Confidentiality Policy
Date Adopted: August 2025
Review Date: July 2026
1. Purpose
To protect the privacy and dignity of carers, families, staff, and volunteers by ensuring that all personal, health, and safeguarding-related information shared with Lighthouse Dementia Support is treated with respect, discretion, and legal compliance.
2. Scope
This policy applies to all trustees, staff, volunteers, and contractors. It covers all forms of confidential information, including:
- Personal details (e.g., name, contact information)
- Health and care-related information
- Safeguarding concerns or disclosures
- Internal organisational matters (e.g., HR, governance)
3. Legal Framework
Lighthouse Dementia Support complies with:
- UK General Data Protection Regulation (UK GDPR)
- Data Protection Act 2018
- Charity Commission guidance on safeguarding and governance
4. Principles
Trust and Respect: Information shared in confidence must be protected.
Consent-Based Disclosure: Information will only be shared externally with explicit consent, unless there is a safeguarding or legal obligation.
Need-to-Know Basis: Access to confidential information is restricted to those who need it to perform their role.
Transparency: Carers and families will be informed how their information is used and stored.
5. Definitions
Confidential Information includes any data or conversation that is not publicly available and is shared in a context of trust. This may be written, verbal, or digital.
Disclosure refers to the sharing of confidential information with a third party, including statutory agencies.
6. Procedures
- All staff, volunteers, and trustees must sign a Confidentiality Agreement upon induction.
- Records are stored securely:
- Digital: Password-protected systems with restricted access
- Physical: Locked cabinets in secure locations
- Any breach of confidentiality must be reported immediately to the CEO and Designated Safeguarding Lead (DSL).
- Decisions about disclosure (e.g., in safeguarding cases) will follow the Safeguarding Policy and be documented.
Carers and families will be given a Privacy Notice explaining how their data is used.
7. Roles and Responsibilities
CEO Oversees policy implementation and breach response
DSL Leads safeguarding-related disclosures
Staff & Volunteers Uphold confidentiality and report concerns
Trustees Monitor compliance and review policy annually
8. Training and Review
- Confidentiality is covered in induction training for all roles.
- Refresher training is provided annually or when policies change.
- This policy is reviewed annually by the board of trustees.
