Plain-English explanations of the technical terms and legislation used in this document.
- Article 28 contract
- A written agreement required by data-protection law whenever one organisation processes personal data on another's behalf, setting out how the data must be protected.
- Caldicott Guardian
- The senior person responsible for protecting the confidentiality of people's health and care information.
- Caldicott Principles
- A set of standards that guide when and how confidential patient information may be used and shared.
- Care Quality Commission (CQC)
- The independent regulator of health and social care services in England.
- Common-law duty of confidentiality
- The long-standing legal duty to keep information that someone shares in confidence, such as patient details, private.
- Computer Misuse Act 1990
- The law that makes it a criminal offence to access or interfere with computer systems or data without authorisation.
- Confidential information
- Information given in circumstances where the person providing it reasonably expects it to be kept private, including all patient clinical information.
- Contemporaneous record
- A note made at the time of an event, or as soon as possible afterwards, so it is accurate and reliable.
- Contraindication
- A reason why a particular treatment should not be given to a specific person because it could be harmful.
- Controller
- The organisation that decides why and how personal data is processed and is legally responsible for it.
- Data processing agreement
- A written contract that sets out the rules a supplier must follow when handling personal data for the organisation.
- Data Protection Act 2018
- The UK law that sits alongside the UK GDPR and governs how personal information must be handled.
- Data Protection Impact Assessment (DPIA)
- A check done before a new activity to identify and reduce risks to people's personal data.
- Data Security and Protection Toolkit (DSPT)
- An annual online self-assessment that shows an organisation is meeting recognised data-security and confidentiality standards.
- Disclosure and Barring Service (DBS) check
- A criminal-records check showing whether a person is suitable to work with patients or vulnerable people.
- Duty of candour
- The legal duty to be open and honest with a person and their family when something goes wrong with their care.
- Encryption
- Scrambling data so it can only be read by someone with the correct key or password, protecting it if a device is lost or stolen.
- Freedom of Information Act 2000
- The law giving people the right to ask public authorities for recorded information they hold.
- General practitioner (GP)
- A doctor who provides general medical care in the community and is often the patient's main point of contact for health.
- Health and Social Care Act 2008 (Regulated Activities) Regulations 2014
- The regulations setting the fundamental standards that registered health and care providers must meet, enforced by the Care Quality Commission.
- Information asset
- An identifiable body of information, and the system that holds it, that has value to the organisation, such as a patient-records system.
- Information asset register
- A list of an organisation's key information and systems, recording what data they hold, where it is kept and who is responsible for it.
- Information Commissioner's Office (ICO)
- The UK's independent authority that upholds information rights and enforces data-protection law.
- Information governance
- The framework for handling people's personal and health information legally, securely and appropriately.
- Informed consent
- Agreement to treatment given freely after the risks, benefits and alternatives have been clearly explained.
- International Data Transfer Agreement
- A standard contract that allows personal data to be sent outside the UK while keeping it properly protected.
- Lawful basis
- One of the legally recognised reasons an organisation must have before it may use someone's personal data.
- Least privilege
- The security rule of giving each person access only to the information and systems they genuinely need for their job.
- Locum
- A practitioner who works temporarily to cover for another, for example during absence or to meet demand.
- Multi-factor authentication (MFA)
- A login method that requires more than one proof of identity, such as a password plus a code sent to a phone.
- National Data Guardian
- The independent adviser who champions the safe and appropriate use of people's health and care information in England.
- Need-to-know basis
- The principle that confidential information is shared only with people who require it to do their job or care for the patient.
- Nominated Individual
- The senior person responsible to the regulator for supervising how a service is provided.
- Personal data
- Any information relating to an identified or identifiable living individual, such as a name, contact details or photograph.
- Personal data breach
- A security failure that leads to personal data being lost, stolen, destroyed, altered or disclosed without authorisation.
- Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECR)
- The rules covering electronic marketing, cookies and the privacy of electronic communications, sitting alongside data-protection law.
- Processor
- A third party that processes personal data on behalf of the controller, such as a cloud system provider or IT support firm.
- Ransomware
- Malicious software that locks or encrypts an organisation's data and demands payment to release it.
- Records Management Code of Practice
- National guidance on how health and care records should be created, kept and how long they should be retained.
- Redaction
- Blacking out or removing parts of a document, such as another person's details, before it is shared or released.
- Registered Manager
- The person registered with the regulator as responsible for the day-to-day running of a service.
- Regulation 17 (Good governance)
- The fundamental standard requiring providers to run their service well, including keeping accurate, complete and secure records.
- Retention schedule
- A plan setting out how long each type of record is kept before it is securely destroyed.
- Senior Information Risk Owner (SIRO)
- A senior person with overall responsibility for managing the organisation's information risks.
- Shared care record
- A joined-up electronic record that lets approved health and care professionals see relevant information about a patient.
- Single assessment framework
- The structure the regulator uses to judge a service, built around quality statements and five key questions (safe, effective, caring, responsive, well-led).
- Special category data
- Sensitive personal data, such as information about health, that needs extra protection under data-protection law.
- Subject access request (SAR)
- A person's legal right to ask for a copy of the personal information an organisation holds about them.
- Summary Care Record
- An electronic summary of key patient information, such as medicines and allergies, that approved clinicians can view.
- UK General Data Protection Regulation (UK GDPR)
- The UK's main data-protection law governing how personal information is collected and used.