Information Governance and Legislation Flashcards
(33 cards)
How is personal data defined by GDPR?
Information relating to natural persons who can be identified or who are identifiable, directly from the information in question; or who can be indirectly identified from that information in combination with other information.
How is data controller defined by GDPR?
Individual or organisation who determines the purposes and means of processing data.
How is data processor defined by GDPR?
Responsible for processing data on behalf of a controller
What are the (7+1) principles of processing personal data under GDPR?
- Lawfulness, fairness and transparency
- Purpose limitation
- Data minimisation
- Accuracy
- Storage limitation
- Integrity and confidentiality
- Protected by appropriate security
- Accountability
Explain lawfulness, fairness and transparency under GDPR.
Tell the subject why you are collecting their data, what you are going to do with it and who you will share it with.
All subjects must be treated equally and their data must not be used to disadvantage them.
The subject must fully understand.
Explain purpose limitation under GDPR.
Only use the data for the purposes for which it was obtained.
Each purpose must be specific to comply with lawfulness, fairness and transparency.
Explain data minimisation under GDPR.
Only collect and keep the data you require.
Only keep the data you can now argue the reason for.
Don’t collect and keep data just in case.
Explain accuracy under GDPR.
Input checks for accuracy.
Automatic verification checks.
Check with the subject it is up to date.
Don’t create duplicates.
Synchronise changes between systems.
Explain storage limitation under GDPR.
Don’t keep for longer than necessary.
Follow retention guidelines (NHS Code of Practice and local policy).
Review what you are holding.
Dispose of information correctly.
What are pieces of legislation governing the use of data in the NHS?
General Data Protection Regulation 2016
(European Union Withdrawal Act 2018)
Data Protection Act 2018
Computer Misuse Act 1990
Freedom of Information Act 2000
Health and Social Care Act 2012
Network and Information Systems Regulations 2018 (NIS)
What is information governance?
Rules to keep data safe, but the rules must be interpreted appropriately
Why is information governance important?
Patients may lose trust if data is not safeguarded, if trust is lost then patients may withhold part or all of their information. A clinical service need information to diagnose and treat, and research needs information to push the boundaries of understanding about healthcare
How is GDPR composed?
Articles - legally binding and mandatory
Recitals - guidance/good practice and open to interpretation
What is the difference between FOIA and GDPR/DPA?
Both are administered by Information Commissioners Office (ICO)
GDPR/DPA2018 - Personal information about a specific individual
FOIA2000 - General information about an organisation or specific information about what the organisation is doing
What are the GDPR lawful bases?
- Explicit consent
- Performance of a contract
- Compliance with legal obligation
- Protect vital interests of the data subject or other natural person
- Public interest or by official public authority
- Legitimate interests, except where these conflict with the fundamental rights and freedoms of the data subject, in particular children
What are the prohibited categories of processing personal data under GDPR?
- Racial or ethnic origin
- Political opinions
- Religious or philosophical beliefs
- Trade union membership
- Identification by genetic or biometric data
- Health
- Information about a person’s sex life
- Sexual orientation
What are the special category permissions under GDPR?
- Explicit consent given
- Obligation or right of the data controller
- Vital interests, if consent not possible
- Activities of a political, philosophical, religious or trade union body
- Data already made public by data subject
- Court/legal cases
- Health or social care
- Public interest
Explain integrity and confidentiality under GDPR.
Confidentiality
Integrity
Availability
How do you demonstrate data protection is embedded within organisational processes?
DPIA
Enhanced recording of activities
Appointment of DPOs
Adherence to codes of conduct
What is a DPIA?
Data Protection Impact Assessment
- Required for any new processing that is likely to result in a high risk to individuals but it is good practice to do anyway
- Consult with DPOs and topic experts
What should a DPIA include?
- Nature, scope and context of processing
- Assessment of necessity and proportionality
- Identification of risks
- Identification of additional measures to mitigate
What are some key points of GDPR?
- Right of access
- Data portability
- Right of erasure
What are the 8 Caldicott Principles?
- Justify purpose
- Only use when necessary
- Use minimum that is required
- Access on strict need to know
- Everyone must understand their responsibilities
- Understand and comply with the law
- Duty to share information
- Regularly review and improve practice
What are the three specific offenses of the Computer Misuse Act 1990?
- Unauthorised access to computer material
- Unauthorised access with the intent to commit or facilitate a crime
- Unauthorised modification of computer material