Plain-English explanations of the technical terms and legislation used in this document.
- ADHD (Attention Deficit Hyperactivity Disorder)
- A neurodevelopmental condition affecting attention, activity levels and impulse control.
- Article 28 (processor contract)
- The part of data-protection law that says a written contract must be in place whenever one organisation processes personal data on another's behalf.
- Article 6 lawful basis
- One of the legally recognised reasons an organisation must have before it may use any personal data.
- Article 9 condition
- An extra legal reason required, on top of an Article 6 basis, before sensitive data such as health information may be used.
- Caldicott Guardian
- The senior person responsible for protecting the confidentiality of people's health and care information.
- Caldicott Principles
- A set of national rules guiding when and how confidential patient information may be used and shared.
- Care Quality Commission (CQC)
- The independent regulator of health and social care services in England.
- Cold chain
- Keeping vaccines and certain medicines within a safe temperature range from delivery to use.
- Common law duty of confidentiality
- The long-standing legal duty to keep information given in confidence private and to share it only with good reason.
- Comorbidity
- An additional health condition a person has alongside their main diagnosis, such as anxiety or autism alongside ADHD.
- Controlled drug
- A medicine whose supply, storage and records are tightly restricted by law because of its potential for misuse.
- Data controller
- The organisation that decides why and how personal data is collected and used.
- Data processor
- A third party that handles personal data on a controller's behalf, following the controller's written instructions.
- Data Protection Act 2018
- The UK law that sits alongside the UK GDPR and sets additional national data-protection rules.
- Data Protection by design and by default
- Building privacy and data protection into systems and services from the outset, rather than adding it later.
- Data Protection Impact Assessment (DPIA)
- A check done before a new activity to identify and reduce risks to people's personal data.
- Data Protection Officer (DPO)
- The named person who oversees an organisation's compliance with data-protection law and advises on it.
- Data subject
- The living individual that a piece of personal data is about.
- Data (Use and Access) Act 2025
- A UK law that updates and adds to existing data-protection rules.
- Data Security and Protection Toolkit (DSPT)
- An annual online self-assessment that shows an organisation handles personal and health data safely.
- Driver and Vehicle Licensing Agency (DVLA)
- The government body responsible for driver licensing, which must be told about medical conditions that may affect driving.
- Electronic patient record (EPR)
- The digital clinical record holding a patient's assessments, treatment and notes.
- Electronic Prescription Service
- A system that sends prescriptions electronically from a prescriber to a dispensing pharmacy.
- General Dental Council (GDC)
- The body that registers and regulates dental professionals in the UK.
- General Medical Council (GMC)
- The body that registers and regulates doctors in the UK.
- General Pharmaceutical Council (GPhC)
- The body that registers and regulates pharmacists and pharmacy technicians in the UK.
- General practitioner (GP)
- A doctor who provides general medical care in the community and often coordinates a patient's overall care.
- Gillick competence
- The test of whether a child is mature enough to understand and consent to their own treatment without a parent.
- Health and Care Professions Council (HCPC)
- The body that registers and regulates a range of health and care professionals in the UK.
- Health and Social Care Act 2008 (Regulated Activities) Regulations 2014
- The regulations setting the fundamental standards that registered care providers must meet.
- Information Commissioner's Office (ICO)
- The UK regulator that enforces data-protection and information-rights law.
- Information governance
- The framework for handling people's personal and health information legally, securely and appropriately.
- Multi-factor authentication
- A login method that requires two or more proofs of identity, such as a password plus a code, for added security.
- National Data Guardian
- The independent national champion for keeping people's health and care data safe and used appropriately.
- Nominated Individual
- The senior person responsible to the regulator for supervising how a service is provided.
- Personal data
- Any information that identifies, or could identify, a living person.
- Personal data breach
- A security failure that leads to personal data being lost, stolen, altered or wrongly disclosed or accessed.
- Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECR)
- The law governing electronic marketing, cookies and the privacy of electronic communications.
- Processing
- Any action taken with personal data, from collecting and storing it to sharing or deleting it.
- Record of Processing Activities (ROPA)
- A written record of what personal data an organisation holds, why, and how it is used and shared.
- Records Management Code of Practice 2023
- National guidance on how long health and care records should be kept and how they should be managed.
- Registered Manager
- The person registered with the regulator as responsible for the day-to-day running of a service.
- Regulation 17 (Good governance)
- The standard requiring providers to run their service well, including keeping accurate, secure records.
- Single assessment framework
- The structure the regulator uses to judge a service, built around quality statements and five key questions (safe, effective, caring, responsive, well-led).
- Safeguarding
- Protecting people's health, wellbeing and rights and keeping them safe from abuse, harm or neglect.
- Senior Information Risk Owner (SIRO)
- The senior person who owns an organisation's information-risk decisions and accepts any remaining risk.
- Special category data
- Particularly sensitive personal data, such as health, genetic or biometric information, that needs extra protection.
- Subject Access Request (SAR)
- A person's legal right to ask for a copy of the personal information an organisation holds about them.
- Telehealth
- Providing clinical care remotely using video, phone or other technology rather than in person.
- Titration
- The careful process of starting a medicine at a low dose and adjusting it to find the most effective, safe level.
- UK General Data Protection Regulation (UK GDPR)
- The UK's main data-protection law governing how personal information is collected and used.