West Kent Clinical Commissioning Group

Size: px
Start display at page:

Download "West Kent Clinical Commissioning Group"

Transcription

1 West Kent Clinical Commissioning Group Information Governance Strategy Release: Final Approved Date: 27/10/2016 Author: Jamie Sheldrake Senior Associate - Information Governance Owner: SOUTH EAST CSU Client: West Kent Clinical Commissioning Group Version No: 08 NHS West Kent CCG Information Governance Strategy 2013/14 1

2 Document History Document Location This document is only valid on the day it was printed. The original document is held and maintained by the NHS Kent and Medway Information Governance Team in the Assistant Chief Executive Directorate. Revision History Date of this revision: 24/01/17 Date of Next revision: 24/01/18 Revision date Previous revision date Summary of Changes 14/10/15 Removal of archive repository as an overall strategy objective this is in line with NHS agenda for a paperless NHS by 2018 Changes marked Alteration of KMCS to following the merger of KMCS and South London CSU 27/10/15 14/10/16 Addition of information on the new General Data Protection Regulations which could be adopted in /01/17 24/01/18 Addition of paragraph on the General Data Protection Regulations and implications of Brexit vote Approvals This document requires the following approvals. Signed approval forms are filed in the Management section of the project files. Name Signature Title Date of Version Issue West Kent Clinical NA NA Sept 15 7 Commissioning Group Information Governance Steering Group West Kent CCG IGSG Jan 17 8 NHS West Kent CCG Information Governance Strategy 2015/16 2

3 Distribution This document has been distributed to: Name Title Date of Version Issue West Kent Clinical NA Sept 15 7 Commissioning Group Information Governance Steering Group West Kent CCG IGSG Dec 16 8 NHS West Kent CCG Information Governance Strategy 2015/16 3

4 Table of Contents Document History... 2 Table of Contents... 4 Introduction... 5 Scope... 7 External Audit... 7 Aim... 7 Ownership... 7 Compliance... 7 Implementation... 8 Appendix 1: Strategy Implementation... 9 IG Core Work-stream 1: Records Management... 9 Records Management... 9 Privacy Impact Assessments (PIA)... 9 Data Flow Mapping (DFM) Information Governance Toolkit Information Asset Management IG Core Work-stream 2: Statutory Assurance Freedom of Information Act Information Sharing Data Protection Act IG Core Work-stream 3: Information Security IG Serious Incident Management IG Training IG Communications IG Steering Group Primary Care Toolkit IG Risk NHS West Kent CCG Information Governance Strategy 2015/16 4

5 Introduction Information Governance is a core governance work stream for NHS organisations and an integral component of the Integrated Governance Framework. Providing patients and staff with the assurance that their personal and sensitive data is managed professionally and in accordance with legislation is fundamental to the efficient management of services and resources. Information Governance integrates with Clinical Governance with respect to the Caldicott Principles and information sharing and with Corporate Governance with respect to providing overarching assurance through the Information Governance Toolkit. The Information Governance (IG) Team within SOUTH EAST CSU authors, implements and manages this strategy for West Kent Clinical Commissioning Group. The Team structures IG services through three core work-streams, Statutory and Mandatory Assurance, Records Management and Information Security and provides expertise and experience to each. The SOUTH EAST CSU IG Team is committed to providing its customers with robust protocols, sound advice and high levels of compliance and helping to drive a culture of responsibility and accountability when processing personal data. Public and media awareness of data breaches and their consequences has never been higher. This is true for organisations of all types. Whether tackling text spammers, phone hacking or careless management the Information Commissioners Office (ICO) has proven itself relentless in exposing and fining organisations where data protection is not taken seriously. The NHS oversees management of one of the largest combined datasets of personal and sensitive data in the UK and this demands that organisations handling confidential staff and particularly patient data develop both practical and robust safeguards for that data. The awareness of what can be achieved by linking personal datasets from different services in terms of both efficiency and patient care has grown rapidly and Information Governance sits at the heart of these initiatives. Information Governance provides advice on sharing personal data appropriately, with patient awareness and consent and practical protocols and safeguards. Information Governance is an enabler to innovation and provides the tools and perspective for legitimate use of personal data. The new General Data Protection Regulations are due to be introduced next year which will take the place of the Data Protection Act The result of the 23 June 2016 referendum on membership of the EU now means that the Government needs to consider the impact on the GDPR. The SECSU IG team will monitoring the situation and following advice of the ICO. The year could see changes and some new ways of working. Through the use of tools such as Privacy Impact Assessment, Information Asset Control, Staff Training and Data Flow Mapping, Information Governance will work with West Kent CCG to provide clarity and reduction of risk. Risk cannot be eliminated entirely though and IG incidents occur in all organisations that manage personal data. The IG Team is experienced at incident investigation and resolution and provides professional relationship management with the ICO. NHS West Kent CCG Information Governance Strategy 2015/16 5

6 Through this strategy, compliance with statutory requirements and satisfactory achievement of the IG Toolkit, Information Governance provides assurance to the Governing Body that the organisation is effectively and securely managing personal information under its control. NHS West Kent CCG Information Governance Strategy 2015/16 6

7 Scope The scope of this strategy covers governance of Personal Confidential Data (PCD) and Corporate Records Management (CRM) including governance of records under the Freedom of Information Act. The Data Protection Act draws a distinction between Personal Data and Sensitive Data. Sensitive Data forms data about a person rather than just identifying them. The safeguards for both are the same with the key procedural distinction being that the processing of Sensitive Data requires more explicit consent. As Sensitive Data must by default also be accompanied by Personal Data, for ease of use, this document will refer to the management of both categories as Personal Data. External Audit All evidence supplied as part of the IG Toolkit (IGT) is available to selected external organisations who may wish to inspect CCG documentation as part of audit. These organisations include internal and external auditors, the Information Commissioner s Office (ICO), and may include other organisations such as the National Commissioning Board. Aim The aim of this strategy is to clarify and structure the operational Information Governance service offering to West Kent Clinical Commissioning Group along with realistic outcomes and timeframes where applicable. The strategy serves to evidence a planned work programme for the IG Toolkit, an assurance model to the West Kent Clinical Commissioning Group Governing Body and an ongoing assessment model for service delivery. Ownership This strategy is authored, maintained and implemented by the SOUTH EAST CSU Information Governance Team on behalf of its client West Kent Clinical Commissioning Group. The IG team will work closely with West Kent Clinical Commissioning Group as needed to drive attainment of the goals and in particular to evidence the IG Toolkit. IG is an organisation wide imperative and engagement with the aims and objectives of this strategy are required by the West Kent Clinical Commissioning Group Governing Body to ensure successful achievement and effective assurance. Compliance Compliance with IG standards will be monitored and audited on a routine basis and as necessary in response to incidents and concerns. Compliance is the means by NHS West Kent CCG Information Governance Strategy 2015/16 7

8 which the CCG can gain assurance that policies and procedures are fully implemented and working well. Audit and compliance are routine features of achieving a satisfactory score in the IG Toolkit. Compliance with IG progress and standards will be reported to the West Kent CCG Information Governance Lead, the Chief Finance Officer. Where implementation or progress does not meet the high standards required then this will be considered for escalation and inclusion on the statement of internal control. Information Governance Serious Incidents will be notified to the West Kent Clinical Commissioning Group SIRO and Caldicott Guardian and SOUTH EAST CSU Caldicott Guardian and SIRO. Implementation Appendix 1 identifies the goals for each of the key IG themes outlined in the introduction through to March 2014, the end of the financial year and the deadline for submitting the annual IG Toolkit assessment. NHS West Kent CCG Information Governance Strategy 2015/16 8

9 Appendix 1: Strategy Implementation IG Core Work-stream 1: Records Management Records Management Secure processing of records with third parties. Appropriate handling of confidential records. Promote culture of best practice Records Management. Clear understanding of Data Controller / Data Processor relationships and responsibilities. Privacy Impact Assessments (PIA) Contracts with all third party organisations that involve processing of personal data are in place and contain appropriate clauses around Data Controller / Data Processor relationships and responsibilities. Out of hours premises audits for confidential data left on desks, on printers / faxes / unlocked computers / in waste bins and unlocked cupboards. Establish and support Records Champions. Provide training and communications support. Lead training / workshops and issue guidance. Examples of contract clauses provided as evidence to IG Toolkit. Audit reports to customer and used as evidence for IG Toolkit. Training records. Comms and training material provide IG Toolkit evidence. Training attendance records. Training material, records and guidance evidence IG Toolkit. West Kent CCG and High level of awareness of PIAs are completed on a routine basis by customer Report of PIAs received West Kent CCG and value of PIAs and significant staff when proposing new or changes to processes provided to customer. uptake. and systems which process personal data. PIAs form IG Toolkit evidence. PIAs are accurately and SOUTH EAST CSU IG Team work with users to PIAs form a valuable and West Kent CCG and NHS West Kent CCG Information Governance Strategy 2015/16 9

10 comprehensively completed providing maximum benefit. Assurance and confidence in advice and feedback. New initiatives proceed on a legitimate (lawful) basis. review PIAs for accuracy and appropriate detail and challenge incomplete or vague responses. SOUTH EAST CSU IG Steering Group comprising senior and expert IG resources review completed PIAs for recommendation. PIA accurately identifies Data Controller / Data Processor relationships and checks third party Processors ICO registration for validity. enabling service for customers. Customer projects / initiatives proceed with good controls and confidence. Clear customer understanding of data handling relationships. West Kent CCG and Data Flow Mapping (DFM) A clear, effective and supported SOUTH EAST CSU IG Team work closely with DFMs evidence IG Toolkit. West Kent CCG and Data Flow Mapping process customer to map flows of personal data. Updated IG Risk Register High risk data flows are recorded on IG Risk Register. IG Risk Register. Evidences IG Toolkit. Drive implementation of Report data flows graded as high risk to customer Mitigation of IG Risks on IG increased security controls. with recommendations for change. Risk Register. Information Governance Toolkit A prioritised plan of work for achieving IG Toolkit (IGT) compliance. Compliant level two scores for all criteria by March 2013 against all customer organisations. Detailed evidence review ensuring requirements are met. Generic CCG/CSO templates and documentation where appropriate avoiding duplication or extensive rework. Customer IG Toolkit submitted on time, i.e. before the end of March 2017 Clear direction and support. SOUTH EAST CSU IG Team work closely with IG Toolkit evidence and NHS West Kent CCG Information Governance Strategy 2015/16 10

11 Assurance of IG Toolkit from Any Qualified Providers (AQP) and other third parties. Regular IG Toolkit customer performance reporting. Liaise with internal/external auditors to provide evidence for review. Validation of uses of personal data for Secondary Uses, e.g. not for primary care under DH Secondary Uses guidelines. customer to provide customer with policies, templates, direction and support in completing and implementing IG Toolkit standards. IG Team work closely with APQs and other parties commissioned by the customer to develop / validate IG Toolkit completion. Note: Work undertaken with parties other than the customer is on a commercial basis. Clear and accurate reporting on Toolkit progress to Governance and Assurance work streams. Review all uses of personal data for non-primary care processing. Make recommendations for validity. Establish New Safe Haven operational environments where agreed. compliance. Evidence of AQP IG Toolkit compliance. Assurance on legitimacy of processing. IG Performance Report Secondary Uses Caldicott register. As required Independent assurance. Information Asset Management Information Asset Management. Maintain Information Asset Registers across all appropriate organisations with Information Asset Owners identified. Information Asset Register. New Safe Haven operational environments. New initiatives, system changes and security of processing. Interface with Secondary Uses, Data Flow Mapping, IG Risk and Information Sharing to identify where personal data is shared. Implement New Safe Haven operational environments to ensure personal data is processed and stored securely. Maintain a presence; oversight and input into projects to ensure that development of systems and infrastructure maintain appropriate security. New Safe Haven register. - NHS West Kent CCG Information Governance Strategy 2015/16 11

12 Systems access. Work with Information Asset Owners and relevant third parties to ensure that systems access controls are in place and effective. West Kent CCG and IG Core Work-stream 2: Statutory Assurance Freedom of Information Act Provide high level accurate Senior Associate consideration of complex - technical expertise on complex requests and exemptions. requests and exemptions Detailed redaction of data in line with FOI and DPA legislation. Expert Internal Review service. Relationship with the Liaise with the ICO on FOI complaints & co-operate - Information Commissioner s with investigation & resolution. Office (ICO) Requests for Internal Review To carry out internal reviews when requested - Information Sharing Accurate technical Information Sharing expertise for individual requests for advice. Written advice notices issued for individual DPA type requests. Information Sharing and advice logs maintained for reference. Responses within 2 working days for individual DPA type requests. Project level Information Sharing expertise. Risk mitigation. Ongoing advice and expertise for project / larger initiatives via membership of project teams, exploration of complex issues and liaison with third party organisations. Interface with Data Flow Mapping and IG Risk to identify and mitigate poor information sharing practice. - Updated risk register and data flow maps. NHS West Kent CCG Information Governance Strategy 2015/16 12

13 Data Protection Act Responsibility and training Ensure CCG has leads responsible for providing data for DPA requests. - West Kent CCG and Provide training / knowledge for person responsible. Tight control over deadlines, service level agreements and escalation of Subject Access Requests. Provide high level accurate technical expertise on Subject Access requests and exemptions. Caldicott Principles. New requests acknowledged within 2 working days. Statutory compliance within 40 calendar days. Information obtained within 20 working days to allow time for redaction. All issues escalated to Senior Associate Senior Associate consideration of complex requests and exemptions. Detailed redaction of data in line with DPA legislation. Work closely with Caldicott Guardians to assist in understanding and implementation of Caldicott Principles. IG Performance Report. - - Current of annual ICO notification. ICO notification reviewed annually for accuracy. ICO registration compliance Efficient DPA structure and process for IG Performance Report. processing Subject Access Requests. Maintain high levels of knowledge and practice in a fast moving field. DPA policy current with rapidly evolving field. DPA administration maintained with 100% accuracy and updated daily. Senior Associate process overview. Accurate performance data. Regular review of ICO decisions and progress of EU changes to legislation. Liaise with legal and other expert professionals as appropriate. Six monthly policy / process reviews (or as required). - Current policy circulated. NHS West Kent CCG Information Governance Strategy 2015/16 13

14 IG Core Work-stream 3: Information Security IG Serious Incident Management IG Serious Incidents (SI) Accurate and up to date Incident log. IG Performance Report. management. Clear and efficient processes All SI investigations completed within mandated IG Performance Report. for reporting and timeframes (45 or 60 days). investigation of IG SIs and incidents. Investigate using the NPSA SI report template and appropriate tools, ensuring the quality, depth and breadth of the investigation. Trend analysis. Inform IG Risk Register of growing trends to drive mitigation. Re-work processes to drive mitigation. Staff Communications to drive mitigation. IG Risk Register. Relationship with the Information Commissioner s Office (ICO) IG Training Liaise with the on ICO on IG SI notifications and cooperate with investigation and resolution. SI resolution. IG Training Strategy. Minimum 95% staff trained on IG annually. Training online and face to face as required. Maintain accurate and current staff registers for all organisations with training compliance for all staff. IG Performance Report. West Kent CCG and NHS West Kent CCG Information Governance Strategy 2015/16 14

15 IG Communications IG Communications Annual IG Communications Strategy for clear and Strategy. timely IG Communications to effectively brief staff on IG operational issues. Respond to emerging issues, events, SI trends with rapid communication. Evidence for IG Toolkits and audit reviews. IG Steering Group Maintain IG Steering Group to provide cross functional advice and consideration. Primary Care Toolkit Quarterly meetings to review progress against strategy, tackle issues, review Privacy Impact Assessments and provide assurance to all customer of an active process for maintaining statutory compliance and best practice. Consideration Privacy Impact Assessments (PIA). Oversight of IG functionality and statutory compliance. Steering Group minutes. IG Performance Report. PIA review outcomes. Primary Care IG Toolkit Work closely with Primary Care to drive engagement compliance. with and monitor completion of the IG Toolkit throughout Primary Care services Create and enforce IGT action plans for Primary Care organisations resisting engagement with the IGT through the contracting route NHS West Kent CCG Information Governance Strategy 2015/16 15

16 IG Risk Detailed and accurate IG Maintain an accurate register and use as a tool for proactive IG Performance Report. Risk Register. risk mitigation. Evidence for IG Toolkit. Risk identification. Interface with Secondary Uses, Data Flow Mapping and Information Sharing to identify, quantify and accurately record IG risks. Updated Risk Registers Evidence for IG Toolkits NHS West Kent CCG Information Governance Strategy 2015/16 16

Information Governance Strategy and Management Framework

Information Governance Strategy and Management Framework Information Governance Strategy and Management Framework Summary: This strategy sets out the framework, structure, system and accountabilities for Information Governance Management within NHS Eastbourne,

More information

INFORMATION GOVERNANCE STRATEGY IMPLEMENTATION PLAN

INFORMATION GOVERNANCE STRATEGY IMPLEMENTATION PLAN INFORMATION GOVERNANCE STRATEGY & IMPLEMENTATION PLAN 2015-2018 Disclaimer The latest version of this document is located on PTHB intranet. Please check the review date and if there are any doubts contact

More information

INFORMATION GOVERNANCE STRATEGY AND STRATEGIC VISION

INFORMATION GOVERNANCE STRATEGY AND STRATEGIC VISION INFORMATION GOVERNANCE STRATEGY AND STRATEGIC VISION Policy approved by: Joint Audit and Governance Committee Date: December 2016 Next Review Date: October 2018 Version: 2.0 Information Governance Strategy

More information

Information Governance Policy and Management Framework

Information Governance Policy and Management Framework Putting Barnsley People First Information Governance Policy and Management Framework Version: 2.0 Approved By: Governing Body Date Approved: February 2014 Name of originator / author: Richard Walker Name

More information

Information Security Risk Management Programme and Strategy

Information Security Risk Management Programme and Strategy Information Security Risk Management Programme and Strategy Table of Contents 1. Introduction... 3 2. Purpose... 3 3. Definitions... 3 4. Roles and Responsibilities... 4 4.1. Accountable Officer... 4 4.2.

More information

Information Governance Management Framework

Information Governance Management Framework Information Governance Management Framework November 2014 Author: Responsibility: Lynda Harris, Head of Information Governance All Staff Effective Date: November 2014 Review Date: November 2015 Reviewing/Endorsing

More information

Information Governance Policy

Information Governance Policy Information Governance Policy Policy Number IG001 Target Audience CCG/ GMSS Staff Approving Committee CCG Chief Officer Date Approved February 2018 Last Review Date February 2018 Next Review Date February

More information

IG01 Information Governance Management Framework

IG01 Information Governance Management Framework IG01 Information Governance Management Framework 1 INFORMATION GOVERNANCE MANAGEMENT FRAMEWORK Document History Document Reference: IG01 Document Purpose: The document compliments all other Information

More information

Data Quality Policy

Data Quality Policy Cambridgeshire and Peterborough Clinical Commissioning Group (CCG) Data Quality Policy 2017-2019 Ratification Process Lead Author(s): Reviewed / Developed by: Approved by: Ratified by: Associate Director

More information

Information Governance Management Framework Version 6 December 2017

Information Governance Management Framework Version 6 December 2017 Information Governance Management Framework Version 6 December 2017 Page 1 of 8 Introduction Robust information governance requires clear and effective management and accountability structures, governance

More information

Information Governance Strategic Management Framework

Information Governance Strategic Management Framework Information Governance Strategic Management Framework 2016-2018 Susan Meakin Information Governance Manager June 2016 Information Governance DOCUMENT CONTROL: Version: 2 Ratified by: Health Informatics

More information

Information Governance Management Framework

Information Governance Management Framework Management Framework Summary: This document sets out the framework, structure, system and accountabilities for Management within West Kent CCG Clinical Commissioning Group. APPROVED BY: Chief Finance Officer

More information

INFORMATION GOVERNANCE POLICY

INFORMATION GOVERNANCE POLICY INFORMATION GOVERNANCE POLICY Including the Information Governance Strategy Framework and associated Information Governance Procedures Last Review Date June 2017 Approving Body Audit Committee Date of

More information

Information Governance Policy

Information Governance Policy Information Governance Policy Version: 4.0 Ratified by: NHS Bury Clinical Commissioning Group Information Governance Operational Group Date ratified: 19 th September 2017 Name of originator /author (s):

More information

INFORMATION GOVERNANCE MANAGEMENT FRAMEWORK

INFORMATION GOVERNANCE MANAGEMENT FRAMEWORK INFORMATION GOVERNANCE MANAGEMENT FRAMEWORK Document History Document Reference: IG33 Document Purpose: The document complements all other Information Governance policies and sets out the management arrangements

More information

NHS Sunderland Clinical Commissioning Group. Information Governance Strategy 2016/17

NHS Sunderland Clinical Commissioning Group. Information Governance Strategy 2016/17 NHS Sunderland Clinical Commissioning Group Information Governance Strategy 2016/17 Document Status Equality Impact Assessment Document Ratified/Approved By Final No impact Executive Committee Governing

More information

United Lincolnshire Hospitals NHS Trust. Governance Statement 2015/16. Scope of responsibility. The governance framework of the organisation

United Lincolnshire Hospitals NHS Trust. Governance Statement 2015/16. Scope of responsibility. The governance framework of the organisation United Lincolnshire Hospitals NHS Trust Governance Statement 2015/16 Scope of responsibility As Accountable Officer, and Chief Executive of this Board, I have responsibility for maintaining a sound system

More information

INFORMATION GOVERNANCE POLICY

INFORMATION GOVERNANCE POLICY INFORMATION GOVERNANCE POLICY CONSULTATION AND RATIFICATION SCHEDULE Document Name: Governance Policy Policy Number/Version: 2.0 Name of originator/author: Midlands & Lancashire CSU Governance Team Ratified

More information

Information Governance Policy

Information Governance Policy Information Governance Policy Applicable to All employees Version1.0 Last Updated March 2014 CONFIDENTIAL Page 2 of 6 Contents 1. Objectives 3 2. Scope 3 3. Principles 3 4. Information Governance Policy

More information

The Information Commissioner s Office, the Information Governance Alliance and several other organisations are issuing guidance on an on-going basis.

The Information Commissioner s Office, the Information Governance Alliance and several other organisations are issuing guidance on an on-going basis. MARCH 2017 GENERAL DATA PROTECTION REGULATION ROTHERHAM CCG ACTION PLAN Themes of the GDPR: Refining/tightening up of existing concepts Standardised law across the EU New concepts in regulation; accountability,

More information

IGPr002 - Information Governance Management Framework

IGPr002 - Information Governance Management Framework IGPr002 - Information Governance Management Framework Page 1 of 10 Table of Contents Information Governance Management Framework... 1 Why we need this Framework... 3 What the Framework is trying to do...

More information

Information Governance Policy

Information Governance Policy Information Governance Policy Owner Author Information Team Information Governance Manager Reviewed by Approved by and date Council/Committee/EMT Board - Date approved Effective from 24 April 2017 Review

More information

Information Governance Assurance Framework

Information Governance Assurance Framework Document Reference POL008 Document Status Approved Version: V4.0 DOCUMENT CHANGE HISTORY Initiated by Date Author IG Toolkit Requirements November 2010 IG Manager Version Date Comments (i.e. viewed, or

More information

GENERAL DATA PROTECTION REGULATION

GENERAL DATA PROTECTION REGULATION GENERAL DATA PROTECTION REGULATION (GDPR) What is General Data Protection Regulation (GDPR) What this means for GP Practices Replaces the Data Protection Act 1998 (DPA) Designed to match data privacy laws

More information

Findings from ICO audits of 16 local authorities

Findings from ICO audits of 16 local authorities Data protection Findings from ICO audits of 16 local authorities January to December 2013 Introduction This report is based on ICO audits of 16 local authorities between January and December 2013. This

More information

INFORMATION COMMISSIONER S OFFICE FOLLOW UP DATA PROTECTION AUDIT REPORT. Information Governance Manager. This paper supports:

INFORMATION COMMISSIONER S OFFICE FOLLOW UP DATA PROTECTION AUDIT REPORT. Information Governance Manager. This paper supports: FOR DISCUSSION INFORMATION GOVERNANCE COMMITTEE 28 APRIL 2015 AGENDA ITEM 2.6 INFORMATION COMMISSIONER S OFFICE FOLLOW UP DATA PROTECTION AUDIT REPORT Report of Paper prepared by Director of Therapies

More information

Information Governance Policy

Information Governance Policy Information Governance Policy Date completed: February 2016 Responsible Director: Approved by/ date: Director of Compliance Review date: October 2017 Amended: Author: Ben Westmancott Information Governance

More information

Information Governance Clauses Clinical and Non Clinical Contracts

Information Governance Clauses Clinical and Non Clinical Contracts Information Governance Clauses Clinical and Non Clinical Contracts Policy Number Target Audience Approving Committee Date Approved Last Review Date Next Review Date Policy Author Version Number IG014 All

More information

INFORMATION GOVERNANCE MANAGEMENT FRAMEWORK

INFORMATION GOVERNANCE MANAGEMENT FRAMEWORK NHS South West Lincolnshire Clinical Commissioning Group (CCG) INFORMATION GOVERNANCE MANAGEMENT FRAMEWORK Document History: Document Reference: Document Purpose: IG01 Date Ratified: January 2015 Ratified

More information

INFORMATION GOVERNANCE MANAGEMENT FRAMEWORK POLICY

INFORMATION GOVERNANCE MANAGEMENT FRAMEWORK POLICY INFORMATION GOVERNANCE MANAGEMENT FRAMEWORK POLICY Version: 1.4 Approved by: Date approved: 19 January 2017 Name of Originator/Author: Name of Responsible Committee/Individual: Date issued: Information

More information

Risk Management and Assurance Strategy

Risk Management and Assurance Strategy Risk Management and Assurance Strategy Version 5.0 Policy number ULHT-MD-GOV-RM-STRAT Document author(s) Head of 2021 Programme Contributor(s) Approved by Policy Approval Group Date approved Date Published

More information

INFORMATION GOVERNANCE POLICY

INFORMATION GOVERNANCE POLICY INFORMATION GOVERNANCE POLICY 1. CONSULTATION AND RATIFICATION SCHEDULE 1.2. Document Name: Governance Policy 1.4. Policy Number/Version: V4.0 1.6. Name of originator/author: Midlands & Lancashire CSU

More information

Chelsea & Westminster Hospital NHS Foundation Trust. Data protection audit report

Chelsea & Westminster Hospital NHS Foundation Trust. Data protection audit report Chelsea & Westminster Hospital NHS Foundation Trust Data protection audit report Executive summary October 2017 1. Background The Information Commissioner is responsible for enforcing and promoting compliance

More information

Information Asset Management Policy

Information Asset Management Policy Information Asset Management Policy 1.0 Purpose 1.1 The purpose of this policy is to outline the management of the Fund s information asset register and the actions that will be taken to provide sufficient

More information

Policy:E7. Escalation Policy N/A. Appended below at Appendix B. Version: E7/01

Policy:E7. Escalation Policy N/A. Appended below at Appendix B. Version: E7/01 Policy:E7 Escalation Policy Version: E7/01 Ratified by: Trust Management Team Date ratified: 11 th September 2013 Title of Author: Board Secretary & Head of Governance Title of responsible Director Medical

More information

Minor adjustments from IG Steering Group 0.3 Neil Taylor September 2013

Minor adjustments from IG Steering Group 0.3 Neil Taylor September 2013 Author(s) Andrew Thomas Version 0.3 Version Date 21 August 2013 Implementation/approval Date Review Date August 2014 Review Body Governing Body Policy Reference Number 014 Version Author Date Reason for

More information

DATA PROTECTION POLICY

DATA PROTECTION POLICY DATA PROTECTION POLICY Operational Owner: Executive Owner: James Newby Data Protection Officer Sarah Litchfield Senior Information Risk Officer Effective date: 25 th May 2018 Review date: May 2021 Related

More information

Information Governance Annual Report. Public Board Meeting

Information Governance Annual Report. Public Board Meeting Title: Report to: Information Governance Annual Report Trust Board Date: 27 March 2017 Security Classification: Public Board Meeting Purpose of Report: This report provides an update in relation to Information

More information

Information Governance Management Framework 2016/17

Information Governance Management Framework 2016/17 Information Governance Management Framework 2016/17 Reference: IG12 Compliance with all CCG policies, procedures, protocols, guidelines, guidance and standards is a condition of employment. Breach of policy

More information

Information governance strategy

Information governance strategy Information governance strategy January 2018 Version 1.0 NHS fraud. Spot it. Report it. Together we stop it. Version control Version Name Date Comment V 1.0 Trevor Duplessis 22/01/18 Due for review Dec

More information

Heart of England NHS Foundation Trust

Heart of England NHS Foundation Trust Heart of England NHS Foundation Trust Data protection audit report Executive summary February 2017 1. Background 1. Background The Information Commissioner is responsible for enforcing and promoting compliance

More information

Auditing data protection

Auditing data protection Data protection Auditing data protection a guide to ICO data protection audits 1 Contents Executive summary 3 1. Audit programme development 5 Audit planning and risk assessment 2. Audit approach 6 Gathering

More information

NOT PROTECTIVELY MARKED

NOT PROTECTIVELY MARKED Meeting Audit Committee Public Session Date and Time Location Pacific Quay, Glasgow Title of Paper General Data Protection Regulation (GDPR) SPA Preparedness Item Number 9.4 Presented By Catherine Topley

More information

INFORMATION GOVERNANCE POLICY

INFORMATION GOVERNANCE POLICY INFORMATION GOVERNANCE POLICY Page 1 of 13 INFORMATION GOVERNANCE POLICY EXECUTIVE SUMMARY Key Messages Principles of Information Governance Openness Confidentiality and Legal Compliance Information Security

More information

INFORMATION GOVERNANCE STRATEGY

INFORMATION GOVERNANCE STRATEGY INFORMATION GOVERNANCE STRATEGY Document Number 2009/49/V2 Document Title Information Governance Strategy Author Phil Cottis Author s Job Title Information Governance & RA Manager Department IM&T Ratifying

More information

INFORMATION GOVERNANCE STRATEGY. Documentation control

INFORMATION GOVERNANCE STRATEGY. Documentation control INFORMATION GOVERNANCE STRATEGY Documentation control Reference Date Approved Approving Body Version Supersedes Consultation Undertaken Target Audience Supporting procedures GG/INF/01 TRUST BOARD Information

More information

DATA QUALITY POLICY. Version: 1.2. Management and Caldicott Committee. Date approved: 02 February Governance Lead

DATA QUALITY POLICY. Version: 1.2. Management and Caldicott Committee. Date approved: 02 February Governance Lead DATA QUALITY POLICY Version: 1.2 Approved by: Date approved: 02 February 2016 Name of Originator/Author: Name of Responsible Committee/Individual: Information Governance, Records Management and Caldicott

More information

Identifies the risk management structure, roles, responsibilities and authority of staff, committees and groups with responsibility for risk

Identifies the risk management structure, roles, responsibilities and authority of staff, committees and groups with responsibility for risk Title Description of document The sets out the process by which the Trust identifies, manages, reduces and mitigates risks to achieving the organisational objectives. It sets out the framework required

More information

Privacy Impact Assessment. Integrated Personal Commissioning (IPC) Programme

Privacy Impact Assessment. Integrated Personal Commissioning (IPC) Programme Privacy Impact Assessment Integrated Personal Commissioning (IPC) Programme Reference number: IG MAY17 Date PIA completed: May 2017 The Clinical Commissioning Group MUST comply with the Data Protection

More information

INFORMATION GOVERNANCE POLICY AND FRAMEWORK

INFORMATION GOVERNANCE POLICY AND FRAMEWORK INFORMATION GOVERNANCE POLICY AND FRAMEWORK Policy approved by: Audit and Governance Committees Date: 9 th October 2017 Next Review Date: September 2018 Version: 4.0 Information Governance Policy & Framework

More information

Privacy Impact Assessment Policy and Procedure

Privacy Impact Assessment Policy and Procedure Privacy Impact Assessment Policy and Procedure This document outlines the Trust s approach and methodology for conducting Privacy Impact Assessments in line with the Information Risk Policy Key Words:

More information

NHS BARNSLEY CCG DATA QUALITY POLICY SEPTEMBER 2016

NHS BARNSLEY CCG DATA QUALITY POLICY SEPTEMBER 2016 Putting Barnsley People First NHS BARNSLEY CCG DATA QUALITY POLICY SEPTEMBER 2016 Version: 1.0 Approved By: Governing Body Date Approved: 8 September 2016 Name of originator / author: Name of responsible

More information

NHS Newcastle Gateshead Clinical Commissioning Group. Information Governance Strategy 2017/18

NHS Newcastle Gateshead Clinical Commissioning Group. Information Governance Strategy 2017/18 NHS Newcastle Gateshead Clinical Commissioning Group Information Governance Strategy 2017/18 Document Status Equality Impact Assessment Document Ratified/Approved By Final No impact Quality, Safety & Risk

More information

Documented and publicly available procedures are in place to ensure compliance with the Freedom of Information Act 2000

Documented and publicly available procedures are in place to ensure compliance with the Freedom of Information Act 2000 Documented and publicly available procedures are in place to ensure compliance with the Freedom of Information Act 2000 Guidance Compliance with the Freedom of Information Act 2000 Introduction 1. The

More information

Data Protection Policy

Data Protection Policy Data Protection Policy StCH Data Protection Policy - POL 53 vs1 - July 2016 1 Document Control Table Document Title: Data Protection Policy Document Ref: POL 53 Author (name and job title): Karen Anderson,

More information

General Data Protection Regulation (GDPR) Strategy

General Data Protection Regulation (GDPR) Strategy General Data Protection Regulation (GDPR) Strategy NHS Digital s Approach to Compliance Published October 2017 Copyright 2017 Health and Social Care Information Centre. The Health and Social Care Information

More information

INFORMATION GOVERNANCE ASSURANCE FRAMEWORK

INFORMATION GOVERNANCE ASSURANCE FRAMEWORK INFORMATION GOVERNANCE ASSURANCE FRAMEWORK Summary This document sets out an overarching framework for the strategic Information Governance agenda in the Business Services Organisation. In particular,

More information

Information Governance Management Framework 2017/18 Reference: IG12

Information Governance Management Framework 2017/18 Reference: IG12 Information Governance Management Framework 2017/18 Reference: IG12 Compliance with all CCG policies, procedures, protocols, guidelines, guidance and standards is a condition of employment. Breach of policy

More information

Information Risk Policy

Information Risk Policy Information Risk Policy Version 1_0 Responsible Person Information Governance Manager Lead Director Director of Performance and Corporate Services Consultation Route Information Governance Steering Group

More information

Data Protection Impact Assessment Policy

Data Protection Impact Assessment Policy Data Protection Impact Assessment Policy Version 0.1 1 VERSION CONTROL Version Date Author Reason for Change 0.1 16.07.18 Debby Jones New policy 2 EQUALITY IMPACT ASSESSMENT Section 4 of the Equality Act

More information

Date: INFORMATION GOVERNANCE POLICY

Date: INFORMATION GOVERNANCE POLICY Date: INFORMATION GOVERNANCE POLICY Information Governance Policy IGPOL/01 Information Systems Corporate Services Division March 2017 1 Revision History Version Date Author(s) Comments 0.1 12/12/2012 Helen

More information

THE GENERAL DATA PROTECTION REGULATION: GUIDANCE ON THE ROLE OF THE DATA PROTECTION OFFICER

THE GENERAL DATA PROTECTION REGULATION: GUIDANCE ON THE ROLE OF THE DATA PROTECTION OFFICER THE GENERAL DATA PROTECTION REGULATION: GUIDANCE ON THE ROLE OF THE DATA PROTECTION OFFICER Contents 1 Introduction 2 2 Key messages 3 3 The requirement to appoint a Data Protection Officer 4 3.1 Public

More information

Draft Internal Audit Plan 2012/13 Audit Committee (September 2012) Airedale NHS Foundation Trust

Draft Internal Audit Plan 2012/13 Audit Committee (September 2012) Airedale NHS Foundation Trust Draft Internal Audit Plan 2012/13 (September 2012) Contents 1. Introduction 2. Risk Assessment 3. Internal Audit Plan Appendix A: 3 Year Indicative Plan 1 1. Introduction MIAA s approach to planning focuses

More information

HSCIC Audit of Data Sharing Activities:

HSCIC Audit of Data Sharing Activities: Directorate / Programme Data Dissemination Services Project Data Sharing Audits Status Approved Director Terry Hill Version 1.0 Owner Rob Shaw Version issue date 21/04/2016 HSCIC Audit of Data Sharing

More information

Parliamentary and Health Ombudsman. Data protection audit report

Parliamentary and Health Ombudsman. Data protection audit report Parliamentary and Health Ombudsman Data protection audit report Executive summary March 2018 1. Background The Information Commissioner is responsible for enforcing and promoting compliance with the Data

More information

Doncaster Council Data Quality Strategy

Doncaster Council Data Quality Strategy Doncaster Council Data Quality Strategy 2016/17-2020/21 Better Data, Better Services Approving Body Date of Approval Date of Implementation Next Review Date Review Responsibility Version Doncaster Council

More information

Information Sharing Policy

Information Sharing Policy Information Sharing Policy DOCUMENT CONTROL: Version: 1 Ratified by: Risk Management Sub Group Date ratified: 19 December 2012 Name of originator/author: Information Governance Manager Name of responsible

More information

The Royal Wolverhampton NHS Trust

The Royal Wolverhampton NHS Trust The Royal Wolverhampton NHS Trust Trust Board Report Meeting Date: Monday 30 March, 2015 Title: Information Governance Toolkit Submission V12 2014/15 Executive Summary: Action Requested: Report of: Author:

More information

Data protection (GDPR) policy

Data protection (GDPR) policy Data protection (GDPR) policy January 2018 Version: 1.0 NHS fraud. Spot it. Report it. Together we stop it. Version control Version Name Date Comment 1.0 Trevor Duplessis 22/01/18 Review due Dec 2018 OFFICIAL

More information

The UK legislation is wholly retrospective and applies to all information held by public authorities regardless of its date.

The UK legislation is wholly retrospective and applies to all information held by public authorities regardless of its date. FREEDOM OF INFORMATION POLICY INTRODUCTION The Freedom of Information (FOI) Act was passed in 2000 and replaces the Open Government Code of Practice that has been in place since 1994. The Act gives the

More information

Burton Hospitals NHS Foundation Trust. On: 22 January Review Date: December Corporate / Directorate. Department Responsible for Review:

Burton Hospitals NHS Foundation Trust. On: 22 January Review Date: December Corporate / Directorate. Department Responsible for Review: POLICY DOCUMENT Burton Hospitals NHS Foundation Trust DATA QUALITY POLICY Approved by: Trust Management Team On: 22 January 2016 Review Date: December 2018 Corporate / Directorate Clinical / Non Clinical

More information

PRIVACY IMPACT ASSESSMENT (PIA) TEMPLATE

PRIVACY IMPACT ASSESSMENT (PIA) TEMPLATE PRIVACY IMPACT ASSESSMENT (PIA) TEMPLATE Reference No: IG40 Version: 1.2 Purpose of Document: Ratified by: Date ratified: 27 th September 2013 Review Date September 2014 Name of originator/author: Contact

More information

General Data Protection Regulation (GDPR) Key considerations and implications for brokers

General Data Protection Regulation (GDPR) Key considerations and implications for brokers General Data Protection Regulation () Key and implications for brokers Contents at at 03 - did you know? 05 How to handle 07 Considerations for Broker Directors 08 General Data Protection Regulation ()

More information

Hours of Work: 37.5 hours per week (part time hours negotiable)

Hours of Work: 37.5 hours per week (part time hours negotiable) JOB DESCRIPTION Post Title: Head of Performance Assurance Location: NHS Oldham CCG Headquarters (Ellen House) Salary/Grade: Band 8c Hours of Work: 37.5 hours per week (part time hours negotiable) Type

More information

Board Assurance and Escalation Framework

Board Assurance and Escalation Framework Lincolnshire Partnership NHS Foundation Trust (LPFT) Board Assurance and Escalation Framework DOCUMENT VERSION CONTROL Document Type and Title: Policy No 5a. with effect from 2/11/15 (former corporate

More information

Appendix: 4.3b APPENDIX D TO THE SERVICE LEVEL AGREEMENT BETWEEN NEL CSU AND ISLINGTON CCG. SLA Performance Measures. Core Services. March 2013 (v5.

Appendix: 4.3b APPENDIX D TO THE SERVICE LEVEL AGREEMENT BETWEEN NEL CSU AND ISLINGTON CCG. SLA Performance Measures. Core Services. March 2013 (v5. Appendix: 4.3b APPENDIX D TO THE SERVICE LEVEL AGREEMENT BETWEEN NEL CSU AND ISLINGTON CCG SLA Performance Measures Core Services March 2013 (v5.0) Overview These KPIs have been co-designed by the CSU

More information

Meeting Date 15 March 2018 Agenda Item 2b

Meeting Date 15 March 2018 Agenda Item 2b Meeting Date 15 March 2018 Agenda Item 2b Report Title Stocktake Report Author Pam Wenger, Report Sponsor Pam Wenger, Presented by Pam Wenger, Freedom of Open Information Purpose of the Report The purpose

More information

For: Information Assurance Discussion and input Decision/approval. Ellen Bull, Deputy Director of Quality Author Contact Details: 3531

For: Information Assurance Discussion and input Decision/approval. Ellen Bull, Deputy Director of Quality Author Contact Details: 3531 Trust Board Item: 15 Date: 07/02/2018 Purpose of the Report: Enclosure: K To request ratification from the Trust Board of Directors on the. which was discussed, refined and approved at the Risk Management

More information

GUIDELINES FOR IMPLEMENTING A PRIVACY MANAGEMENT PROGRAM For Privacy Accountability in Manitoba s Public Sector

GUIDELINES FOR IMPLEMENTING A PRIVACY MANAGEMENT PROGRAM For Privacy Accountability in Manitoba s Public Sector GUIDELINES FOR IMPLEMENTING A PRIVACY MANAGEMENT PROGRAM For Privacy Accountability in Manitoba s Public Sector TABLE OF CONTENTS INTRODUCTION... 2 Accountable privacy management 2 Getting started 3 A.

More information

JOB DESCRIPTION per week.

JOB DESCRIPTION per week. JOB DSCRIPTION 1. Job Details: Job Title: Hours: Deputy Information Governance Manager 37.5 per week. Band: 6 Department / Directorate: Information Management &Technology The Information Management & Technology

More information

Information Governance, Management & Technology Committee Terms of Reference

Information Governance, Management & Technology Committee Terms of Reference Information Governance, Management & Technology Committee Terms of Reference 1. Introduction The Information Governance, Management and Technology (IGM&T) Committee is established on behalf of NHS Rushcliffe

More information

Trust Board Meeting in Public: Wednesday 17 January 2018 TB

Trust Board Meeting in Public: Wednesday 17 January 2018 TB Trust Board Meeting in Public: Wednesday 17 January 2018 Title Progress report regarding organisational preparedness for the General Data Protection Regulation (Data Protection Act 2018) Status History

More information

East Riding of Yorkshire Council Data protection audit report. Executive summary March 2014

East Riding of Yorkshire Council Data protection audit report. Executive summary March 2014 East Riding of Yorkshire Council Data protection audit report Executive summary March 2014 1. Background The Information Commissioner is responsible for enforcing and promoting compliance with the Data

More information

SOMERSET PARTNERSHIP NHS FOUNDATION TRUST STRENGTHENING GOVERNANCE ARRANGEMENTS. Report to the Trust Board 24 May 2016

SOMERSET PARTNERSHIP NHS FOUNDATION TRUST STRENGTHENING GOVERNANCE ARRANGEMENTS. Report to the Trust Board 24 May 2016 R SOMERSET PARTNERSHIP NHS FOUNDATION TRUST STRENGTHENING GOVERNANCE ARRANGEMENTS Report to the Trust Board 24 May 2016 Sponsoring Director: Author: Purpose of the report: Key Issues and Recommendations:

More information

Freedom of Information/Environmental Information Regulations Policy and Procedure

Freedom of Information/Environmental Information Regulations Policy and Procedure Policy Number: 8.3 Version number: 01 Date of issue: Date Archived: Reason for policy: (Redraft/new) New policy to ensure compliance with current legislation Authorised by: On Behalf of Management (Signature)

More information

REPORT TO MERTON CLINICAL COMMISSIONING GROUP GOVERNING BODY

REPORT TO MERTON CLINICAL COMMISSIONING GROUP GOVERNING BODY REPORT TO MERTON CLINICAL COMMISSIONING GROUP GOVERNING BODY Date of Meeting: 24 th March 216 Agenda No: 8.2 Attachment: 15 Title of Document: Board Assurance Framework Report Author: Terri Burns, Corporate

More information

Humber Information Sharing Charter

Humber Information Sharing Charter External Ref: HIG 01 Review date November 2016 Version No. V07 Internal Ref: NELC 16.60.01 Humber Information Sharing Charter This Charter may be an uncontrolled copy, please check the source of this document

More information

GDPR General Data Protection Regulation

GDPR General Data Protection Regulation GDPR General Data Protection Regulation Compliance Information Guide - May 2018 About this document Ticket Arena & Event Genius Disclaimer DISCLAIMER: This is a brief presentation for information purposes

More information

OFFICIAL. Date 18 April 2018 Pacific Quay, Glasgow General Data Protection Regulation (GDPR) Police Scotland Preparedness Item Number 11.

OFFICIAL. Date 18 April 2018 Pacific Quay, Glasgow General Data Protection Regulation (GDPR) Police Scotland Preparedness Item Number 11. Meeting Date Location Pacific Quay, Glasgow Title of Paper General Data Protection Regulation (GDPR) Police Scotland Preparedness Item Number 11.2 Presented By ACC Alan Speirs Recommendation to Members

More information

Overarching Information Governance Policy

Overarching Information Governance Policy Document Information Board Library Reference Document Type Document Subject Original Document Author Reviewed By Review Cycle IM&T_01 Policy Information Information IGMG 3 Years Note: This document is

More information

BROOKS PERSONAL TRAINING

BROOKS PERSONAL TRAINING BROOKS PERSONAL TRAINING Data Protection Policy Data Protection Policy Lent 2017 0 DATA PROTECTION POLICY Table of Contents: 1. Document Control... 2 2. Introduction... 3 3. General Statement of Scope...

More information

General Data Protection Regulation (GDPR) Readiness

General Data Protection Regulation (GDPR) Readiness For External Distribution Canada Life UK General Data Protection Regulation (GDPR) Readiness Customers, Clients and Business Partners FAQ GDPR TP FAQ January 2018 Frequently Asked Questions (FAQ) Document

More information

Agenda Item 8. Page 31

Agenda Item 8. Page 31 Agenda Item 8 Proposed Governance Arrangements for Joint Commissioning of Health and Social Care between Lincolnshire County Council, the Four Lincolnshire Clinical Commissioning Groups and the Local Area

More information

MACQUARIE TELECOM GROUP LIMITED CORPORATE GOVERNANCE

MACQUARIE TELECOM GROUP LIMITED CORPORATE GOVERNANCE MACQUARIE TELECOM GROUP LIMITED CORPORATE GOVERNANCE A. Introduction Macquarie Telecom Group Limited operates in a challenging, rapidly changing telecommunications and hosting environment and the Board

More information

APPENDIX 1 DRAFT REVIEW AGAINST THE CODE OF CORPORATE GOVERNANCE

APPENDIX 1 DRAFT REVIEW AGAINST THE CODE OF CORPORATE GOVERNANCE APPENDIX 1 DRAFT REVIEW AGAINST THE CODE OF CORPORATE GOVERNANCE 2016-17 Introduction The main principle underpinning the development of the new Delivering Good Governance in Local Government: Framework

More information

PHWIGC framework that addresses the issues raised by the Francis Report. Author: John Morley & Jane Evans Information Governance Managers

PHWIGC framework that addresses the issues raised by the Francis Report. Author: John Morley & Jane Evans Information Governance Managers PHWIGC 17 03 Information Governance Audits Purpose of Document: To describe the process that Public Health Wales Information Governance Managers will follow when undertaking announced and unannounced Information

More information

INFORMATION GOVERNANCE POLICY

INFORMATION GOVERNANCE POLICY INFORMATION GOVERNANCE POLICY Unique Reference / Version Primary Intranet Location Information Management & Governance Secondary Intranet Location Policy Name Information Governance Policy Version Number

More information

The ICT Service:

The ICT Service: GDPR for schools 1 Intro and aims The ICT Service: support@theictservice.org.uk, 0300 300 00 00 Cambridgeshire County Council: Information and Records Team. Data.protection@cambridgeshire.gov.uk 01223

More information

NIHR Local Clinical Research Networks

NIHR Local Clinical Research Networks NIHR Local Clinical Research Networks Annual Plans 2014-15 Guidance WORKING DRAFT Version 0.4 WORKING DRAFT v0.4 Document Control This document is updated and issued annually by the national CRN Coordinating

More information

This Policy supersedes the following Policy, which must now be destroyed:

This Policy supersedes the following Policy, which must now be destroyed: Document Title Reference Number Lead Officer Author(s) (name and designation) Ratified by Forensic Readiness Policy NTW(O)56 Lisa Quinn Executive Director of Performance and Assurance Sue Proud Information

More information