Plain-English explanations of the technical terms and legislation used in this document.
- Access to Health Records Act 1990
- The law that governs who may see the health records of a person who has died.
- Adequacy decision
- A formal finding that a country outside the United Kingdom protects personal data well enough for data to be sent there safely.
- Anonymised data
- Information from which all details that could identify a person have been removed, so it can no longer be linked back to them.
- Article 28 contract
- A written contract required by data-protection law that sets out how a third party must handle personal data it processes on an organisation's behalf.
- Caldicott Guardian
- The senior person responsible for protecting the confidentiality of people's health and care information and enabling appropriate sharing.
- Caldicott Principles
- A set of eight principles that guide the safe and appropriate use of confidential patient information.
- Care Quality Commission (CQC)
- The independent regulator of health and social care services in England.
- Closed-circuit television (CCTV)
- A camera and recording system used to monitor premises for safety and security.
- Commissioning Support Unit (CSU)
- An organisation that provides shared services, such as data-protection support, to local health bodies.
- Common law duty of confidentiality
- A long-standing legal duty to keep information given in confidence private and to use it only for proper purposes.
- Confidential patient information (CPI)
- Information that identifies a patient and is held under a duty of confidence.
- Data controller
- The organisation that decides why and how personal data is processed and is legally responsible for it.
- Data Protection Act 2018
- The United Kingdom law that sits alongside the UK GDPR and sets the national rules for handling personal data.
- Data Protection Impact Assessment (DPIA)
- A check done before a new activity to identify and reduce risks to people's personal data.
- Data Protection Officer (DPO)
- The appointed expert who advises an organisation on data protection, monitors compliance and acts as a contact point for individuals and the regulator.
- Data processor
- A third party that handles personal data on behalf of, and under the instructions of, the data controller.
- Data subject
- The living individual that personal data is about.
- Data (Use and Access) Act 2025
- Recent United Kingdom legislation that updates how personal data and digital information may be used and accessed.
- Data Security and Protection Toolkit (DSPT)
- An online self-assessment that health and care organisations complete each year to show they handle personal data and protect systems securely.
- Data Security Awareness (Level 1)
- The basic annual data-security and information-governance training that all health and care staff are expected to complete.
- Encryption
- Scrambling information so that only someone with the correct key can read it, keeping it safe if a device is lost or intercepted.
- EMIS Web
- A widely used clinical record system for general practice (named here only as an example).
- General Medical Council (GMC)
- The body that registers and regulates doctors in the United Kingdom.
- GP Connect
- A service that lets authorised health and care staff view and share a patient's general practice record to support their care.
- Information Commissioner's Office (ICO)
- The United Kingdom regulator responsible for upholding data-protection and information rights.
- Information governance
- The framework for handling people's personal and health information legally, securely and appropriately.
- Information sharing agreement
- A written agreement between organisations setting out what data they will share, why and how it will be protected.
- Integrated Care Board
- The local statutory body responsible for planning and arranging publicly funded health services in an area.
- International Data Transfer Agreement
- A standard contract that allows personal data to be sent outside the United Kingdom while keeping it protected.
- Lasting power of attorney
- A legal arrangement that lets a person appoint someone to make decisions on their behalf if they are unable to.
- Lawful basis
- The specific legal reason, set out in data-protection law, that an organisation must have before it can process personal data.
- Lloyd George envelope
- The traditional folder used to store a patient's paper general practice records.
- Multi-factor authentication
- A security method that requires two or more proofs of identity, such as a password plus a code, before access is granted.
- National Data Opt-Out
- A national choice that lets patients stop their confidential information being used for purposes beyond their own care, such as research and planning.
- National Health Service Act 2006
- The Act of Parliament that provides the legal framework for the health service in England, including the rules on using confidential patient information.
- Notifiable breach
- A personal data breach serious enough that the law requires it to be reported to the regulator.
- Nursing and Midwifery Council (NMC)
- The body that registers and regulates nurses and midwives in the United Kingdom.
- Personal data
- Any information that relates to a living person who can be identified from it.
- Personal data breach
- A security incident that leads to personal data being lost, stolen, destroyed, altered or disclosed without authorisation.
- Phishing
- A scam in which fraudulent messages try to trick people into revealing passwords, data or money.
- Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECR)
- The rules that govern marketing and other communications sent by electronic means such as email, text and telephone.
- Privacy notice
- A public statement explaining what personal data an organisation collects, why, and what rights people have over it.
- Quality and Outcomes Framework (QOF)
- A voluntary scheme that rewards general practices for the quality of care they provide against agreed measures.
- Ransomware
- Malicious software that locks or encrypts an organisation's data until a ransom is paid.
- Record of Processing Activities (ROPA)
- A documented register of all the ways an organisation uses personal data, which data-protection law requires it to keep.
- Records Management Code of Practice
- National guidance setting out how long health and care records should be kept and how they should be managed and disposed of.
- Redaction
- Blacking out or removing parts of a document so that certain information cannot be read.
- Registered Manager
- The person registered with the regulator as responsible for the day-to-day running of a service.
- Regulation 17 (Good governance)
- The part of the care regulations requiring providers to have effective systems for running the service safely, including good record-keeping.
- Senior Information Risk Owner (SIRO)
- The senior leader accountable for managing the organisation's information risk.
- Serious harm test
- The check used to decide whether releasing health information could seriously harm a person's physical or mental health, in which case it may be withheld.
- Shared Care Record
- A local system that brings together a person's records from different health and care organisations to support their care.
- Single assessment framework
- The structure the regulator uses to judge a service, built around quality statements and five key questions (safe, effective, caring, responsive, well-led).
- Smartcard
- A secure card used to log in to clinical systems and confirm a staff member's identity and access rights.
- Special category data
- Particularly sensitive personal data, such as health, genetic or biometric information, that needs extra protection in law.
- Subject Access Request (SAR)
- A person's legal right to ask for a copy of the personal information an organisation holds about them.
- SystmOne
- A widely used clinical record system for general practice (named here only as an example).
- UK General Data Protection Regulation (UK GDPR)
- The United Kingdom's main data-protection law governing how personal information is collected and used.
- Unique patient identifier
- The individual number used to identify a patient correctly across health and care services.