Statutory Disclosures of Information

In this category, these are the organisations we share information about you with:

Statutory Disclosures of Information

Recipients or categories of recipients of the personal or special categories of personal data

Purpose of the processing and data retention periods

 

Lawful basis
General Data Protection Regulation
- Article 6, Article 9 -
Data Protection Act

- Section 8, Section 10, Part 1 of Schedule 1 - 

Your Rights

Safeguarding Concerns – to prevent an individual, or to prevent a serious crime

Some members of public are recognised as needing safeguarding protection, for example children and vulnerable adults. If an individual is identified as being at risk from harm, we have a duty to do what we can to protect that individual, and we are bound ‘Safeguarding’ laws to do so.

Where there is a suspected or actual safeguarding issue we will share information that we hold about you with other relevant agencies such as local Ambulance trusts, the police, A&E departments, out of hours services, 111 or Social Services)

The source of the information shared in this way is your electronic GP record.

Data Retention Period

All records held by the Practice will be kept for the duration specified in the Records Management Codes of Practice for Health and Social Care.

 

 

The processing of personal data is permitted under the following GDPR and DPA conditions:

GDPR Article 6(1) (e) - public interest or in the exercise of official authority;

DPA Section 8 (d) - processing is necessary for the exercise of statutory functions;

The processing of special categories of personal data concerning health is permitted under the following conditions:

Article 9 (2) (c) – the processing is necessary to protect the vital interests of the data subject;

Article 9(2) (b) – processing is necessary for the purposes of carrying out the obligations and exercising specific rights of the controller or of the data subject in the field of employment and social security and social protection law;

In accordance with DPA Schedule 1, Part 3, (30) (b) - the conditions for protecting individual’s vital interests is met where the data subject is physically or legally incapable of giving consent.

In accordance with DPA Schedule 1, Part 2 (18) (1a) - the conditions is met where the processing is necessary for  protecting an individual from neglect or physical, mental or emotional harm,  or protecting the physical, mental or emotional well-being of an individual

Related Legislations:

Section 47 of The Children Act 1989.

Section 45 of the Care Act 2014

This sharing is a legal and professional requirement and therefore there is no right to object.

The Children Act 1989 requires local authorities to investigate where a child is the subject of an emergency protection order, is in police protection or where there is a reasonable cause to suspect that a child is suffering or is likely to suffer harm.

The Act requires the local authority to safeguard and promote the welfare of children who are in need, within their geographical area and to request help from specified authorities including General Practices, NHS Trusts, Clinical Commissioning Groups (CCGs) and NHS England.

Right to complain: If you are dissatisfied with the way Otford Medical Practice process your data, you have the right to appeal/complain to the Information Commissioner (IC). The IC can be contacted at:
Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
Tel: 0303 123 1113 or 01625 545 745
Email:
https://ico.org.uk/global/contact-us/ 

The Care Quality Commission (CQC)

The Care Quality Commission (CQC) is a regulatory body established under the Health and Social Care Act. The CQC regulates health and social care services in England to ensure that safe health and care are provided. The law allows CQC to access identifiable patient data/medical records in our clinical system for the purposes of their assessment and investigation of significant safety incident.

The data will be shared with the Care Quality Commission, its officers and staff and members of the inspection teams that visit us from time to time.

The source of the information shared in this way is your electronic GP record.

Data Retention Period

All records held by the Practice will be kept for the duration specified in the Records Management Codes of Practice for Health and Social Care.

 

The processing of personal data is permitted under the following conditions:

Article 6(1) (c) - processing for legal obligation;

DPA Section 8 (d) - Processing is necessary for the exercise of statutory functions.

The processing of special categories of personal data concerning health is permitted under the following conditions:

Article 9 (2) (h) - processing is necessary for medical or social care treatment or, the management of health or social care systems and services

DPA Section 10 (1) (c) - health and social care purposes.

In accordance with DPA Schedule 1, Part 1 (2) health or social care purposes means the purposes of preventive or occupational medicine; medical diagnosis; the provision of health care or treatment; the provision of social care, or the management of health care systems or services or social care systems or services.

You have the right to:

  • To access, view or request copies of your personal information;
  • request rectification of any inaccuracy in your personal information;
  • restrict the processing of your personal information where:
  • accuracy of the data is contested,
  • the processing is unlawful or,
  • where we no longer need the data for the purposes of the processing.

Right to object: You have a general right to raise an objection to the processing of your personal data in some particular circumstances. This right only applies where we cannot demonstrate compelling legitimate grounds for continued processing of your personal data for the purposes of direct provision of care, and compliance with a legal obligation to which we are subject. 

If you wish to exercise any of your rights please contact the Practice (data controller) or the DPO and your request will be carefully considered.

Right to complain: If you are dissatisfied with the way Otford Medical Practice process your data, you have the right to appeal/complain to the Information Commissioner (IC). The IC can be contacted at:
Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
Tel: 0303 123 1113 or 01625 545 745
Email:
https://ico.org.uk/global/contact-us/ 

Law Enforcement and Regulatory Bodies

In some circumstances the Practice may be legally required to share personal information with law enforcements and regulatory bodies (without the consent of the data subject) such as: the Police; Courts of Justice; HMRC and DVLA for the purposes of prevention or detection of crime; apprehension or prosecution of offenders; the assessment or collection of any tax or duty or, of any imposition of a similar nature.

GPs are obliged to notify the DVLA when fitness to drive requires notification but an individual cannot or will not notify the DVLA themselves, and if there is concern for road safety, which would be for both the individual and the wider public.

The Practice will review each request based on its merits before deciding whether to release information to the ‘relevant authorities’.

The source of the information shared in this way is your electronic GP record.

Data Retention Period

All records held by the Practice will be kept for the duration specified in the Records Management Codes of Practice for Health and Social Care.

 

 

The processing of personal data is permitted under the following conditions:

Article 6(1) (e) - public interest or in the exercise of official authority;

DPA Section 8 (d) - Processing is necessary for the exercise of statutory functions.

The processing of special categories of personal data concerning health is permitted under the following conditions:

Article 9 (2) (G) – the processing is  necessary for reasons of substantial public interest

In accordance with DPA Schedule 1, Part 2, (10) (1c) – the condition is met where the processing is necessary for the prevention or detection of an unlawful act  

This sharing is a legal and professional requirement and therefore there is no right to object. Personal data processed for these purposes are exempt for the first data protection principle (processed lawfully, fairly and in a transparent manner).

Right to complain: If you are dissatisfied with the way Otford Medical Practice process your data, you have the right to appeal/complain to the Information Commissioner (IC). The IC can be contacted at:
Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
Tel: 0303 123 1113 or 01625 545 745
Email:
https://ico.org.uk/global/contact-us/ 

Medico-Legal

Medico-Legal - Where a medical professional is holding personal data for the purpose of providing medical reports in connection with legal action.

The source of the information shared in this way is your electronic GP record.

 

The processing of personal data is permitted under the following conditions:

GDPR Article 6(1) (c) - processing for legal obligation;

The processing of special categories of personal data concerning health is permitted under the following conditions:

GDPR Article 9 (2) (f) – the processing is necessary for the establishment, exercise or defence of legal claims;

In accordance with DPA Schedule 1, Part 3, (33) - the conditions for processing for legal claims is met where it is in connection with, any legal proceedings including prospective legal proceedings or; for the purpose of obtaining a legal advice or; establishing exercising or defending legal rights.

This sharing is a legal and professional requirement and therefore there is no right to object.

Right to complain: If you are dissatisfied with the way Otford Medical Practice process your data, you have the right to appeal/complain to the Information Commissioner (IC). The IC can be contacted at:
Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
Tel: 0303 123 1113 or 01625 545 745
Email:
https://ico.org.uk/global/contact-us/ 

General Medical Council (GMC)

General Medical Council (GMC) is a public body that maintains the official register of medical practitioners within the United Kingdom. Its primary responsibility is ‘to protect, promote and maintain the health and safety of the public’ by controlling entry to the register, and suspending or removing members when necessary.

Under the Medical Act 1983, the GMC has the power to request access to a patient’s medical records for the purposes of an investigation into a doctor’s fitness to practise.

The source of the information shared in this way is your electronic GP record.

Data Retention Period

All records held by the Practice will be kept for the duration specified in the Records Management Codes of Practice for Health and Social Care.

 

The processing of personal data is permitted under the following conditions:

Article 6(1) (c) - processing for legal obligation;

GDPR Article 6(1) (e) - public interest or in the exercise of official authority;

DPA Section 8 (d) - processing is necessary for the exercise of statutory functions;

The processing of special categories of personal data concerning health is permitted under the following paragraph:

Article 9 (2) (h) - processing is necessary for medical or social care treatment or, the management of health or social care systems and services

DPA Section 10 (1) (c) – processing is necessary for health and social care purposes;

In accordance with DPA Schedule 1, Part 1, (2) - health or social care purposes means the purposes of preventive or occupational medicine; medical diagnosis; the provision of health care or treatment; the provision of social care, or the management of health care systems or services or social care systems or services.

Related Legislation:

The Medical Act 1983

You have the right to:

  • To access, view or request copies of your personal information;
  • request rectification of any inaccuracy in your personal information;
  • restrict the processing of your personal information where:
  • accuracy of the data is contested,
  • the processing is unlawful or,
  • where we no longer need the data for the purposes of the processing.

Right to object: You have a general right to raise an objection to the processing of your personal data in some particular circumstances. This right only applies where we cannot demonstrate compelling legitimate grounds for continued processing of your personal data for the purposes of direct provision of care, and compliance with a legal obligation to which we are subject.

Right to complain: If you are dissatisfied with the way Otford Medical Practice process your data, you have the right to appeal/complain to the Information Commissioner (IC). The IC can be contacted at:
Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
Tel: 0303 123 1113 or 01625 545 745
Email:
https://ico.org.uk/global/contact-us/ 

The Health Service Ombudsman (HSO)

The Health Service Ombudsman (HSO) was set up by Parliament to provide an independent complaint handling service for complaints that have not been resolved by the NHS in England and UK government departments.

The HSO has the power to request access to a patient’s medical records for the purpose of an investigation.

The source of the information shared in this way is your electronic GP record.

Data Retention Period

All records held by the Practice will be kept for the duration specified in the Records Management Codes of Practice for Health and Social Care.

 

 

The processing of personal data is permitted under the following paragraph:

Article 6(1) (c) - processing for legal obligation;

GDPR Article 6(1) (e) - public interest or in the exercise of official authority;

The processing of special categories of personal data concerning health is permitted under the following paragraph:

Article 9 (2) (h) - processing is necessary for medical or social care treatment or, the management of health or social care systems and services;

DPA Section 10 (1) (c) – processing is necessary for health and social care purposes;

In accordance with DPA Schedule 1, Part 1, (2) - health or social care purposes means the purposes of preventive or occupational medicine; medical diagnosis; the provision of health care or treatment; the provision of social care, or the management of health care systems or services or social care systems or services.

Related Legislation:

The Health Services Commissioners Act 1993,s12

You have the right to:

  • To access, view or request copies of your personal information;
  • request rectification of any inaccuracy in your personal information;
  • restrict the processing of your personal information where:
  • accuracy of the data is contested,​​​​​​​
  • the processing is unlawful or,
  • where we no longer need the data for the purposes of the processing.

Right to object: You have a general right to raise an objection to the processing of your personal data in some particular circumstances. This right only applies where we cannot demonstrate compelling legitimate grounds for continued processing of your personal data for the purposes of direct provision of care, and compliance with a legal obligation to which we are subject. 

Right to complain: If you are dissatisfied with the way Otford Medical Practice process your data, you have the right to appeal/complain to the Information Commissioner (IC). The IC can be contacted at:
Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
Tel: 0303 123 1113 or 01625 545 745
Email:
https://ico.org.uk/global/contact-us/ 

NHS Counter Fraud

 

 

Under the NHS Act 2006, investigations into fraud in the NHS may require access to confidential patient information.

This means that we are compelled by the law to share your data.

The source of the information shared in this way is your electronic GP record.

Data Retention Period

All records held by the Practice will be kept for the duration specified in the Records Management Codes of Practice for Health and Social Care.

 

The processing of personal data is permitted under the following paragraph:

Article 6(1) (c) - processing for legal obligation;

The processing of special categories of personal data concerning health is permitted under the following paragraph:

Article 9 (2) (h) - processing is necessary for medical or social care treatment or, the management of health or social care systems and services

In accordance with DPA Schedule 1, Part 1, (2) - health or social care purposes means the purposes of preventive or occupational medicine; medical diagnosis; the provision of health care or treatment; the provision of social care, or the management of health care systems or services or social care systems or services.

Related Legislation:

S10 NHS Act 2006

Right to complain: If you are dissatisfied with the way Otford Medical Practice process your data, you have the right to appeal/complain to the Information Commissioner (IC). The IC can be contacted at:
Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
Tel: 0303 123 1113 or 01625 545 745
Email:
https://ico.org.uk/global/contact-us/ 
​​​​​​​

NHS Digital – Statutory Data Collection

NHS Digital is a national information and technology partner to the health and social care system. NHS Digital use digital technology to transform the NHS and social care.

NHS Digital carries out National Data collections/ extraction from the GP record. These include:

National Diabetes Audit (NDA) - A national monitoring system, auditing the care of patients with diabetes. The data extracted for the purpose of NDA includes NHS Number, date of birth and postcode, as well as clinical parameters related to diabetes. NDA is a mandatory data extraction under section 259 of the Health and Social Care Act 2012, this means that we are compelled by law to share your data

Individual GP Level Data (IGPLD) - A national monitoring system to enable NHS Digital to provide GPs with clinical information on the care provision for their patients. The data extracted includes the NHS number. IGPLD is a mandatory data extraction under 259 of the Health and Social Care Act 2012, this means that we are compelled by law to share your data

FGM) - NHS Digital collects data on FGM within the NHS in England on behalf of the Department of Health (DH). Data collected is used to produce information that helps improve NHS and local authorities to improve on how they support women and girls who have had or, who are at risk of FGM.

FGM Enhanced Dataset is a mandatory data extraction under section 259 of the Health and Social Care Act 2012, this means that we are compelled by law to share your data when required.

The source of the information shared in this way is your electronic GP record.

Data Retention Period

All records held by the Practice will be kept for the duration specified in the Records Management Codes of Practice for Health and Social Care

 

The processing of personal data is permitted under the following condition:

Article 6(1) (c) - processing for legal obligation;

The processing of special categories of personal data concerning health is permitted under the following GDPR and DPA conditions:

GDPR Article 9 (2) (h) - processing is necessary for medical or social care treatment or, the management of health or social care systems and services;

DPA Section 10 (1) (c) – processing is necessary for health and social care purposes;

In accordance with DPA Schedule 1, Part 1, (2) - health or social care purposes means the purposes of preventive or occupational medicine; medical diagnosis; the provision of health care or treatment; the provision of social care, or the management of health care systems or services or social care systems or services.

Related Legislation:

S259 of the Health and Social Care Act 2012

You have the right to:

  • To access, view or request copies of your personal information;
  • request rectification of any inaccuracy in your personal information;
  • restrict the processing of your personal information where:
  • accuracy of the data is contested,​​​​​​​
  • the processing is unlawful or,
  • where we no longer need the data for the purposes of the processing.

Right to object: You do not have the right to object as the sharing is a legal and professional requirement under the law.

Whilst there is no right to object when we are complying with a legal obligation, NHS Digital respects Type 1 objections (9Nu0 read codes) present in the GP record and no data will be extracted and uploaded if so.

Right to complain: If you are dissatisfied with the way Otford Medical Practice process your data, you have the right to appeal/complain to the Information Commissioner (IC). The IC can be contacted at:
Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
Tel: 0303 123 1113 or 01625 545 745
Email:
https://ico.org.uk/global/contact-us/ 

NHS England

NHS England is responsible for securing, planning, designing and paying for Primary Care & Specialised NHS services not otherwise funded by Kent and Medway CCGs. This includes planned and emergency hospital care, mental health, rehabilitation, community and primary medical care (GP) services.

We may often share personal information with NHS England potentially for safeguarding concerns that need escalating beyond our borough.

Where required the Practice may also have to share staff personal information with NHS England for the purpose of allegations framework or performers list.

The source of the information that may be shared in this instance are in the staff record and patient’s electronic GP record.

Data Retention Period

All records held by the Practice will be kept for the duration specified in the Records Management Codes of Practice for Health and Social Care.

 

The processing of personal data is permitted under the following conditions:

Article 6(1) (c) - processing for legal obligation;

DPA Section 8 (d) - processing is necessary for the exercise of statutory functions;

The processing of special categories of personal data concerning health is permitted under the following paragraph:

Article 9 (2) (h) - processing is necessary for medical or social care treatment or, the management of health or social care systems and services.

In accordance with DPA Schedule 1, Part 1, (2) - health or social care purposes means the purposes of preventive or occupational medicine; medical diagnosis; the provision of health care or treatment; the provision of social care, or the management of health care systems or services or social care systems or services.

You have the right to:

  • To access, view or request copies of your personal information;
  • request rectification of any inaccuracy in your personal information;
  • restrict the processing of your personal information where:
  • accuracy of the data is contested,​​​​​​​
  • the processing is unlawful or,
  • where we no longer need the data for the purposes of the processing.

Right to object: You do not have the right to object as the sharing is a legal and professional requirement under the law.

If you wish to exercise any of your rights please contact the Practice (data controller) or the DPO and your request will be carefully considered.

Right to complain: If you are dissatisfied with the way Otford Medical Practice process your data, you have the right to appeal/complain to the Information Commissioner (IC). The IC can be contacted at:
Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
Tel: 0303 123 1113 or 01625 545 745
Email:
https://ico.org.uk/global/contact-us/ 

National Cancer Diagnosis Audit (NCDA).

The National Cancer Diagnosis Audit (NCDA) looks at primary and secondary care data relating to patients diagnosed with cancer. It helps to understand pathways to cancer diagnosis, what works well and where improvements could be made.

The audit looks specifically at clinical practice in order to understand:

  • interval length from patient presentation to diagnosis;
  • use of investigations prior to referral;
  • what the referral pathways for patients with cancer are and how they compare with those recorded by the cancer registry

 

The processing of personal data is permitted under the following conditions:

Article 6(1) (c) - processing for legal obligation;

DPA Section 8 (d) - processing is necessary for the exercise of statutory functions;

The processing of special categories of personal data concerning health is permitted under the following paragraph:

Article 9 (2) (h) - processing is necessary for medical or social care treatment or, the management of health or social care systems and services.

In accordance with DPA Schedule 1, Part 1, (2) - health or social care purposes means the purposes of preventive or occupational medicine; medical diagnosis; the provision of health care or treatment; the provision of social care, or the management of health care systems or services or social care systems or services.

You have the right to:

  • To access, view or request copies of your personal information;
  • request rectification of any inaccuracy in your personal information;
  • restrict the processing of your personal information where:
  • accuracy of the data is contested,​​​​​​​
  • the processing is unlawful or,
  • where we no longer need the data for the purposes of the processing.

Right to object: You do not have the right to object as the sharing is a legal and professional requirement under the law.

If you wish to exercise any of your rights please contact the Practice (data controller) or the DPO and your request will be carefully considered.

Right to complain: If you are dissatisfied with the way Otford Medical Practice process your data, you have the right to appeal/complain to the Information Commissioner (IC). The IC can be contacted at:
Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
Tel: 0303 123 1113 or 01625 545 745
Email:
https://ico.org.uk/global/contact-us/ 

Public Health

 

Public Health England is an executive agency of the Department of Health and Social Care, and a distinct organisation with operational autonomy.

The main purpose of the organisation is to protect and improve the health and wellbeing of citizens. These include the management of smoking, alcohol and obesity; management of epidemics and infections such as flu, measles, tuberculosis or outbreaks of food poisoning.

The source of the information shared in this way is your electronic GP record.

Data Retention Period

All records held by the Practice will be kept for the duration specified in the Records Management Codes of Practice for Health and Social Care.

 

The processing of personal data is permitted under the following paragraph:

Article 6(1) (c) - processing for legal obligation;

The processing of special categories of personal data concerning health is permitted under the following condition:

GDPR Article 9(2) (i) – processing is necessary for reasons of public interest in the area of public health, such as protecting against serious cross-border threats to health or ensuring high standards of quality and safety of health care and of medicinal products or medical devices.

In accordance with DPA Schedule 1, Part 1 (3) (a) – the condition is met where the processing is necessary for reasons of public interest in the area of public health, and is carried out by or under the responsibility of a health professional, or by another person who in the circumstances owes a duty of confidentiality under an enactment or rule of law.

 

Related Legislations:

The Health Protection (Notification) Regulations 2010 (SI 2010/659);

The Health Protection (Local Authority Powers);

Regulations 2010 (SI 2010/657)

You have the right to:

  • To access, view or request copies of your personal information;
  • request rectification of any inaccuracy in your personal information;
  • restrict the processing of your personal information where:
  • accuracy of the data is contested,​​​​​​​
  • the processing is unlawful or,
  • where we no longer need the data for the purposes of the processing.

Right to object: You have a general right to raise an objection to your personal data being shared with the recipient.

If you wish to exercise any of your rights please contact the Practice (data controller) or the DPO and your request will be carefully considered.

Right to complain: If you are dissatisfied with the way Otford Medical Practice process your data, you have the right to appeal/complain to the Information Commissioner (IC). The IC can be contacted at:
Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
Tel: 0303 123 1113 or 01625 545 745
Email:
https://ico.org.uk/global/contact-us/