Development policy

Confidentiality and information sharing

People deserve privacy and an honest explanation of its limits. Confidentiality is important, but it is not an absolute promise when safety or law requires information to be shared.

VersionDraft 0.1
Prepared4 August 2026
Current ownerFounder during development
ApprovalRequired before services begin

Purpose and scope

This draft applies to founders, future trustees or directors, staff, volunteers, contractors and peer supporters. It covers conversations, emails, meetings, online groups, notes and information received from another organisation.

Our starting principles

  • Be clear at the start about what can and cannot remain private
  • Collect and share the minimum information needed for a clear purpose
  • Use consent where appropriate, but never suggest consent is the only possible basis for safeguarding action
  • Respect people’s dignity and avoid gossip, informal case discussion or curiosity-led access
  • Record important decisions to share—or not share—and the reasons
  • Tell the person what was shared where it is safe and appropriate to do so

When information may be shared

Information may be shared without consent where there is a lawful and proportionate reason, including a concern that a child or adult may be at risk, an immediate threat to life, a legal requirement or a serious crime. The safeguarding lead should normally guide the decision unless delay could increase danger.

A disclosure must never be investigated by a peer supporter. Listen, clarify only what is necessary, avoid promising secrecy, record the person’s own words where possible and pass the concern through the agreed route.

How decisions will be made

  1. Identify the purpose.What risk or need are we trying to address?
  2. Check authority and necessity.What lawful basis applies, and is sharing necessary and proportionate?
  3. Choose the minimum.Share only relevant, accurate and timely information with the right person.
  4. Act safely.Do not alert someone if that could increase risk or undermine a lawful enquiry.
  5. Record and review.Note what was decided, who received information, when, why and any follow-up.

Secure practice

Personal information must not be stored in personal messaging accounts, shared devices or unapproved cloud folders. Group participants must not record sessions, copy messages or share another person’s story. Access will be role-based and removed promptly when a role ends.

Guidance informing this draft

DfE information-sharing advice for safeguarding practitioners and ICO safeguarding data-sharing guidance.