Confidentiality in social work is not secrecy. It is a set of obligations about how personal information is collected, recorded, stored, shared and eventually destroyed — obligations owed to the person the record is about, and increasingly enforced by data protection regulators as well as professional bodies. The details vary by country; the principles do not.
Five principles that apply everywhere
- Collect and record only what the purpose needs. Data minimisation is a legal principle in the UK, EU, South Africa, Kenya, Nigeria and elsewhere, and a professional one in every code of ethics.
- Have a lawful basis, and know what it is. Consent is one basis; statutory duty, legitimate interest, vital interest and public task are others. Child protection work is rarely done on consent alone.
- Tell the person. What you record, why, who sees it, and their rights. In writing where practicable.
- Share only what is necessary, with those who need it, and record the decision. Sharing without consent is lawful in most regimes where necessary to protect a person from serious harm — but the record must say what was shared, with whom, and on what basis.
- Keep it secure, keep it accurate, and keep it only as long as required. Retention periods are set by law or policy; records outlive their purpose in filing cabinets and inboxes.
Before you write it down
- Is this relevant to the purpose of the record?
- Would I be comfortable with the person reading it? In most regimes, they can.
- Is it fact, report or opinion, and is that clear?
- Does it identify a third party who has not consented, and does it need to?
- Am I writing it into a secure system, or into an email, a phone note or a third-party tool where a reference code should be used instead of a name?
Before you share it
- Do I have consent, and does the consent cover this recipient and this purpose?
- If not: is there a legal basis for sharing without consent, and can I name it?
- Is this the minimum that the recipient needs?
- Is the channel secure?
- Have I recorded what I shared, with whom, when, and why?
How the regimes compare
The countries CaseworkAI serves have data protection laws of different ages and strengths. The table is a practitioner’s orientation; confirm specifics with your organisation’s data protection lead.
| Jurisdiction | Law | Regulator | Practitioner notes |
|---|---|---|---|
| United Kingdom | UK GDPR; Data Protection Act 2018 | ICO | Subject access within one month; special category data (health, ethnicity) needs an additional condition; safeguarding sharing supported by statutory guidance. |
| Kenya | Data Protection Act 2019 | ODPC | Registration of data controllers; sensitive data (health, children) requires consent or a statutory basis; cross-border transfer conditions. |
| Uganda | Data Protection and Privacy Act 2019 | PDPO | Similar architecture to Kenya; special personal data protections. |
| Nigeria | Nigeria Data Protection Act 2023 | NDPC | Lawful basis, data subject rights, controller registration for larger processors. |
| Ghana | Data Protection Act 2012 (Act 843) | DPC | Registration; sensitive data protections; cross-border rules. |
| South Africa | POPIA 2013 | Information Regulator | “Special personal information” (health, children) has explicit protections; information officer required. |
| Rwanda | Law N° 058/2021 | NCSA | Cross-border transfer requires authorisation; sensitive data protections. |
| Philippines | Data Privacy Act 2012 (RA 10173) | NPC | Sensitive personal information protections; breach notification; consent-led with statutory exceptions. |
| Australia | Privacy Act 1988; APPs; state laws | OAIC and state bodies | Health and child protection records often governed by state legislation alongside the APPs; NDIS records retained 7 years. |
| Canada | PIPEDA; provincial laws (Quebec Law 25, BC/Alberta PIPA) | OPC and provincial commissioners | Public-sector social work usually under provincial public-sector privacy law rather than PIPEDA. |
| Romania | EU GDPR | ANSPDCP | As UK GDPR in substance; EU transfer rules. |
| Colombia | Law 1581 of 2012 | SIC | Authorisation-based; sensitive data and children’s data protections; cross-border rules. |
Try CaseworkAI free
CaseworkAI is built on the principles above: nothing is stored, notes are deleted once the document is sent, and workers are asked to use reference codes rather than names. It is registered with the UK ICO as a data controller (ZC132263).
Generate your first document →Free for individual social workers, forever · ICO registered · GDPR compliant
Using third-party tools
Any tool outside your organisation’s secure system — email, messaging apps, transcription, AI drafting — is a data-sharing decision. The questions are the same as for any sharing: what does the tool receive, what does it keep, where is it processed, and does your organisation’s policy permit it? The practical safeguards are consistent across every regime: use reference codes and never names in anything that leaves the secure system; prefer tools that retain nothing; and check that your organisation has a data processing agreement where one is required.
Related guides
Frequently asked questions
Can the person see everything in their record?
In most regimes they have a right of access, with exceptions for information that would seriously harm them or another person, or that identifies a third party who has not consented. Write every record on the assumption they will read it.
When can I share without consent?
Where the law permits it — most commonly where necessary to protect a child or adult from serious harm, or where a statutory duty requires it. Record the basis, what was shared, with whom and when.
Is it safe to use CaseworkAI with client information?
CaseworkAI retains nothing after the document is sent and asks for reference codes rather than names. Whether it is permitted in your setting is your organisation’s decision under its own policy; a data processing agreement is available for organisations that need one.