Sharing Personal Data ‘What you need to know’ Corporate Information Governance Team Strategic Intelligence.

Slides:



Advertisements
Similar presentations
NATIONAL INFORMATION GOVERNANCE BOARD
Advertisements

Children Index Information sharing course
The Data Protection (Jersey) Law 2005.
Getting data sharing right for every child
Legislation & ICT By Savannah Inkster. By Savannah Computer Laws 1.Data Protection ActData Protection Act 2.Computer Misuse ActComputer Misuse Act 3.Copyright,
Donna Monk MAPPA Co-ordinator.  Understand the purpose and function of MAPPA  Understand the language and terminology of MAPPA  Explore the framework.
National Smartcard Project Work Package 8 – Information Law Report.
Data Protection Act Description The Data Protection Act controls how your personal information can be used and protects from the misuse of your.
Confidentiality… important facts to know and critical things to do!
DATA PROTECTION AND PATIENT CONFIDENTIALITY IN RESEARCH Nic Drew Data Protection Manager University Hospital of Wales   
Data Protection Paul Veysey & Bethan Walsh. Introduction Data Protection is about protecting people by responsibly managing their data in ways they expect.
Data Protection Overview
CENTRAL SCOTLAND POLICE Data Protection & Information Security Stuart Macfarlane Information Governance Unit Police Service of Scotland.
The Information Commissioner’s Office David Evans.
Regulation of Personal Information Daniel Pettitt, Leon Sewell and Matthew Pallot.
HSC Diploma and Apprenticeships Principles of communication in adult social care settings 301.
Health & Social Care Apprenticeships & Diploma
Amicus Legal Consultants THE DEPLOYMENT OF SPECIAL INVESTIGATIVE MEANS IN PROACTIVE ANTI-CORRUPTION INVESTIGATIONS.
Elma Graham. To understand what data protection is To reflect on how data protection affects you To consider how you would safeguard the data of others.
The Data Protection Act 1998 The Eight Principles.
OCR Nationals Level 3 Unit 3.  To understand how the Data Protection Act 1998 relates to the data you will be collecting, storing and processing  To.
Data Protection: An enabler? David Freeland, Senior Policy Officer 23 October 2014.
Information sharing: the legal framework Dr Caroline Ball Chair, Norfolk Safeguarding Children Board.
Data Protection Act AS Module Heathcote Ch. 12.
DATA PROTECTION & FREEDOM OF INFORMATION. What is the difference between Data Protection & Freedom of Information? The Data Protection Act allows you.
Data Protection Act & Freedom of Information Simon Mansell Corporate Governance and Information Team.
Data Protection Act ‘ What you need to know’ Corporate Information Governance Team Strategic Intelligence.
Data Protection Corporate training Data Protection Act 1998 Replaces DPA 1994 EC directive 94/46/EC The Information Commissioner The courts.
Processing personal health data: the regulator’s perspective Ken Macdonald Assistant Commissioner Information Commissioner’s Office.
DATA PROTECTION ACT 1998 Became law on 1 March 2000 Only applies to the use of personal data, that is data which relates to an identifiable living individual,
The Data Protection Act What Data is Held on Individuals? By institutions: –Criminal information, –Educational information; –Medical Information;
PROTECTING CLIENT DATA HIPAA, HITECH AND PIPA PART 1B.
BTEC ICT Legal Issues Data Protection Act (1998) Computer Misuse Act (1990) Freedom of Information Act (2000)
Legal issues The Data Protection Act Legal issues What the Act covers The misuse of personal data By organizations and businesses.
The Data Protection Act What the Act covers The misuse of personal data by organisations and businesses.
12/12/2015 Data Protection Act /12/2015 The DP Act A law that protects personal privacy and upholds individual’s rights Anyone who handles personal.
Introduction Data protection is relevant to every individual, business or organisation today, not just Local Government. As well as protecting privacy,
Data Protection - Rights & Responsibilities Information Commissioner’s Office Orkney Practice Forum 4 th July 2007.
1 Data Protection & Confidentiality Young Carers Workers Conference, Harrogate, 25 March 2009 Paul Ticher
Information Systems Unit 3.
An Introduction to the Privacy Act Privacy Act 1993 Promotes and protects individual privacy Is concerned with the privacy of information about people.
Human Rights Act, Privacy in the context of auditing Phil Huggins Chief Technologist, IRM PLC
Computer Laws Data Protection Act 1998 Computer Misuse Act 1990.
INFORMATION GOVERNANCE AND CONFIDENTIALITY Information Governance Facilitator.
Data Protection and research Rachael Maguire Records Manager.
DATA PROTECTION ACT (DPA). WHAT IS THE DATA PROTECTION ACT?  The Data Protection Act The Data Protection Act (DPA) gives individuals the right.
DATA PROTECTION ACT INTRODUCTION The Data Protection Act 1998 came into force on the 1 st March It is more far reaching than its predecessor,
Disclosure & record keeping February
GCSE ICT Data and you: The Data Protection Act. Loyalty cards Many companies use loyalty cards to encourage consumers to use their shops and services.
Session 11 Data protection. 1 Contents Part 1: Introduction Part 2: Applicability and responsibility Part 3: Our procedures on data protection Part 4:
DATA PROTECTION AND RUNNING A COMPLIANT PUB WATCH SCHEME Nigel Connor Head of Legal –JD Wetherspoon PLC.
© University of Reading Lee Shailer 06 June 2016 Data Protection the basics.
Can you share? Yes you can!! Angus Council Adult Protection Maureen H Falconer, Senior Policy Officer Information Commissioner’s Office.
Getting data sharing right for every child Maureen H Falconer Senior Policy Officer Information Commissioner’s Office.
Angela McKinnon Child health lead Aberdeenshire CHP NHS Grampian Jan 2015.
Workshop Understanding your responsibilities under the Data Protection Act 1998 and the Freedom of Information Act 2000 Adele Rhodes Girling.
Freedom of Information Act ‘What you need to know’ Corporate Information Governance Team Strategic Intelligence.
Clark Holt Limited (Co. No ), Hardwick House, Prospect Place, Swindon, SN1 3LJ Authorised and regulated by the Solicitors Regulation.
Introduction to Data Protection Plan »Brief Introduction to Data Protection  Example  Principles  P3, 4, 7  Sensitive Data  Conditions for Processing.
Data Protection Laws in the European Union John Armstrong CMS Cameron McKenna.
The Data Protection Act 1998
Data Protection and Confidentiality
The Data Protection Act 1998
Data Protection Legislation
GENERAL DATA PROTECTION REGULATION (GDPR)
New Data Protection Legislation
G.D.P.R General Data Protection Regulations
Data Protection and Running a Compliant Pub Watch SCHeme
Data Protection principles
D3 Confidentiality.
Presentation transcript:

Sharing Personal Data ‘What you need to know’ Corporate Information Governance Team Strategic Intelligence

Sharing personal data Sharing must comply with the law These laws must be complied with when sharing personal data: 1. Human Rights Act Data Protection Act Common law duty of confidence The following slides provide information on how to comply with the law. Failure to comply could result in someone suffering damage or distress as a result. Deliberate breaches could also amount to a criminal offence or a disciplinary offence

Sharing personal data Human Rights Act – right to a private life Article 8 of the European Convention of Human Rights, gives people the right to a private life, family life, home and correspondence. Public authorities are not allowed to interfere with people’s privacy, for example disclose their personal data, unless the disclosure is lawful and necessary and is for: public safety or the economic wellbeing of the country prevention of disorder or crime protection of health or morals the rights and freedoms of others national security Disclosures must be proportionate. The public interest in making the disclosure must outweigh the person’s right to a private life. In practice, if the person disclosing the information complies with the Data Protection Act, disclosure is unlikely to breach the Human Rights Act.

Sharing personal data Data Protection Act - the principles The Data Protection Act is the main law that governs how organisations process i.e. obtain, use, record and disclose personal data, about living people and sets out 8 principles which must be complied with. These are summarised as: Personal data must be: 1. Processed fairly & lawfully 2. Processed for specified & lawful purposes 3. Adequate, relevant & not excessive 4. Accurate & where necessary kept up to date 5. Not kept for longer than is necessary 6. Processed in accordance with the rights of data subject 7. Kept secure 8. Transferred only to countries with adequate security

Sharing personal data Data Protection Act – sharing must be fair The first data protection principle is very important. It requires personal data to be shared fairly. In order to be ‘fair’, the subject of the data must be told that their information will be shared, with whom and why, and it must be communicated to the person in a way in which they can understand. This is sometimes known as providing a ‘privacy notice’ or a ‘fair processing statement’ and is often stated on forms when personal data is collected. However, this may not always be the case and therefore it is best practice to tell the person that their data is being shared (or it can be in writing). A person does not have to be told their information will be shared, if by doing this it would prejudice the prevention or detection of a crime or put someone at increased risk of harm.

Sharing personal data Data Protection Act – sharing must be lawful The first data protection principle also requires that any sharing is lawful. The Data Protection Act provides several powers which allows personal data to be shared. For example, it can be shared if one or more of the following applies: the person has given their consent there is a specific legal obligation to share disclosure is necessary to protect someone’s life or from serious harm disclosure is necessary in the public interest and is necessary for our organisation or another organisation to undertake its official duties disclosure is for a legitimate and lawful purpose and does not cause unwarranted prejudice to the person disclosure is in the substantial public interest disclosure will assist in the prevention or detection of an unlawful act Disclosures must be relevant, not excessive and proportionate.

Sharing personal data Data Protection Act – sharing with consent If it is appropriate to obtain consent, then the person giving it must be fully informed, understand why their information may be shared, who will see it and what might happen as a result. Consent must also be freely given and not obtained through coercion. Where possible consent should be in writing. Competent Where a child is under 12 yrs, consent should be obtained from the parent or carer. Where a child is over 12 but under 16yrs, you need to assess whether they are competent to consent for themselves and if so, obtain their consent. Individuals aged 16yrs and over are presumed, in law, to have the capacity to give or withhold consent to the sharing of their personal data, unless there is evidence to the contrary. If a person is considered not to have capacity to make decisions (whether child or adult), their views should still be sought as far as possible.

Sharing personal data Data Protection Act – sharing without consent It is not always necessary or appropriate to obtain consent in some circumstances, for example if: someone has been hurt and information needs to be shared quickly to help them; obtaining consent would put someone at increased risk of harm; obtaining consent would prejudice a criminal investigation or prevent a person being caught or questioned for a crime they may have committed the information must be disclosed regardless of whether consent is given, for example if a court order or other legal obligation requires disclosure. The Data Protection Act provides other powers to share without consent (see previous slides)

Sharing personal data Data Protection Act – share information securely… Whenever personal data is shared, it must only be given to people who have a legal power to see it and it must be shared in a way that is secure. Verbal – make sure you cannot be overheard by people who shouldn’t hear. If sharing over the phone, make sure you know who you are talking to, they are the right person to speak to and are legally entitled to the information. – sensitive personal data should not be sent by unless both the sender and recipient have a secure address i.e. both addresses contain one of the following sets of letters:.pnn.gov.uk,.gsi.gov.uk, gsx.gov.uk, gsm.net and nhs.net. To obtain a secure address go to ‘Keep Devon’s Data Safe’ on the Source.‘Keep Devon’s Data Safe’

Sharing personal data Data Protection Act – …share information securely …continued Post – mark it ‘for the attention of the addressee only’ and make sure envelopes and packages are properly sealed. Tell the person receiving it that you have sent it and ask them to contact you if they do not receive it within the expected time frame. Limit the amount of personal data disclosed, to those details necessary for the recipient to carry out their role effectively. Fax – mark the cover sheet ‘for the attention of the addressee only’. Only fax the minimum personal data you need to. Do not identify clients by name unless you have to and there is no other secure means of sending the information. Telephone the recipient beforehand, to ensure they know they will shortly be receiving a fax. Double check the fax number before sending. If personal data is lost or sent to the wrong person, you must notify the Information Governance Team immediately on or

Sharing personal data Duty of Confidentiality – sharing confidential data… There may be times when you want to share personal data which was originally provided to you in confidence. Case law has surmised confidential information as something that has the “…necessary quality of confidence about it” and is not public knowledge. A duty of confidence will generally arise in circumstances where a person receives information that he/she knows or ought to know, is being given in confidence. In such cases the organisation or person given the information, is restricted from using it for a purpose other than that for which it was provided, or disclosing it without the individual’s permission, unless there is an overriding reason in the public interest for this to happen or another law or power permits disclosure.

Sharing personal data Duty of Confidentiality – …sharing confidential data …continued When deciding whether there is a public interest in sharing confidential personal data, ask yourself the following questions: do I have the person’s consent? is the sharing necessary to protect a child, young person or adult from harm? is the sharing necessary to prevent or detect a crime? is the sharing necessary to apprehend an offender? is the sharing necessary to comply with a court order or legal obligation? If you can say yes to one or more of these, then you can override a duty of confidence and share confidential personal data. Disclosures must be kept to a minimum, be relevant, and proportionate to what you are trying to achieve.

Sharing personal data Summary Only share personal data if it is for a legitimate & lawful reason Tell the person you want to share their data, with whom and why Decide whether you need the person’s consent. If you have consent, it must be informed, explicit & they must have capacity to give consent Decide whether you can share without consent - do you have other powers? Keep personal data disclosures to a minimum Check the identity of the person you want to share data with & their entitlement Be careful when discussing clients, that you cannot be overheard Do not send personal data by unless sender and recipient have a secure address. If this is not possible, password protect the document or use alternative methods of disclosing the data securely. To find out more go to the Knowing when to Share pages on the SourceKnowing when to Share