Purposes for processing
The Secretary of State for Health (SofS) is accountable to Parliament for the health system, including the business of NHS England. The Department of Health and Social Care (DHSC) supports the SofS in his role which includes accounting to Parliament for NHS England’s performance and the effectiveness of the health and care system overall.
NHS England is an arm’s length body of DHSC and shares responsibility for accounting to the public and to Parliament for policies, decisions and activities across the health and care sector. Accountability to Parliament will often be demonstrated through responses to parliamentary questions, MPs’ letters, and appearances before parliamentary committees.
Categories of personal data
The data collected by NHS England is stored in the Parliamentary Business Team’s central files. This will include a record for the individual with an associate file relating to their contact. Files may hold items such as individual’s name, contact information and any other information relating to their communication. There may also be instances where individuals contact specific teams within NHS England. As such, information provided at this point will be collected (i.e. name and contact information).
Sources of the data
NHS England will collect information when members of the public, parliament or DHSC contact the organisation in relation to an MP request or Parliamentary Question. In doing so, NHS England collect relevant information at the point of contact to enable the team to provide a response to the request.
MP requests are often received by the NHS England Chief Executive Office and The National Medical Director’s Office. They are then passed to the Parliamentary Business Team.
Categories of recipients
The information including information about the member of the public and MP is used by:
- Parliamentary Business Team
- NHS England Chief Executive Officer
- NHS England National Medical Director’s Office
- Any other team within NHSE that may directly receive such requests
The request information not including personal data about the applicant is used by:
- NHS England teams that hold any information relevant to the request.
- Capita under contract with NHS England in the handling of any relevant information that they hold on behalf of NHS England.
- Commissioning Support Units (CSUs) under contract with NHS England in the handling of any relevant information that they hold on behalf of NHS England.
Legal basis for processing
For GDPR purposes NHS England’s lawful basis for processing is Article 6(1)(e) ‘…exercise of official authority…’. For the processing of special categories data, the basis is Article 9(2)(h) ‘…health or social care…’.