What you need to know about GDPR
The Trust processes a lot of sensitive personal information about both patients and staff. We have a responsibility to ensure that this information is protected at all times and shared in an appropriate manner.
The EU General Data Protection Regulations (GDPR) came into force on 25 May 2018 and directly applicable as law in the UK. It will replace the Directive that is the basis for the UK Data Protection Act (DPA) 1998. The basic premise of the DPA will remain; the GDPR will be an enhancement of the DPA.
Do these changes impact me and my department?
Yes it does. The Trust’s preparations are well advanced but we still need help from you. Under GDPR, fines that can be administered against organisations will be increased to £17 million or 4% of turnover. The fines can be for any breach of GDPR not just data security breaches.
How can I help?
- Ensure that you and your team are up to date with information governance training
- That any personal identifiable information is kept secure i.e.
- Patient notes are not left in public places
- PCs are locked when left unattended
- All offices and filing cabinets are locked
- Always check that you have the correct recipients contact details before sending
- Always check that you are sending correspondence to the right patient
- Do not open any suspicious looking emails
- If a breach or near miss does occur that it is reported immediately on Datix and your line manager is informed. Under GDPR we will be expected to report any high risk incident within 72 hours to the Information Commissioner’s Office
- The Information Governance Team is continuing to conduct risk assessments to identify information flows and assets. Please provide them with any assistance required
- If suppliers or any third parties contact you about their readiness or the Trust’s for GDPR that the Information Governance team are made aware
Ensuring the Trust is compliant with GDPR doesn’t end on 25 May. Compliance is on-going and will be monitored by the current data protection regulator, the Information Commissioner’s Office (ICO).
All staff need to be aware of their responsibilities under GDPR and over the coming weeks the Information Governance Team will continue to provide updates on GDPR outlining staff responsibility on WeShare.
If you have any queries or concerns please contact the Information Governance Team.