
How does an independent fostering agency manage information sharing?
An independent fostering agency manages information sharing under UK data protection law, keeping accurate records and sharing only relevant information with authorised professionals involved in a child’s care. Information may be shared with consent or where safeguarding, legal or regulatory duties require it, using secure procedures to protect children, foster carers and applicants.
Partnering with an
Ofsted Outstanding Provider
An independent fostering agency manages information sharing through defined roles, documented procedures and regular oversight. The aim is to ensure that each person involved in a child’s care has the information needed to make safe decisions, while preventing unnecessary access to private details. This includes information about children, foster carers, applicants, birth families and other members of a household.
The agency’s information governance arrangements normally set out:
- which types of information may be collected and why;
- who is responsible for recording, checking and updating it;
- which professionals may access particular records;
- when information can be disclosed to someone outside the agency;
- how decisions to share or withhold information are recorded; and
- how long records are kept before secure disposal or review.
These arrangements are based on the UK General Data Protection Regulation and the Data Protection Act 2018, alongside safeguarding duties and social care requirements. Data protection is not intended to prevent professionals from sharing information that is necessary to protect a child. It requires the agency to identify a lawful and proportionate reason, use the information for an appropriate purpose and avoid disclosing more than is needed.
Information is usually organised around the child’s care plan and the people who need to act on it. Records may include assessment material, household checks, training and supervision notes, placement information, health details, education information, contact arrangements, significant events and records of decisions. Sensitive information is handled carefully because an apparently minor detail may identify a child, reveal a birth family’s circumstances or affect the safety of a placement.
Access should be based on job role and involvement rather than general interest. For example, a supervising social worker may need access to information relevant to supporting a foster household, while an administrator may only need limited details to maintain a particular record. Managers and safeguarding leads may review information where a concern, allegation or significant incident requires oversight. Systems should provide an audit trail so that access, amendments and disclosures can be investigated where necessary.
Sharing with foster carers is an important part of safe placement planning. Carers need clear, usable information about a child’s needs, routines, health, education, relationships, known risks and agreed strategies. They may also need information about contact with parents or other people who are important to the child. The agency and placing authority should consider what the carer needs to know before accepting a placement and what further information should be provided as circumstances change.
That does not mean a foster carer receives unrestricted access to every document. Information about other people, historic events or confidential professional assessments may need to be summarised, redacted or shared only with those who have a specific responsibility. Carers should be given guidance on storing records, discussing a child’s circumstances, using digital devices and avoiding disclosure through social media or informal conversations. They should also know who to contact when they believe important information is missing or inaccurate.
Information may be shared between the agency and other professionals involved in the child’s welfare, such as the placing authority, social workers, schools, health services, police or safeguarding bodies. Good practice is to share through an agreed professional route, confirm the recipient’s identity and record what was disclosed, to whom, for what purpose and on what basis. Verbal disclosures should normally be followed by a written record, particularly where they affect risk management, contact, health or placement decisions.
Consent is considered carefully rather than treated as the answer to every sharing decision. Where appropriate, the child, parent, foster carer or applicant may be told what information is being collected and how it will be used. A person’s agreement may be relevant to routine or optional sharing. However, consent may not be necessary where disclosure is required by law, needed to protect a child or another person, or necessary for a professional to carry out a safeguarding responsibility. If consent is refused but the risk requires disclosure, the agency should document the reasoning and share only the information that is justified.
Children should be involved in information decisions in a way that reflects their age, understanding and communication needs. Staff should explain, as far as possible, who will be told information and why. A child’s wishes and feelings matter, but confidentiality cannot be promised if information indicates that the child or someone else may be at risk. The agency may also need to balance a child’s privacy with a foster carer’s need to understand and manage a safeguarding concern.
Applicants and foster carers have privacy rights over information held about them. They can ask how their information is used and may be able to request access to their records, correction of inaccurate information or clarification of the agency’s retention arrangements. Access requests can be subject to legal restrictions, especially where disclosure would reveal another person’s confidential information or create a safeguarding risk. The agency should explain any limitation and consider whether information can be released in an edited form.
Records must be kept accurate, relevant and distinguish between fact, professional assessment, allegation and opinion. When information is disputed, the record should not simply be deleted if it forms part of the safeguarding history. Instead, the disagreement and any later clarification may need to be added so that future readers can understand the context. Significant decisions should include the evidence considered, the people consulted and the reasons for the outcome.
Retention is also part of information management. An agency follows its retention schedule and applicable social care requirements, keeping records for an appropriate period because they may be needed for ongoing care, complaints, legal proceedings, regulatory review or a later request for a person’s history. When records no longer need to be retained, disposal should prevent reconstruction or unauthorised access.
If information is sent to the wrong person, lost, accessed without permission or disclosed too widely, the agency should treat this as a data incident. Its procedure should include containing the problem, assessing the possible harm, notifying relevant internal leads and deciding whether the Information Commissioner’s Office or affected individuals must be informed. Safeguarding action takes priority where the incident could place a child or another person at risk.
When assessing an independent fostering agency, ask how it explains information use, how foster carers receive essential placement details, how children are supported to understand confidentiality, how access is controlled and how concerns about inaccurate or missing information are handled. Clear answers indicate that information sharing is being managed as part of safe care and professional accountability, rather than as an informal exchange between individuals.

Independent fostering agencies should anonymise information when people do not need to know a child’s identity to perform their role. This is particularly relevant to staff training, audits, service reviews and policy development, where learning can often be shared without disclosing names, addresses, schools or other identifying details.
Where information is pseudonymised rather than fully anonymised, it can still be personal data if someone with access to the identifying key could work out who the record concerns. It must therefore remain protected, with access limited to authorised staff. Documents prepared for meetings or review should contain only the detail needed for that purpose, while papers containing identifiable information should be shared through approved secure systems.
When assessing an agency, ask how it separates information used for a child’s direct care from information used for wider learning. A sound approach includes checks for indirect identifiers, clear approval before records are circulated and a process for correcting or withdrawing material that reveals more than intended.
Find out how we manage information sharing
If you are considering fostering, contact Become A Foster Family to discuss how information is handled and ask any questions before you apply.
