Data Controller

NHS West Yorkshire Integrated Care Board

Purpose

The ICB collects and uses information from Serious Incident reports from Primary and Secondary Care Providers to ensure incidents are dealt with appropriately and lessons learnt.

Lawful basis

GDPR Article 6(1)(e) processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority.

Related legislation:

NHS Act 2006/Health and Social Care Act 2012.

GDPR Article 9(2)(h) - processing is necessary for the purposes of the provision of health or social care or treatment or the management of health or social care systems and services.

Type of information used

Identifiable: Personal (such as name, address, date of birth) and Special Category Data.

Who we will share the information with (recipients)

Your information may be shared with Primary and Secondary healthcare providers involved in the incident.

Where there is a requirement to provide incident reports externally, the information will be anonymised unless there is a legal requirement to provide your details.

Do we use any processors

The Health Informatics Service (THIS), and West Yorkshire ICB Leeds IT and Leeds City Council IT Integrated Digital Service (IDS) our IT suppliers who store all our information securely on their servers.

Microsoft Azure, supported by IT staff, host our data.

How we collect (the source) and use the information

We are statutorily required to fully investigate and review incidents and will receive information from Primary and Secondary Care Providers.

You will be kept informed of the requirements we are required to meet, where information is to be shared externally.

How long we will keep the information

20 years.

Your rights

Under the UK General Data Protection Regulation all individuals have certain rights in relation to the information which the ICB holds about them. Not all rights apply equally to all our processing activities as certain rights are not available depending on the lawful basis for the processing.

If you require further detail each link below will take you to the Information Commissioner’s Office website where further detail is provided in the section ‘When does the right apply’.

These rights are:

Under the NHS Constitution you have the right to privacy and to expect the NHS to keep your information confidential and secure.

If you have an enquiry in relation to your data protection rights please contact wyicb.foi@nhs.net