← All courses
Care practiceMandatoryApprox. 45 min

Record keeping and data protection

Writing daily logs and incident records that stand up to scrutiny, and handling children's personal data lawfully under UK GDPR.

Who receives it
All staff
Frequency
Annual
Delivery
E-learning
Evidence recorded
Training register, certificate

Learning outcomes

  • Write factual, contemporaneous records free of opinion and jargon
  • Apply the UK GDPR principles to children's records
  • Share information appropriately without breaching confidentiality
  • Respond correctly to a request from a child to see their file

Module 1 of 3

Records children will one day read

Care-experienced adults routinely request their childhood files. What you write today may be read by that person in twenty years' time. Write about them, not around them: describe behaviour and context, avoid labels such as 'attention seeking' or 'manipulative', and record their strengths and good days as carefully as their difficult ones.

Records must be contemporaneous — written the same shift — factual, and clearly distinguish what you saw, what you were told, and what you concluded. Sign, date and time every entry. Never alter an earlier entry; add a correcting entry instead.

Remember

  • Fact, not opinion: 'shouted and threw a cup' rather than 'was aggressive'
  • Quote the child's own words in a disclosure
  • Never backdate or overwrite an entry

Module 2 of 3

UK GDPR in practice

Children's care records include special category data — health, ethnicity, sexuality, religion — which requires extra care. Only access records for children you are working with, and only share what the recipient needs to know for their role.

Confidentiality is never a reason to withhold a safeguarding concern. Data protection law explicitly permits sharing to protect a child from harm; the greater risk is failing to share.

Module 3 of 3

Access and breaches

A child of sufficient understanding, or their representative, can make a subject access request. Do not respond yourself: pass it to the manager, who has one calendar month to respond and must consider third-party information.

Report any breach — an email sent to the wrong person, a lost notebook, a file left in a car — to the manager immediately. Serious breaches must reach the ICO within 72 hours, so delay is what turns a mistake into a failure.

Sign in to record your completion

You can read the course now, but you need a staff account for your completion and certificate to be saved and shared with your manager.

Staff sign in

Knowledge check

Answer all 3 questions correctly to record this module against your training log.

  1. 1. Which entry is written correctly?
  2. 2. You realise you emailed a child's report to the wrong address. What do you do?
  3. 3. Confidentiality means you should never share information about a child. True or false?