Article

Children’s social care needs safer data sharing

29 September 2026

Make an enquiry
Social worker speaking with a child during a home visit while another adult sits nearby.

The recent report by the Local Government Association (LGA) on digital maturity in children’s social services delivers a clear message. The sector has invested in modern analytical tools and enjoys broadly supportive leadership, but the foundations — data flows, data sharing, governance and service-specific strategy — remain dangerously immature.

The report presents insights drawn from a survey conducted by the LGA (in partnership with the Department for Education) in late 2025, to which 110 of 151 eligible English local authorities responded.

Headline insights

The report is rich, but some points stand out. The indications are that:

Security risks

  • 71% of authorities receive safeguarding data from external partners via email attachments
  • Only 25% use automated or API-based methods
  • Just two authorities use APIs as their sole transfer method.

Data risks

  • Councils have sophisticated Power BI dashboards and other data analysis tools, but the information feeding them is still being transmitted manually, re-keyed and exposed to avoidable security risks
  • Training and support for using these sophisticated tools may also be lacking.

AI risks

  • 79% of authorities are using AI in children’s services, yet only 4% have an AI strategy specific to children’s services and 7% have no AI strategy at all.

Data sharing is still a key obstacle

Incompatible systems (62%), a lack of unique identifiers such as the NHS number, or inconsistent use of them (60%), unresolved differences in information governance frameworks (52%) and a lack of consensus about how to share personal data lawfully (51%) are the principal barriers to sharing information between the police, NHS and independent sector health providers, schools, foster carers and other participants.

Only 5% of authorities have data-sharing agreements to support out-of-area fostering placements; 17% have none; and 25% don’t know either way.

For children moving between authorities or subject to emergency referrals, these gaps are not administrative inconveniences — they are safeguarding risks.

What should the children’s social care ecosystem be doing?

  1. Fix the plumbing before decoratingInvesting in dashboards and AI while safeguarding data still travels by email attachment, and while manual data entry or unvalidated data is widespread, is building on sand. Local authorities, health providers and the police need to prioritise secure, automated data transfer and agree interoperable standards and identifiers.

    That means confronting the contractual and technical barriers within key IT solutions such as case-management systems (CMS) — a market dominated by just two suppliers. Organisations should adopt data standards, document IT and data strategies and use procurement and contracting discipline to secure APIs and suppliers that support the objective.

  2. Get data-sharing agreements in orderThe survey shows that data sharing is a distinguishing feature of maturity. Among the weakest authorities, 79% experienced five or more external data-sharing barriers, compared with 13% in the strongest.

    Authorities, fostering agencies, health providers and education providers need standardised, practical data-sharing agreements that facilitate lawful sharing for children’s social services and safeguarding.

    A blanket prohibition in the name of information governance and compliance is mistaken and dangerous. Specialist data protection lawyers are clear: documented, structured data sharing in this context is lawful. The UK’s Information Commissioner’s Office (ICO) agrees (see its guidance, ‘Children and the UK GDPR’). We know from experience that the first step is to establish consensus between organisations through discussion. The contract comes later.

  1. Govern AI before the next headlineThe gap between 79% adoption and 4% service-specific strategy is a crisis in waiting. The impact of AI on data protection rights, confidentiality and legal privilege is messy in any context and is potentially front-page news in the context of social work or safeguarding records about children.

    The way to navigate the mess is to get briefed on the various layers of risk, set AI strategy and policy in the light of that, outlaw the use of ‘shadow AI’ (where users adopt the technology before their   organisations get on board), ensure good data protection risk assessment, human oversight and user compliance, and apply procurement and contracting discipline to ensure deployed AI is safe and fits the governing framework.

  1. Take cyber security and incident readiness seriouslyEmail-based safeguarding data transfers, low adoption of secure APIs, variable CMS capability and supplier dependency indicate the presence of direct and foreseeable cyber risks.

    In this context, ultimately human barriers between teams and organisations risk the privacy of children, their birth and placement families and safeguarding measures. Part-cooked cyber security can also put at risk the availability of key IT systems and the teams that rely on them: children’s social services stop. The consequences extend well beyond regulatory fines.

Nurturing innovation in the supply chain; disciplined procurement; supply contracts that lock in appropriate standards, obligations and risk apportionment on cyber security, data portability and interoperability; data-sharing agreements and processes that allow lawful data sharing and distinguish genuine legal obstacles from perceived ones; and AI governance frameworks. All of these are necessary components of the infrastructure that underpins effective children’s social services and safeguarding.

Predictable alternatives

Without improvement, the sector faces an increasing volume of data-subject access requests from care leavers navigating fragmented records and avoidable breaks in the system, FOI requests exposing governance gaps, cyber security and data-security breaches involving some of the most sensitive information imaginable, regulatory investigations by Ofsted and/or the ICO, enforcement action and compensation claims arising from inaccurate, misattributed or improperly disclosed records.

The LGA’s report makes the position clear: digital maturity in children’s social care depends on the managed and strategic interaction of supply chain management, contracts, IT and data governance, cyber security, workforce capability and lawful information sharing, internally within organisations and across relevant organisations and sectors.

Every participant in the ecosystem — local authorities, health providers, education providers, the police, fostering agencies and foster carers — has a part to play, and the time to act is now.

How can we help you?

Related articles

View All