How we are protecting privacy and confidentiality
NHS England takes its responsibility to handle health and care data lawfully, proportionately, ethically and in confidence very seriously.
This is why privacy by design is at the heart of the NHS Federated Data Platform (FDP).
Protecting personal data is a core principle that guides how we design and operate technology solutions.
We protect patient data in the following ways:
Strict access controls
Only people who need to access patient data as part of their role in, or working on behalf of, the NHS will be able to do so.
Clear controls are in place to define who can access data, what they can see, and what they are permitted to do.
Access is limited to the minimum data necessary for an individual to carry out their role and is approved on a case-by-case basis by the relevant data controller.
The use of personal data is governed by the Data Protection Act 2018 and the UK General Data Protection Regulation (UK GDPR).
Organisations are required to comply with these laws, and the Information Commissioner’s Office (ICO) can take enforcement action where they do not.
Read more information on possible penalties.
NHS privacy enhancing technology
NHS privacy enhancing technology (NHS-PET) provides a standard approach to enabling safe data access and use within the FDP. This includes data treatment and data protection measures.
NHS-PET can transform data into an appropriate format for use, including techniques such as pseudonymisation or de-identification.
This helps reduce the risk of individuals being identified while still enabling analysis for health and care purposes.
NHS-PET is currently used by NHS England and integrated care boards (ICBs) to support the processing of data.
ICBs use this capability to carry out their statutory functions, such as population health management, and must ensure they have an appropriate legal basis for any processing they undertake.
Data will continue to be kept secure in line with established best practice.
Additional functionality will be introduced through a phased approach as the platform develops.
Any changes to how data is processed will require updates to the relevant privacy notice and Data Protection Impact Assessment (DPIA).
These must be reviewed and approved prior to implementation, in line with the NHS Federated Data Platform Information Governance Framework.
Lawful use of data
All uses of data within the FDP must be ethical, for the public good, and compliant with applicable laws.
This includes data protection laws such as the UK General Data Protection Regulation (UK GDPR) and the common law duty of confidentiality.
In line with UK GDPR, we apply the data minimisation principle, meaning that only the minimum amount of data necessary is processed for a specific purpose.
Respecting patient choice
The use of patient data within the NHS Federated Data Platform (FDP) respects national opt-out policies.
National data opt-outs and type 1 opt-outs are applied in line with these policies where they are relevant to the data being processed.
Where opt-outs apply, they are implemented at the appropriate point in the data flow, including before data enters the platform where relevant.
The approach to applying opt-outs is set out in the relevant product DPIA.
Product-specific privacy notices provide further detail on how opt-outs are applied for each use.
You can read more about all these elements in the sections below:
How we're protecting patient data
Patient data within the FDP is used to support direct care, service planning and analysis.
Bringing data together in one place helps ensure that relevant information is available to clinicians delivering care and staff planning services.
Data may also be used for purposes such as analysing activity, auditing quality, and planning service delivery to help improve patient outcomes.
For example:
- At North Cumbria Integrated Care NHS Foundation Trust, the platform has been used to improve planning for elective surgery. By bringing together relevant information, it has reduced the time spent on theatre planning and increased surgical capacity.
- National tools use historic A&E admissions data alongside factors such as seasonality, weather and public holidays to provide forecasts of expected demand. This helps trusts plan for busy periods and ensure appropriate resources, including for specific patient groups such as paediatric care.
- At Chelsea and Westminster NHS Foundation Trust, software has been used within gynaecology services to track patients with suspected cancer through diagnosis and treatment. This has helped reduce waiting times and improve the experience for patients.
Information about how privacy and confidentiality will be protected is published on our website.
Information about opt-outs and the FDP is published on our website.
Learn more about how healthcare professionals use and share patient data.
Further information about how NHS England and other organisations may use data in the FDP and NHS-PET can be found in the NHS Federated Data Platform overarching privacy notice .
Access to data within the FDP must deliver a clear benefit to patients and/or the NHS in England.
Access to NHS health and social care data is carefully controlled, and only authorised users are granted access for approved purposes.
Where appropriate data sharing agreements are in place, local NHS organisations – such as NHS trusts and ICBs, on behalf of integrated care systems (ICSs) – may be able to access and use data across organisational boundaries to support care and operational delivery.
For example, an ICS co-ordinating the discharge of patients from hospital to community or care settings may need to access data across multiple organisations.
Local instances of the platform may also interact with a national instance where appropriate.
This can support a system-wide view of operational pressures, such as understanding how many patients are in hospital, waiting times for treatment, and where pressures exist across the NHS.
The information made available in any national view is limited to what is necessary for these purposes and is handled in line with applicable legal, privacy and security requirements.
There will always be a valid lawful basis for the collection and processing of personal data (including special category data) within the FDP, as required under data protection legislation.
For example, personal data may be processed where a clinician is providing direct care to a patient.
The use of data must also comply with other relevant legal frameworks, including:
- Common Law Duty of Confidentiality
- Human Rights Act 1998
- Privacy and Electronics Communications Act 2003
- Health and Care Act 2022
- The Security of Network and Information Regulation 2018
- The Re-use of Public Sector Information Regulations 2015
Each NHS organisation acts as the data controller for its own use of the platform.
Data remains under the control of the NHS at all times.
The FDP supplier operates only under the instructions of NHS organisations when processing data and is not permitted to access, use or share data for its own purposes.
Data made available within the platform is handled in ways that protect patient confidentiality. This includes applying measures such as data minimisation and de-identification.
De-identification involves reducing the likelihood that individuals can be identified from the data.
This may include techniques such as aggregation, anonymisation and pseudonymisation, depending on the purpose and level of access required.
Where appropriate, this data treatment is supported by NHS-PET. The approach taken is consistent with Information Commissioner’s Office (ICO) guidance.
Where confidential patient information is used, the requirements of the common law duty of confidentiality must also be satisfied.
Robust data governance processes are in place to support the lawful and appropriate use of data.
These include the completion of a DPIA, the establishment of data sharing agreements where required, and the publication of privacy notices.
These must be completed and approved before any data is shared or processed within the platform.
NHS organisations hold different types of data. This includes:
- Operational and analytical data – such as information about hospital capacity (for example, bed availability), aggregate data (such as total numbers of patients), and de-identified individual-level data, where information about a person has been treated so they cannot be directly identified. This data is often held across multiple clinical and operational systems.
- Confidential patient information – data that identifies a patient, including details about their health, care or treatment. Some of this is known as special category data and requires additional protections.
The FDP allows NHS organisations to access and use these types of data, where this is lawful and appropriate, and to bring them together to support analysis and decision-making.
Only the minimum data necessary is made available within the platform.
Where personal data is required for direct care – for example, to support diagnosis, schedule treatment or manage discharge – it may be used in identifiable form.
Access is limited so that each user can only see the information they need to carry out a specific task relating to a patient’s care.
For direct care purposes, the data controller is the NHS organisation responsible for the patient’s care (for example, an NHS trust).
Data used for this purpose is held within that organisation’s local instance of the platform and is not used for other purposes without an appropriate legal basis.
Where data is used for purposes other than direct care, such as planning and improving health and care services, steps are taken to reduce how identifiable it is.
This may include the use of de-identification techniques, such as removing or reducing personal identifiers (for example, name or date of birth).
Depending on the use, data may be aggregated, anonymised or pseudonymised to help protect patient confidentiality.
Even where data has been de-identified, it may still be considered personal data and must be handled in line with data protection law, including having an appropriate legal basis for its use.
In some cases, NHS organisations may need to link data to better understand the factors influencing health outcomes across different population groups.
For example, local Population Health Management teams link data to understand current health and care needs and to identify trends in their population. Health outcomes are often influenced by a combination of clinical, social, environmental and economic factors, which can only be understood by bringing data together.
By linking data in this way, local health and care services can design and deliver more proactive and targeted models of care.
In these cases, the data controller is typically the relevant ICB, acting on behalf of the ICS, to plan and commission services that meet the needs of their population.
The use of data for these purposes is subject to national opt-out policies.
National data opt-outs and type 1 opt-outs are applied where they are relevant to the data being processed, in line with policy requirements.
The approach to applying opt-outs is set out in the relevant product DPIA and implemented at the appropriate point in the data flow.
Product-specific privacy notices provide further detail on how opt-outs are applied for each use.
Type 1 opt-outs do not currently apply to products used in the FDP.
If this changes in the future – because a new product processes confidential patient information in a way which would mean that the type 1 opt-out would apply – the relevant user organisation would be responsible for ensuring that the type 1 opt-out was applied, and the NHS FDP Privacy Notice would be updated to make this clear.
Find out more about type 1 opt-outs.
The NHS national data opt-out allows patients to choose whether their confidential patient information is used for purposes beyond their individual care, such as planning.
The FDP is used to support direct care and the planning and improvement of health and care services. It is not designed to support research use.
Where data is used for planning purposes, national data opt-outs and type 1 opt-outs are applied where they are relevant to the data being processed, in line with national policy.
The approach to applying opt-outs is set out in the relevant product DPIA and implemented at the appropriate point in the data flow.
Product-specific privacy notices provide further detail on how opt-outs are applied for each use.
There is no separate opt-out specifically for data being included in the FDP.
The platform brings together data that is already held by NHS organisations and is used for the same purposes for which it was originally collected, such as direct care and service planning.
At present, the FDP is not used to process identifiable patient data for purposes other than direct care.
Where data is used for planning and improving services, steps are taken to reduce how identifiable it is; for example, through de-identification techniques.
Where data is effectively anonymised, the national data opt-out would not apply.
Any future uses of the FDP beyond those currently in place would be subject to appropriate engagement with patients, the public and stakeholders, as well as clear governance and assurance processes.
All uses of data must have a valid legal basis and be supported by appropriate governance, including a DPIA, in line with UK GDPR and common law duty of confidentiality.
If, in the future, the FDP is used for purposes where the national data opt-out applies, it will be respected.
This means that the records of patients who have registered a national data opt-out will not be used for those purposes.
Where data is currently used for purposes beyond an individual’s direct care – such as planning NHS services – de-identified data is typically used.
Where identifiable data is required, it must be supported by an appropriate legal basis, and patients may be able to opt out of its use in certain circumstances by registering a national data opt out.
Anonymisation
Anonymisation involves the application of 1 or more anonymisation techniques (for example, character shuffling, encryption, character substitution to symbols, etc) to personal data.
When done effectively, the anonymised information cannot be used by the user or recipient to identify an individual either directly or indirectly, taking into account all the means reasonably likely to be used by them.
This is otherwise known as a state of being rendered anonymous in the hands of the user or recipient.
Pseudonymisation
Has the meaning given in UK GDPR being the processing of personal data in such a manner that the personal data can no longer be attributed to a specific individual without the use of additional information – provided that such additional information is kept separately and is subject to technical and organisational measures to ensure that the personal data are not attributed to an identified or identifiable natural person.