Plain-English explanations of the technical terms and legislation used in this document.
- Age Appropriate Design Code (Children's Code)
- A statutory code of practice setting out how online services should protect children's personal data.
- Article 28 contract
- A written data-processing contract required by data-protection law before a third party may handle personal data on an organisation's behalf.
- Caldicott Guardian
- The senior person responsible for protecting the confidentiality of people's health and care information and enabling appropriate sharing.
- Care Quality Commission (CQC)
- The independent regulator of health and social care services in England.
- Common Law Duty of Confidentiality
- A long-standing legal duty, developed by the courts, to keep information shared in confidence private and use it only for the purpose it was given.
- Computer Misuse Act 1990
- The law that makes unauthorised access to, or interference with, computer systems and data a criminal offence.
- Contemporaneous records
- Notes made at the time of, or as soon as possible after, the event they describe.
- Cyber Essentials Plus
- A government-backed certification that independently tests an organisation's defences against common cyber attacks.
- Data controller
- The organisation that decides why and how personal data is processed.
- Data minimisation
- The principle of collecting and keeping only the personal data that is actually needed for the purpose.
- Data processor
- A third party that processes personal data on the controller's behalf and on its documented instructions.
- Data Protection Act 2018
- The United Kingdom law that sits alongside the UK GDPR and governs how personal data is used.
- Data Protection Impact Assessment (DPIA)
- A check done before a new or high-risk activity to identify and reduce risks to people's personal data.
- Data Protection Officer (DPO)
- The independent person who advises an organisation on data-protection law and monitors its compliance.
- Data Security and Protection Toolkit
- An online self-assessment tool that health and care organisations use to show they handle personal information safely.
- Data subject
- The living individual that personal data is about.
- Duty of candour
- The legal duty to be open and honest with a person and their family when something goes wrong with their care.
- Electronic patient record (EPR)
- The digital system that stores a patient's clinical and personal information.
- Encryption
- Scrambling data so that only someone with the right key can read it.
- Explicit consent
- A clear, specific and unambiguous agreement to a particular use of personal data, required for sensitive (special category) data.
- General Medical Council (GMC)
- The body that registers and regulates doctors in the United Kingdom.
- General practitioner (GP)
- A doctor who provides general medical care in the community and usually holds a patient's main medical record.
- Gillick competence
- A test of whether a child under 16 has enough understanding to consent to their own treatment without a parent.
- Health and Social Care Act 2008 (Regulated Activities) Regulations 2014
- The regulations setting out the fundamental standards that registered care providers must meet, enforced by the Care Quality Commission.
- Information Commissioner's Office (ICO)
- The United Kingdom regulator that enforces data-protection and information-rights law.
- Information governance
- The framework for handling people's personal and health information legally, securely and appropriately.
- International Data Transfer Agreement (IDTA)
- A standard contract that lawfully covers transfers of personal data from the United Kingdom to another country.
- Lawful basis
- One of the specific legal grounds in data-protection law that must apply before personal data can be processed.
- Multi-factor authentication
- A login method that requires two or more proofs of identity, such as a password plus a code sent to a phone.
- Near miss
- An event that could have caused harm but did not, by chance or because it was caught in time.
- Network and Information Systems Regulations 2018 (NIS Regulations)
- The law setting cyber-security and incident-reporting duties for operators of essential and certain digital services.
- Personal data
- Any information that relates to an identified or identifiable living person.
- Personal data breach
- A security failure that leads to personal data being lost, destroyed, altered, disclosed or accessed without authorisation.
- Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECR)
- The law governing electronic marketing, cookies and the privacy of electronic communications.
- Privacy by design and by default
- Building data-protection safeguards into a service from the outset and as the standard setting.
- Privacy notice
- A clear statement telling people how their personal data is collected and used.
- Record of Processing Activities (ROPA)
- A written record of the personal data an organisation holds, why it holds it and who it is shared with.
- Records Management Code of Practice
- Official guidance on how long health and care records should be kept and how they should be managed.
- Registered Manager
- The person registered with the regulator as responsible for the day-to-day running of a service.
- Retention schedule
- A documented timetable setting out how long each type of record is kept before secure disposal.
- Role-based access control
- Restricting access to information based on a person's job role and what they need to see.
- Safeguarding
- Protecting people's health, wellbeing and rights and keeping them safe from abuse, harm or neglect.
- Senior Information Risk Owner (SIRO)
- The senior person accountable for managing information risk across an organisation.
- Special category data
- Particularly sensitive personal data, such as health, sex life, ethnicity or religious beliefs, that needs extra protection.
- Standard Contractual Clauses
- Approved standard contract terms used to lawfully transfer personal data to another country.
- Subject access request (SAR)
- A person's legal right to ask for a copy of the personal information an organisation holds about them.
- Transport Layer Security (TLS)
- A widely used method of encrypting data as it travels across the internet.
- Triage
- The process of assessing and prioritising patients according to the urgency and nature of their needs.
- UK General Data Protection Regulation (UK GDPR)
- The United Kingdom's main data-protection law governing how personal information is collected and used.
- Virtual private network (VPN)
- A secure, encrypted connection that protects data sent over a public or untrusted network.