The Information Commissioner's Office published findings this week that should concern every registered manager and social care leader in the UK. Research conducted as part of its Better Records Together campaign found that 89% of people who accessed their own care records through a Subject Access Request were left with questions or concerns. Nearly three quarters experienced poor communication from their local authority. And 69% said the process took longer than expected — with some individuals waiting up to sixteen years for records about their own lives.
The ICO is not treating these findings as background evidence for future policy consideration. It has already issued reprimands to Glasgow City Council and City of Edinburgh Council, an enforcement notice to Bristol City Council for child social care data delays, and an £18,000 fine to Scottish charity Birthlink for destroying approximately 4,800 personal records. It has stated that it will prioritise enforcement action where there are persistent delays and insufficient action to prevent harm.
For care providers operating under CQC regulation, this represents a second, parallel regulatory expectation that sits alongside inspection preparation but is governed by different legislation, different enforcement powers, and a different regulator — one that is now demonstrably willing to use those powers.
What Better Records Together Actually Requires
The Better Records Together campaign, launched in December 2025, is specifically focused on the lifecycle of care records — from how they are created, through how they are handled, to how they are accessed and disclosed when requested. The ICO has published care records standards and is asking senior leaders to publicly commit to five steps.
The first is to champion care records at leadership level — making it clear that the organisation's performance in handling care records is a genuine priority, not a back-office administrative function.
The second is to implement the care records standards across the organisation — not just circulating them to information governance leads, but ensuring all staff understand why they matter and that they are everyone's responsibility.
The third is to resource the teams involved in every stage of the records process adequately to manage demand. The ICO's findings suggest that delays in responding to Subject Access Requests are often a resource problem as much as a compliance problem.
The fourth is to provide staff with training and support so they can handle care records confidently and in line with ICO standards — which requires those standards to be communicated, understood, and embedded in daily practice rather than stored in a policy document that is rarely consulted.
The fifth is to invest to transform — building records now that follow ICO standards, on the basis that correctly created records reduce future administrative burden, legal risk, and harm to the people whose information they contain.
Why This Matters for CQC-Regulated Providers Specifically
Care providers already operating under CQC regulation may wonder whether Better Records Together adds a new burden on top of existing compliance obligations, or whether meeting one set of requirements naturally satisfies the other.
The honest answer is that the two frameworks are complementary but not coextensive. CQC's assessment framework focuses on the quality and safety of care as evidenced through documentation — whether records demonstrate safe practice, effective governance, and appropriate responses to incidents. The ICO's care records standards focus on the rights of the people whose information is held — whether records are accurate, accessible, handled securely, retained appropriately, and disclosed correctly when requested.
A provider can have documentation that satisfies CQC's evidence requirements while simultaneously failing ICO standards — for example, by keeping care plans that demonstrate governance but being unable to respond to a Subject Access Request in the legally required timeframe, or by holding records about individuals in formats that are not meaningfully accessible to those individuals.
Conversely, a provider focused entirely on ICO compliance might have records that are well-organised and accessible but do not contain the evidential content CQC inspectors are looking for.
The integrated position — records that are created accurately from actual care and practice, governed by clear standards, handled with appropriate security, and accessible to the people they concern — satisfies both frameworks simultaneously. That is not a coincidence. Both the CQC and the ICO, approaching the question from different regulatory angles, are describing the same underlying requirement: that records about real people should reflect the reality of their care, be maintained with appropriate governance, and serve those people's interests rather than simply the organisation's administrative convenience.
The Record as Account
Angela Balakrishnan, the ICO's Executive Director of Strategic Communications and Public Affairs, put it directly at this week's briefing: "Behind every care record is a real person and their life story. This is something that we must never lose sight of."
This framing — the record as account, carrying the reality of a person's experience through the system — is the most important way to understand what Better Records Together is actually asking for. The ICO's findings about people waiting years for their own records, or being left with questions and concerns when they finally receive them, are not primarily a data protection failure in the technical sense. They are a failure to treat records as accounts that belong, in a meaningful sense, to the people they concern.
The practical implication for care providers is that the quality of records matters not just as an inspection evidence base but as an obligation to the individuals whose care those records document. A care home manager who creates accurate, well-structured records from actual interactions — rather than adapting generic templates that plausibly describe what might have happened — is doing something that both the CQC and the ICO would recognise as compliant, and more importantly something that genuinely serves the people in their care.
Start Your Policy Document — first document freeWhat Providers Should Do Now
The ICO's five-step framework provides a useful practical checklist, but care providers need to translate those steps into specific actions rather than treating them as aspirational commitments.
On creation, the most common failure point in care records is the gap between what actually happened and what the record says happened. Generic care plans, templated progress notes that do not reflect individual circumstances, and documentation assembled retrospectively rather than contemporaneously all create records that may satisfy a surface audit while failing to accurately represent the care provided. The ICO's "invest to transform" step is specifically about building records correctly from the start, because correcting poor records retrospectively is far more expensive and legally risky than creating them correctly in the first place.
On access, providers should audit their current Subject Access Request process — specifically, the time from receipt of a request to dispatch of the response, the format in which records are provided, and whether the information provided is genuinely comprehensible to the person requesting it. The ICO's enforcement action to date has focused substantially on delays, and the statutory timeframe of one month from receipt of a valid SAR is non-negotiable.
On retention and disposal, the Birthlink enforcement action — an £18,000 fine for destroying approximately 4,800 personal records — is a reminder that records cannot be disposed of arbitrarily. Retention schedules must be in place, followed, and documented. Records that might be the subject of a future SAR or legal proceedings cannot be destroyed simply because they are old or inconvenient to store.
On staff training and support, the ICO's research finding that 71% of people experienced poor communication during the SAR process suggests that front-line staff often lack either the knowledge or the support to handle these requests correctly. Training that covers the legal requirements, the process for responding, and the communication standards the ICO expects is not optional.
The Enforcement Direction of Travel
The ICO's supervision pilot, monitoring the performance of 19 organisations across 2025 and 2026, signals that this campaign is moving from awareness to accountability. The organisations under supervision are being monitored directly; those that have not yet engaged with Better Records Together should not assume that non-engagement is an acceptable position.
The enforcement actions already taken — reprimands, enforcement notices, financial penalties — demonstrate that the ICO is prepared to use its regulatory powers in this area. A registered manager who has not reviewed their records creation, handling, access, and disclosure processes in light of the Better Records Together standards is carrying a regulatory risk that is now quantifiable, not merely theoretical.
The ICO's campaign page provides free resources and a pledge mechanism for organisations that want to signal their commitment publicly. Engaging with the campaign materials, implementing the standards, and being able to demonstrate that commitment in the event of a regulatory inquiry is the minimum appropriate response to a regulator that has made its expectations, and its enforcement appetite, clear.
ReporticaAI helps care providers produce accurate, compliant documentation structured from their own knowledge of their service — policies, care plans, governance records, and CQC inspection preparation — built on the PAIDS™ (Professional AI Documentation Standards) framework, which operationalises the same provenance, accuracy, and accountability principles that underpin both CQC and ICO regulatory expectations.
This article is published in accordance with PAIDS™ (Professional AI Documentation Standards) — well-sourced, thoroughly researched, and defensible with verifiable data. reporticaai.co.uk/governance