Data Controller
NHS West Yorkshire Integrated Care Board
Purpose
Controlled Drugs Monitoring - The ICB has a duty to assist the relevant Controlled Drug Accountable Officer (CDAO) of NHS England in the carrying out of the CDAO’s functions under The Controlled Drugs (Supervision of Management and Use) Regulations 2013. These functions include the investigation into fraudulent prescriptions for Controlled Drugs. The regulations aim to strengthen the governance arrangements for the use and management of controlled drugs.
Lawful basis
GDPR Article 6(1)(e) - processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority.
GDPR Article 9 (2)(h) - processing is necessary for the purposes of the provision of health or social care or treatment or the management of health or social care systems and services.
Type of information used
Personal and clinical information.
Who we will share the information with (recipients)
Personal data is shared between the ICB and local healthcare providers, including GP practices. They do this to facilitate the implementation of recommendations by the medicines management team (MMT).
Do we use any processors
The Health Informatics Service (THIS), and West Yorkshire ICB Leeds IT and Leeds City Council IT Integrated Digital Service (IDS) our IT suppliers who store all our information securely on their servers.
Microsoft Azure, supported by IT staff, host our data.
How we collect (the source) and use the information
Medicines management staff access the patient clinical record from within a GP practice. They access personal and medical details in line with the current project and at all times with the knowledge and written consent of the GP practice. As a result of the information accessed, recommendations may be made to a GP, or medicines may be amended and the patient informed by telephone or letter.
Details of the audit (which includes personal or sensitive data) is retained in a restricted folder (accessible only by members of the MMT) for a short period to allow for any queries raised as a result of the work to be answered after which time it is deleted – a maximum of 12 months
How long we will keep the information
One year.
Your rights
Under the UK General Data Protection Regulation all individuals have certain rights in relation to the information which the ICB holds about them. Not all rights apply equally to all our processing activities as certain rights are not available depending on the lawful basis for the processing.
If you require further detail each link below will take you to the Information Commissioner’s Office website where further detail is provided in the section ‘When does the right apply’.
These rights are:
- The right to be informed about the processing of your data
- The right of access to the data held about you
- The right to have that information amended in the event that it is not accurate
- The right to have the information deleted
- The right to restrict processing
- The right to have your data transferred to another organisation (data portability)
- The right to object to processing
- Rights in relation to automated decision making and profiling
Under the NHS Constitution you have the right to privacy and to expect the NHS to keep your information confidential and secure.
If you have an enquiry in relation to your data protection rights please contact wyicb.