Comment

31.01.18

Are you ready for GDPR?

Source: NHE Jan/Feb 18

Danny Mortimer, chief executive of NHS Employers, outlines the major changes that NHS organisations must prepare for ahead of the General Data Protection Regulation (GDPR).

The most important change to data privacy for 20 years is being introduced this year, and every NHS organisation must make sure they’re fully prepared.

Changes under the EU’s GDPR and Data Protection Act 2018 will come into effect from 25 May 2018 – and the government has confirmed the UK will continue to comply after Brexit.

The new laws mean governance, HR, legal and IT teams must work closely together to make sure their organisation complies.

To help NHS organisations, NHS Employers has published the ‘Changes to data protection requirements under GDPR’ factsheet, which has been developed in conjunction with healthcare legal specialists. The factsheet summarises the key changes and new data protection principles, provides a glossary of terms, and outlines important steps NHS organisations can take to prepare. The main changes include:

  • Appointing a data protection officer: Responsibilities will include informing and advising the organisation and its employees of their data protection obligations, monitoring the organisation’s compliance and internal data protection policies, advising on the necessity of data protection impact assessments, and being the point of contact for the data protection authorities and individuals;
  • An explicit accountability: Organisations will be required to show they comply with the revised data protection principles by implementing appropriate and proportionate technical and organisational measures, maintaining relevant documentation on processing activities, implementing measures that meet the principles of data protection, and undertaking data protection impact assessments where appropriate;
  • Ensuring the legal grounds for processing personal data is understood: Employers must be completely clear about their grounds for collecting, using and retaining personal data. Organisations should spend time now establishing what personal data they collect, what purposes it is put to, and the legal basis for processing the information. Multiple legitimising conditions may apply to the same personal data, depending on the circumstances;
  • Privacy notices: Currently, under the preexisting data protection law, employers are required to make available to employees and job applicants a privacy notice setting out certain information. In future, employers will need to ensure they provide more detailed information within their privacy notices. Employers are advised to review all documents which require a self-declaration from job applicants and employees to make sure the new requirements and the rights of the individuals are made expressively clear;
  • Subject access requests: Employers will no longer be able to insist data can only be provided for a fee. Going forward, the data must be passed to the employee or individual without any charge, in the first instance;
  • There will now be a mandatory breach reporting requirement: Where there has been a high-risk data breach, the employer will need to notify and provide information within 72 hours. Organisations can be subject to significant penalties where they are in breach of the new requirements, as well as face legal claims from individuals or employees whose data protection rights have been infringed.

There is now just four months for each organisation to prepare and put all the necessary processes in place. They will have to ensure all the changes are widely communicated and understood by all staff and that any necessary training is undertaken.

GDPR does, of course, have much wider implications for governance arrangements in the NHS, and health organisations are recommended to read the NHS Employers factsheet in conjunction with more detailed guidance produced by the Information Commissioner’s Office.

 

Top image © Tanaonte

FOR MORE INFORMATION
W: www.tinyurl.com/Changes-to-data-protection
W: www.ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr 

Comments

There are no comments. Why not be the first?

Add your comment

national health executive tv

more videos >

latest healthcare news

NHS England commits £30m to join up HR and staff rostering systems

09/09/2020NHS England commits £30m to join up HR and staff rostering systems

As NHS England looks to support new ways of working, it has launched a £30m contract tender for HR and staff rostering systems, seeking sup... more >
Gender equality in NHS leadership requires further progress

09/09/2020Gender equality in NHS leadership requires further progress

New research carried out by the University of Exeter, on behalf of NHS Confederation, has shown that more progress is still needed to achieve gen... more >
NHS Trust set for big savings in shift to digital patient letters

09/09/2020NHS Trust set for big savings in shift to digital patient letters

Up and down the country, NHS trusts are finding new and innovative ways to leverage the power of digital technologies. In Bradford, paper appoint... more >

the scalpel's daily blog

Covid-19 can signal a new deal with the public on health

28/08/2020Covid-19 can signal a new deal with the public on health

Danny Mortimer, Chief Executive, NHS Employers & Deputy Chief Executive, NHS Confederation The common enemy of coronavirus united the public side by side with the NHS in a way that many had not seen in their lifetimes and for others evoked war-time memories. It was an image of defiance personified by the unforgettable NHS fundraising efforts of Captain Sir Tom Moore, resonating in the supportive applause during the we... more >
read more blog posts from 'the scalpel' >

interviews

Matt Hancock says GP recruitment is on the rise to support ‘bedrock of the NHS’

24/10/2019Matt Hancock says GP recruitment is on the rise to support ‘bedrock of the NHS’

Today, speaking at the Royal College of General Practitioners (RCGP) annual conference, Matt Hancock highlighted what he believes to be the three... more >
NHS dreams come true for Teesside domestic

17/09/2019NHS dreams come true for Teesside domestic

Over 20 years ago, a Teesside hospital cleaner put down her mop and took steps towards her midwifery dreams. Lisa Payne has been delivering ... more >
How can winter pressures be dealt with? Introduce a National Social Care Service, RCP president suggests

24/10/2018How can winter pressures be dealt with? Introduce a National Social Care Service, RCP president suggests

A dedicated national social care service could be a potential solution to surging demand burdening acute health providers over the winter months,... more >
RCP president on new Liverpool college building: ‘This will be a hub for clinicians in the north’

24/10/2018RCP president on new Liverpool college building: ‘This will be a hub for clinicians in the north’

The president of the Royal College of Physicians (RCP) has told NHE that the college’s new headquarters based in Liverpool will become a hu... more >

last word

Haseeb Ahmad: ‘We all have a role to play in getting innovations quicker’

Haseeb Ahmad: ‘We all have a role to play in getting innovations quicker’

Haseeb Ahmad, president of the Association of the British Pharmaceutical Industry (ABPI), sits down with National Health Executive as part of our Last Word Q&A series. Would you talk us th... more > more last word articles >

editor's comment

26/06/2020Adapting and Innovating

Matt Roberts, National Health Executive Editorial Lead. NHE May/June 2020 Edition We’ve been through so much as a health sector and a society in recent months with coronavirus and nothing can take away from the loss and difficulties that we’ve faced but it vital we also don’t disregard the amazing efforts we’v... read more >

health service focus

‘We are the NHS’: NHS England publish newest People Plan

30/07/2020‘We are the NHS’: NHS England publish newest People Plan

NHS England has published its People Plan for... more >
How NHS Property Services adapted to a new way of working

01/07/2020How NHS Property Services adapted to a new way of working

From May/June 2020 edition Trish Stephen... more >