Consent, Privacy and Information Governance in Person-Centred Technology
Person-centred technology only strengthens independence when people remain in control of what is used, what is shared, who can see information and what happens if they say no. Consent, privacy and information governance must therefore sit at the heart of digital enablement rather than being treated as background IT processes.
As digital systems become increasingly embedded within adult social care, providers are expected to demonstrate not only technical compliance but also how consent, privacy and individual choice are protected in practice. Organisations developing their approach can explore the wider Digital Transformation in Social Care Knowledge Hub, which examines digital governance, cyber resilience, artificial intelligence, data management and person-centred technology across adult social care.
This applies across Person-Centred Technology and must align with robust Digital Records, Data Quality and Information Governance. It also connects closely to Digital Safeguarding and Technology-Enabled Harm and Mental Capacity, Consent and Best Interests Decisions, because digital tools can affect privacy, autonomy, risk, rights and daily decision-making.
Why Consent and Privacy Matter in Person-Centred Technology
Technology can be enabling. It can help people remain at home, reduce unnecessary staff prompts, support community access, improve safety, strengthen communication and provide reassurance. However, the same technology can become intrusive if it is introduced without proper consent, explanation, review and governance.
A sensor may support safety, but it may also feel like surveillance. GPS tracking may support independence, but it may also restrict privacy if used too broadly. Family access to digital records may provide reassurance, but it may also expose personal information the person does not want shared. Digital prompts may support routines, but they may also become controlling if the person cannot opt out or adapt them.
The core principle is simple: technology should support the person’s life, not make the person fit around the system.
What Consent Looks Like in Day-to-Day Delivery
In adult social care, consent for technology is rarely static. People’s confidence, capacity, circumstances, risks, preferences and tolerance for monitoring can change over time. Providers must therefore treat consent as an ongoing, reviewable agreement rather than a one-off signature obtained at installation.
Operationally, staff must be able to explain:
- what the technology does
- why it is being used
- what data it collects
- who can see that data
- how long information is retained
- what happens if the system alerts staff
- what alternatives exist
- how the person can refuse or withdraw consent
Just as importantly, people must be able to withdraw consent without fear that support will be reduced, withdrawn or made conditional on digital compliance. If a person says no, the provider should have a safe alternative support plan.
Consent Is Not the Same as Compliance
One of the risks in digital enablement is confusing acceptance with consent. A person may tolerate a device because staff say it is necessary. They may not understand what information is being collected. They may agree because family members are anxious. They may stop objecting because they feel their concerns are not heard.
True consent requires understanding, choice and freedom to refuse. Providers should be especially cautious where people have communication needs, cognitive impairment, learning disabilities, dementia, acquired brain injury, autism, mental health needs or fluctuating capacity.
Strong services check whether the person understands the technology in a way that is meaningful to them. This may require accessible information, pictures, demonstration, social stories, video explanation, supported decision-making, interpreter support or involvement from someone who knows the person well.
Mental Capacity and Best Interests
Where there is doubt about capacity, providers must consider whether the person can understand, retain, use or weigh the relevant information and communicate their decision. The decision must be specific to the technology being proposed.
For example, a person may have capacity to consent to medication reminders but not fully understand a more complex remote monitoring system. Another person may understand a falls pendant but not understand the implications of family access to digital records.
Where the person lacks capacity for the specific decision, providers must follow a best interests process. This should consider:
- the person’s past and present wishes
- their values, preferences and routines
- the risks being addressed
- less restrictive alternatives
- family, advocate or representative views
- whether the technology is proportionate
- how the decision will be reviewed
The best interests decision should never be reduced to convenience, staffing efficiency or family reassurance alone.
Privacy, Dignity and the Risk of Over-Monitoring
Privacy is a care quality issue. People receiving support still have the right to private routines, private relationships, private information and ordinary dignity. Digital tools can challenge this if providers do not set clear boundaries.
Over-monitoring may include:
- collecting more data than necessary
- allowing too many people to access records
- using sensors in private spaces without clear justification
- keeping tracking active beyond the agreed purpose
- sharing daily records with family without proper consent
- retaining alerts or location data longer than needed
- using technology to observe ordinary choices rather than manage real risk
Providers should ask whether the technology is the least intrusive way to achieve the agreed outcome. If a less intrusive approach can support the person safely, that should usually be preferred.
Operational Example 1: Telecare Opt-In With a Defined Alternative
A provider offered a falls sensor following a near-miss incident. The person wanted reassurance overnight but did not want continuous monitoring throughout the day. Staff initially proposed a broader sensor arrangement, but the person clearly said they only wanted support overnight.
The provider worked with the person to agree:
- night-time activation only
- who would receive alerts
- how staff would respond
- what information would be recorded
- when consent would be reviewed
- what alternative support would be available
The support plan also recorded that if the sensor was declined, withdrawn or failed, staff-led welfare checks would be used as the alternative. Consent was reviewed monthly and recorded in accessible language.
This strengthened assurance because the provider could evidence consent, proportionality, alternative planning and ongoing review.
Operational Example 2: Controlled Family Access to Digital Care Records
A family requested access to digital care notes because they were anxious about changes in their relative’s health. The person agreed to share appointment outcomes and general wellbeing summaries but did not want daily logs, personal care notes or private conversations visible.
The provider avoided an all-or-nothing approach. Instead, managers agreed role-based access controls and recorded the person’s preferences in the support plan.
The arrangement included:
- defined categories of information that could be shared
- information that would remain private
- named family access permissions
- review arrangements
- staff guidance on what not to disclose
- supervision checks to ensure boundaries were followed
This allowed family reassurance without undermining the person’s autonomy. It also gave the provider a clear audit trail if challenged by relatives, commissioners or inspectors.
Operational Example 3: Time-Limited Location Tracking to Support Independence
A person was becoming disoriented in the community following a change in health. They wanted to continue going out independently, but staff and family members were concerned about safety. GPS tracking was discussed as a possible short-term measure.
The provider did not treat tracking as a permanent solution. The plan defined:
- why location tracking was being considered
- when location data could be viewed
- who could access it
- what would trigger staff response
- how travel confidence would be rebuilt
- when the arrangement would be reviewed
- what would need to happen before the tracking was stepped down
The arrangement was agreed as a short-term safety measure while travel confidence was developed. Review showed that as confidence improved, tracking could be reduced and then removed.
This is a strong example of proportionate digital enablement. The technology supported independence rather than replacing it.
Operational Example 4: Saying No to Family Over-Sharing
A family member wanted live access to daily notes, medication entries, activity records and staff observations. Their concern came from a protective place, but the person receiving support did not want this level of information shared.
The provider held a supported discussion with the person, family member, key worker and manager. The person agreed that family could receive monthly wellbeing summaries and be contacted if significant health or safeguarding concerns arose, but did not consent to unrestricted access.
The provider recorded:
- the person’s decision
- what information could be shared
- what information could not be shared
- how family concerns would be managed
- how the agreement would be reviewed
This protected the person’s dignity while maintaining constructive family involvement. It also showed that privacy was not treated as secondary to family reassurance.
Commissioner and Regulator Expectations
Expectation 1: Least Intrusive and Proportionate Use of Technology
Commissioners expect providers to demonstrate that technology is used as the least restrictive option capable of achieving safety, wellbeing or independence outcomes. Tender evaluations and commissioner reviews may test whether providers can justify why a particular tool is used and whether non-digital alternatives were considered.
Providers should be able to show:
- the outcome being supported
- the risks being addressed
- the person’s views
- options considered
- why the chosen approach is proportionate
- how it will be reviewed
Expectation 2: Clear Governance and Accountability for Data Use
Regulators and commissioners will expect providers to show how data is governed in practice. This includes access controls, audit trails, incident response arrangements, staff training and named accountability for digital governance.
Statements of compliance must be backed by operational evidence. A policy alone is not enough if staff cannot explain how consent, privacy and access controls work in daily support.
Expectation 3: Evidence That People Can Refuse
A strong digital consent process should make refusal possible. Providers should record what happens if technology is declined, withdrawn or fails. This protects choice and reassures commissioners that care is not conditional on accepting monitoring or data collection.
Practical Consent and Privacy Controls
Accessible and Specific Consent Records
Consent documentation should clearly state the technology used, its purpose, what data is collected, who can access it, how long it will be used and when consent will be reviewed. Where people use alternative communication methods, information must be adapted and recorded accordingly.
Built-In Refusal and Withdrawal Pathways
Support plans should explicitly record what happens if technology is declined, withdrawn or fails. This protects the person’s rights and avoids creating a situation where digital participation becomes a condition of support.
Data Minimisation as Standard Practice
Providers should collect only what is necessary to achieve the agreed outcome. Excessive data collection increases risk, undermines trust and creates unnecessary governance burden.
Role-Based Access Controls
Not everyone needs access to all information. Staff, managers, families, clinicians and commissioners may need different levels of visibility. Role-based access helps ensure information is shared appropriately.
Regular Permission Audits
Access permissions should be reviewed routinely, especially when staff change roles, family circumstances change or technology is used across multiple services.
Governance and Assurance Mechanisms
Strong providers evidence that consent and privacy controls are working in practice. This may include:
- routine audits of consent reviews and access permissions
- manager sampling of support plans to confirm technology use aligns with agreements
- clear incident reporting for privacy breaches or inappropriate use
- regular supervision discussions on dignity, control and restriction risk
- staff training records on data protection and digital boundaries
- review of family access arrangements
- digital governance logs
- evidence that consent has been revisited after changes in need
Good governance should connect digital decision-making to the person’s rights and outcomes, not simply technical compliance.
Digital Safeguarding and Technology-Enabled Harm
Technology can reduce safeguarding risk, but it can also create new safeguarding issues. Providers should remain alert to technology-enabled harm, including inappropriate monitoring, coercive control, unauthorised access, privacy breaches, misuse of location data or family pressure to share information.
Staff should know how to escalate concerns where technology appears to be used in a way that undermines dignity, privacy or autonomy.
Safeguarding governance should consider:
- whether technology is being used as agreed
- whether anyone is pressuring the person to share data
- whether monitoring has become excessive
- whether staff understand privacy boundaries
- whether digital incidents are recorded and learned from
What Good Looks Like
When consent and privacy are handled well, technology supports confidence, independence and safety without eroding dignity. People understand what is being used and why. Staff know what information can be accessed and shared. Families are reassured without overriding autonomy. Managers can evidence proportionality, review and accountability.
Good evidence includes:
- accessible consent records
- capacity or best interests documentation where relevant
- options considered
- privacy boundaries
- access controls
- review dates
- withdrawal plans
- incident and breach reporting
- staff supervision notes
- person and family feedback
The strongest providers can evidence improved outcomes alongside reduced complaints, clearer commissioning assurance and stronger inspection narratives.
Common Pitfalls
- Treating consent as a one-off signature rather than an ongoing agreement.
- Using technology because staff or families want reassurance without fully involving the person.
- Collecting more data than is necessary.
- Failing to define who can access information.
- Not recording what happens if technology is refused.
- Leaving GPS tracking, sensors or alerts in place after the original need has changed.
- Assuming family access is always appropriate.
- Failing to review capacity when circumstances change.
- Not auditing access permissions.
- Ignoring the risk that technology can become restrictive or intrusive.
Conclusion
Person-centred technology only works when people understand what data is collected, why it is needed and what choices they have. Consent, privacy and information governance are not administrative extras. They are central to dignity, autonomy and safe digital support.
Strong providers treat consent as ongoing, privacy as essential and data governance as part of care quality. They ensure technology is proportionate, reviewable and connected to the person’s own outcomes.
When this is achieved, digital enablement can support independence without undermining control. It can reassure without over-monitoring. It can strengthen safety while preserving dignity. That is what person-centred technology should mean in adult social care.
Latest from the knowledge hub
- Digital Anxiety and Stress Monitoring in Learning Disability Services: Identifying Triggers and Preventing Escalation
- Digital Emotional Wellbeing Monitoring in Learning Disability Services: Recognising Distress Before Crisis
- Digital Diabetes Monitoring in Learning Disability Services: Supporting Safer Health Management and Daily Choice
- Digital Respiratory Health Monitoring in Learning Disability Services: Recognising Deterioration Before Crisis