Data Protection and Safeguarding

It is important to note that UK Data Protection law provides no barrier to voicing concerns to a safeguarding authority when it concerns vulnerable children and adults. 

In fact, UK law provides a pathway to allow you to make an assessment of the risk to the data subjects, along with the process of sharing with others who can provide protection.

Following the death of Arthur Labinjo-Hughes, and subsequent jailing of his Father and Step-Mother for his death, I wanted us to highlight that Data Protection Law is no barrier to sharing information with safeguarding teams.  Whilst public authorities need express powers to share information, I have adapted a scenario to show a logical flow of actions a Data Controller can take to ensure that they “share” concerns first.

This follows a logical flow of management actions that justifies sharing. We await the public inquiry to determine if this was the case but there is form.

Is data protection law a hindrance?

In my studies, I have seen serious case reviews highlight the risk of professionals caught like rabbits in headlights fearing Data Protection Law a hindrance. This is not the first such horrific case of child abuse. In 2000, Victoria Climbié died after being admmitted to hospital with 128 different injuries, caused by adults who should have been providing care.  Those adults were eventually sent to prison for her murder. A public inquiry led by Lord Laming changed the way authorities deals with these cases.

In an official inquiry report into her death and the failings of the system, it was stated that professionals were reluctant to share information on her welfare which contributed to her death.  Lord Laming stated in s.146 of the report:

However, I was told that the free exchange of information about children and families about whom there are concerns is inhibited by the legislation on data protection and human rights. It appears that, unless a child is deemed to be in need of protection, information cannot be shared between agencies without staff running the risk of contravening this legislation. This has two consequences: either it deters information sharing, or it artificially increases concerns in order that they can be expressed as the need for protection.  (s.146  The Victoria Climbié Inquiry)

The full report can be read here.

Data sharing for public authorities

We at DPAS run a Data Sharing Course, but it might be timely to develop this course further to support Public Authorities.  This may help them understand the legal gateway allowing them to share information relating to those at risk.  In the meantime I hope the scenario will assist in understanding some of the main considerations and learning points required in these situations. 

However in conclusion my request to you is simple. “If in doubt, share!”

Keep attacking.

If you’re interested in attending any of the courses that we offer, you can see our upcoming events here.

To get in touch, feel free to use our contact form, or call 0203 3013384.

Meet the Team Nigel Gooding

by Nigel Gooding, LLM Information Rights Law & Practice

Nigel is founder of the Data Privacy Advisory Service, and he plays a vital part in our success. Due to his extensive experience, Nigel is recognised as a leading expert in the industry.

related posts

Alex Haslam

How to Report a Data Breach: A Practical Guide

A practical guide to data breach reporting under UK GDPR, covering when you must notify the ICO, how to report a breach (and what to do if you don’t need to), and when affected individuals need to be told. Includes the key steps, timeframes, and documentation requirements to keep your organisation compliant.

Read More »
Jack Penaligon

How to Respond to a Data Breach: A Practical Guide

This blog provides an overview of the practical steps organisations can take to reduce the impact of a data breach once it has been identified. It focuses on the actions that should be taken during the early stages of an incident to contain the breach, protect affected individuals, and meet regulatory requirements.

The article discusses a range of mitigation measures, including contacting unintended recipients of personal data, securing the deletion or recovery of exposed information, isolating compromised systems, and maintaining clear records of actions taken. It also explores the challenges posed by both digital and physical data breaches, highlighting the importance of balancing operational needs with data protection obligations.

Finally, the blog emphasises the value of preparation, explaining how established procedures, communication templates, and predefined response plans can help organisations respond more effectively and demonstrate accountability during a regulatory investigation.

Read More »
Noah de Wild

How to Assess a Data Breach: A Practical Guide

This blog explains how to assess a data breach by identifying its cause, determining what information was exposed, and evaluating the potential impact on affected individuals and the organisation. It outlines common causes of breaches, the importance of understanding the type and scale of compromised data, and how assessing the timeline of an incident can help businesses respond effectively, meet legal obligations, and reduce long-term risks.

Read More »

Get a Free Consultation