Record keeping and data protection
Writing daily logs and incident records that stand up to scrutiny, and handling children's personal data lawfully under UK GDPR.
- Who receives it
- All staff
- Frequency
- Annual
- Delivery
- E-learning
- Evidence recorded
- Training register, certificate
Learning outcomes
- Write factual, contemporaneous records free of opinion and jargon
- Apply the UK GDPR principles to children's records
- Share information appropriately without breaching confidentiality
- Respond correctly to a request from a child to see their file
Module 1 of 3
Records children will one day read
Care-experienced adults routinely request their childhood files. What you write today may be read by that person in twenty years' time. Write about them, not around them: describe behaviour and context, avoid labels such as 'attention seeking' or 'manipulative', and record their strengths and good days as carefully as their difficult ones.
Records must be contemporaneous — written the same shift — factual, and clearly distinguish what you saw, what you were told, and what you concluded. Sign, date and time every entry. Never alter an earlier entry; add a correcting entry instead.
Remember
- Fact, not opinion: 'shouted and threw a cup' rather than 'was aggressive'
- Quote the child's own words in a disclosure
- Never backdate or overwrite an entry
Module 2 of 3
UK GDPR in practice
Children's care records include special category data — health, ethnicity, sexuality, religion — which requires extra care. Only access records for children you are working with, and only share what the recipient needs to know for their role.
Confidentiality is never a reason to withhold a safeguarding concern. Data protection law explicitly permits sharing to protect a child from harm; the greater risk is failing to share.
Module 3 of 3
Access and breaches
A child of sufficient understanding, or their representative, can make a subject access request. Do not respond yourself: pass it to the manager, who has one calendar month to respond and must consider third-party information.
Report any breach — an email sent to the wrong person, a lost notebook, a file left in a car — to the manager immediately. Serious breaches must reach the ICO within 72 hours, so delay is what turns a mistake into a failure.
Sign in to record your completion
You can read the course now, but you need a staff account for your completion and certificate to be saved and shared with your manager.
Staff sign inKnowledge check
Answer all 3 questions correctly to record this module against your training log.
