Information Sharing Policy

Size: px
Start display at page:

Download "Information Sharing Policy"

Transcription

1 Information Sharing Policy DOCUMENT CONTROL: Version: 1 Ratified by: Risk Management Sub Group Date ratified: 19 December 2012 Name of originator/author: Information Governance Manager Name of responsible Information Governance Steering Group committee/individual: Date issued: 20 December 2012 Review date: December 2015 Target Audience All staff

2 CONTENTS SECTION PAGE NO 1. INTRODUCTION 3 2. PURPOSE 3 3. SCOPE 4 4. RESPONSIBILITIES, ACCOUNTABILITIES AND DUTIES 4 5. PROCEDURE/IMPLEMENTATION Legal and Guiding Principles Who needs information Information Sharing Agreements Informed decision-making for sharing information 9 6. TRAINING IMPLICATIONS 10 7 MONITORING ARRANGEMENTS EQUALITY IMPACT ASSESSMENT SCREENING Privacy, Dignity and Respect Mental Capacity Act LINKS TO ANY ASSOCIATED DOCUMENTS REFERENCES APPENDICES Flowchart of Key questions for information sharing Information Sharing Agreement Template 15 Page 2 of 18

3 1. INTRODUCTION Government policy places a strong emphasis on the need to share information about service users between health care organisations, professional bodies and commercial third parties, in order to provide the effective provision of seamless care. It is also important that service users trust providers to respect their privacy and keep their information confidential. The public services involved in the provision of health and social care have a legal responsibility to ensure that their use of personal information is lawful, properly controlled and that an individual s autonomy is respected. It is important to achieve a balance between the need to share information to provide quality care and protecting confidentiality. 2. PURPOSE The purpose of the Information Sharing Policy is to outline the guiding principles for information sharing, based on legal and ethical requirements. The policy aims to: Provide a framework to establish and regulate working practice and to provide guidance to enable the secure and confidential sharing of person-identifiable information; Provide guidance and explain the security and confidentiality laws and principles which underpin the use and exchange of person-identifiable information; To define the common purposes for sharing personal information; Remove barriers to effective information sharing; To ensure compliance with the Information Governance Toolkit. 2.1 DEFINITIONS Personal Information Any data from which an individual can be identified either from the data or from the data and other information which is in the possession of, or likely to come into the possession of, the data controller Sensitive Information The Data Protection Act defines categories of sensitive personal data, namely, personal data consisting of information as to:- a) the racial or ethnic origin of the data subject, b) their political opinions, Page 3 of 18

4 c) their religious beliefs or other beliefs of a similar nature, d) whether they are a member of a trade union, e) their physical or mental health or condition, f) their sexual life, g) the commission or alleged commission by them of any offence, or any proceedings for any offence committed or alleged to have been committed by them, the disposal of such proceedings or the sentence of any court in such proceedings. Anonymised Information Anonymisation is where all elements of potential identifiers to be removed completely so that it does not identify an individual. Pseudonymised Information Where data is anonymised but retains a single key such as a code or reference number, known only to the provider of the information so that when it is shared, the provider can link back to the individual. 3. SCOPE This policy applies to all Trust staff, and any staff undertaking activities on behalf of the Trust including agency staff and contractors, as well as volunteers, visitors and service users. 4. RESPONSIBILITIES, ACCOUNTABILITIES AND DUTIES 4.1 Chief Executive The Chief Executive has overall responsibility for Information Sharing in the Trust and for establishing and maintaining effective policies and procedures for meeting all statutory requirements and guidance relating to the processing and sharing of all types of information and data. 4.2 Director of Business Assurance The Director of Business Assurance has responsibility for governance processes including information and as Senior Information Risk Owner (SIRO) is accountable for the management of all risks relating to information and data security. 4.3 Medical Director As Caldicott Guardian the Medical Director has responsibility for overseeing all arrangements, protocols and procedures where confidential patient information may be shared. 4.4 Information Governance Manager The Information Governance Manager has responsibility for the implementation of the Information Sharing Policy and that Page 4 of 18

5 information sharing systems and processes are developed, coordinated and monitored. 4.5 Records Manager The Records Manager has responsibility to ensure that when sharing information there is compliance with records management and safe haven policies, processes, standards and legislation. 4.6 Managers Managers have a responsibility to make themselves familiar with the requirements of this policy and for advising staff to make themselves familiar with and understand the need for robust protocols to support working with partners and sharing information. 4.7 Staff All staff are responsible for the safety and confidentiality of information and that they comply with relevant legislation, guidance and policies and procedures at all times. Staff should also ensure that they are up to date with mandatory Information Governance training. Failure to comply with this policy may have serious consequences for the care of service users and the organisation and may include the individual being subject to civil, criminal or disciplinary proceedings. 5. PROCEDURE/IMPLEMENTATION Information sharing partners may use personal-identifiable information for different purposes, the main being for: managing the care and treatment of services users assuring and improving the quality of care and treatment prevention and detection of serious crime safeguarding children and vulnerable adults research and development On no account must personal identifiable information be divulged to anyone other than an authorised person who is either concerned directly with the care, diagnosis and/or treatment of an individual or has a justified non clinical need. If there is any doubt whatsoever as to the authority of the person or body asking for information of this nature advice must be sought from your line manager, Information Governance Team. If a query requires advice out of hours the manager on call should be contacted. Any inappropriate disclosures of information should be reported through the incident reporting system. Page 5 of 18

6 5.1 Legal and Guiding Principles Legal Principles The sharing of personal-identifiable information is subject to three major legal considerations Common Law Duty of Confidentiality, Human Rights Act 1998 and the Data Protection Act Common Law of Confidentiality is not coded in an Act of Parliament but built up from case law where practice has been established by individual judgement. The main principle is that information confided should not be used or disclosed further, except as originally understood by the confider or with their permission. As a result information can be only shared with the consent of the service user or where the information has been properly anonymised. Article 8 of the Human Rights Act 1998 covers the individual s right to privacy and states: Everyone has the right to respect for his private and family life, his home and his correspondence. Although this right is not absolute a breach must be justified. In order to justify a breach, the following will need to be shown: acted in accordance with the law; acted in the pursuit of a legitimate aim; and acted in a way necessary in democratic society. The Data Protection Act 1998 provides a framework that governs the processing of person-identifiable information personal data. Processing includes holding, obtaining, recording, using and disclosing of information. The Act applies to all forms of media from paper to images. The principles are: Be processed fairly and lawfully and shall not be processed unless certain conditions are met. Be obtained for specified and lawful purposes and shall not be processed in any manner incompatible with those purposes. Be adequate, relevant and not excessive for those purposes. Be accurate and kept up to date. Not be kept for longer than is necessary for those purposes. Be processed in accordance with the data subject's rights under the 1998 Act. Be the subject of appropriate technical and organisational measures against unauthorised or unlawful processing, accidental loss or destruction. Not be transferred to a country outside the European Economic Area, unless that country or territory has equivalent levels of protection for personal data. For further information on Data Protection please refer to the Data Protection Policy on the Trust website. Page 6 of 18

7 Guiding Principles Guiding principles are based on the six principles of good practice identified by the Caldicott Report, Justify the purpose what is the purpose of the disclosure? This should be clearly defined and scrutinised by Caldicott Guardian. Only Use patient identifiable information when absolutely necessary is the proposed disclosure a proportionate response to the need? Information should not be disclosed unless essential for the purpose specified. Use only the minimum necessary - what is the nature and extent of the information to be disclosed? Should be on a strict need to know basis - to who is the disclosure to be made? Everyone who has access to patient identifiable information should be aware of their responsibilities Understand and comply with the law In addition to the Caldicott principles the NHS Confidentiality Code of Practice describes the duty of confidence arising when one person discloses information to another. The Code: is a legal obligation that is derived from case law; is a requirement established within professional codes of conduct; must be included within NHS employment contracts as a specific requirement linked to disciplinary procedures; must be included in third party contract; must be included in all information sharing agreements. 5.2 Who needs the information? Internal Services within the Trust Health care for service users can run across more than one service and it is important that where relevant information is shared to enable that the care treatment and support needs are met. Coordinating Care with Social Services and other Agencies Health care is commonly a shared responsibility between health and local authorities; joint access to client information is essential if that responsibility is to be fulfilled effectively. Bodies such as housing authorities have an important part to play in helping people regain access to normal living and social inclusion, and they need to have appropriate information if they are to provide the right level of support and act in the interests of all of their residents and the wider population. The service user needs to be aware that some information sharing will be necessary and this can usually be discussed with the service user as part of the Care Planning Process. If a service user raises any objections the possible consequences of not having a Page 7 of 18

8 coordinated approach should be explained and assurance given that other agencies would receive only information which they really need to know (see also the Care Programme Approach Policy for further information). Any objections should be recorded in the service user s notes. The service user s ultimate decision should be respected unless there are overriding considerations to the contrary. Regulatory Bodies There are regulatory bodies that require notification of specific instances such as death of detained service user and Absent without Leave service user which require notification to the Care Quality Commission. This information is required to be either anonymised or pseudonymised. Coroners All enquiries from the Coroner s office are dealt with by the Information Governance Team through the Access to Health Records Policy. When a request is received the information is released by the Information Governance Team only with prior approval from the Assistant Director. Police /Court/Prison/Probation As with any general disclosure of information, requests from the police/ court are dealt with by the Information Governance Team. Staff must not feel pressured or intimidated into giving information just because the police have requested it. Information can only be released if the service user or employee has given their consent or with a court order. Please refer to the Access to Health Records Policy for more information or contact the Information Governance Team. In certain circumstances an individual s right to confidentiality may be overridden by the public s interest in having access to information. Decisions to disclose such information must be discussed with the Information Governance Team. The decision made must be recorded in the relevant file (e.g. health record/personnel file) and the reasons justifying the action taken. If a service user is taken into custody or appears in court, information may need to be exchanged. This may be necessary to ensure that those who need care receive it and that the criminal justice authorities can take the individual s health (including mental health) into account in determining the appropriate outcome. When an offender who is a service user is serving a community sentence, or has been released from custody, probation staff can be in the position of supervising people who are either receiving health care or are in need of such care. Probation staff need regular contact with the appropriate health workers to ensure that they are Page 8 of 18

9 fulfilling their public protection duties. An explicit and agreed approach to information sharing must be in place for sharing with the police or probation service. NHS Protect Formerly known as the NHS Counter Fraud and Security Management Service operate under the authority of the Secretary of State for Health Directions on Countering Fraud in the NHS. This direction places specific duties upon RDaSH to make available to NHS Protect any files or data as required in the pursuance of its counter fraud function. In addition, it has statutory powers conferred by the NHS Act 2006 that require the production of any documents containing information relevant to the exercise of any of its functions, further advice can be sought from the LCFS. Press and Broadcasting Media Under no circumstances should staff communicate directly with any press and/or broadcasting organisations. The Trust has a designated point of contact within Business Assurance Directorate for all press enquiries. Any queries should be referred to the Head of Communications. 5.3 Information Sharing Agreement This policy sets out the framework for Information Sharing however Information Sharing Agreements must be developed with the various agencies with which the Trust works with. An electronic register for all Information Sharing Agreements will be managed by the Information Governance Team that will ensure an agreement is in place with the required agencies and that the agreements are reviewed and re-signed on an annual basis. Whether the Trust is developing or is required to sign up to a third parties Information Sharing Agreement this will be agreed by the Information Governance Steering Group prior to signing and implementation. The authorised signatory for Rotherham Doncaster and South Humber Foundation Trust is the Caldicott Guardian. 5.4 Informed decision making for sharing information If the Trust is asked to share information or feels that information should be shared the Information Governance Team will make an informed decision on a case per case basis whether to do so unless there is a statutory duty or court order to share. Key questions to be considered are (see also appendix 1): 1. Is there a clear and legitimate purpose to share the Page 9 of 18

10 information? Take each case for sharing information individually if you acted previously one way it does not mean that the same course of action is required every time. If in doubt seek advice contact the Information Governance Team. NB: Names need not to be used at this point. 2. Does the information enable a person to be identified and is it confidential? Information should be shared with consent wherever appropriate staff should be open and honest with service users from the outset as to what, why and how information should or could be shared. 3. If there is no consent is there a good reason not to seek it, is there sufficient public interest to share? 4. If information is to be shared will it be done appropriately and securely? Only share what is necessary make sure the information being shared is relevant, accurate, and proportionate. Can it be anonymised or pseudonymised Ensure that an effective system is in place to ensure that the information is shared securely and only to the authorised person. Please refer to the Safe Haven Policy and the Policy and Procedure for the Secure Storage and Transfer of Patient Identifiable Data for more details. 5. Have you recorded the decision regarding sharing information? Always keep a record of the decision made and the reasons for it whether you share the information or not. 6. TRAINING IMPLICATIONS As a Trust policy, all staff need to be aware of the key points that it covers. Staff can be made aware through a variety of means such as: Information Governance Training Local induction Team Brief Weekly Newsletter Team meetings Page 10 of 18

11 7. MONITORING ARRANGEMENTS Area for Monitoring How Who by Reported to Frequency Breaches In Policy Information Sharing Agreements Information Governance Toolkit Incident Reporting Process Information Governance Annual Report Annual Submission Information Governance Manager Information Governance Manager Information Governance Manager Information Governance Steering Group Information Governance Steering Group Risk Management Sub Group Information Governance Steering Group By exception Annual Annual 8. EQUALITY IMPACT ASSESSMENT SCREENING - The completed Equality Impact Assessment for this Policy has been published on the Equality and Diversity webpage of the RDaSH website click here 8.1 Privacy, Dignity and Respect The NHS Constitution states that all patients should feel that their privacy and dignity are respected while they are in hospital. High Quality Care for All (2008), Lord Darzi s review of the NHS, identifies the need to organise care around the individual, not just clinically but in terms of dignity and respect. Indicate how this will be met As a consequence the Trust is required to articulate its intent to deliver care with privacy and dignity that treats all service users with respect. Therefore, all procedural documents will be considered, if relevant, to reflect the requirement to treat everyone with privacy, dignity and respect, (when appropriate this should also include how same sex accommodation is provided). Page 11 of 18

12 8.2 Mental Capacity Act Central to any aspect of care delivered to adults and young people aged 16 years or over will be the consideration of the individuals capacity to participate in the decision making process. Consequently, no intervention should be carried out without either the individuals informed consent, or the powers included in a legal framework, or by order of the Court Therefore, the Trust is required to make sure that all staff working with individuals who use our service are familiar with the provisions within the Mental Capacity Act. For this reason all procedural documents will be considered, if relevant to reflect the provisions of the Mental Capacity Act 2005 to ensure that the interests of an individual whose capacity is in question can continue to make as many decisions for themselves as possible. Indicate How This Will Be Achieved. All individuals involved in the implementation of this policy should do so in accordance with the Guiding Principles of the Mental Capacity Act (Section 1) 9. LINKS TO ANY ASSOCIATED DOCUMENTS Policy for Clinical Record Keeping Standards and Clinical Records Management Access to Health records Policy Records Management Policy Information Governance Policy Informatics Security Policy Policy for the Secure Storage and Transfer of Person Identifiable Data (PID) Data Protection Policy Protocol For Access Control Policy for the Secure Storage and Transfer of Person Identifiable Data Safeguarding Adults Policy Safeguarding Children Policy Policy for the provision of, access to and use of interpreters for service users and carers Common Law of Confidentiality Data Protection Act 1998 Human Rights Act 1998 Confidentiality NHS Code of Practice Multi-Agency Public Protection Arrangements (MAPPA) and duty to cooperate Children Act 2004 Page 12 of 18

13 Crime Disorder Act 1998 NHS Act 2006 Secretary of State Directions on Countering Fraud in the NHS 2004 Safety and justice sharing personal information in the context of domestic violence ( 10 REFERENCES Human Rights Act 1998 Information Sharing and Mental Health Guidance to Support Information Sharing by Mental Health Services 11 APPENDICES Appendix 1 Flowchart for key question for information sharing Appendix 2 - Sharing Information Protocol Template Page 13 of 18

14 Appendix 1 Flowchart of Key questions for information sharing You are asked to or wish to share informational Is there a clear and legitimate purpose for sharing the information? No Yes No Does the information enable a person to be identified? Yes No Is the information confidential? Not Sure Seek advice from IG Team Yes Yes Do you have consent? No You can share Yes Is there sufficient public interest to share? (for advice contact IG team) No Do not share Share Information: Identify how much information to share Distinguish fact from opinion Ensure that you giving the right information to the right person Ensure you are sharing the information securely Inform the person that the information has been shared if they were not aware of this and it would not create or increase the risk of harm Record the information sharing decision and your reasons, in line with local procedures. If there are concerns that a child may be at risk of significant harm or an adult may be a risk of serious harm, then follow the relevant procedures without delay. Seek advice if you are not sure what to do at any stage and ensure that the outcome of the decision is recorded. IG@rdash.nhs.uk Telephone: Page 14 of 18

15 Appendix 2 Information Sharing Agreement (ISA) Between Rotherham Doncaster and South Humber NHS Foundation Trust (RDaSH) & <Second Party> Version: Draft 1 Name of originator/author: Effective date: Latter approval signature date on last page Review date: 2 years after latter signature date Page 15 of 18

16 This agreement defines the information that will be transferred between the organisations listed and arrangements for assisting compliance with relevant legislation and guidance including the Data Protection Act Parties to the Agreement Organisation Data Controller Rotherham Doncaster and South Humber NHS Trust (RDaSH) Caldicott Guardian Dr Navjot Ahluwalia ICO Notification Registration no: Z <Second Party> ICO Notification Registration no: Purposes of the Agreement General Requisites of the Agreement Both organisations have an up-to-date Data Protection Act Registration (Notification), which covers them for the information and activities detailed in this ISA. Each organisation signing this agreement shall have appointed a responsible officer who will ensure the protection of personal information e.g. Caldicott Guardian or senior manager responsible for data protection. Page 16 of 18

17 Both organisations will, as appropriate, ensure that records are accurate, complete and up-todate. Shared information will be stored in a secure fashion appropriate to its sensitivity. All equipment used and data transfer methods, within both organisations will meet current NHS security standards. Shared information will only be used for the agreed purposes. Specific Requisites Information to be Shared Methods Used for Sharing Data Usage and Record Retention Records will be retained and disposed of in accordance with the requirements of applicable current legislation. Staff Development/Support Issues Both organisations will ensure that all staff having access to the information shared will have received adequate security related training. Consent From Service Users Contact Details Comments or questions regarding this ISA should be addressed to: Page 17 of 18

18 <Name> <Title>, RDaSH. < address> Tel - <phone no.> <Name> <Title>, <organisation> - < address> Tel - <phone no.> Approval Signatures ISA Approved by: Date Print Name For Rotherham Doncaster and South Humber NHS Foundation Trust ISA Approved by: Date Print Name For <Second Party> Page 18 of 18

Data Protection Policy

Data Protection Policy Reference: Date Approved: April 2015 Approving Body: Board of Trustees Implementation Date: August 2015 Supersedes: 2.0 Stakeholder groups Governance Committee, Board of Trustees consulted: Target Audience:

More information

Data Protection Policy

Data Protection Policy Data Protection Policy StCH Data Protection Policy - POL 53 vs1 - July 2016 1 Document Control Table Document Title: Data Protection Policy Document Ref: POL 53 Author (name and job title): Karen Anderson,

More information

Data protection (GDPR) policy

Data protection (GDPR) policy Data protection (GDPR) policy January 2018 Version: 1.0 NHS fraud. Spot it. Report it. Together we stop it. Version control Version Name Date Comment 1.0 Trevor Duplessis 22/01/18 Review due Dec 2018 OFFICIAL

More information

Information Governance Strategic Management Framework

Information Governance Strategic Management Framework Information Governance Strategic Management Framework 2016-2018 Susan Meakin Information Governance Manager June 2016 Information Governance DOCUMENT CONTROL: Version: 2 Ratified by: Health Informatics

More information

Humber Information Sharing Charter

Humber Information Sharing Charter External Ref: HIG 01 Review date November 2016 Version No. V07 Internal Ref: NELC 16.60.01 Humber Information Sharing Charter This Charter may be an uncontrolled copy, please check the source of this document

More information

Data Protection. Policy

Data Protection. Policy Data Protection Policy Why do we need this policy? What does the policy apply to? Which parts of SQA are affected? SQA is committed to adopting best practice in protecting the personal information of all

More information

DATA PROTECTION POLICY 2018

DATA PROTECTION POLICY 2018 DATA PROTECTION POLICY 2018 Amesbury Baptist Church is committed to protecting all information that we handle about people we support and work with, and to respecting people s rights around how their information

More information

Data Protection Policy

Data Protection Policy Data Protection Policy This policy will be reviewed by the Trust Board three yearly or amended if there are any changes in legislation before that time. Date of last review: Autumn 2018 Date of next review:

More information

Information Governance Policy

Information Governance Policy Information Governance Policy Version: 4.0 Ratified by: NHS Bury Clinical Commissioning Group Information Governance Operational Group Date ratified: 19 th September 2017 Name of originator /author (s):

More information

DATA PROTECTION POLICY 2016

DATA PROTECTION POLICY 2016 DATA PROTECTION POLICY 2016 ADOPTED FROM BRADFORD METROPOLITAIN COUNCIL MODEL POLICY AUTUMN 2016 To be agreed by Governors on; 17/10/16 Signed by Chair of Governors: Statutory policy: Yes Frequency of

More information

Information Governance Policy

Information Governance Policy Information Governance Policy Date completed: February 2016 Responsible Director: Approved by/ date: Director of Compliance Review date: October 2017 Amended: Author: Ben Westmancott Information Governance

More information

Leeds Interagency Protocol for Sharing Information

Leeds Interagency Protocol for Sharing Information Leeds Interagency Protocol for Sharing Information The Protocol An inter-agency initiative to provide a framework for sharing personal information about service users between health and social care organisations

More information

INFORMATION GOVERNANCE POLICY

INFORMATION GOVERNANCE POLICY INFORMATION GOVERNANCE POLICY Including the Information Governance Strategy Framework and associated Information Governance Procedures Last Review Date June 2017 Approving Body Audit Committee Date of

More information

Data Management and Protection Policy

Data Management and Protection Policy Data Management and Protection Policy Approved by Governor committee: Finance and Audit Date to be reviewed: June 2018 Responsibility of : Director of Finance and Operations Date ratified by Governing

More information

Breakthrough Data Protection Policy Approved by Lead Organisation: November 2017 Next Review Date: November 2018

Breakthrough Data Protection Policy Approved by Lead Organisation: November 2017 Next Review Date: November 2018 Breakthrough Data Protection Policy Approved by Lead Organisation: November 2017 Next Review Date: November 2018 Introduction The Partner organisations within the Breakthrough Programme need to collect

More information

PRIVACY IMPACT ASSESSMENT (PIA) TEMPLATE

PRIVACY IMPACT ASSESSMENT (PIA) TEMPLATE PRIVACY IMPACT ASSESSMENT (PIA) TEMPLATE Reference No: IG40 Version: 1.2 Purpose of Document: Ratified by: Date ratified: 27 th September 2013 Review Date September 2014 Name of originator/author: Contact

More information

Baptist Union of Scotland DATA PROTECTION POLICY

Baptist Union of Scotland DATA PROTECTION POLICY Baptist Union of Scotland DATA PROTECTION POLICY Adopted: May 2018 1 1.The Baptist Union of Scotland 48, Speirs Wharf, Glasgow G4 9TH (Charity Registration SC004960) is committed to protecting all information

More information

Data Protection Policy

Data Protection Policy Data Protection Policy Name of Chair: Mr David Mann Name of Headteacher: Mrs Eileen Bissell Name of person Responsible: Mrs Eileen Bissell Adopted and Agreed on: October 2015 Date of Review: October 2018

More information

Human Resources. Data Protection Policy IMS HRD 012. Version: 1.00

Human Resources. Data Protection Policy IMS HRD 012. Version: 1.00 Human Resources Data Protection Policy IMS HRD 012 Version: 1.00 Disclaimer While we do our best to ensure that the information contained in this document is accurate and up to date when it was printed

More information

EARLS HALL BAPTIST CHURCH DATA PROTECTION POLICY

EARLS HALL BAPTIST CHURCH DATA PROTECTION POLICY EARLS HALL BAPTIST CHURCH DATA PROTECTION POLICY Adopted: 5 June 2018 1 Earls Hall Baptist Church is committed to protecting all information that we handle about people we support and work with, and to

More information

General Optical Council. Data Protection Policy

General Optical Council. Data Protection Policy General Optical Council Data Protection Policy Authors: Lisa Sparkes Version: 1.2 Status: Live Date: September 2013 Review Date: September 2014 Location: Internet / Intranet Document History Version Date

More information

INFORMATION GOVERNANCE POLICY

INFORMATION GOVERNANCE POLICY INFORMATION GOVERNANCE POLICY Unique Reference / Version Primary Intranet Location Information Management & Governance Secondary Intranet Location Policy Name Information Governance Policy Version Number

More information

IGPr002 - Information Governance Management Framework

IGPr002 - Information Governance Management Framework IGPr002 - Information Governance Management Framework Page 1 of 10 Table of Contents Information Governance Management Framework... 1 Why we need this Framework... 3 What the Framework is trying to do...

More information

GUIDANCE NOTES DATA PRIVACY IMPACT ASSESSMENT

GUIDANCE NOTES DATA PRIVACY IMPACT ASSESSMENT GUIDANCE NOTES DATA PRIVACY IMPACT ASSESSMENT A Data Privacy Impact Assessment (DPIA) helps the University to assess the necessity and proportionality of processing personal data. A DPIA will enable the

More information

Section a What this Policy is for Policy Statement. 2. Why this policy is important... 3

Section a What this Policy is for Policy Statement. 2. Why this policy is important... 3 Norwich Central Baptist Church DATA PROTECTION POLICY Adopted: May.2018 Norwich Central Baptist Church (NCBC) is committed to protecting all information that we handle about people we support and work

More information

Scottish Charity Number SC Dingwall Baptist Church DATA PROTECTION POLICY

Scottish Charity Number SC Dingwall Baptist Church DATA PROTECTION POLICY Dingwall Baptist Church DATA PROTECTION POLICY Adopted: By Trustees Dingwall Baptist Church May 2018 1 Dingwall Baptist Church is committed to protecting all information that we handle about people we

More information

We reserve the right to update this privacy notice at any time. Please check our website from time to time for any changes we may make.

We reserve the right to update this privacy notice at any time. Please check our website from time to time for any changes we may make. What is the purpose of this document? NORTHERN IRELAND SCREEN COMMISSION (Company Number NI031997) whose registered office is at 3 rd Floor Alfred House, 21 Alfred Street, Belfast, BT2 8ED is committed

More information

SAFFRON WALDEN COMMUNITY CHURCH DATA PROTECTION POLICY. Adopted: [ ]

SAFFRON WALDEN COMMUNITY CHURCH DATA PROTECTION POLICY. Adopted: [ ] SAFFRON WALDEN COMMUNITY CHURCH DATA PROTECTION POLICY Adopted: [17-04-2018] 1 SAFFRON WALDEN COMMUNITY CHURCH is committed to protecting all information that we handle about people we support and work

More information

Data Protection. Document Detail Type of Document (Stat Policy/Policy/Procedure) Category of Document (Trust HR-Fin-FM-Gen/Academy) General

Data Protection. Document Detail Type of Document (Stat Policy/Policy/Procedure) Category of Document (Trust HR-Fin-FM-Gen/Academy) General Data Protection Document Detail Type of Document (Stat Policy/Policy/Procedure) Policy Category of Document (Trust HR-Fin-FM-Gen/Academy) General Index reference number Approved 26/04/18 Approved by Trust

More information

VMS Software Ltd- Data Protection Privacy Policy

VMS Software Ltd- Data Protection Privacy Policy VMS Software Ltd- Data Protection Privacy Policy Introduction The purpose of this document is to provide a concise policy statement regarding the Data Protection obligations of VMS Software Ltd. This includes

More information

INFORMATION GOVERNANCE STRATEGY AND STRATEGIC VISION

INFORMATION GOVERNANCE STRATEGY AND STRATEGIC VISION INFORMATION GOVERNANCE STRATEGY AND STRATEGIC VISION Policy approved by: Joint Audit and Governance Committee Date: December 2016 Next Review Date: October 2018 Version: 2.0 Information Governance Strategy

More information

Information Governance Policy

Information Governance Policy Information Governance Policy Policy Number IG001 Target Audience CCG/ GMSS Staff Approving Committee CCG Chief Officer Date Approved February 2018 Last Review Date February 2018 Next Review Date February

More information

Information Governance Policy

Information Governance Policy Author Darren Rigg Head of Information Governance Corporate Lead Bryan Machin Executive Director of Finance and Resources Document Version 1 Date ratified by Quality Committee 24 th October 2014 Date issued

More information

Data Protection Policy

Data Protection Policy THE CIPPENHAM SCHOOLS TRUST Data Protection Policy *Date for revision: Summer Term 2018 Responsibility for policy: Responsibility for operational: Trustees Trustees Reviewed by Directors: *subject to any

More information

Queen s Croft High School DATA PROTECTION POLICY AND PRIVACY NOTICE

Queen s Croft High School DATA PROTECTION POLICY AND PRIVACY NOTICE Queen s Croft High School DATA PROTECTION POLICY AND PRIVACY NOTICE Prepared by: Peter Hawksworth, Headteacher Checked by: Jackie Hesslegrave, Business Manager Adopted by Governors: November 2017 Review

More information

Privacy Impact Assessment: Standard Operating Procedure

Privacy Impact Assessment: Standard Operating Procedure Corporate Privacy Impact Assessment: Standard Operating Procedure Document Control Summary Status: Version: Author/Title: Owner/Title: Approved by: Ratified: Related Trust Strategy and/or Strategic Aims

More information

Information Governance Policy and Management Framework

Information Governance Policy and Management Framework Putting Barnsley People First Information Governance Policy and Management Framework Version: 2.0 Approved By: Governing Body Date Approved: February 2014 Name of originator / author: Richard Walker Name

More information

POLICY ON INFORMATION, SECURITY & DATA PROTECTION

POLICY ON INFORMATION, SECURITY & DATA PROTECTION POLICY ON INFORMATION, SECURITY & DATA PROTECTION As a recruitment company, First Recruitment is a data controller. This means it processes personal data about its work seekers, individual client contacts

More information

Wellbeing and Education Safeguarding. Privacy Statement

Wellbeing and Education Safeguarding. Privacy Statement Wellbeing and Education Safeguarding Privacy Statement Hackney Learning Trust September 2018 2 1. Introduction The Editorial Board of the London Child Protection Procedures has considered what changes

More information

Data Protection Policy

Data Protection Policy Data Protection Policy University of London Data Protection UoL website link: http://www.london.ac.uk/238.html Email: records.managament@london.ac.uk Contents 1 Policy statement... 3 2 Introduction and

More information

GROUP DATA PROTECTION POLICY

GROUP DATA PROTECTION POLICY GROUP DATA PROTECTION POLICY Conducting business the right way Safeguarding our customer and employee personal data Version 1 [August 2016] CONDUCTING BUSINESS THE RIGHT WAY Our Values, Doing the Right

More information

DATA PROTECTION POLICY

DATA PROTECTION POLICY DATA PROTECTION POLICY Operational Owner: Executive Owner: James Newby Data Protection Officer Sarah Litchfield Senior Information Risk Officer Effective date: 25 th May 2018 Review date: May 2021 Related

More information

DATA PROTECTION POLICY

DATA PROTECTION POLICY 1. Introduction This policy is intended to provide information about how the School will use (or process ) personal data about individuals including: Current, past and prospective pupils; Parents, carers

More information

Data Protection Policy

Data Protection Policy Data Protection Policy Contents 1. Purpose and scope... 2 2. Background... 2 3. Principles... 2 4. Aims and commitments... 3 5. Roles and responsibilities... 3 6. Breaches of data privacy legislation...

More information

NEW LIFE BAPTIST CHURCH NORTHALLERTON DATA PROTECTION POLICY. Adopted: 20 June 2018 To be reviewed: June 2021

NEW LIFE BAPTIST CHURCH NORTHALLERTON DATA PROTECTION POLICY. Adopted: 20 June 2018 To be reviewed: June 2021 NEW LIFE BAPTIST CHURCH NORTHALLERTON DATA PROTECTION POLICY Adopted: 20 June 2018 To be reviewed: June 2021 NEW LIFE BAPTIST CHURCH, NORTHALLERTON (referred to in this policy as NLBC) is committed to

More information

DATA PROTECTION POLICY

DATA PROTECTION POLICY DATA PROTECTION POLICY Document Control History Title Data Protection Policy Version no. 1.0 Date of publication May 2018 Author(s) Amanda Cramb, HR Manager Next review date May 2021 Page 1 Introduction

More information

Privacy Impact Assessment Policy and Procedure

Privacy Impact Assessment Policy and Procedure Privacy Impact Assessment Policy and Procedure This document outlines the Trust s approach and methodology for conducting Privacy Impact Assessments in line with the Information Risk Policy Key Words:

More information

Information Governance Clauses Clinical and Non Clinical Contracts

Information Governance Clauses Clinical and Non Clinical Contracts Information Governance Clauses Clinical and Non Clinical Contracts Policy Number Target Audience Approving Committee Date Approved Last Review Date Next Review Date Policy Author Version Number IG014 All

More information

The current version (July 2018) is derived from, and supersedes, the version published in February 2017 and earlier versions.

The current version (July 2018) is derived from, and supersedes, the version published in February 2017 and earlier versions. Page 2 of 10 Data Protection Policy Chief Information Officer Chief Information Officer Data Protection Officer The current version (July 2018) is derived from, and supersedes, the version published in

More information

DATA PROTECTION POLICY

DATA PROTECTION POLICY Registered Address: Mountdale Gardens, Leigh-on-Sea, Essex SS9 4AW Executive Headteacher: Mrs. J. Mullan Telephone: (01702) 524193 Fax: (01702) 526761 DATA PROTECTION POLICY SEN TRUST SOUTHEND KINGSDOWN

More information

DATA PROTECTION POLICY

DATA PROTECTION POLICY Registered Address: Mountdale Gardens, Leigh-on-Sea, Essex SS9 4AW Executive Headteacher: Mrs. J. Mullan Telephone: (01702) 524193 Fax: (01702) 526761 DATA PROTECTION POLICY SEN TRUST SOUTHEND KINGSDOWN

More information

SHENLEY BROOK END SCHOOL

SHENLEY BROOK END SCHOOL SHENLEY BROOK END SCHOOL DATA PROTECTION POLICY Linked Policies: CCTV Review Information Reviewed by Finance Pay and Personnel Committee 15 May 2012 Reviewed by Policy Committee August 2013 Adopted by

More information

POLICY IN RELATION TO SPECIAL LEAVE

POLICY IN RELATION TO SPECIAL LEAVE POLICY IN RELATION TO SPECIAL LEAVE DOCUMENT CONTROL: Version: 9 Ratified by: HR&OD Policy and Planning Group Date ratified: 6 June 2013 Name of originator/author: Director of Workforce and Organisational

More information

Data Protection Policy

Data Protection Policy Data Protection Policy Reviewed by: Reviewed when Resources Committee As required Date written and last reviewed July 2018 Source and date of model policy, if applicable n/a Contents 1. Aims... 2 2. Legislation

More information

Overarching Information Governance Policy

Overarching Information Governance Policy Document Information Board Library Reference Document Type Document Subject Original Document Author Reviewed By Review Cycle IM&T_01 Policy Information Information IGMG 3 Years Note: This document is

More information

Tourettes Action Data Protection Policy

Tourettes Action Data Protection Policy Tourettes Action Data Protection Policy Effective date: 01/01/2018 Review date: 01/01/2020 Approved: Suzanne Dobson, CEO Tourettes Action Author: Pippa McClounan, Office Manager Tourettes Action Version

More information

St Mark s Church of England Academy Data Protection Policy

St Mark s Church of England Academy Data Protection Policy St Mark s Church of England Academy Data Protection Policy 1 Contents Purpose:... Error! Bookmark not defined. Scope:... Error! Bookmark not defined. Procedure:... Error! Bookmark not defined. Definitions:...

More information

General Personal Data Protection Policy

General Personal Data Protection Policy General Personal Data Protection Policy Contents 1. Scope, Purpose and Users...4 2. Reference Documents...4 3. Definitions...5 4. Basic Principles Regarding Personal Data Processing...6 4.1 Lawfulness,

More information

NHS Sunderland Clinical Commissioning Group. Information Governance Strategy 2016/17

NHS Sunderland Clinical Commissioning Group. Information Governance Strategy 2016/17 NHS Sunderland Clinical Commissioning Group Information Governance Strategy 2016/17 Document Status Equality Impact Assessment Document Ratified/Approved By Final No impact Executive Committee Governing

More information

Data Protection Policy

Data Protection Policy Data Protection Policy (Data Protection Act 1998) (This policy will be updated to incorporate GDPR by May 2018) Page 1 of 9 Data Protection Policy 1 Statement of Policy The Constellation Trust needs to

More information

REDDISH VALE HIGH SCHOOL PRIMARY PRIVACY NOTICE

REDDISH VALE HIGH SCHOOL PRIMARY PRIVACY NOTICE REDDISH VALE HIGH SCHOOL PRIMARY PRIVACY NOTICE Overview Reddish Vale High School is committed to ensuring that we re transparent about the ways in which we use your personal information and that we have

More information

Closed Circuit TV Policy

Closed Circuit TV Policy Western Isles Health Board Procedure Document Closed Circuit TV Policy Version 1 Author Gordon Jamieson, Chief Executive Date of issue QIPB approval Next review due date Reviewers/review team Document

More information

LEICESTER HIGH SCHOOL DATA PROTECTION POLICY

LEICESTER HIGH SCHOOL DATA PROTECTION POLICY LEICESTER HIGH SCHOOL DATA PROTECTION POLICY 1. Background Data protection is an important legal compliance issue for Leicester High School. During the course of the School's activities it collects, stores

More information

Trinity is committed to protecting the privacy and security of personal data.

Trinity is committed to protecting the privacy and security of personal data. This privacy notice applies data processing activities undertaken by Trinity College for security and monitoring relating to staff, students and visitors to Trinity premises including CCTV, other security

More information

APCC Policy Statement

APCC Policy Statement Purpose APCC Internal Data Security Policy Statement: APCC Business 1. The APCC is committed to being transparent about how it collects and uses the personal data of its workforce and to meeting its data

More information

Information Governance Policy

Information Governance Policy Information Governance Policy Applicable to All employees Version1.0 Last Updated March 2014 CONFIDENTIAL Page 2 of 6 Contents 1. Objectives 3 2. Scope 3 3. Principles 3 4. Information Governance Policy

More information

Project Title. Project Number. Privacy Impact Assessment

Project Title. Project Number. Privacy Impact Assessment Project Title Project Number Privacy Impact Assessment This document is classified as Official and is disclosable under the terms of the Freedom of Information Act. No part of the report should be disseminated

More information

DATA PROTECTION POLICY

DATA PROTECTION POLICY APPENDIX. DATA PROTECTION POLICY Document Status Author Director of Registry Services (Data) Date of Origin 27 th July 2011 This Version July 2014 Review requirements Date of next review July 2016 Approval

More information

Data Protection Policy

Data Protection Policy Policy Current Status Operational Last Review: May 2018 Responsibility for Review: Director of Administration, Contracts and Health Next Review: September 2019 Internal Approval: & Safety SLT Originated:

More information

SCHOOLS DATA PROTECTION POLICY. Guidance Notes for Schools

SCHOOLS DATA PROTECTION POLICY. Guidance Notes for Schools SCHOOLS DATA PROTECTION POLICY Guidance Notes for Schools Please read this policy carefully and ensure that all spaces highlighted in the document are completed prior to publication. Please ensure that

More information

INFORMATION GOVERNANCE POLICY AND FRAMEWORK

INFORMATION GOVERNANCE POLICY AND FRAMEWORK INFORMATION GOVERNANCE POLICY AND FRAMEWORK Policy approved by: Audit and Governance Committees Date: 9 th October 2017 Next Review Date: September 2018 Version: 4.0 Information Governance Policy & Framework

More information

Freedom of Information/Environmental Information Regulations Policy and Procedure

Freedom of Information/Environmental Information Regulations Policy and Procedure Policy Number: 8.3 Version number: 01 Date of issue: Date Archived: Reason for policy: (Redraft/new) New policy to ensure compliance with current legislation Authorised by: On Behalf of Management (Signature)

More information

GDPR Subject Access Request Procedure

GDPR Subject Access Request Procedure GDPR Subject Access Request Procedure May 2018 Also available in large print (16pt) And electronic format. Ask Student Services for details. www.perth.uhi.ac.uk Perth College is a registered Scottish charity,

More information

Competence Framework for Safeguarding Adults

Competence Framework for Safeguarding Adults Competence Framework for Safeguarding Adults Introduction This competency framework seeks to develop and demonstrate the competency of staff in delivering services that safeguard adults with care and support

More information

Data Protection Policy Approved by: COG Approved: 9 August 2017 Review date: August 2019 Version: Statement of Intent

Data Protection Policy Approved by: COG Approved: 9 August 2017 Review date: August 2019 Version: Statement of Intent Data Protection Policy Approved by: COG Approved: 9 August 2017 Review date: August 2019 Version: 4 1. Statement of Intent 1.1 Radian 1 must collect, store and process information about its customers,

More information

CHANNING SCHOOL DATA PROTECTION POLICY

CHANNING SCHOOL DATA PROTECTION POLICY CHANNING SCHOOL DATA PROTECTION POLICY The School may amend/change/update this Policy from time to time. 1. Background Data protection is an important legal compliance issue for Channing School. During

More information

The Society of St Stephen s House Site Security and Monitoring Privacy Notice

The Society of St Stephen s House Site Security and Monitoring Privacy Notice This privacy notice applies to data processing activities undertaken by The Society of St Stephen s House for security and monitoring relating to staff, students and visitors to College premises A summary

More information

GDPR DATA PROCESSING NOTICE FOR FS1 RECRUITMENT UK LTD FOR APPLICANTS AND WORKERS

GDPR DATA PROCESSING NOTICE FOR FS1 RECRUITMENT UK LTD FOR APPLICANTS AND WORKERS GDPR DATA PROCESSING NOTICE FOR FS1 RECRUITMENT UK LTD FOR APPLICANTS AND WORKERS What is the purpose of this document? FS1 Recruitment UK Ltd is committed to protecting the privacy and security of your

More information

GDPR P4 Privacy Policy Statement & Guidance for Employees and External Providers

GDPR P4 Privacy Policy Statement & Guidance for Employees and External Providers Once we have received notification that you have withdrawn your consent, we will no longer process your information for the purpose or purposes you originally agreed to, unless we have another legitimate

More information

Humber Information Sharing Charter

Humber Information Sharing Charter External Ref: HIG 01 Insert here the logo of the signatory organisation Review date November 2016 Version No. V07 Internal Ref: ERYC CFS ILS 02 Humber Information Sharing Charter This Charter may be an

More information

LIFE STYLE CARE PLC. Privacy Statement for Employees. August 2018

LIFE STYLE CARE PLC. Privacy Statement for Employees. August 2018 LIFE STYLE CARE PLC Privacy Statement for Employees August 2018 Key points Why we use your personal data: We typically use your personal information for purposes related to your employment relationship

More information

Getting ready for the new data protection laws A guide for small businesses, charities and voluntary organisations

Getting ready for the new data protection laws A guide for small businesses, charities and voluntary organisations Getting ready for the new data protection laws A guide for small businesses, charities and voluntary organisations Page 1 of 22 Your business and the new data protection laws Data protection and privacy

More information

Reportable Conduct Scheme Information sheet Frequently Asked Questions

Reportable Conduct Scheme Information sheet Frequently Asked Questions Reportable Conduct Scheme Information sheet Frequently Asked Questions This information sheet provides answers to some of the more common questions about the Reportable Conduct Scheme. Why does Victoria

More information

Brasenose College is committed to protecting the privacy and security of personal data.

Brasenose College is committed to protecting the privacy and security of personal data. This privacy notice (v1.2) applies to data processing activities undertaken by Brasenose College for security and monitoring relating to staff, students and visitors to College premises including CCTV,

More information

Depending on the circumstances, we may collect, store, and use the following categories of personal information about you:

Depending on the circumstances, we may collect, store, and use the following categories of personal information about you: Ignata Group Data Protection / Privacy Notice What is the purpose of this document? Ignata is committed to protecting the privacy and security of your personal information. This privacy notice describes

More information

Data Protection Policy

Data Protection Policy Data Protection Policy Version Date Revision Author Summary of Changes 1.0 21 st May 2018 Ashleigh Morrow EXECUTIVE STATEMENT At CASTLEREAGH NURSERY SCHOOL (the School ), we believe privacy is important.

More information

WHISTLE BLOWING POLICY

WHISTLE BLOWING POLICY WHISTLE BLOWING POLICY Introduction The Tandridge Learning Trust is committed to the highest possible standards of honesty, openness, probity and accountability. It seeks to conduct its affairs in a responsible

More information

Data Protection Policy. Data protection. Date: 28/4/2018. Version: 1. Contents

Data Protection Policy. Data protection. Date: 28/4/2018. Version: 1. Contents Company Name: Document: Topic: System People ( the Company ) Data Protection Policy Data protection Date: 28/4/2018 Version: 1 Contents Introduction Definitions Data processing under the Data Protection

More information

RAW MARKETING DATA PROTECTION POLICY

RAW MARKETING DATA PROTECTION POLICY RAW MARKETING DATA PROTECTION POLICY Introduction We take your privacy very seriously and have updated our Privacy Statement in line with the upcoming GDPR regulation. Were absolutely committed to reflecting

More information

Information Management Policy

Information Management Policy Information Management Policy Policy Owner: Head of Professional Standards Department Responsible: Policy Author: Chief Officer Approval: PSD Information Management Anne Chafer Information Manager Deputy

More information

INFORMATION GOVERNANCE STRATEGY

INFORMATION GOVERNANCE STRATEGY INFORMATION GOVERNANCE STRATEGY Document Number 2009/49/V2 Document Title Information Governance Strategy Author Phil Cottis Author s Job Title Information Governance & RA Manager Department IM&T Ratifying

More information

The Data Controller for all personal data stored and processed by Horiba MIRA Ltd is:

The Data Controller for all personal data stored and processed by Horiba MIRA Ltd is: Page 1 of 8 Owned By: Data Protection Officer Review Due: March 2020 DATA PRIVACY POLICY It is the policy of Horiba MIRA Ltd (MIRA) that it shall at all times respect the privacy of individuals by processing

More information

Equality and Diversity Policy

Equality and Diversity Policy Equality and Diversity Policy Warwickshire First Aid Training is a progressive training organisation providing mandatory training to a range of organisations. We provide a range of First Aid, health and

More information

Equality and Diversity Policy

Equality and Diversity Policy Equality and Diversity Policy Hertfordshire, Bedfordshire and Luton Clinical Commissioning Groups Page 1 of 15 DOCUMENT CONTROL SHEET Document Owner: Director of Workforce Document Author(s): Louise Thomas,

More information

Safeguarding Children Policy

Safeguarding Children Policy Safeguarding Children Policy Title Author/Lead Officer Position Department/Section Contact details Safeguarding Children Policy Clare Eccles/Paul Tuckey Safer Estates Manager Neighbourhood Services clare.eccles@cheltborohomes.org

More information

Code of Conduct for Staff

Code of Conduct for Staff Diocese of Bristol Academies Trust Code of Conduct for Staff Date Adopted: 4 th June 2015 Date Reviewed:.v 1 Final Page 1 History of most recent Policy changes (must be completed) Date Page Change Origin

More information

INFORMATION GOVERNANCE STRATEGY IMPLEMENTATION PLAN

INFORMATION GOVERNANCE STRATEGY IMPLEMENTATION PLAN INFORMATION GOVERNANCE STRATEGY & IMPLEMENTATION PLAN 2015-2018 Disclaimer The latest version of this document is located on PTHB intranet. Please check the review date and if there are any doubts contact

More information

Recruiting Ex-Offenders Policy

Recruiting Ex-Offenders Policy Recruiting Ex-Offenders Policy Ref: ELCCG_HR25 Version: Version 3 Supersedes: Version 2 Author (inc Job Title): Ratified by: (Name of responsible Committee) LCSU HR Remuneration Committee Date ratified:

More information

Data Protection Policy for Staff DJJK. Apr of 10

Data Protection Policy for Staff DJJK. Apr of 10 Data Protection Policy for Staff DJJK Apr 2018 1 of 10 Review and Amendment Record Date Person Conducting the Review Mar 2018 PMS New Policy, GDPR Apr 2018 DJJK Review Changes Made 2 of 10 1 Introduction

More information

Data Protection Policy & Procedures

Data Protection Policy & Procedures Data Protection Policy & Procedures Scope In this document, the terms we, us, our and/or Clear Sky refer to Clear Sky Children s Charity. The term you and/or your refer to all employees of Clear Sky, who

More information