GDPR and the CQC
Are CQC (Care Quality Commission) inspectors capable of assessing data protection and GDPR compliance in the care sector? From what we are seeing, it seems not. Should the CQC even be auditing data Protection? In a sector that has poor grip on data protection, should interference from the CQC lead to positive outcomes?
We sent our intrepid reporter/Managing Director, part-time comedian (not good enough to be full-time), Howard Freeman, to find out.

The inspector made his way though the documentation and made many notes. An encouraging start, we all thought as the inspection began. The care home was doing very well on care records, care plans and health and safety. Then, the inspector asked about information governance and data protection. I was keen to see how this would play out. Having not introduced myself and having been ignored by the inspector, I worked hard to contain my excitement.
Common Mistakes
Many people think they understand the GDPR. The reality is often very different. A great example is the model train company, Accurascale. They make great products but, they haven’t the first idea how to handle data. Read my report here. This has meant annoyed and uninformed customers and some interesting debates. A very common mistake so please read on.
The inspector decided to dive into the GDPR file and picked up HR first. The inspector decided that we shouldn’t keep bank details in personnel records. Interesting opinion and I decide to ask why? The reply was that it represented significant and unacceptable risk to the employee. Really, how? The explanation was that bank details were special category data, often known as sensitive data. I tried not to snigger.
We all know that financial data should be kept securely. However, the Care Sector, like many others is legally required to prove that an employee has right to work in the UK, or to be in the UK legally! The banking sector is required to go through a process known as KYC, in other words, Know Your Customer. Evidence of a UK bank account is part of an on-boarding process that proves that someone has the right to work in the UK. This evidence must be kept for the length of employment plus a retention period, set by the CQC. I asked the inspector what this period was. I was told, it doesn’t concern you. So much for transparency! A key principle of the GDPR! CQC are you listening?
No date of birth?
The next part was very interesting. We were advised that asking for an applicant’s date of birth on an application form was inappropriate. Are you kidding me??!! Ok, you would argue that knowing how old someone is could lead to prejudice based on age. Maybe.
However, if the application is progressed, identity documents will need to be produced, which I am fairly certain will have a date of birth of them. A CV can also give away age. If you left school in 1984 with some ‘O’ levels, you were probably born in 1967 or 1968. We can do the math from there.
This had to be the most pointless piece of advice/guidance ever! If they attend for interview, we can probably hazard a guess on age. Who is the inspector kidding? The truth of the matter was that the home was very well run, as so many are, and a search for faults was being carried out.
However, for factual accuracy, a visa, a passport, and a driving licence will all have dates of birth. Perhaps we shouldn’t ask for name either? Therefore, any guidance that suggests that a provider shouldn’t ask for this information, is best ignored.

The Reality
The CQC must realise that data gathering and retention is important for so many different reasons.
KYC data is vital and providers must know who they employ and that they are legally entitled to do so. Where data is stored is irrelevant as long as it is secure. HR need banking data to meet their own regulatory DPR requirements whilst finance need it in order to pay the employee. The CQC cannot and should not dictate how and where this is stored. Leave that to us!
The date of birth issue on application forms is ridiculous. There is a small chance that an applicant might be a victim of discrimination based on age. As Jerry Hunt said, we are not old, we are experienced. The sector needs experience, is all I ever hear. Therefore, discrimination based on age has a low probability. Do ask why shouldn’t a date of birth be on an application form? If you apply to join your local library, they will ask the same question. Why does the CQC think that the care sector should be excluded from recording a piece of critical identifying information?
Back to the Studio
Howard has been put back in his box and is snoozing, a little loudly but, he is calm after an exciting day in the field.
The points raised however are valid and it is not the job of the CQC to audit data protection or the GDPR. However, they may have a case for auditing compliance with the NHS Digital Security Protection Toolkit provided that the NHS has requested this.
The CQC is the independent regulator of health and adult social care in England. The ICO is the regulator for data protection.
In closing, the values of the CQC include teamwork which means working in a collaborative way to help the sector. When it comes to data protection we don’t see this, we don’t feel it and know that the CQC needs to work with us to produce the right outcomes. The inspector in this case will not be named but was not a team player and we wonder if the CQC is also a team player when it comes to integrity.
Who are we?
Fortis DPC is a specialist data protection practice servicing all areas of the care sector, delivering straightforward advice and guidance in plain English. Fortis DPC prides itself on delivery standards, a fixed price commercial modelled delivery compliance and assurance to the sector.
You can email us at [email protected] or talk to a living person on 03333 22 1011.
Leave a Reply