risks, preventing harm and ensuring appropriate support and protection for vulnerable individuals. This policy supports compliance with NHS safeguarding requirements, the Data Protection Act 2018, UK General Data Protection Regulation (UK GDPR), Caldicott Principles and national safeguarding guidance.
- Scope
This policy applies to all employees, partners, locums, trainees, contractors and volunteers working within the practice.
It covers the sharing of information relating to:
- Children and young people.
- Vulnerable adults and adults at risk.
- Families and carers where safeguarding concerns exist.
- Requests for information from external agencies involved in safeguarding investigations or enquiries.
- Policy Statement
The practice is committed to working collaboratively with partner agencies to safeguard children, young people and vulnerable adults.
Information-sharing protocols, in line with national and local guidance, are in place within the practice. Staff must follow these protocols whenever safeguarding concerns arise, or information is requested by authorised agencies.
The welfare and safety of children, young people and vulnerable adults will always be a primary consideration when determining whether information should be shared.
- Principles of Information Sharing
The practice will ensure that information shared:
- Is necessary, proportionate, relevant, accurate and timely.
- Is shared only with those who have a legitimate need to know.
- Supports the prevention, detection or investigation of abuse, neglect or exploitation.
- Complies with applicable legislation and professional guidance.
- Is appropriately documented within the patient record.
Consent should be sought wherever possible unless:
- Seeking consent would place the individual or another person at increased risk of harm.
- It would prejudice the prevention, detection or prosecution of a serious crime.
- There is a statutory duty or legal basis to share information without consent.
- The public interest in safeguarding outweighs the individual’s right to confidentiality.
- Requests from External Agencies
The practice is clear about how to handle requests from outside agencies asking to share information about vulnerable children, young people or adults.
Requests may be received from:
- Children’s Social Care.
- Adult Social Care.
- Multi-Agency Safeguarding Hubs (MASH).
- Police.
- NHS safeguarding teams.
- Education services.
- Domestic abuse services.
- Other authorised safeguarding professionals.
When requests are received, staff must:
- Verify the identity and authority of the requester.
- Determine the lawful basis for sharing information.
- Consult the Safeguarding Lead, Caldicott Guardian, GP Partner or Practice Manager where necessary.
- Share only information relevant to the safeguarding concern.
- Record the request, decision-making process and information disclosed within the patient’s record.
- Respond promptly where there is a risk of significant harm or immediate safeguarding concern.
Where there are concerns regarding a child’s safety or an adult at risk, information may be shared without consent if this is necessary to protect them from abuse or neglect.
- Data Protection and Confidentiality
All staff are aware of Data Protection and Confidentiality issues in relation to safeguarding requirements.
The Data Protection Act 2018 and UK GDPR need to be considered where personal information is shared. However, data protection legislation should not be viewed as a barrier to appropriate safeguarding information sharing.
Staff must ensure that:
- Information is processed lawfully, fairly and transparently.
- Only relevant information is shared.
- Information is transferred securely.
- Confidential records are protected at all times.
- Decisions to share or not share information are documented.
The practice will follow NHS, Information Commissioner’s Office (ICO), and local Integrated Care Board (ICB) guidance regarding information governance and safeguarding.
- Staff Responsibilities
All staff must:
- Complete safeguarding and information governance training appropriate to their role.
- Recognise situations where information sharing may be necessary to protect vulnerable individuals.
- Follow local safeguarding procedures.
- Seek advice from the Safeguarding Lead if unsure.
- Maintain appropriate records of safeguarding concerns and information sharing decisions.
Safeguarding Leads will provide advice and support regarding complex information-sharing decisions.
- Informing Patients and the Registered Population
The registered population are informed of the practice’s information-sharing policy with regard to safeguarding children, young people and vulnerable adults.
Information will be made available through:
- The practice website.
- Practice notice boards and waiting room displays.
- Other patient communication channels as appropriate.
Patients will be informed that:
- Their personal information is treated confidentially.
- Information may be shared without consent where safeguarding concerns exist.
- The practice has a legal and professional duty to protect children, young people and vulnerable adults from harm.
- Record Keeping
All safeguarding information-sharing activities must be recorded accurately, including:
- The nature of the concern.
- Information requested or shared.
- Who information was shared with.
- The legal basis for sharing.
- Whether consent was obtained or why it was not sought.
- Advice received from safeguarding or information governance leads.
Records should be contemporaneous, factual and stored securely within the clinical record.
- Monitoring and Review
This policy will be reviewed every year, or sooner if there are changes to:
- National safeguarding guidance.
- NHS requirements.
- Data protection legislation.
- Local safeguarding partnership procedures.
The Practice Manager and Safeguarding Lead are responsible for ensuring the policy remains current and effective.
