How do we make sure a borrowed carer only sees the resident information they need?
You control this by using consent-scoped access rather than handing over a full resident record: a borrowed carer should only ever see the minimum data needed for that specific visit — care needs, risks, medication due, and relevant notes — not the resident's entire history, financial details, or unrelated care plan sections. This is achieved through role-based permissions and a pre-visit handover brief, not by trusting goodwill or paper policies alone.
Why "full access" is the wrong default
When a care home shares a shift with a partner-agency carer or freelancer, the instinct is often to grant them the same access an in-house carer has, on the basis that it's simpler. But that's a UK GDPR problem waiting to happen: care records are special-category data, and access should always be minimised to what's necessary for the task. A borrowed carer covering one evening visit has no legitimate need to see, for example, a resident's full six-month medication history, safeguarding case notes from an unrelated incident, or another resident's data that happens to sit in the same file.
The right question isn't "can we trust this carer?" — most are perfectly trustworthy — it's "does this system make it structurally impossible for them to over-access data, regardless of intent?"
What "minimum necessary" looks like in practice
For a single shared shift, a borrowed carer typically needs:
- Current care needs and support plan relevant to that visit
- Known risks (falls, allergies, behaviours that affect safety)
- Medication due during that visit, with clear instructions
- Any recent changes or incidents relevant to continuity of care
- Emergency contact and escalation information
They don't need: full historical eMAR going back months, financial or billing information, safeguarding records unrelated to the visit, or data on other residents. A well-designed handover separates "what's needed to deliver this visit safely" from "the resident's entire record."
How to build this into your process
- Define access by role, not by person. Set a standard "visiting/borrowed carer" permission level that's deliberately narrower than an in-house carer's, and apply it consistently rather than deciding case-by-case.
- Time-box access. Access should switch on for the shift and switch off afterwards — a borrowed carer shouldn't retain a standing view of the resident's record once the visit ends.
- Log every access. Keep an audit trail of who viewed what and when, so you can demonstrate compliance if CQC or a data subject access request ever asks.
- Get consent right at the resident/family level, not just the agency level — your privacy notice and care agreement should cover the fact that carer-sharing may happen and what data is shared when it does.
- Brief, don't dump. A short, focused pre-visit summary is safer and more useful than raw access to a full record — a carer arriving for one shift needs the headline, not the archive.
Where honest AI helps, and where it doesn't
An AI handover summariser can generate a short pre-visit brief pulled only from the consent-scoped data a borrowed carer is entitled to see — surfacing the relevant risks and instructions without exposing the underlying full record. This speeds up safe handover, because a carer walking into an unfamiliar visit gets up to speed in seconds rather than digging through notes. But the AI doesn't decide what data policy applies — that's a human/organisational decision, encoded once and then applied consistently. And sharing itself should always work on a request-and-accept basis, with a person on each side agreeing to the match, rather than any automatic placement of a carer into a resident's care.
Nanum's platform is built around this principle: a borrowed carer sees a consent-scoped, minimum-necessary slice of the record, not the full file, and an AI-generated handover brief helps them get oriented quickly. This is a genuine differentiator from single-agency systems, which generally aren't designed for cross-organisation access at all.
The compliance basics to get right
Under UK GDPR, minimisation and purpose limitation apply regardless of whether the carer is your own staff or borrowed. If you're unsure how your data-sharing agreement with a partner agency should be worded, or what your DPA/data protection officer needs to sign off, it's worth checking directly with the ICO's guidance or your own DPO rather than assuming a template covers it — the specifics vary by care setting and funding type.
Try Nanum — two ways to start
New care providers can choose either offer:
- 3 months free on the Core plan, or
- the Pro plan at Core rates for 6 months.
It's the simplest way to see whether safe, AI-matched cross-agency carer sharing ends your uncovered shifts — with a human approving every placement. Book a demo to get started.