Will sharing carers with another agency create GDPR or data-protection risk?
Sharing carers between agencies does not automatically breach UK GDPR — the risk comes from how records are shared, not from the fact of sharing itself. If a borrowed carer only ever sees the minimum, consent-scoped information needed for that specific visit, and both agencies have a lawful basis and clear data-processing arrangement in place, staff-sharing can be done compliantly. The risk appears when providers default to giving a visiting carer full access to a client's whole record, or share data with no agreement covering who's responsible for what.
Why this is a real question, not a small one
Care records are special-category data under UK GDPR — health information, medication history, sometimes safeguarding notes. When a carer from Agency A covers a shift for Agency B, that carer is briefly handling Agency B's client data. Two agencies means two data controllers (or one controller/one processor, depending on the arrangement), and that needs a clear basis, not an assumption.
The common failure mode isn't malicious misuse — it's over-sharing by default. A full care file handed over on paper, a login shared, a WhatsApp message with more detail than the visit requires. None of that is inherently about carer-sharing being risky; it's about care providers not having a minimised way to hand over data at all, shared staff or not.
What "consent-scoped" access actually means
Done properly, a shared/borrowed carer should see only:
- The specific client(s) and visit(s) they're covering — not the whole caseload.
- The care and medication information relevant to that visit — not the full historical file.
- Time-limited access — ending when the shift or cover period ends, not standing access indefinitely.
This is what "consent-scoped, minimised access" means in practice: the client (or their representative) has consented to their data being used for care delivery, and the system only exposes what's needed, to who needs it, for as long as they need it — a direct application of the UK GDPR data minimisation principle.
Practical steps before you share carers with another agency
- Check the lawful basis. Most care providers rely on a mix of contract and vital interests/health-care provision conditions for special-category data — confirm this covers a borrowed-carer scenario, not just your own staff.
- Get a data-sharing agreement in place between the two agencies, setting out who controls what, retention, and breach responsibilities. The ICO publishes guidance on data-sharing agreements — worth checking directly if you're unsure.
- Verify DBS status before any access is granted, not after — an enhanced DBS check (and ideally Update Service registration) should be confirmed for any carer accessing another provider's clients.
- Limit what's handed over. A short, relevant handover brief beats a full record dump every time.
- Keep an audit trail of who accessed what, and when — useful for CQC evidence as well as GDPR accountability.
- Time-box the access. Make sure permissions expire automatically once the cover period ends.
How Nanum is built around this
Nanum's carer-sharing model is designed so a borrowed carer — whether a platform-verified freelancer or a carer from a partner agency — only ever sees a consent-scoped, minimum-safe slice of a resident's record, not the full file. An AI handover summariser is used to generate a short pre-visit brief from that scoped data, so the carer is prepared without needing broader access. Every match is request-and-accept between humans on both sides — nothing is silently auto-placed — which keeps a clear, attributable decision trail for accountability. None of this replaces your own data-protection responsibilities as a controller, but it removes the common failure mode of over-sharing by default.
This doesn't make GDPR compliance automatic — your agency is still the data controller for your clients' records, and you should confirm your own arrangements meet UK GDPR and any local authority data-sharing requirements. But the technical design — scoped access, time-limited handover, human approval — addresses exactly the risk this question is really about.
FAQ
Do we need a formal data-sharing agreement with every partner agency we share carers with? Yes, in most cases — a written agreement setting out roles, retention and responsibilities is the standard way to evidence GDPR accountability between two organisations sharing client data. The ICO's data-sharing code of practice is the right reference point if you're setting one up.
Is a borrowed carer's access to client records different from a permanent staff member's? It should be narrower — limited to the specific client and visit they're covering, for the duration of the cover period, rather than open access to a full caseload. This is the minimisation principle in practice, and it's also just good safeguarding.
Does DBS status transfer between agencies when carers are shared? A DBS certificate itself doesn't automatically transfer, but the Update Service lets a carer's existing enhanced check be checked online by a new agency, which speeds this up considerably. Always confirm current status before granting any data access, regardless of how recently the carer was checked elsewhere.
Try Nanum — two ways to start
New care providers can choose either offer:
- 3 months free on the Core plan, or
- the Pro plan at Core rates for 6 months.
It's the simplest way to see whether safe, AI-matched cross-agency carer sharing ends your uncovered shifts — with a human approving every placement. Book a demo to get started.