GP practices already share patient data for these purposes, but this new data collection will be more efficient and effective. We have agreed to share the patient data we look after in our practice with NHS Digital who will securely store, analyse, publish, and share this patient data to improve health and care services for everyone. This includes:
- informing and developing health and social care policy
- planning and commissioning health and care services
- taking steps to protect public health (including managing and monitoring the coronavirus pandemic)
- in exceptional circumstances, providing you with individual care
- enabling healthcare and scientific research
This means that we can get on with looking after our patients and NHS Digital can provide controlled access to patient data to the NHS and other organisations who need to use it to improve health and care for everyone.
Contributing to research projects will benefit us all as better and safer treatments are introduced more quickly and effectively without compromising your privacy and confidentiality.
NHS Digital has engaged with the British Medical Association (BMA), Royal College of GPs (RCGP) and the National Data Guardian (NDG) to ensure relevant safeguards are in place for patients and GP practices.
Opting Out
If you don’t want your identifiable patient data to be shared for purposes except for your own care, you can opt-out by registering a Type 1 Opt-out or a National Data Opt-out, or both. These opt-outs are different, and they are explained in more detail below. Your individual care will not be affected if you opt out using either option.
Type 1 Opt-Outs – If you do not want your identifiable patient data to be shared outside of the GP practice for purposes except your own care, you can register an opt-out with the GP practice. This is known as a Type 1 Opt-out. Type 1 Opt-outs were introduced in 2013 for data sharing from GP practices, but may be discontinued in the future as a new opt-out has since been introduced to cover the broader health and care system, called the National Data Opt-out. If this happens, patients who have registered a Type 1 Opt-out will be informed. There is more information about National Data Opt-outs below.
NHS Digital will not collect any patient data for patients who have already registered a Type 1 Opt-in line with current policy. If this changes patients who have registered a Type 1 Opt-out will be informed.
If you do not want your patient data shared with NHS Digital for the purposes above, you can register a Type 1 Opt-out with your GP practice. You can register a Type 1 Opt-out at any time. You can also change your mind at any time and withdraw a Type 1 Opt-out.
If you have already registered a Type 1 Opt-out with us your data will not be shared with NHS Digital. If you wish to register a Type 1 Opt-out with your us before data sharing starts with NHS Digital, this should be done by returning this form to the practice. If you do intend to opt out of the GP DPR we will update this Privacy Notice with the date by which you must provide your opt-out by to allow time for processing it.
If you have previously registered a Type 1 Opt-out and you would like to withdraw this, you can also use the form to do this. You can send the form by post or email to your us at the GP Practice or call 0300 3035678 for a form to be sent out to you.
If you do not want NHS Digital to share your identifiable patient data with anyone else for purposes beyond your own care, then you can also register a National Data Opt-out.
National Data Opt-out
If you don’t want your confidential patient information to be shared by NHS Digital with other organisations for purposes except your own care – either GP data, or other data it holds, such as hospital data – you can register a National Data Opt-out.
If you have registered a National Data Opt-out, NHS Digital will not share any confidential patient information about you with other organisations, unless there is an exemption to this, such as where there is a legal requirement or where it is in the public interest to do so, such as helping to manage contagious diseases like coronavirus. You can find out more about exemptions on the NHS website.
There is an intention for the National Data Opt-out to apply to any confidential patient information shared by the GP practice with other organisations for purposes except your individual care. This means it will replace the Type-1 Opt-out. If this happens, patients who have registered a Type 1 Opt-out will be informed.
Please note that the National Data Opt-out will not apply to confidential patient information being shared by GP practices with NHS Digital, as it is a legal requirement for us to share this data with NHS Digital and the National Data Opt-out does not apply where there is a legal requirement to share data.
You can find out more about and register a National Data Opt-out or change your choice on nhs.uk/your-nhs-data-matters or by calling 0300 3035678.
You can also set your opt-out preferences via the NHS App if you are registered to use this application.
The legal bases for processing this information.
The Health and Social Care Act 2012 covers the sharing and collection of health and care data. It says that when the Secretary of State for Health and Social Care needs to collect and analyse data to help the health service, they can tell NHS Digital to do this for them.
The instruction, which NHS Digital must act on, is called a direction. In this case:
1.) The Secretary of State for Health and Social Care sent a direction to NHS Digital, instructing them to collect and analyse general practice data for health and social care purposes including policy, planning, commissioning, public health, and research purposes.
2.) NHS Digital sent all GP practices a document called a Data Provision Notice, giving details of the data it needs GP Practices like ours to share so it can comply with the direction. All GP Practices in England are required to share data with NHS Digital when they are sent a Data Provision Notice.
Under data protection law, we can only share patient data if we have a legal basis under Articles 6 and 9 of the UK GDPR. Our legal basis for sharing patient data with NHS Digital is Article 6(1)(c) – legal obligation, as we are required under the 2012 Act to share it with NHS Digital.
When we are sharing patient data about health, we also need a legal basis under Article 9 of the UK GDPR. This is:
- Article 9(2)(g) – as we are sharing patient data for reasons of substantial public interest, for the purposes of NHS Digital exercising its statutory functions under the General Practice Data for Planning and Research Directions. It is substantially in the public interest to process patient data for planning and research purposes to improve health and care services for everyone. This is permitted under paragraph 6 of Schedule 1 of the Data Protection Act 2018 (DPA).
- Article 9(2)(h) – as we are sharing patient data for the purposes of providing care and managing health and social care systems and services. This is permitted under paragraph 2 of Schedule 1 of the DPA.
- Article 9(2)(i) – as patient data will also be used for public health purposes. This is permitted under paragraphs 3 of Schedule 1 of the DPA.
- Article 9(2)(j) – as patient data will also be used for the purposes of scientific research and for statistical purposes. This is permitted under paragraph 4 of Schedule 1 of the DPA.