Data protection laws and personal data Flashcards

(30 cards)

1
Q

What is personal data?

A

Information relating to an identifiable natural person, who can be directly/indirectly identified by reference to an identifier

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Give 3 examples of identifiers?

A

Name, address, cultural identity

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What act was implemented in the UK to protect personal data?

A

General Data Protection Regulation (GDPR) implemented Data Protection Act 2018

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

How does the DPA 2018 state data should be processed?

A

Fairly and lawfully

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What right does the DPA 2018 give living people/their authorised representatives?

A

Right to apply for access to personal data irrespective of where data was produced

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

In what 2 situations does DPA 2018 not apply?

A

Deceased person

Data is anonymous

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Does DPA 2018 apply to NHS or private health records?

A

Both

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

How does DPA 2018 apply to employers?

A

Employers could hold info on employees’ mental, physical health

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Who developed the Caldicott principles?

A

Dame Fiona Caldicott

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is the purpose of the Caldicott principles?

A

Demonstrate how staff should handle their access to patient’s personal information

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is the role of the Caldicott Guardian?

A

Safeguarding and governing of use of personal data in the Trust

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

How many Caldicott principles are there?

A

8

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What do Caldicott principles state about decisions regarding sharing confidential info?

A

Must be justified

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What do Caldicott principles state about when to share confidential info?

A

Only when necessary

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What do Caldicott principles state about how much confidential info to share?

A

Minimum necessary amount

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What do Caldicott principles state about sharing info on a need-to-know basis?

A

Only tell others what they need to know at the time that need to know the info

17
Q

What do Caldicott principles state about staff responsibilities regarding sharing confidential info?

A

Staff should be aware of their responsibilities

18
Q

What do Caldicott principles state about the law?

A

Staff must comply with the law

19
Q

What do Caldicott principles state about balance between duties of sharing info and confidentiality?

A

Duty of sharing info for individual care is just as important as duty of confidentiality

20
Q

What do Caldicott principles state about informing patients and service users?

A

They should be informed about how their personal data is used

21
Q

If personal data is incorrect or incomplete, what can the data subject do?

A

They have the right to correct data

22
Q

If a patient’s personal records contain an incorrect clinical opinion, can the patient exercise their right to correct data?

A

No, incorrect clinical opinions can’t be removed/corrected but patient can add note stating that they disagree with the clinical opinion

23
Q

What right does a data subject have that allows them to request to remove personal data?

A

Right of erasure

24
Q

Why does a data subject’s right to erasure not apply to health records?

A

Healthcare professionals can refuse to comply if data is needed for processing eg. in public interest, or they have official authority

25
Can children access their personal records?
Yes, if they have capacity
26
Give 2 situations in which a patient can access their child's personal records?
Child gives consent to parents Child doesn't have capacity, so patients are given access in child's best interests
27
Can divorced or separated parents access their child's personal records if required?
Yes, they still have the same parental responsibility
28
Generally, do deceased patients' notes stay confidential?
Yes
29
Give 2 examples of when deceased patients' notes are shared?
Access to Health Records Act 1990 applied Court-ordered
30
What is the Access to Health Records Act 1990?
Permits access to deceased person's records by others with claim arising from that patient's death