← Back to DataForte UK

Most of the data governance issues I find during an audit didn't happen overnight. They built up quietly, one shortcut at a time, while everyone was focused on rotas, care plans, and keeping the service running. By the time CQC or the ICO comes looking, they're no longer small. Here are the five I see most often, and what to do about each one before an inspector finds it first.

01 Care records stored on personal devices

A support worker photographs a wound on their own phone to send to a nurse. A manager keeps a spreadsheet of service user contacts on their personal laptop "just for convenience." Individually, these feel harmless. Collectively, they mean sensitive personal data is sitting outside your organisation's control, unencrypted, and outside any audit trail.

The fix: a clear, written policy on approved devices and apps for handling personal data, paired with a simple, secure way for staff to actually do their jobs without needing to work around it.

02 A policy that exists on paper but not in practice

Almost every provider I meet has a data protection policy. Far fewer can tell me the last time staff were tested on it, or show me evidence that it reflects how the service actually operates day to day. CQC inspectors don't just want to see a document. They want to see it lived.

The fix: review your policy against real working practices at least annually, and keep a simple record of when staff last engaged with it.

03 Sharing information without a clear basis

Family members ask for updates. Other agencies request records. Local authorities want reports. Each of these can be legitimate, but "we've always just sent it over" isn't a lawful basis, and it isn't a defensible answer if the ICO asks why.

The fix: a straightforward information-sharing protocol that staff can actually follow, so every disclosure has a documented reason behind it.

04 No real audit trail

Who accessed a service user's file, and when, and why? If that question makes you pause, you're not alone; it's one of the most common gaps I find. Without an audit trail, you can't demonstrate accountability, and you can't respond quickly or confidently to a subject access request.

The fix: systems and processes that log access as a matter of routine, not something bolted on after a request lands.

05 Training that happened once, years ago

Data protection training during induction is a good start. It isn't enough on its own. Staff turnover, new technology, and evolving risks all mean a single session from years back won't hold up to scrutiny, and more importantly, it won't hold up in practice.

The fix: short, scenario-based refreshers that reflect real situations your team actually faces, delivered regularly rather than once and forgotten.

None of these five require a huge overhaul. They require someone looking closely enough to spot them before an inspector, a family member, or the ICO does it for you. That's exactly the work I do with supported living and domiciliary care providers: a structured look at where the gaps are, in plain English, with a realistic plan to close them.

Not sure where your organisation stands?

A free 30-minute discovery call is the easiest way to find out. No obligation, no jargon.

Book a Free Discovery Call