Central North Leeds Primary Care Network
Privacy Notice
Background
The Information we hold on you
The GP practices within Central North Leeds PCN keep data on you relating to who you are, where you live, your contact details, your family, details of your occupation – if any – and, possibly, your employers, your lifestyle, your health problems and diagnoses, the reasons you seek help, as well, at your appointments. Your record also contains details if you have a carer, where you are seen, when you are seen, and who by: as well as all referrals to specialists and other health and social care providers, tests carried out here and in other places, investigations and scans, treatments and outcomes of treatments, your treatment history, the observations and opinions of other health care workers, within and without the NHS as well as comments and aide memoires reasonably made by health and care professionals in this practice who are appropriately involved in your health care. All of this data helps us in providing you with the best possible care, and, as quickly as possible in an emergency.
All health related data is seen as ‘special category’ or ‘sensitive data’ under the 2018 Data Protection Act which means that it is shared and processed with particular care. This applies to your data whether it is in electronic formats or on paper.
When registering for NHS care, all patients who eligible for NHS care receive a unique NHS Number and are registered on a national database, the database is held by NHS Digital, a national organisation which has legal responsibilities to collect NHS data in the public interest.
Why we hold and process your data
Your GP practice holds and processes your personal data in order to provide you with direct care. Together with anonymised and pseudonymised patient data (in other words data that cannot be used to identify you) your personal data is also used to:
- Improve the quality and standard of care that we and other organisations provide;
- Evaluate existing services;
- Developing preventative treatment of illness and disease;
- Monitoring standards of patient safety
- Act in the public interest as legally directed – for instance, in times of pandemic
You also have a choice over whether you wish to use your confidential data – i.e. data that CAN be traced back to you for purposes of:
- Researching and developing new treatments
- Planning future services in the locality
Who do we share information with?
As GPs, we cannot provide all your treatment ourselves, so we need to delegate this responsibility to others across our organisation, within your practice and with other organisations such as pharmacies or hospitals. Centra North Leeds PCN also pools resources with other primary care organisations in the area. Such services may be provided as part of our local Primary Care Network (PCN) and our partners in secondary health care and in social care
As GPs, we cannot provide all your treatment ourselves, so we need to delegate this responsibility to others across our organisation, within your practice and with other organisations such as pharmacies or hospitals. Centra North Leeds PCN also pools resources with other primary care organisations in the area. Such services may be provided as part of our local Primary Care Network (PCN) and our partners in secondary health care and in social care
Once you have seen any outside care provider, they will normally send details of the care they have provided you with to your Practice, so that we can understand and support your health and treatment better and update your health care record.
The sharing of personal data, within Central North Leeds PCN and with those other organisations involving our services, as well as secondary care organisations and social care organisations is assumed and is allowed by law (including the Data Protection Act2018). However, we will gladly discuss this with you in more detail if you would like to know more. We keep a register of our Information Assets which also sets out a Record of Processing Activity. The majority of patient data processing and storage happens via our SystmOne and EMIS patient record systems.
We have an overriding responsibility to do what is in your best interests under the 2018 Data Protection Act ‘in performance of a public task’ (see legal bases in the summary below). Central North Leeds PCN team (clinicians, administration and reception staff) only access the information they need to allow them to perform their function and fulfil their roles. A list of the types of organisation we share with is provided below. This summary also contains details of your rights in relation to your data under the Act and how to exercise them.
For commissioning and healthcare planning purposes:
In some cases, for example when looking at population healthcare needs, some of your data may be shared (usually in such a way that you cannot be identified from it). The following organisations may use data in this way to inform policy or make decisions about general provision of healthcare, either locally or nationally:
- Leeds City Council: Public Health, Adult or Child Social Care Services
- Leeds Integrated Care Board (or their approved data processors)
- NHS Digital (Formerly known as (HSCIC)
- The “Clinical Practice Research Datalink” (EMISWeb practices) or ResearchOne Database (SystmOne practices).
- Other data processors which you will be informed of as appropriate.
Central North Leeds PCN does NOT share your data with insurance companies or solicitors, except by your specific instruction or consent.
Your data is NOT shared or sold for any marketing purpose.
Communication with our patients
Central North Leeds PCN will use your contact details in order to inform you of progress in your treatment or to work with you in managing your health. Because we can communicate and get data to you more quickly and more securely, we prefer to use email and text messaging services. Please ensure that we always have your current, up to date, email address and mobile telephone number so that we can do this. If you would prefer us NOT to communicate with you in these ways, please let us know.
If you have downloaded the NHS app (or other similar app), we may also use this to communicate with you and to update your referrals etc.
Communication with Our Patients Section of the privacy notice template.
“Sometimes we partner with other service providers in order to communicate with you such as Google and SurveyMonkey etc. Please be aware that these third parties will leave cookies to track your use of their services. Please check their cookie policies for details.”
Safeguarding and the Caldicott Guardian
Central North Leeds PCN is dedicated to safeguarding all its patients, including children and vulnerable adults. This means that information will be shared in their best interests. Such decisions are the ultimate responsibility of our Caldicott Guardian. The Caldicott Guardian is the senior person – always a doctor and often a partner within a practice – responsible for protecting the confidentiality of people’s health and care information. The duty to share data for the benefit of individuals can be more important as the duty to protect patient confidentiality, and actions taken as a result of safeguarding concerns will override data protection. The decision of the Caldicott Guardian is final and there is no appeal process.
Medical Audits and Medicines Management
Central North Leeds PCN will conduct audits of its services and treatment as well as reviews of medicines prescribed to its patients. Reviews of patient data are necessary to allow us to monitor, test and update our services and prescribing to ensure that you receive the most appropriate and cost-effective treatments. These reviews may take the form of internal audits or those conducted by other commissioned healthcare organisations such as the local Medicine Management Team.
Automated Data Processing and Risk Stratification
Electronic tools of prediction, based upon algorithms and artificial intelligence are used within the NHS to determine a patient’s future risks and treatment needs. Wherever we can, we want to prevent admissions to A&E and secondary care which would be otherwise necessary. Such preventative care may, for instance, use these tools to determine the risk and consequence of a future fall in an elderly patient. Under Covid 19 these tools are being used to identify vulnerable patients and patients who need to be shielded.
However, under the 2018 Data Protection Act, when the COPI notice described above is withdrawn, you do have the right to opt out of having your data processed in such automated ways. If you wish to opt out, please contact the practice.
Research and Planning
Central North Leeds PCN takes part in research that uses anonymised or pseudonymised data. This means that patient data cannot be traced back to individuals and is therefore no longer personal data under the 2018 Data Protection Act.
Anonymised or pseudonymised patient data held by Central North Leeds PCN may also be used to evaluate present services that provide direct care or to plan future ones within Central North Leeds PCN Services or across the local area.
Identifiable patient data can be used in planning and managing the response of the NHS, nationally, to the Covid 19 virus. This will continue until the COPI notice above is withdrawn.
Sometimes, Central North Leeds PCN is contacted to ask whether its patients would consider taking part in research on a particular condition. In all such cases, where the data used would identify individual patients, data can only be used where patients have given their consent, and you will be contacted accordingly. Such research projects take place in secure research environments where data protection and data security keep patient data safe, but you have the right to choose not to have your personally identifiable data used in this way (see below).
Data Opt-Outs (The National Data Opt-out) and Your Right to Object
You cannot opt-out of your data being shared for the purposes of providing you with direct care. You can opt-out from having your confidential data (i.e. data that can identify you) being used for purposes beyond direct care, such as research and planning. To do this, you can check or change your preferences at www.nhs.uk/your-nhs-data-matters on-line and follow the instructions if you wish to opt out. This opt-out is recorded against your NHS number on the NHS ‘spine’.
There are some situations where your data will be shared in addition to providing you with direct care. These include:
- Situations where data is needed in the “public interest”, e.g in cases of epidemic where communicable diseases need to be diagnosed and the spread of their infection prevented or controlled;
- To monitor and deliver vaccination programmes
- To manage risks of infection from food or water supplies or the environment
You can find out more about how your patient information is used at https://www.hra.nhs.uk/ and https://understandingpatientdata.org.uk/what-you-need-know/
Central North Leeds PCN is compliant with the national data opt-out policy
How long is the information retained?
The medical record is retained at the patient’s practice for the lifetime of the patient, after which it is presently sent to Primary Care Services England (PCSE). If you move to another practice your records will be transferred to that practice.
Summary
Data Controller
|
Your GP practice
|
Data Protection Officer
|
Our Data Protection Officer is Aaron Linden and email is: wyicb-leeds.dpo@nhs.net you can also contact the Business manager at your GP practice.
|
Purpose of Processing your personal information
|
Direct Care delivered to an individual patient, much of which is provided in our clinical services. After a patient agrees to a referral for direct care elsewhere, such as a referral to a specialist in a hospital, necessary and relevant information about the patient, their circumstances and their problem will need to be shared with the other healthcare workers, such as specialist, therapists, technicians etc. The information that is shared is to enable the other healthcare and social care professionals to provide the most appropriate advice, investigations, treatments, therapies and or care.
|
Lawful Basis for Processing your personal information
|
The processing of personal data in the delivery of direct care and for providers’ administrative purposes in this surgery and in support of direct care elsewhere is supported under the following Article 6 and 9 conditions of the GDPR: Article 6 (1) (c) – the processing is necessary for compliance with a legal obligation to which the controller (the practice is subject) and/or Article 6(1)(e) ‘…the processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority…’. Health data is defined as a special kind of personal data and is also processed by Sutton PCN under Article 9(2)(h) ‘necessary for the purposes of preventative or occupational medicine for the assessment of the working capacity of the employee, medical diagnosis, the provision of health or social care or treatment or the management of health or social care systems and services..’ The sharing of your personal data also takes place in accordance with the common law duty of confidentiality. Performance of this duty does not require consent from the patient where the proposed use of their data is either for individual care or in the public interest.
|
Recipient or categories of recipients of your personal data
|
According to the particular course of treatment, your data will be shared with health and care professionals and support staff at hospitals, diagnostic and treatment centres who contribute to your personal care. These will include: GPs, Hospitals, Primary Care Networks, Local GP provider organisation’s, Commissioning Support Units, Social Care Services Health and Social Care Information Centre (HSCIC), Clinical Excellence Group, Community Pharmacists, District Nurses, Independent Contractors such as dentists, opticians, pharmacists, Private Sector Providers, Voluntary Sector Providers, Ambulance Trusts, Integrated Care Boards, Local Authorities, Education Services, Fire and Rescue Services, Police & Judicial Services, The Child Health Information Service, Substance Misuse Remote Workers, Leeds Coroner’s Service, Voluntary Sector Providers, Private Sector Providers, Social Prescribing Link Workers.
|
Your right to object
|
You have the right to object to some or all of the information being processed, which is detailed under Article 21. Exercising your right to object may well prevent the referral or course of treatment from going ahead. You should be aware that this is a right to raise an objection, that is not the same as having an absolute right to have your wishes granted in every circumstance.
|
Your right to access and correction
|
You have the right to access your data and to have any inaccuracies corrected. There is no right to have medical records deleted except when ordered by a court of Law.
|
How long do we hold your personal data for?
|
We retain your personal data in line with both national guidance and law, which can be found here: https://www.nhsx.nhs.uk/information-governance/guidance/records-management-code/
|
Your right to complain
|
If you have a question or wish to complain about the use of your data, please contact your GP practice or the Data Protection Officer at: yicb-leeds.dpo@nhs.net The use of personal data is overseen by the Information Commissioners Office, often known as the ICO. You can call their helpline Tel: 0303 123 1113 (local rate) 01625 545 745 (national rate) or you can write to them at The ICO, Wycliffe House, Water Ln, Wilmslow SK9 5AF
|
Version 1.0 Published June 2024