Plain-English explanations of the technical terms and legislation used in this document.
- Accessible Information Standard (DCB1605)
- A standard requiring health and care providers to give people information in a format they can read and understand, such as easy-read or large print.
- Adequacy regulation
- A UK government decision that another country protects personal data well enough for data to be sent there without extra safeguards.
- Article 28 contract
- A written agreement the UK data-protection law requires between an organisation and any outside company that processes personal data on its behalf.
- Caldicott Guardian
- The senior person responsible for protecting the confidentiality of people's health and care information.
- Caldicott Principles
- A set of national rules guiding when and how confidential health and care information may be used and shared.
- Care Quality Commission (CQC)
- The independent regulator of health and social care services in England.
- Common law duty of confidentiality
- A legal duty, developed by the courts, to keep information shared in confidence private and not disclose it without good reason.
- Cyber Essentials
- A UK government-backed certification scheme that shows an organisation has basic protections in place against common cyber attacks.
- Data (Use and Access) Act 2025
- A UK law that updates how personal and other data may be used, shared and accessed.
- Data controller
- The organisation that decides why and how personal data is collected and used.
- Data processor
- An outside party that handles personal data only on the instructions of the organisation that controls it.
- Data Protection Act 2018
- The UK law that sits alongside the UK GDPR and sets additional rules for handling personal data.
- Data protection by design and by default
- Building privacy protections into a service from the start and setting the most privacy-friendly options as standard.
- Data Protection Impact Assessment (DPIA)
- A check done before a new activity to identify and reduce risks to people's personal data.
- Data Protection Officer (DPO)
- The appointed expert who advises an organisation on data-protection law and monitors that it is followed.
- Data Security and Protection Toolkit
- An online self-assessment that health and care organisations complete each year to show they handle data securely.
- Data subject
- The living individual that a piece of personal data is about.
- Information Commissioner's Office (ICO)
- The UK regulator that enforces data-protection and information-rights law.
- Information governance
- The framework for handling people's personal and health information legally, securely and appropriately.
- International Data Transfer Agreement
- A standard UK contract that provides legal safeguards when personal data is sent to a country outside the UK.
- Lasting Power of Attorney
- A legal document letting someone make decisions, such as about health and welfare, on behalf of a person who cannot decide for themselves.
- Lawful basis
- One of the specific legal reasons the law requires before an organisation may process personal data.
- Least privilege
- Giving each member of staff access only to the information and systems they need to do their job.
- Mental capacity
- Whether a person can understand and make a particular decision for themselves at the time it needs to be made.
- Multi-factor authentication
- A login method that requires more than one form of proof, such as a password plus a code, to confirm who you are.
- National Data Guardian
- An independent adviser who champions the safe and confidential use of people's health and care data in England.
- National Data Opt-Out
- A choice people can make to stop their confidential health information being used for purposes beyond their direct care.
- Nominated Individual
- The senior person responsible to the regulator for supervising how a service is provided.
- Notifiable event
- An incident a provider is legally required to report to the regulator, such as a death or serious injury.
- Personal data
- Any information that relates to and can identify a living individual.
- Personal data breach
- A security failure that leads to personal data being lost, destroyed, altered or disclosed without authorisation.
- Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECR)
- The UK law governing electronic marketing, cookies and the privacy of electronic communications.
- Privacy notice
- A clear statement telling people what data an organisation collects about them and how it is used.
- Record of Processing Activities (ROPA)
- A written record of all the ways an organisation uses personal data, required under data-protection law.
- Records Management Code of Practice 2023
- National guidance setting out how long health and care records should be kept and how they should be managed.
- Redaction
- Blacking out or removing information from a document, for example to protect details about another person.
- Registered Manager
- The person registered with the regulator as responsible for the day-to-day running of a service.
- Regulated activity
- A type of care or treatment the law requires a provider to register with the regulator to deliver.
- Risk assessment
- A structured check identifying what could cause harm and what is being done to prevent it.
- Safeguarding
- Protecting people's health, wellbeing and rights and keeping them safe from abuse, harm or neglect.
- Senior Information Risk Owner (SIRO)
- The board-level person who owns the organisation's information risk and signs off how it is managed.
- Single assessment framework
- The structure the regulator uses to judge a service, built around quality statements and five key questions (safe, effective, caring, responsive, well-led).
- Special category data
- Sensitive personal data, such as information about health, that the law gives extra protection.
- Subject Access Request (SAR)
- A person's legal right to ask for a copy of the personal information an organisation holds about them.
- UK General Data Protection Regulation (UK GDPR)
- The UK's main data-protection law governing how personal information is collected and used.
- Virtual Private Network (VPN)
- A secure, encrypted connection that lets staff access systems safely over the internet, including when working remotely.