Plain-English explanations of the technical terms and legislation used in this document.
- Article 28 data processing agreement
- A written contract required by data protection law that sets out how a supplier may handle personal data on the organisation's behalf.
- Audit trail (audit log)
- An automatic record of who accessed or changed information and when, used to detect and investigate misuse.
- Best interests
- A decision made for someone who cannot decide for themselves, choosing the option that is best for them.
- Caldicott Guardian
- The senior person responsible for protecting the confidentiality of people's health and care information.
- Caldicott Principles
- A set of principles that govern how patient-identifiable information should be handled, used and shared safely and lawfully.
- Care Quality Commission (CQC)
- The independent regulator of health and social care services in England.
- Common law duty of confidentiality
- The long-standing legal duty not to disclose information given in confidence, such as patient information, without consent or another legal basis.
- Controller
- The organisation that decides how and why personal data is processed, and which is legally responsible for it.
- Cyber Essentials / Cyber Essentials Plus
- A government-backed certification scheme showing an organisation has basic cyber security controls in place; the Plus level adds an independent technical check.
- Data (Use and Access) Act 2025
- A law that updates the UK's data protection and data-sharing rules, including for health and adult social care.
- Data Protection Act 2018
- The UK law that sits alongside the UK General Data Protection Regulation and governs how personal data is used.
- Data Protection Impact Assessment (DPIA)
- A check done before a new activity to identify and reduce risks to people's personal data.
- Data Protection Officer (DPO)
- The person who advises an organisation on data protection law and monitors its compliance.
- Data Security and Protection Toolkit (DSPT)
- An annual online self-assessment that lets a health or care provider show it meets the national data security and protection standards.
- Data subject
- The living individual that a piece of personal data is about, such as a patient or employee.
- Disclosure and Barring Service (DBS) check
- A criminal-records check showing whether a person is suitable to work with patients or vulnerable people.
- Duty of candour
- The legal duty to be open and honest with a person and their family when something goes wrong with their care.
- Electronic patient record (EPR)
- A patient's clinical record held in a computer system rather than on paper.
- Encryption
- Scrambling data so it can only be read by someone with the correct key, protecting it if a device is lost or stolen.
- Exfiltration
- The unauthorised copying or removal of data from an organisation's systems, often by an attacker.
- Fundamental standards
- The minimum standards of safety and quality below which care must never fall.
- Health and Social Care Act 2008 (Regulated Activities) Regulations 2014
- The regulations setting out the fundamental standards that providers of regulated care must meet, enforced by the Care Quality Commission.
- Health Research Authority (HRA)
- The body that protects and promotes the interests of patients and the public in health and social care research.
- Information Commissioner's Office (ICO)
- The UK's independent regulator for data protection and information rights.
- Information governance
- The framework for handling people's personal and health information legally, securely and appropriately.
- Lawful basis
- One of the legally recognised reasons that allows an organisation to use personal data.
- Mobile device management (MDM)
- Software that lets an organisation secure, control and, if needed, remotely wipe phones, tablets and laptops.
- Multi-factor authentication (MFA)
- A login that requires two or more proofs of identity, such as a password plus a code, to make accounts harder to compromise.
- National Cyber Security Centre (NCSC)
- The UK government organisation that provides advice and support on protecting against cyber threats.
- National Data Guardian
- The independent adviser who champions the safe and confidential use of people's health and care data.
- Near miss
- An event that could have caused harm but did not, by chance or because it was caught in time.
- Network and Information Systems Regulations 2018
- The law requiring operators of certain essential and digital services to keep their networks and information systems secure.
- Nominated Individual
- The senior person responsible to the regulator for supervising how a service is provided.
- Notifiable event
- An incident a provider is legally required to report to the regulator, such as a death or serious injury.
- Personal data
- Any information that identifies, or can identify, a living individual.
- Phishing
- A scam, usually by email, that tricks people into revealing passwords or clicking harmful links.
- Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECR)
- The rules that govern electronic marketing, cookies and the security of phone, text and email communications.
- Ransomware
- Malicious software that locks or encrypts an organisation's data until a ransom is paid.
- Recovery point objective (RPO)
- The maximum amount of recent data an organisation can afford to lose in an incident, which sets how often backups are needed.
- Recovery time objective (RTO)
- The target time within which a system or service must be restored after a failure or outage.
- Registered Manager
- The person registered with the regulator as responsible for the day-to-day running of a service.
- Regulated activity
- A type of care or treatment the law requires a provider to register with the regulator to deliver.
- Research Ethics Committee (REC)
- A panel that reviews health research proposals to protect the rights, safety and wellbeing of participants.
- Residual risk
- The level of risk that remains once the existing controls have been taken into account.
- Risk assessment
- A structured check identifying what could cause harm and what is being done to prevent it.
- Role-based access control
- Limiting access to information and systems according to a person's job role, so they see only what they need.
- Safeguarding
- Protecting people's health, wellbeing and rights and keeping them safe from abuse, harm or neglect.
- Senior Information Risk Owner (SIRO)
- The senior person, usually a board member, who owns and is accountable for the organisation's information risk.
- Service level agreement (SLA)
- A contract that defines the level of service a supplier must provide, such as system availability or how quickly faults are fixed.
- Single assessment framework
- The structure the regulator uses to judge a service, built around quality statements and five key questions (safe, effective, caring, responsive, well-led).
- Special category data
- Sensitive personal data, such as health information, that the law gives extra protection.
- Spine
- The national database and messaging system that links health and care IT systems across England.
- Statement of Purpose
- A required document describing who a service is, what it does and where, shared with the regulator.
- Sub-processor
- A second supplier that a data processor uses to help deliver its service and which also handles personal data.
- Subject Access Request (SAR)
- A person's legal right to ask for a copy of the personal information an organisation holds about them.
- UK General Data Protection Regulation (UK GDPR)
- The UK's main data-protection law governing how personal information is collected and used.
- Uninterruptible power supply (UPS)
- A battery-backed power source that keeps key equipment running for a short time during a power cut.
- Whistleblowing (speaking up)
- Raising a concern about wrongdoing, risk or malpractice at work, protected by law.