Important information about this website

From 1 July 2022, NHS Kirklees CCG will become part of NHS West Yorkshire Integrated Care Board. We will continue to work with health and care colleagues to improve outcomes for people in Kirklees and across West Yorkshire.

The changes mean that from 30 June, this website will be archived and will no longer be updated. A new website for the Kirklees Health and Care Partnership – http://www.kirkleeshcp.co.uk – will be launched on 1 July

Home »

Privacy Policy

A supplementary Kirklees Covid-19 Privacy Notice has now been added which describes how we may use your information to protect you and others during the Coronavirus outbreak.

What is a Privacy Notice

A privacy notice tells you how an organisation holds, uses and shares your personal information.

We need to tell you certain details about our use of your personal information to meet our legal duties. These details are:

  • Why we need your personal information,
  • How it will be used, and
  • Who it will be shared with by us.

You also have a number of rights which allow you to control your personal information.

These rights are described in the ‘Your Rights’ section. For more information about your data protection rights, please visit the ‘Your Data Matters’ page on the Information Commissioner Office’s website.

There are a number of laws which tell organisations how to collect and use personal information, these are:

  • UK General Data Protection Regulation
  • Data Protection Act 2018
  • Human Rights Act 1998
  • Common Law Duty of Confidentiality

This privacy notice uses a number of terms which are defined in the Glossary section.

Contact details

NHS Kirklees CCG is the ‘Data Controller’ for the personal information it processes, unless otherwise stated.

The Data Protection Officer (DPO) for NHS Kirklees CCG is the Head of Corporate Governance and they can be contacted at:

Data Protection Officer

NHS Kirklees CCG

2nd Floor

Norwich Union House

Market Street

Huddersfield

HD1 2LF

Email: kirkccg.contactus@nhs.net

Telephone: 01484 464000

The DPO’s role is to inform and advise the CCG about its data protection obligations, to make sure the CCG meets data protection laws, and advise on data protection impact assessments. The DPO is also the first point of contact for the Information Commissioner Office (ICO) and for individuals who have questions about how their personal information is used by the CCG, including exercising their data protection rights.

If you have any questions regarding the personal information we hold about you or you have a complaint about how we use your personal information, the first step you should take is to contact our Data Protection Officer using the contact details above.

If you feel that we have not dealt with your complaint properly, you have the right to lodge a complaint with the ICO at any time. Their contact details are:

Information Commissioner’s Office

Wycliffe House,

Water Lane,

Wilmslow

SK9 5AF

Tel: 0303 123 1113

www.ico.org.uk

Changes to our privacy notice

We review our privacy notice on a regular basis to ensure that you are always well informed about how we use your information.


This privacy notice was last reviewed: 1 April 2021

Data protection notification

The ICO maintains a public register of organisations that process personal information. As a data controller, NHS Kirklees CCG is registered with the ICO.

The information we collect

Where possible we will use anonymised information to carry out our work but sometimes we may need to use your personal information to do our work, promote our services and to support/manage our staff. We explain these instances in greater detail below.

We may also process ‘Special category data’, which is personal information of a more sensitive nature and requires additional protection. Special category data includes:

  • Racial or ethnic origin
  • Political opinions
  • Trade union membership
  • Religious or philosophical beliefs
  • Genetic data
  • Biometric data (where used for identification purposes)
  • Physical and mental health
  • Sex life and sexual orientation.

Use of Personal and Sensitive (Identifiable) Information

The following list includes details of where we collect and use personal information. The tables below include information on the purpose, the type of information used, the legal basis identified for the collection and use of the information, how we collect and use the information required, any third parties we may share the information with and your rights regarding the use of the information including, where relevant, your right to opt out.

Patient/Service User Information
Visitors to our website
Communications and Engagement
Continuing Healthcare (CHC) and Children’s Continuing Care (CCC)
Individual Funding Requests (IFR)
Complaints
Safeguarding
Commissioning
Risk Stratification
Invoice validation
NHS England Annual 360 Survey of CCG Stakeholders
Personal Health Budgets (PHB)
Freedom of Information Requests
Assuring Transformation (Learning Disability Data)
GPES data for pandemic planning (GDPPR COVID 19)
Staff Information
Job Applicants
Workforce (Staff)
Occupational Health
Payroll
Declarations of Interest
National Fraud Initiative
Internal/External Audits
Flu Vaccinations
Individual Staff Risk Assessments

How we keep your personal information safe

We have a legal duty to protect any personal information we collect from you. We use cyber security technology and encryption software to protect your information, and keep strict security standards to prevent any unauthorised access to it.

All our staff have contractual obligations of confidentiality, enforceable through disciplinary procedures. All our staff have annual refresher training on how to keep your personal information safe.

We take steps to make sure that the information we hold about you is secure – such as storing information in secure locations, only allowing information to be accessed by authorised personnel, using encryption on laptops and mobile phones and making sure information is sent safely and securely.

If you would like to find out more about how we keep your information safe, please visit our Policies page.

How the NHS and Care Services use your information

Whenever you use a health or care service, such as attending Accident & Emergency or using Community Care services, important information about you is collected to help ensure you get the best possible care and treatment.

The information collected about you when you use these services can also be provided to other approved organisations, where there is a legal basis, to help with planning services, improving care provided, research into developing new treatments and preventing illness. All of these help to provide better health and care for you, your family and future generations. Confidential personal information about your health and care is only used in this way where allowed by law and would never be used for insurance or marketing purposes without your explicit consent.

You have a choice about whether you want your confidential patient information to be used in this way.

To find out more about the wider use of confidential personal information and to register your choice to opt out if you do not want your information to be used in this way, visit the NHS website. If you do choose to opt out you can still consent to your information being used for specific purposes.

If you are happy with this use of information you do not need to do anything. You can change your choice at any time. The CCG is currently compliant with the national data opt-out requirements.

How will NHS Kirklees CCG use your information

What is itVisitors to our website  
Data ControllerNHS Kirklees CCG  
PurposeWhen someone visits our website (https://www.kirkleesccg.nhs.uk/) we use a third party service, Google Analytics, to collect standard internet log information and details of visitor behaviour patterns.  We do this to check how the CCG’s website is used and find out things such as the number of visitors to the various parts of the site, to help us communicate our work more effectively.   You can find out more about Google Analytics in our Cookie Policy.  
Lawful basisThe CCG’s legal basis for processing personal data under the UK GDPR is Article 6(1) f – Legitimate Interests  
Type of information usedPersonal data: IP address
Who we will share the information with (recipients)This information is not shared outside the CCG.
Do we use any processorsWe use a third party content management system, WordPress, to publish the website. WordPress is run by Automattic Inc. We use a standard WordPress feature to collect anonymous information about visitor activity on the website, for example the number of people viewing pages, in order to monitor and report on the effectiveness of the website and to help us to improve it. No information is stored with Automattic Inc. The CCG’s website, including the WordPress Content Management System, is securely hosted by a third-party, Urbansoul Design.  
How we collect (the source) and use the informationWhen someone visits our website, information is collected in an internet log to enable us to monitor how the website is used. This is done to find out things such as the number of visitors to the various parts of the site.  
How long we will keep the informationSix years or until deletion requested
Your RightsUnder the UK GDPR you have the right:
To be informed about the processing of your information (this notice)
Of access to the information held about you
To have the information corrected in the event that it is inaccurate
To have your information deletedTo restrict or stop processing
To object to it being processed or used
Not to be subject automated decision-taking or profiling
To be notified of data breaches
What is itCommunications and Engagement
Data ControllerNHS Kirklees CCG
PurposeIn order for us to understand the needs of the community we look after and to promote our work and services, we carry out various engagement activities, such as events and surveys. In order to invite people to take part in engagement activities, we have to hold contact details for individuals. To make sure the views of the whole community are heard, we occasionally collect personal information and special category data from surveys, including information about race, gender, age, and health issues.   We will also occasionally take photographs and videos during our engagement events for publicity use. We will always ask for your permission when we take a photo or video of you to make sure you are happy with us using your image. You will always have the right to say no at the time or withdraw your permission at a later date.  
Lawful basisThe CCG’s legal basis for processing personal data under the UK GDPR is Article 6(1) a – consent. For the processing of special category data, the legal basis is Article 9(2) a – explicit consent.  
Type of information usedPersonal Data: name, address, email address and photograph. Special category data: gender, religious beliefs, health, ethnic-origin.  
Who we will share the information with (recipients)The information you provide as a member of one of our patient involvement groups is never shared outside of the CCG.
Do we use any processorsWe occasionally use Smart Survey to carry out our surveys. For more information please see Smart Survey’s Privacy Notice. The Health Informatics Service (THIS), our IT supplier who store all our information securely on their servers.  
How we collect (the source) and use the informationWe will only receive this information directly from you.
How long we will keep the informationYour information will be held for 6 years, until it is no longer required, or until a request for your information to be deleted is received, whichever is soonest. Details on how to let us know that you no longer want us to contact you about engagement events, or to have your details removed from our system, are below. The information will be stored in a secure environment and access to it will be restricted to only people who need to access it.  
Your RightsUnder the UK GDPR you have the right:
To be informed about the processing of your information (this notice)Of access to the information held about you
To have the information corrected in the event that it is inaccurate
To have your information deleted
To restrict or stop processing
To have your information transferred to someone else
Not to be subject to automated decision-taking or profiling
To be notified of data breaches  
If you do withdraw consent, you may no longer be able to receive invitations to engagement events, or other engagement activities carried out by the CCG.  To withdraw your consent, please use the contact details below: Communications Team
NHS Kirklees CCG
2nd Floor,
Norwich Union House
Market Street
Huddersfield
HD1 2LF
Email: kirkccg.contactus@nhs.net
Telephone: 01484 464000  
What is itContinuing Healthcare (CHC) and Children’s Continuing Care (CCC)
Data ControllerNHS Kirklees CCG
PurposeNHS Continuing Healthcare (CHC) is explained on the NHS website. To determine if someone is eligible for CHC, or CCC and arrange a care and support package that meets their assessed needs and represents a fair market price, information about the individual will need to be collected, reviewed and shared with care providers.  
Lawful basisThe CCG’s lawful basis for processing personal data under the UK GDPR is Article 6(1) e – Public Task. For special category data the basis is Article 9(2) h – Management of Healthcare Systems. The consent of the patient or their legal representative is obtained to satisfy the Common Law Duty of Confidentiality.  
Type of information usedPersonal data: name, age, contact details, address and postcode of residence, NHS number, local record identifier.
Special Category data: ethnic origin, physical and mental health data.  
Who we will share the information with (recipients)We will only share your information with providers (such as domiciliary care providers) as needed in order to process your Continuing Healthcare application.  We will need to receive and share your information with providers who have been or will be involved in your care. This ensures we have accurate records regarding your needs, and will help with the assessment and review process of continuing healthcare.  We may also share your information with the local authority, Doncaster CCG (which processes previously unassessed periods of care on behalf of the CCG), our solicitors and others in line with the “need to know” principle.  
Do we use any processorsQA Plus Ltd – supplier of iQA electronic record system used for NHS Continuing Healthcare, NHS Funded Nursing Care and Complex Care Patients.

The Phoenix Partnership – supplier of SystmOne electronic patient records system.  The Health Informatics Service (THIS), our IT supplier who store all our information securely on their servers.  

Valuing Care Ltd – supplier of the Valuing Care fair pricing software which uses the cost breakdown of proposed and actual placements to determine a fair market price for care and enable like for like comparison.

The Health Informatics Service (THIS), our IT supplier who store all our information securely on their servers.
How we collect (the source) and use the informationNormally, the type of information that we process about you is information you have provided yourself, although we may seek further information in relation to your health and care needs. We will obtain this additional information from your healthcare records that may include Care Home records, Health Records (for example GP, Hospital, Mental Health, District Nursing) and Social Care Records.
How long we will keep the information8 years from end of care or when you are last seen.   Where your request has been rejected, information will be kept for 2 years.  
Your RightsWith regards to Continuing Healthcare under the UK GDPR you have the right:
To be informed about the processing of your information (this notice)
Of access to the information held about you
To have the information corrected in the event that it is inaccurate
To restrict or stop processing
To object to it being processed or used
Not to be subject automated decision-taking or profiling
To be notified of data breaches  
What is itIndividual Funding Requests (IFR)
Data ControllerNHS Kirklees CCG
PurposeYou can request funding to pay for treatments not covered usually by the NHS. These requests are looked at on a case by case basis. You can find out more about Individual Funding Requests on our website.   We will need to process your personal and health information in order to consider and process you funding request accurately and fairly.  
Lawful basisThe CCG’s legal basis for processing this personal data under the UK GDPR is Article 6(1) e – exercise of official authority. For special category data the basis is Article 9(2) h – provision of health or social care or treatment.  
Type of information usedPersonal data: name, address date of birth, NHS number.
Special Category data: Physical and Mental Health information, ethnic origin, gender.  
Who we will share the information with (recipients)The information may be shared with NHS or private providers of health services.
Do we use any processorsThe Health Informatics Service (THIS), our IT supplier who store all our information securely on their servers. Blueteq – content management system.  
How we collect (the source) and use the informationInformation to make payments in relation to funding treatment is provided by you. We may also receive information from the clinician who submits an IFR application on your behalf.  
How long we will keep the information8 years from end of care or when you are last seen.   Where your request has been rejected, information will be kept for 2 years.  
Your RightsWith regards to Individual Funding Requests under the UK GDPR you have the right:
To be informed about the processing of your information (this notice)
Of access to the information held about you
To have the information corrected in the event that it is inaccurate
To restrict or stop processingTo object to it being processed or used
Not to be subject automated decision-taking or profiling
To be notified of data breaches  
What is itComplaints
Data ControllerNHS Kirklees CCG
PurposeMost NHS care and treatment goes well but sometimes things can go wrong. If you are unhappy with your care or the service you have received, you have the right to complain to both providers and commissioners about services provided.   In order to resolve and investigate a complaint you have made, we will require some personal information. We may also need details about the nature of the complaint, which may include special category data.   We will only use the personal information we collect to process the complaint and check on the level of service we provide. We do compile and publish statistics showing information such as the number of complaints we receive, but not in a form which identifies anyone.  
Lawful basisThe CCG’s legal basis for processing this personal data under the UK GDPR is Article 6(1) e – exercise of official authority.   For special category data the basis is Article 9(2) h – management of health or social care.  
Type of information usedPersonal: name, address date of birth, NHS number

Special Category: details of the complaint which may contain special category data such as gender, ethnic origin, physical and mental health details.  
Who we will share the information with (recipients)Where the complaint is not raised by the patient, we will usually need to disclose the complainant’s identity to whoever the complaint is about. This is so we can get the patient’s consent to proceed with the complaint and for the complainant to correspond with us on behalf of the patient.   We usually have to disclose the complainant’s identity to the care provider in order to move forward with the investigation. If a complainant doesn’t want information identifying him or her to be disclosed, we will try to respect that. However, it may not be possible to handle a complaint on an anonymous basis.  
Do we use any processorsThe Health Informatics Service (THIS), our IT supplier who store all our information securely on their servers.  
How we collect (the source) and use the informationWhen the CCG receives a complaint from a person, a complaint file is made up which will normally contain the identity of the complainant, the identity of the patient (where this is a different person) and any other individuals involved, plus details of the complaint, including health information.   The CCG will only use the identifiable information we collect from you to process the complaint and to check the level of service we provide.  
How long we will keep the informationComplaint files are kept for 10 years from closure of incident.  
Your RightsWith regards to Complaints under the UK GDPR you have the right:
To be informed about the processing of your information (this notice)
Of access to the information held about you
To have the information corrected in the event that it is inaccurate
To restrict or stop processing
To object to it being processed or used
Not to be subject automated decision-taking or profiling
To be notified of data breaches  
What is itSafeguarding
Data ControllerNHS Kirklees CCG
PurposeWe have a legal duty to have arrangements in place for safeguarding adults and children (children and adults at risk of abuse or neglect). Information for safeguarding purposes is used to assess and evaluate safeguarding concerns, to make sure individuals are effectively protected.   The information collected by us in the event of a safeguarding situation will be as much personal information as is necessary in order to handle the situation.  
Lawful basisThe CCG’s legal basis for processing this personal data under the UK GDPR is Article 6(1) e exercise of official authority. For special category data the basis are: Article 9(2) b – social security and social protection law. Article 9(2) c – vital interests Article 9(2) h – management of  health or social care   For the purposes of Article 9(2)(b), a wide range of acts relate to safeguarding powers and duties. These include e.g. the Children Acts 1989 and 2004, the Care Act 2014, the Crime and Disorder Act 1998, the Mental Capacity Act (2005), the Sexual Offences Act 2003, the Counter-Terrorism and Security Act 2015 and the Modern Day Slavery Act 2015. This list is not exhaustive.
Type of information usedThe information collected by CCG staff in the event of a safeguarding situation will be as much personal information as is necessary or possible to obtain in order to handle the situation.

Personal data: name, address, date of birth, NHS number

Special category data: ethnic origin, physical and mental health details.  
Who we will share the information with (recipients)Information may be shared with Safeguarding Boards, Multi-Agency Safeguarding Hubs (MASH), Multi-Agency Risk Assessment Conference (MARAC), Local Authority, other Health and Social Care organisations or the Police.  
Do we use any processorsThe Health Informatics Service (THIS), our IT supplier who store all our information securely on their servers.  
How we collect (the source) and use the informationWe may receive information relating to safeguarding concerns from you directly, relatives, or through notification of concerns from other Health and Social Care organisations.   All Health and Social Care professionals have a legal requirement to share information with appropriate organisations where safeguarding concerns about children or adults have been raised. Where it is appropriate to do so, the organisations will keep you informed of what information is required to be shared.   Access to this information is strictly controlled and where there is a need to share information, e.g. with police or social services, all information will be transferred safely and securely ensuring only those with a requirement to know of any concerns are appropriately informed.  
How long we will keep the informationInformation is kept in accordance with the Records Management Code of Practice for Health and Social Care 2016 – depending on the nature of the records held, some records will be kept for longer than the minimum retention periods within the Code of Practice.  
Your RightsWith regards to Safeguarding under the UK GDPR you have the right:
To be informed about the processing of your information (this notice)
Of access to the information held about you
To have the information corrected in the event that it is inaccurate
To restrict or stop processing
To object to it being processed or used
Not to be subject automated decision-taking or profiling
To be notified of data breaches  
What is itCommissioning
Data ControllerNHS Kirklees CCG
PurposeOrganisations that provide NHS-funded care must, by law, submit certain information to NHS Digital about services provided to you and the population we serve.   This information is known as commissioning datasets. The CCG obtains these datasets from NHS Digital. They include information about patients registered with our GP Practices. This enables us to plan, design, purchase and pay for the best possible care available for you and the whole of the population we cover.  
Lawful basisThe CCG’s legal basis for processing this personal data under the UK GDPR is Article 6(1) e official authority. For special category data the basis is Article 9(2) h management of health or social care systems and services. A section 251 approval from the Secretary of State, through the Confidentiality Advisory Group, enables the pseudonymised information to be sent to the CCG via NHS Digital for our Commissioning purposes.  
Type of information usedPersonal data (pseudonymised): age, postcode   Special category data (pseudonymised): physical and mental health details  
Who we will share the information with (recipients)We do not share the information provided to us by NHS Digital outside of the CCG, unless the information is in aggregate and small number suppressed format.  
Do we use any processorsYorkshire Data Services for Commissioning Regional Office (DSCRO)  hosted by North of England Commissioning Support (NECS) obtains the identifiable information from the Secondary Uses Service (SUS) at NHS Digital. The DSCRO also receives identifiable information directly from providers. They pseudonymise the information and pass it to the CCG.   The Health Informatics Service (THIS), our IT supplier who store all our information securely on their servers.  
How we collect (the source) and use the informationThe datasets we receive from NHS Digital have been linked and are in a format that does not directly identify you. Information such as your age, ethnicity and gender, as well as coded information about any clinic or Accident and Emergency attendances, hospital admissions and treatment will be included.   We also receive information from the GP Practices within our CCG that does not identify you.   We use these datasets for a number of purposes such as: Performance managing contractsReviewing the care delivered by providers to ensure service users are receiving quality and cost effective careTo prepare statistics on NHS performance to understand health needs and support service redesign, modernisation and improvementTo help us plan future services to ensure they continue to meet our local population needs  
How long we will keep the informationDatasets received via NHS Digital are retained for as long as the Data Sharing Agreement is in place.
Your RightsWith regards to Commissioning under the UK GDPR you have the right:
To be informed about the processing of your information (this notice)
Of access to the information held about you
To have the information corrected in the event that it is inaccurate
To restrict or stop processing
To object to it being processed or used
Not to be subject automated decision-taking or profiling
To be notified of data breaches  
What is itRisk Stratification
Data ControllerNHS Kirklees CCG
PurposeInformation from health and social care records, using the NHS Number provided via the Secondary Uses Service (SUS) at NHS Digital, is looked at to identify groups of patients who would benefit from some additional help from their GP or care team. This is known as ‘Risk Stratification’. Risk stratification involves applying computer based algorithms to secondary and primary care information to identify those patients who are most at risk from certain medical conditions and who will benefit from clinical care to help prevent or better treat their condition.   The aim is to prevent ill health and possible future hospital stays, rather than wait for you to become sick.   We are not allowed to access personal records of service users, so we receive de-identified information for Risk Stratification.   This de-identified information is provided to us by a service called Data Services for Commissioners Regional Office (DSRCO). They specialise in converting patient information, within a secure environment, into a format commissioners can legally use; anonymised patient level information. You can find more comprehensive information about this on the NHS Digital Website.   GPs are able to identify individual patients from the risk stratified data when it is necessary to discuss the outcome and consider preventative care, however the CCG can never identify an individual from the risk stratified data that we see.  
Lawful basisThe CCG’s legal basis for processing this personal data under the UK GDPR is Article 6(1) e exercise of official authority.   For special category data the basis is Article 9(2) h management of health or social care systems and services. A section 251 approval (CAG 7-04(a)/2013) from the Secretary of State, through the Confidentiality Advisory Group of the Health Research Authority, enables the pseudonymised information to be sent to the CCG via NHS Digital in order to help us plan the most appropriate health services for our population.  
Type of information usedOnly de-identified information (NHS number removed) is accessible to the CCG.
Only GP Practices have access to identifiable information (NHS Number) of their own patients in order to see who may benefit from additional help.  
Who we will share the information with (recipients)This information is not shared outside of the CCG
Do we use any processorsData Services for Commissioners Regional Office (DSCRO) hosted by North of England Commissioning Support (NECS)   The Health Informatics Service (THIS), our IT supplier who store all our information securely on their servers.  
How we collect (the source) and use the informationWe get this information from NHS Digital, who are able to share this with us under the Health and Social Care Act (2012). This allows NHS Digital to collect, analyse and share national data and statistical information. To access this information, we must submit an application and demonstrate that we meet the appropriate governance and security requirements.  
How long we will keep the informationDatasets received via NHS Digital are retained for as long as the Data Sharing Agreement is in place.
Your RightsWith regards to Risk Stratification under the UK GDPR you have the right:
To be informed about the processing of your information (this notice)
Of access to the information held about you
To have the information corrected in the event that it is inaccurate
To restrict or stop processing
To object to it being processed or used
Not to be subject automated decision-taking or profiling
To be notified of data breaches  
What is itInvoice validation
Data ControllerNHS Kirklees CCG
PurposeInvoice validation is an important process. It involves using your NHS number to check that we are the CCG responsible for paying for your treatment.   There are situations where your personal information is needed to ensure that the correct service provider is paid.   In these cases, service providers need to share your personal information, such as your NHS Number, with a Controlled Environment for Finance (CEfF). North of England Commissioning Support Unit (NECS) is an accredited CEfF, and this allows them to process patient identifiable information on our behalf, for the purposes of invoice validation. We will also use your NHS number to check whether your care has been paid for through specialist commissioning, which NHS England will pay for.   NHS England has published guidance on how invoices must be processed and Commissioners have a duty to detect, report and investigate any incidents of where a breach of confidentiality has been made.  
Lawful basisThe CCG’s legal basis for processing this personal data under the UK GDPR is Article 6(1) e exercise of official authority. For special category data the basis is Article 9(2) h management of health or social care systems and services. A section 251 approval (CAG 7-07(a)(c)/2013) from the Secretary of State, through the Confidentiality Advisory Group of the Health Research Authority, enables the CCG to process identifiable information for the purpose of invoice validation within a Controlled Environment for Finance.  
Type of information usedPersonal data: NHS number, Date of Birth, Postcode
Special category Data: Health information  
Who we will share the information with (recipients)This information is not shared outside of the CCG.
Do we use any processorsNorth of England Commissioning Support Unit who operate the Controlled Environment for Finance
NHS Shared Business Services – used by the Controlled Environment for Finance as a Data Processor  
How we collect (the source) and use the informationOrganisations that provide treatment submit their invoices to us for payment. Our CEfF receives additional information, including your NHS Number, or occasionally date of birth and postcode, from the organisation that provided your treatment.   NHS Digital sends information into the secure area, including the NHS number and details of the treatment received. The information is then validated ensuring that any discrepancies are investigated and resolved between the CEfF and the organisation that submitted the invoice. The invoices will be paid when the validation is completed.   The CCG does not receive any identifiable information for purposes of invoice validation; however we do receive aggregated reports to help us manage our finances.  
How long we will keep the informationInvoices are retained for 6 years after the end of the financial year to which they relate.
Your RightsWith regards to Invoice Validation under the UK GDPR you have the right:
To be informed about the processing of your information (this notice)
Of access to the information held about you
To have the information corrected in the event that it is inaccurate
To restrict or stop processing
To object to it being processed or used
Not to be subject automated decision-taking or profiling
To be notified of data breaches  
What is itNHS England Annual 360 Survey of CCG Stakeholders
Data ControllerNHS Kirklees CCG
PurposeThe Annual NHS England (NHSE) 360 stakeholder survey forms an important part of our annual assurance process, and allows us and NHSE to monitor relationships with our partners and inform future developments. We are required to provide contact information of our partners to NHSE (data controller) and the company responsible for carrying out the survey on their behalf (data processer).  The information supplied includes stakeholder: names, organisations, role, email address and contact phone number.   Prior to us sharing this with NHS England and the surveying company, stakeholders are informed in writing of their proposed participation and given the opportunity to opt-out.   The survey asks a series of questions about working relationships between us and our partners, either online or by phone.   The results of the survey are reported to us anonymously, and aggregated for national reporting purposes; however, due to the small numbers in some stakeholder groups it is possible that individuals may be identifiable.  
Lawful basisOur legal basis under GDPR is Article 6(1) e – exercise of official authority.  
Type of information usedPersonal: names, email address and contact phone number.  
Who we will share the information with (recipients)NHS England and the company carrying out the survey on behalf of NHS England.
Do we use any processorsThe Health Informatics Service (THIS), our IT supplier who store all our information securely on their servers.  
How we collect (the source) and use the informationThe CCG will only receive anonymised results of the survey, however due to the small numbers in some stakeholder groups it is possible that individual stakeholders may be identifiable.
How long we will keep the informationInformation is kept in accordance with the Records Management Code of Practice for Health and Social Care 2016
Your RightsWith regards to NHS England Annual 360 Survey of CCG Stakeholders under the UK GDPR you have the right:
To be informed about the processing of your information (this notice)
Of access to the information held about you
To have the information corrected in the event that it is inaccurate
To restrict or stop processing
To object to it being processed or used
Not to be subject automated decision-taking or profiling
To be notified of data breaches  
Individuals have the right to object to the processing of their information in this way under article 21.  If you do not wish the CCG to forward your details to NHS England and the surveying company for the purposes of the 360 stakeholder survey, please contact the CCG’s Data Protection Officer at: kirkccg.contactus@nhs.net  
What is itPersonal Health Budgets (PHB)
Data ControllerNHS Kirklees CCG
PurposeA Personal Health Budget is an amount of money to pay for your health and wellbeing needs agreed between you and your local NHS team. Personal Health Budgets help people with long term health conditions manage their care and support in a way that suits them. It helps them to have more choice and flexibility in the way their care and support needs are met.  
Lawful basisThe CCG’s lawful basis for processing personal data under GDPR is Article 6(1) e – Public Task. For special category data the basis is Article 9(2) h – Management of Healthcare Systems. Relevant legislation: National Health Service (Direct Payments) Regulations 2013  
Type of information usedPersonal data: name, age, contact details, NHS number
Special category data: ethnic origin, physical and mental health data.  
Who we will share the information with (recipients)Other health and care organisations involved in delivering or arranging the care required. The third party looking after your money where this has been arranged.  
Do we use any processorsThe Health Informatics Service (THIS), our IT supplier who store all our information securely on their servers.  
How we collect (the source) and use the informationNormally, the type of information that we process about you is information you have provided yourself, although we may seek further information in relation to your health and care needs.   We will obtain this additional information from records that may include Care Home records, Health Records (for example GP, Hospital, Mental Health, District Nursing) and Social Care Records.  
How long we will keep the informationWe will keep this information for 8 years.   Where requests have been rejected information will be retained for 2 years.  
Your RightsWith regards to Personal Health Budgets under the UK GDPR you have the right:
To be informed about the processing of your information (this notice)
Of access to the information held about you
To have the information corrected in the event that it is inaccurate
To restrict or stop processing
To object to it being processed or used
Not to be subject automated decision-taking or profiling
To be notified of data breaches  
What is itFreedom of Information Requests (FOI)
Data ControllerNHS Kirklees CCG
PurposeAs we are a public authority, we have a duty to respond to requests made under the Freedom of Information Act 2000 (FOIA), Environmental Information Regulations 2004 (EIR), and the Re-Use of Public Sector Information Regulations 2015 (RPSI). Our website gives you information about how to make an FOI request along with the process.  
Lawful basisThe CCG’s lawful basis for processing personal data under the UK GDPR is Article 6(1) c – Legal Obligation  Relevant legislation: FOIA, EIR and RPSI  
Type of information usedPersonal: name and either email or postal address only
Who we will share the information with (recipients)We will not share your information outside of the CCG.
Do we use any processorsThe Health Informatics Service (THIS), our IT supplier who store all our information securely on their servers.  
How we collect (the source) and use the informationWe will only collect identifiable information such as name and contact details which are provided by the individual making the FOI request.   We will only use this information to respond to requests and in correspondence with you following appeals.   The personal information we process is freely provided by you, should you wish to exercise your right to use the above legislation in order to access information held by or on behalf of the CCG.   Where the individual is making a request under the Re-Use of Public Sector Regulations 2015, by law we also require the name of the organisation and the re-use purpose.  
How long we will keep the informationFOI requests and associated responses will be kept for 3 years following the closure of the request except in cases where there has been a subsequent appeal. For those cases, information will be kept for 6 years following the closure of the appeal.  
Your RightsWith regards to Freedom of Information Requests under the UK GDPR you have the right:
To be informed about the processing of your information (this notice)
Of access to the information held about you
To have the information corrected in the event that it is inaccurate
To restrict or stop processing
Not to be subject automated decision-taking or profiling
To be notified of data breaches  
What is itAssuring Transformation (Learning Disability Data)
Data ControllerNHS Kirklees CCG
PurposeAssuring Transformation (AT) data collects information about people with learning disabilities and/or autism, who may have a mental health condition or behaviour that challenges, in in-patient settings, and provides it to us. This allows us to have a broad oversight of their care.  
Lawful basisThe CCG’s lawful basis for processing personal data under GDPR is Article 6(1) e – Public Task.   For special category data the basis is Article 9(2) h – Management of Healthcare Systems.   Relevant legislation: A section 251 approval (CAG 8-02(a-c)/2014) from the Secretary of State, through the Confidentiality Advisory Group, enables the flow of personal confidential information from organisations to commissioners, about the services that they provide for: people in in-patient beds with learning disabilities and/or autism of,any ageany level of security (general / low / medium / high)any status under the Mental Health Act (informal or detained)   However, the information cannot be shared if: the individual has objected to the use of their information as part of the AT datathe individual lacks capacity to make their own decision  
Type of information usedPersonal data: name, address, date of birth
Special category data: physical and mental health information.  
Who we will share the information with (recipients)Information will be received from healthcare providers and shared with NHS Digital and NHS England.
Do we use any processorsThe Health Informatics Service (THIS), our IT supplier who store all our information securely on their servers.  
How we collect (the source) and use the informationThe AT information is sent to the CCG from healthcare providers and collected by NHS Digital on NHS England’s behalf.   It covers all people with learning disabilities and/or autism that are being cared for in in-patient settings and includes: the number of people in in-patient settings; discharges and admissions; whether individuals have a care plan, a care co-ordinator, regular care reviews and access to independent advocacy; the age and gender of individuals; and the type of in-patient setting that is providing their care. The information collected is published in reports by NHS Digital. The reports don’t include any personal information, like names, birthdays or NHS numbers in them.  
How long we will keep the informationInformation relating to Assuring Transformation will be retained as per the standard care records retention set out in the Records Management Code of Practice for Health and Social Care 2016.  
Your RightsYou have the right to object to your information being used in the AT data collection. You can object to your information by contacting us:   Data Protection Officer
NHS Kirklees CCG
2nd Floor
Norwich Union House
Market Street
Huddersfield
HD1 2LF
email: kirkccg.contactus@nhs.net  
With regards to Assuring Transformation under the UK GDPR you have the right:
To be informed about the processing of your information (this notice)
Of access to the information held about you
To have the information corrected in the event that it is inaccurate
To restrict or stop processing
To object to it being processed or used
Not to be subject automated decision-taking or profiling
To be notified of data breaches
What is itGeneral Practice Extraction Service data for pandemic planning (GDPPR COVID 19)
Data ControllerNHS Kirklees CCG  
PurposeTo support the response to the COVID-19 outbreak, NHS Digital has been legally directed to collect and analyse healthcare information about patients from their GP record for the duration of the COVID-19 emergency period. NHS Digital will make this data available to us in a form in which we are unable to identify individuals as pseudonymised data.   We will use this pseudonymised data to provide intelligence to support our local response to the COVID-19 emergency. We look at this data so that health care provision can be planned to support the needs of our population, during the COVID-19 outbreak.   Typical uses of this data include, but not limited to: Understanding which patients are at riskUnderstanding where resources need to be allocatedAnalysis of missed appointments  
Lawful basisThe CCG’s legal basis for processing personal data under the UK GDPR is Article 6(1) c – Legal Obligation   For the processing of special category data, the legal basis is Article 9(2) h – Preventive or occupational medicine.   We are able to receive and process this data under a notice issued by the Secretary of State for Health and Social Care under Regulation 3(4) and 3(3) of the Control of Patient Information Regulations (COPI), dated 20th March 2020.   Under Section 26 of the Health and Social Care Act 2012, we have a duty to provide and manage health services for the population.
Type of information usedPersonal Data: Pseudonymised data   Special Category Data: Health information.  
Who we will share the information with (recipients)We will not share this data with anyone else.   Only aggregated reports with small number suppression can be shared externally.
Do we use any processorsNHS North of England Commissioning Support Unit Calderdale and Huddersfield NHS Foundation Trust
How we collect (the source) and use the informationNHS Digital will make this data available to us.  We will use the data to provide intelligence to support our local response to the COVID-19 emergency.  
How long we will keep the informationWe will retain this data until the COPI notice expires. The date the COPI notice is currently due to expire is 30/09/2021.  
Your RightsWith regards to this processing, under the UK GDPR you have the right:
Of access to the information held about you
To have the information corrected in the event that it is inaccurate
To restrict or stop processing
Not to be subject automated decision-taking or profiling
To be notified of data breaches

What is itJob Applicants
Data ControllerNHS Kirklees CCG
PurposeWe process information provided by applicants for the management of their application and the subsequent selection process.  
Lawful basisThe CCG’s lawful basis for processing personal data under the UK GDPR is Article 6(1) c – Legal Obligation   For special category data the basis is article 9(2) b – employment laws.   For criminal conviction information (obtained via the Disclosure and Barring Service (DBS)) processing meets the requirements of Article 10 of the GDPR under Schedule 1, Part 1 of the Data Protection Act 2018 – processing in connection with employment, health and research – Processing necessary for the purposes of performing or exercising obligations or rights of the controller or the data subject under employment law, social security law or the law relating to social protection.   Relevant legislation: the provisions of the Safeguarding Vulnerable Groups Act 2006 as a basis for carrying out DBS checks.  
Type of information usedAnonymous – for shortlisting and selection purposes   Personal data: name, address, date of birth following the short-listing process.   Special category data: race or ethnicity, health information  
Who we will share the information with (recipients)We share this information with the North of England Commissioning Support Unit as providers of the Human Resources service for the CCG, including the management of NHS Jobs on behalf of the CCG.  
Do we use any processorsNorth of England Commissioning Support Unit – management of NHS Jobs (recruitment website)   The Health Informatics Service (THIS), our IT supplier who store all our information securely on their servers.  
How we collect (the source) and use the informationThe recruitment process involves passing details provided by you on your application regarding your qualifications, skills and work experience, (but excluding your name, address and other personal information) to the short-listing and selection panels. After shortlisting, the names of those being interviewed will be provided to the interview panel. On occasion the interview panel may include colleagues external to the CCG, such as the Local Authority.   We also use information provided by you to make sure that we are fair to all applicants and to help fulfil our obligations to monitor equality and diversity within the organisation.  
How long we will keep the informationFor unsuccessful job applicants, information is retained for 1 year.   For successful applicants, job application information is retained for 3 years.  
Your RightsWith regards to Job Applications under the UK GDPR you have the right:
To be informed about the processing of your information (this notice)
Of access to the information held about you
To have the information corrected in the event that it is inaccurate
To restrict or stop processing
Not to be subject to automated decision-taking or profiling
To be notified of data breaches  
What is itWorkforce (Staff)
Data ControllerNHS Kirklees CCG
PurposeThe CCG holds personal and confidential information of its staff for employment-related purposes, such as recruitment, payment of salary, sickness and absence monitoring and professional development purposes.
Lawful basisThe CCG’s lawful basis for processing personal data under the UK GDPR is Article 6(1) c – Legal Obligation.
 
For special category data the basis is article 9(2) b – employment laws.
Type of information usedPersonal data: name, date of birth, address, postcode.  

Special category data: racial or ethnic origin, political beliefs and information concerning health.  

Information relating to criminal convictions (DBS checks).  
Who we will share the information with (recipients)The CCG shares information with a variety of organisations and individuals for a number of lawful purposes including:
Public disclosure under Freedom of Information – e.g. requested names or contact details of senior managers or those in public-facing roles;
Disclosure of job applicant details – e.g. to named referees for reference checks, to the Disclosure & Barring Service for criminal record checks
Disclosure to employment agencies – e.g. in respect of agency staff;
Disclosure to banks & insurance companies – e.g. to confirm employment details in respect of loan/mortgage applications/guarantees;
Disclosure to professional registration organisations – e.g. in respect of fitness to practice hearings;
Disclosure to Occupational Health professionals (subject to explicit consent);
Disclosure to police or fraud investigators – e.g. in respect of investigations into incidents, allegations or enquiries.
Disclosure to the CCG’s HR providers.
Do we use any processorsThe CCG uses a third-party provider to undertake its Human Resources, Learning and Development administrative support (North of England Commissioning Support Unit).
 
The CCG’s Human Resources advisory support is provided by Wakefield CCG.
 
The Health Informatics Service (THIS), our IT supplier who store all our information securely on their servers.
How we collect (the source) and use the informationThe types of information that the CCG processes include personal information contained within your HR record which you provided us when you started working for the CCG.
How long we will keep the information6 years after the staff member leaves or the 75th birthday, whichever is sooner.
Your RightsWith regards to your staff record, under the UK GDPR you have the right:
To be informed about the processing of your information (this notice)
Of access to the information held about you
To have the information corrected in the event that it is inaccurate
To restrict or stop processing
Not to be subject automated decision-taking or profiling
To be notified of data breaches
What is itOccupational Health
Data ControllerNHS Kirklees CCG
PurposeThe CCG holds personal and confidential information of its staff for administering sick leave and pay, managing absence, managing a safe working environment and ensuring fitness for work.  
Lawful basisThe CCG’s lawful basis for processing personal data under the UK GDPR is Article 6(1) b – contractual relationship. For special category data the basis is article 9(2) h – assessment of the working capacity of the employee.  
Type of information usedPersonal data: name, date of birth, address, postcode. Special category data: racial or ethnic origin, political beliefs and information concerning health.
Who we will share the information with (recipients)The CCG uses a third party provider to undertake its Occupational Health function. Therefore, your personal human resources information will be shared with South West Yorkshire Partnership NHS Foundation Trust.   In addition to the above sharing, information which is required to be disclosed by law will be disclosed to the relevant organisation, for example the Department for Work and Pensions in line with their statutory obligations relating to the working capacity of an employee.  
Do we use any processorsThe Health Informatics Service (THIS), our IT supplier who store all our information securely on their servers.  
How we collect (the source) and use the informationThe types of information that the CCG processes include personal information contained within your HR record which you provided us when you started working for the CCG.
How long we will keep the information6 years after the staff member leaves or the 75th birthday, whichever is sooner.
Your RightsWith regards to your occupational health record, under the UK GDPR you have the right:
To be informed about the processing of your information (this notice)
Of access to the information held about you
To have the information corrected in the event that it is inaccurate
To have your information deleted
To restrict or stop processing
To have your information transferred to someone else
Not to be subject to automated decision-taking or profiling
To be notified of data breaches  
What is itPayroll
Data ControllerNHS Kirklees CCG
PurposeThe CCG holds personal information of its staff in order to pay staff correctly.  
Lawful basisThe CCG’s lawful basis for processing personal data under the UK GDPR is Article 6(1) b – contractual relationship.  
Type of information usedPersonal data: name, date of birth, address, postcode, financial details (bank account details).  
Who we will share the information with (recipients)The CCG uses a third party provider to undertake its payroll function. Therefore, your personal human resources information will be shared with Leeds Teaching Hospitals NHS Trust.   The CCG will not share your personal information with any other organisation, unless there is a legal obligation placed upon the CCG to share with another organisation, for example HMRC for the purposes of tax.  
Do we use any processorsLeeds Teaching Hospitals NHS Trust   The Health Informatics Service (THIS), our IT supplier who store all our information securely on their servers.  
How we collect (the source) and use the informationThe types of information that the CCG processes includes personal information which you provided us when you started working for the CCG.
How long we will keep the information10 years.
Your RightsWith regards to payroll, under the UK GDPR you have the right:
To be informed about the processing of your information (this notice)
Of access to the information held about you
To have the information corrected in the event that it is inaccurate
To have your information deleted
To restrict or stop processing
To have your information transferred to someone else
Not to be subject to automated decision-taking or profiling
To be notified of data breaches  
What is itDeclarations of Interest
Data ControllerNHS Kirklees CCG
PurposeWe are required to maintain and publish a register of interests, gifts and hospitality of all our staff, as well as our Governing Body Members.  
Lawful basisThe CCG’s lawful basis for processing personal data under the UK GDPR is Article 6(1) e – Public Task.   Statutory guidance for CCGs on Managing Conflicts of Interest under Section 14O of the National Health Service Act 2006 (as amended by the Health and Social Care Act 2012)  
Type of information usedPersonal: name and job role
Who we will share the information with (recipients)Information may be shared with NHS England.  
Do we use any processorsOur IT supplier is The Health Informatics Service (THIS) and they host the declarations of interest portal, and our website.  
How we collect (the source) and use the informationThe information is collected directly from staff and Governing Body Members.
How long we will keep the informationThe CCG will keep a private record of historic interests and offers/receipt of gifts and hospitality for a minimum of 6 years after the date on which it expired.  
Your RightsIn exceptional circumstances, where the public disclosure of information could lead to a real risk of harm or is prohibited by law, a person’s name or other information may be withheld from the published registers. If you feel that substantial damage or distress may be caused to you or somebody else by the publication of information in the registers, you are entitled to request that the information is not published. Such requests must be made in writing:  
Conflict of Interest Guardian NHS Kirklees CCG
2nd Floor
Norwich Union House
Market Street
Huddersfield
HD1 2LF
email: kirkccg.contactus@nhs.net  
With regards to the Declaration of Interests, under the UK GDPR you have the right:
To be informed about the processing of your information (this notice)
Of access to the information held about you
To have the information corrected in the event that it is inaccurate
To restrict or stop processing
To object to it being processed or used
Not to be subject automated decision-taking or profiling
To be notified of data breaches  
What is itNational Fraud Initiative
Data ControllerNHS Kirklees CCG
PurposeWe have a duty to protect the public funds we administer. We may share information provided to us with other bodies responsible for; auditing, or administering public funds, or where undertaking a public function, in order to prevent and detect fraud under the National Fraud Initiative.   The Cabinet Office is responsible for carrying out data matching exercises.  
Lawful basisThe CCG’s lawful basis for processing personal data under the UK GDPR is Article 6(1) c – Legal Obligation.   Relevant legislation: Part 6 of the Local Audit and Accountability Act 2014 (LAAA).  
Type of information usedPersonal data: your name, the organisation you work for and your pay amounts

Who we will share the information with (recipients)The Cabinet Office and Counter Fraud Authority
Do we use any processorsThe Health Informatics Service (THIS), our IT supplier who store all our information securely on their servers.  
How we collect (the source) and use the informationWe participate in the Cabinet Office’s National Fraud Initiative: a data matching exercise to assist in the prevention and detection of fraud. We are required to provide particular sets of information to the Minister for the Cabinet Office for matching for each exercise, as detailed in the National Fraud Initiative’s privacy notice.   Data matching involves comparing computer records held by one body against other computer records held by the same or another body to see how far they match. This is usually personal information. Computerised data matching allows potentially fraudulent claims and payments to be identified. Where a match is found it may indicate that there is an inconsistency which requires further investigation. No assumption can be made as to whether there is fraud, error or other explanation until an investigation is carried out.   Data matching by the Cabinet Office is subject to a Code of Practice.  
How long we will keep the informationThe datasets used in the matching exercise by the Cabinet Office will be kept as per the National Fraud Initiative – Data Deletion Schedule
Your RightsWith regards to the National Fraud initiative, under the UK GDPR you have the right:
To be informed about the processing of your information (this notice)
Of access to the information held about you
To have the information corrected in the event that it is inaccurate
To restrict or stop processing
Not to be subject automated decision-taking or profiling
To be notified of data breaches  
What is itInternal/External Audits
Data ControllerNHS Kirklees CCG
PurposeAs a public body we are required to undertake regular audits by both internal and external auditors. These audits look at various aspects of our work and are there to ensure that our internal controls, processes, guidelines and policies are in compliance with governmental requirements.  
Lawful basisThe CCG’s lawful basis for processing personal data under the UK GDPR is Article 6(1) c – Legal Obligation.   Relevant legislation: Section 7 of the Local Audit and Accountability Act 2014.  
Type of information usedPersonal data: name, contact details, financial details of roles.
Who we will share the information with (recipients)KPMG our external auditors and Audit Yorkshire our internal auditors.
Do we use any processorsBoth KPMG and Audit Yorkshire process this information for us.   The Health Informatics Service (THIS), our IT supplier who store all our information securely on their servers.  
How we collect (the source) and use the informationWe collect this information from a number of organisations who support us in our work. This may include Payroll (Leeds Teaching Hospital), HR (North of England Commissioning Support Unit), and from information we already hold as part of our day to day work.  
How long we will keep the informationInformation is kept in accordance with the Records Management Code of Practice for Health and Social Care 2016
Your RightsWith regards to internal/external audits, under the UK GDPR you have the right:
To be informed about the processing of your information (this notice)
Of access to the information held about you
To have the information corrected in the event that it is inaccurate
To restrict or stop processing
Not to be subject automated decision-taking or profiling
To be notified of data breaches  

National Flu Immunisation Programme for Health and Social Care Workers

What is itNational Flu Immunisation Programme for Health and Social Care Workers
Data ControllerNHS Kirklees CCG  
PurposeAnnual vaccination against influenza (flu) is recommended for all health and social care workers to help reduce the risk of contracting the virus and transmitting it to patients, service users, colleagues and family members.    Vaccination also helps reduce sickness absences and contributes to keeping the NHS and care services running through winter pressures.    We will collect your personal details for the purpose of the administration of the flu vaccination for CCG staff. This includes understanding how many vaccinations will be required, booking you in to have a vaccination, and understanding the number of people who have had the vaccination within the organisation.   Where you have arranged to receive the flu vaccination independently, e.g. from a local pharmacy, we request you share this information with the HR Team in order to monitor uptake. If you claim the cost of the vaccination through the CCG expenses system then you will need to provide a receipt so that Payroll can process the expense.  
Lawful basisThe CCG’s legal basis for processing personal data under the UK GDPR is Article 6(1) f – Legitimate interest.   For the processing of special categories data, the legal basis is Article 9(2) h – Preventive or occupational medicine.  
Type of information usedPersonal data: Your name, work email address   Special category data: That you have booked/received a flu vaccination.   We will not ask, or collect from you any other personal information in relation to this purpose.    The flu vaccination provider will request a consent form be completed and signed at the time of your appointment. Consent for the vaccination will be given at the time of your appointment.  
Who we will share the information with (recipients)Non-identifiable aggregate data will be used by the CCG to monitor delivery of the programme and to support the provision of national returns on uptake of the programme.  
Do we use any processorsThe Human Resources Team – this service is provided by the North of England Commissioning Support Unit.   Flu Xpress Ltd – provider of flu vaccinations, including online booking system.  
How we collect (the source) and use the informationYou will be required to enter your name and work email address into online appointment booking system provided by Flu Xpress. The CCG’s HR team will act as administrators for the booking system to information support the management of your appointment.  The HR team will keep a record of when you received a flu vaccination and use the information to provide a statistical report on uptake of the vaccine for SMT and Governing Body.  
How long we will keep the informationYour information will be stored in line with the Records Management Code of Practice for Health and Social Care 2016.    HR will keep a record that you have had a flu vaccination during the period of this year’s Flu Immunisation Programme. After this time only non-identifiable aggregate data will be retained.   The details of your flu vaccination booking will be kept on the online appointment booking system for one month following your flu vaccination appointment and then automatically deleted.  
Your RightsWith regards to this process, under the UK GDPR you have the right:
To be informed about the processing of your information (this notice)
Of access to the information held about you
To have the information corrected in the event that it is inaccurate
To restrict or stop processing
To object to it being processed or used
To be notified of data breaches

Employee COVID-19 Individual Risk Assessment

What is itEmployee COVID-19 individual risk assessment
Data ControllerNHS Kirklees CCG  
PurposeCertain groups are more vulnerable to serious illness (and death) due to COVID-19. The evidence about these heightened risk factors is growing as more is understood about the virus.   It is important that all employees are supported appropriately in relation to potential risk relating to COVID-19.   
Lawful basisThe CCG’s legal basis for processing personal data under the UK GDPR is Article 6(1) e – Public Task.   For the processing of special categories data, the legal basis is Article 9(2) b – Employment.   Schedule 1 condition 1 of the Data Protection Act 2018, which applies due to the CCG’s health and safety obligations as an employer.  
Type of information usedPersonal data: name, age   Special category data: health information relating to your COVID-19 risk status.   We will not ask, or collect from you the details of a diagnosis or reasons of why you or a family member considers themselves to be in a vulnerable category. You may discuss specifics with your line manager but this information will not be stored.  
Who we will share the information with (recipients)This data will be shared with your line manager, limited members of the HR team and Occupational Health if an OH referral is required. Non-identifiable data will be shared with Senior Management Team as part of planning work.  
Do we use any processorsWorkforce Teams, North of England Commissioning Support (NECS)

 
How we collect (the source) and use the informationData will be collected from you by your line manager and recorded into a risk assessment tool. 
How long we will keep the informationMay be destroyed 6 years after the staff member leaves or the 75th birthday, whichever is sooner.   Your information will be stored in line with the Records Management Code of Practice for Health and Social Care 2016.  
Your RightsWith regards to this process, under the UK GDPR you have the right:
To be informed about the processing of your information (this notice)
Of access to the information held about you
To have the information corrected in the event that it is inaccurate
To restrict or stop processing
To object to it being processed or used
Not to be subject to automated decision-taking or profiling
To be notified of data breaches

How we use information provided by NHS Digital

We use information collected by NHS Digital from healthcare providers such as hospitals, community services and GPs, which includes information about the patients who have received care and treatment from the services that we fund.

The information we receive does not include patients’ names or home addresses, but it will usually include information such as your date of birth, ethnicity and gender as well as coded information about your visits to clinics, Emergency Department, hospital admissions and other NHS services.

The Secretary of State for Health has given limited permission for us (and other NHS commissioners) to use certain confidential patient information when it is necessary for our work and unless we have a legal basis to use identifiable information, de-identified information is used for all purposes other than direct care. This approval is given under Regulations made under Section 251 of the NHS Act 2006 and is based on the advice of the Health Research Authority’s Confidentiality and Advisory Group.

In order to use this information, we have to meet strict conditions that we are legally required to follow, which includes making a written commitment to NHS Digital that we will not use information in any way that would reveal your identity.

You can find more information about this in the sections on commissioning information, invoice validations and risk stratification.

Retaining your information

Personal information is held for a specific length of time by the CCG depending on the type of personal information it is. The length of time is defined by the NHS retention schedule which can be viewed online here: NHS Digital Records Management Code of Practice for Health and Social Care 2016

Your Rights in relation to the processing of your personal information

Your right to be informed if your personal information is being usedYou have the right to be informed about the collection and use of your personal information. Our privacy notice is the main way the CCG provides you with this information. In some cases, we will provide you with more specific information at the time we collect personal information from you, such as when you apply for Continuing Healthcare or make a complaint to us.   For more information on this right please see the ICO’s website  
Your right to get copies of your informationYou have the right to request access to any of your information that the CCG may process, so you can verify this is being processed lawfully. This is commonly known as a ‘Subject Access Request’ (SAR).   You can apply to see the information we hold about you personally, or someone else you have authorised can make an application on your behalf. A child’s parent or guardian, a patient representative, or a person appointed by the Court may also apply.   If you wish to ask us for confirmation of whether we process information about you or access your personal information, then please contact our Data Protection Officer :   Data Protection Officer
NHS Kirklees CCG
2nd Floor
Norwich Union House
Market Street
Huddersfield
HD1 2LF
email: kirkccg.contactus@nhs.net
Telephone: 01484 464000  
There are some exemptions, which mean you may not always receive all the information we process.  
Your right to get your information correctedIf we hold any personal information about you that is inaccurate or incomplete, you are entitled to have this information corrected. If we have shared this information with anyone else, we will also contact those we shared your information with and inform them of the rectification. If contacting the recipients of the information is impossible, or involves a disproportionate effort – we will give you a full explanation why this is the case.  
Your right to have your information deletedYou are entitled to have your personal information erased in order to prevent further processing of your information. This right applies in certain circumstances only.   These circumstances are:   1.   Where the personal information is no longer necessary in relation to the purpose for which it was originally collected/processed.   2.    If you withdraw your consent for us to process your information (if this was the basis on which it was collected).   3.    The personal information was unlawfully processed (i.e. a breach of UK data protection laws).   4.   The personal information has to be erased in order to comply with a legal obligation.   However, this right doesn’t apply if we are processing your information to comply with a legal obligation or to exercise our official authority as a CCG.  
Your right to limit how organisations use your informationYou have the right to stop further processing of your personal information. We may still retain just enough information about you to ensure that the restriction is respected in future.   You can request that further processing of your information be limited in the following circumstances:   1.    If you contest the accuracy of the information, we hold about you we will restrict the processing until the accuracy of the information has been verified;   2.    If we are processing your information as it is necessary for the performance of a public interest task and you have objected to the processing, we will restrict processing while we consider whether our legitimate grounds for processing are overriding;   3.    If the processing of your personal information is found to be unlawful but you oppose erasure and request restriction instead; or   4.    If we no longer need the information we hold about you, but you require the information to establish, exercise or defend a legal claim.   If we have shared this information with anyone else, we will also contact those we shared your information with and inform them of the restriction.   If contacting the recipients of the information is impossible, or involved a disproportionate effort – we will give you a full explanation why this is the case.   We will inform you if we decide to lift a restriction on processing.  
Your right to information portabilityYou have the right to get your personal information from an organisation in a way that is accessible and in electronic form.   You also have the right to transfer your information from one organisation to another, if it is ‘technically feasible’.  
Your right to object to the use of your informationYou have the right to object to an organisation processing your personal information, if processing your information for the following reasons:   • for a task carried out in the public interest
• for its legitimate interests
• for scientific or historical research, or statistical purposes, or
• for direct marketing.   If you raise an objection, we will no longer process your personal information, unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms. We may also continue processing your information, despite your objection, if the processing is for the establishment, exercise or defence of legal claims.  
Your right to object to automated decision makingAs the CCG does not make any decisions based solely on automated processing, individuals’ rights in relation to personal information processed in this way are not applicable.  
Your right to withdraw consentIf an organisation is processing your information on the basis that you have given your consent for them to do so, you have the right to withdraw this consent at any time. It should be as easy to withdraw consent as it is to give it. If you withdraw your consent, we will stop the processing as soon as possible. In order to do this please contact:   Data Protection Officer
NHS Kirklees CCG
2nd Floor
Norwich Union House
Market Street
Huddersfield
HD1 2LF
email: kirkccg.contactus@nhs.net
Telephone: 01484 464000    
For more information about your data protection rights, please visit the ‘Your Data Matters’ page on the ICO’s website.   If you have any questions about your rights, or would like to exercise any of your rights, please contact:   Data Protection Officer
NHS Kirklees CCG
2nd Floor Norwich Union House Market Street Huddersfield HD1 2LF
email: kirkccg.contactus@nhs.net Telephone: 01484 464000    


Glossary

AnonymisedInformation which is about you but from which you cannot be personally identified.
AggregatedGrouped information about individuals that has been combined to show general trends or values without identifying individuals
Caldicott GuardianA senior person responsible for protecting the confidentiality of patient and service-user information and enabling appropriate information sharing. Each NHS and Social Care organisation is required to have a Caldicott Guardian.
ConsentThe consent of the ‘data subject’ means any freely given, specific, informed and unambiguous indication of his or her wishes by which the data subject, either by a statement or by a clear affirmative action, signifies agreement to personal data relating to them being processed.
Data ControllerData Controller means the natural or legal person, public authority, agency or any other body which alone or jointly with others determines the purposes and means of the processing of personal data.
Data ProcessorProcessor means a natural or legal person, public authority, agency or any other body which processes personal data on behalf of the controller.
Data Protection OfficerThe Data Protection Officer (DPO) is responsible for the provision of advice on data protection compliance obligations, data protection impact assessment and monitoring of data protection compliance which includes conducting assurance audits.
Data SubjectAn identified or identifiable ‘living individual’ whose personal data is processed by a controller or processor. Otherwise known within data protection legislation as a ‘natural person’.
EncryptionThe process of transforming information (referred to as plain text) using an algorithm (called ‘cipher’) to make it unreadable to anyone except those possessing special knowledge, usually referred to as a ‘key’.
Health RecordInformation relating to the physical or mental health or condition of an individual, and has been made by or on behalf of a health professional in connection with the care of that individual.
Identifiableinformation which contains personal details that identify individuals such as name, address, email address, NHS Number, full postcode, date of birth.
Personal DataPersonal data means any information relating to an identified or identifiable natural person (“data subject”); an identifiable person is one who can be identified, directly or indirectly, in particular by reference to an identifier, including (but not limited to);
• Name
• Date of Birth
• Post Code
• Address
• National Insurance Number
• Photographs, digital images etc.
• NHS or Hospital/Practice Number
• Location data
Personal data that has been pseudonymised e.g. key coded, can fall within the scope of data protection legislation depending on how difficult it is to attribute the pseudonym to a particular individual.
ProcessingProcessing means any operation or set of operations performed upon personal data or sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
Pseudonymisedindividual level information where individuals can be distinguished by using a coded reference, which does not reveal their ‘real world’ identity
RecordInformation created, received and maintained as evidence and information by an organisation or person, in pursuance of legal obligations or in the transaction of business (the ISO standard, ISO 15489-1:2016 Information and documentation – records management).
Records ManagementThe process by which an organisation manages all the aspects of records whether internally or externally generated and in any format or media type, from their creation, all the way through their lifecycle to their eventual disposal.
Senior Information Risk Owner (SIRO)The SIRO is a senior officer of the CCG. The SIRO acts as an advocate for information risk across the CCG and leads and implements the information risk assessment programme.
Special Category DataSpecial Category Data (or sensitive personal data) are personal data, revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership; data concerning health or sex life and sexual orientation; genetic data or biometric data.
Subject Access RightEntitles the data subject to have access to and information about the personal data that a controller has concerning them.  Also known as the Right of Access.