Submission Notes

Melissa Ream is also working with Lisa to co-ordinate this. This relates to Kelly's email on the 4th. The HIN have been engaged by DHSC to help produce a booklet on developments utilising AI to support Women's Health. To achieve this DHSC will conduct a data collection process, through a survey, which will then be passed to HIKSS to review responses and put together the booklet. The DHSC DPO office has been engaged and provided some guidance regarding consent steps; HIKSS are considering asking for some slight changes to enable further contact where the HIN feels it can support the innovators. The review process will include a panel, including an AI fellow, who works as a GP. We are asking whether a formal agreement is needed before providing access to any data. There is also no formal contract that I am aware of; subjects are aware of data being passed to HIKSS in the consent step, but there's nothing to cover the exchange of results between DHSC and KSS.

I would advise against totally relying on a DPO being happy (even me!). Of course, if you are acting as a processor you need a contract/DP Agreement, and the consent needs to reach the standard of informed consent. Tick boxes alone could be inadequate, i.e. they may need supplementing with a detailed explanation, guidance, and perhaps a means of asking questions for clarification.

Real world evaluation of implementation of maternity information and training system at Epsom and St Helier. Pseudonymised patient-level data including age band, ethnicity and postcode sector, plus clinician surveys/interviews.

  1. As a processor for RBC I agree that you will need a DPA or suitable contract with them.
  2. The Trust would need informed consent from its patients to share any identifiable or re-identifiable personal (outcome) data.
  3. If there is any such data sharing, the DSA, based on the patient consent, should be between the Trust and RBC and not with UI (regardless of the supply route) as UI would only be processing it whilst acting as a processor for RBC and not in its own right.

Dana Daderko is also working on this with Léa.

Definition

LifeBox is a digital pre-operative assessment tool which supports patient assessment, hospital decision-making, and personalised patient care. We are undertaking a quantitative and health economic evaluation covering its use in Royal Sherwood hospitals, commissioned by Definition Health, who own/provide LifeBox).

The fact that you are processing pseudonymous data means that you are processing personal data even though you can't identify whose data it is. This is not a problem assuming that you have contracts/DPAs with the controllers and represents a good minimisation and data security approach. Assuming you have satisfactory contracts and DPAs with the processors, this appears to be a standard UI processing operation.

Special and Criminal Activity Data Notes

Possibly health and equalities data will be asked in qualitative collection. This data will also be in the anonymous quantitative data, but it will not be possible to link the two sets of results.

Data Protection Threshold Assessment

  • Form
  • Background
  • Guide
  • Follow-up
  • Initial Assessments
  • Submissions

Item 1

You must be logged in to submit the form.

Item 2

Background

The privacy of our clients and partners, especially those in the health and care sectors, along with their patients, clients, and employees, is critical to us and their organisations as is the security of data. Processing personal data legally and securely prevents regulatory violations, avoids negative publicity, and shows respect for data subjects.

The UK’s Data Protection Act, 2018 (DPA) came into force on 25 May 2018, implementing the EU General Data Protection Regulation (GDPR) as the main legislation governing the processing of personal data in the UK. BREXIT changed the legal basis, with all data protection legislation becoming simply part of UK law.

The EU-based legislation was absorbed, fundamentally unchanged, into that framework and apart from technical changes such as referring to the GDPR as the UK GDPR rather than the ‘EU GDPR’, little has changed following the UK’s departure from the EU. If the law is significantly amended, we will update our procedures to comply with it and assist our clients in doing the same.

Most recently, the Data (Use and Access) Act, 2025 has amended the DPA/GDPR in some respects and its provisions will be considered when assessing DPTAs.

Data Protection Impact Assessments

The Legislation states that “where a type of processing is likely to result in a high risk to the rights and freedoms of individuals, the controller must, prior to the processing, carry out a Data Protection Impact Assessment (DPIA). Furthermore, if the assessment reveals processing involving high risks that cannot be mitigated, the ICO must be consulted before starting the processing.

Data Protection Threshold Assessments

Amongst other uses, this tool is employed to screen programmes and decide whether full DPIAs or other actions are required.

Item 3

Guide

Accessing the Form
The Data Protection Threshold Assessment form works well on most devices, but it may not be easy to use on small displays such as smartphones, which should be avoided.

Using the Form

  • Use the Form tab to raise a new assessment form.
  • Some fields may already be completed as defaults or based on your profile – most of these can still be altered.
  • There are 9 pages – take your time, working through them in order, returning to [Previous] pages as necessary.
  • You can navigate between pages (as long as all mandatory fields have been completed) either sequentially using the [Next] and [Previous] buttons at the bottom of each page, or by ‘jumping’ via the numbered progress bar at the top.
  • Most fields are always visible and some contain guidance notes.
  • Some input fields and guidance notes are revealed or hidden depending on your responses.
  • Fields marked with an **asterisk *** must be completed to submit the form.
  • Pages and the form as a whole are saved whenever you click a [Next] button to move to a new page.
  • Clicking the [Submit] button on the final page saves the form and shares it with the DPO.
  • See the Follow-up tab to find out what happens next after you submit a DPTA form.

Item 4

Follow-up

On receipt of your Data Protection Threshold Assessment form, the DPO will:

  1. Send you an acknowledgement email with a pdf copy of your submission.
  2. Check your submission.
  3. Add comments or questions in the DPO Notes field.
  4. Contact you for further details and clarification if required.
  5. Post a copy of the initial assessment in the table on the Initial Assessments tab.
  6. Update the submission status from Draft to Assessed.
  7. Usually email an updated copy of your form.
  8. Post a copy of the DPTA in the table on the Submissions tab.

The Submissions tab record can be subsequently updated by you or the DPO and you can also export records from the table in CSV format for use with Excel and other application.

Further follow-up could include:

  • Proposing actions as needed.
  • Providing assistance with tasks such as completing a full DPIA and checking or preparing documents.

Item 5

Initial Assessments

Item 5

Submissions