Plain-English explanations of the technical terms and legislation used in this document.
- Common-law duty of confidentiality
- The long-standing legal duty to keep information someone shares in confidence, such as their health details, private and to use it only for the purpose it was given.
- Data concerning health
- Information about a person's physical or mental health, which the law treats as especially sensitive and protects more strictly.
- Data Protection Act 2018
- The UK law that sits alongside the UK GDPR and sets the detailed rules for handling people's personal information.
- Data Protection Impact Assessment (DPIA)
- A check done before a new activity to identify and reduce risks to people's personal data.
- Dermatoscopic image
- A close-up photograph of the skin taken through a magnifying device, used to examine moles, lesions or skin conditions.
- Encryption (in transit and at rest)
- Scrambling data so it cannot be read without the right key, both while it is being sent ('in transit') and while it is stored ('at rest').
- Identifiable image
- A photograph or video from which a patient can be recognised, either directly or when combined with other information held about them.
- Information Commissioner's Office (ICO)
- The UK's independent regulator for data protection and information rights.
- Information governance
- The framework for handling people's personal and health information legally, securely and appropriately.
- Lawful basis
- The specific legal reason, set out in data-protection law, that allows an organisation to use someone's personal information.
- Need-to-know basis
- The principle that information is seen only by people who genuinely require it to do their job or care for the patient.
- Practice or clinic-management system (PMS)
- The secure software the clinic uses to hold patient records, including their clinical images.
- Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECR)
- The UK law governing electronic marketing, such as messages sent by email, text or phone.
- Registered Manager
- The person registered with the regulator as responsible for the day-to-day running of a service.
- Special category data
- Sensitive personal information, such as data about health, that the UK GDPR protects more strictly than ordinary personal data.
- Standard Operating Procedure (SOP)
- A written, step-by-step set of instructions for carrying out a routine task consistently and safely.
- Subject Access Request (SAR)
- A person's legal right to ask for a copy of the personal information an organisation holds about them.
- UK General Data Protection Regulation (UK GDPR)
- The UK's main data-protection law governing how personal information is collected and used.