Confidentiality in social work is not secrecy. It is a set of obligations about how personal information is collected, recorded, stored, shared and eventually destroyed — obligations owed to the person the record is about, and increasingly enforced by data protection regulators as well as professional bodies. The details vary by country; the principles do not.

Five principles that apply everywhere

  1. Collect and record only what the purpose needs. Data minimisation is a legal principle in the UK, EU, South Africa, Kenya, Nigeria and elsewhere, and a professional one in every code of ethics.
  2. Have a lawful basis, and know what it is. Consent is one basis; statutory duty, legitimate interest, vital interest and public task are others. Child protection work is rarely done on consent alone.
  3. Tell the person. What you record, why, who sees it, and their rights. In writing where practicable.
  4. Share only what is necessary, with those who need it, and record the decision. Sharing without consent is lawful in most regimes where necessary to protect a person from serious harm — but the record must say what was shared, with whom, and on what basis.
  5. Keep it secure, keep it accurate, and keep it only as long as required. Retention periods are set by law or policy; records outlive their purpose in filing cabinets and inboxes.

Before you write it down

Before you share it

How the regimes compare

The countries CaseworkAI serves have data protection laws of different ages and strengths. The table is a practitioner’s orientation; confirm specifics with your organisation’s data protection lead.

JurisdictionLawRegulatorPractitioner notes
United KingdomUK GDPR; Data Protection Act 2018ICOSubject access within one month; special category data (health, ethnicity) needs an additional condition; safeguarding sharing supported by statutory guidance.
KenyaData Protection Act 2019ODPCRegistration of data controllers; sensitive data (health, children) requires consent or a statutory basis; cross-border transfer conditions.
UgandaData Protection and Privacy Act 2019PDPOSimilar architecture to Kenya; special personal data protections.
NigeriaNigeria Data Protection Act 2023NDPCLawful basis, data subject rights, controller registration for larger processors.
GhanaData Protection Act 2012 (Act 843)DPCRegistration; sensitive data protections; cross-border rules.
South AfricaPOPIA 2013Information Regulator“Special personal information” (health, children) has explicit protections; information officer required.
RwandaLaw N° 058/2021NCSACross-border transfer requires authorisation; sensitive data protections.
PhilippinesData Privacy Act 2012 (RA 10173)NPCSensitive personal information protections; breach notification; consent-led with statutory exceptions.
AustraliaPrivacy Act 1988; APPs; state lawsOAIC and state bodiesHealth and child protection records often governed by state legislation alongside the APPs; NDIS records retained 7 years.
CanadaPIPEDA; provincial laws (Quebec Law 25, BC/Alberta PIPA)OPC and provincial commissionersPublic-sector social work usually under provincial public-sector privacy law rather than PIPEDA.
RomaniaEU GDPRANSPDCPAs UK GDPR in substance; EU transfer rules.
ColombiaLaw 1581 of 2012SICAuthorisation-based; sensitive data and children’s data protections; cross-border rules.

Try CaseworkAI free

CaseworkAI is built on the principles above: nothing is stored, notes are deleted once the document is sent, and workers are asked to use reference codes rather than names. It is registered with the UK ICO as a data controller (ZC132263).

Generate your first document →

Free for individual social workers, forever  ·  ICO registered  ·  GDPR compliant

Using third-party tools

Any tool outside your organisation’s secure system — email, messaging apps, transcription, AI drafting — is a data-sharing decision. The questions are the same as for any sharing: what does the tool receive, what does it keep, where is it processed, and does your organisation’s policy permit it? The practical safeguards are consistent across every regime: use reference codes and never names in anything that leaves the secure system; prefer tools that retain nothing; and check that your organisation has a data processing agreement where one is required.

Related guides

Frequently asked questions

Can the person see everything in their record?

In most regimes they have a right of access, with exceptions for information that would seriously harm them or another person, or that identifies a third party who has not consented. Write every record on the assumption they will read it.

When can I share without consent?

Where the law permits it — most commonly where necessary to protect a child or adult from serious harm, or where a statutory duty requires it. Record the basis, what was shared, with whom and when.

Is it safe to use CaseworkAI with client information?

CaseworkAI retains nothing after the document is sent and asks for reference codes rather than names. Whether it is permitted in your setting is your organisation’s decision under its own policy; a data processing agreement is available for organisations that need one.