Your Information And How We Use It - Privacy / Fair Processing Notice – Data Protection Act (1998)

Our CCG holds some information about you. This document outlines how that information is used, who we may share that information with and how we keep it secure. The full document can be pdf downloaded here (428 KB)

This notice does not provide exhaustive detail. However, we are happy to provide any additional information or explanation needed. Any requests for this should be sent to the address;

NHS Lincolnshire East Clinical Commissioning (CCG)
Address: Cross O Cliff, Bracebridge Heath, Lincoln LN4 2HN

We keep our Privacy Notice under regular review. This Privacy Notice was last reviewed in September 2016.

1. What we do

Our CCG is responsible for planning, buying and monitoring (also known as commissioning) health services from healthcare providers such as hospitals and GP practices for our local population to ensure the highest quality of healthcare. We also have a performance monitoring role of these services, which includes responding to any concerns from our patients on services offered.

2. How we use your information

Our CCG holds some information about you and this document outlines how that information is used, who we may share that information with, how we keep it secure (confidential) and what your rights are in relation to this.

3. What kind of information we use?

We use the following types of information/data:

• identifiable - containing details that identify individuals
• pseudonymised - about individuals but with identifying details (such as name or NHS number) replaced with a unique code
• anonymised - about individuals but with identifying details removed
• aggregated - anonymised information grouped together so that it doesn't identify individuals

4. What do we use anonymised data for?

We use anonymised data to plan health care services. Specifically we use it to:

• check the quality and efficiency of the health services we commission
• prepare performance reports on the services we commission.
• work out what illnesses people will have in the future, so we can plan and prioritise services and ensure these meet the needs of patients in the future
• review the care being provided to make sure it is of the highest standard

5. What do we use your sensitive and personal information for?

There are some limited exceptions where we may hold and use sensitive personal information about you. For example the CCG is required by law to perform certain services that involve the processing of sensitive personal information.

The areas where we regularly use sensitive personal information include:

• a process where you or your GP can request special treatments that is not routinely funded by the NHS, which are known as Individual Funding Requests
• assessments for continuing healthcare and appeals
• responding to your queries, compliments or concerns
• assessment and evaluation of safeguarding concerns
• where there is a provision permitting the use of sensitive personal information under specific conditions, for example to:

• understand the local population needs and plan for future requirements, which is known as “risk Stratification for commissioning".
• ensure that the CCG is billed accurately for the treatment of its patients, which is known as “invoice validation”.

Sensitive personal information may also be used in the following cases:

• where the information is necessary for your direct healthcare
• where we are responding to patients, carers or Member of Parliament communication
• where you have freely given your informed agreement (consent) for us to use your information for a specific purpose
• where there is an overriding public interest in using the information e.g. in order to safeguard an individual, or to prevent a serious crime
• where there is a legal requirement that will allow us to use or provide information (e.g. a formal court order).

6. Do you share my information with other organisations?

We commission a number of organisations (both within and outside the NHS) to provide healthcare services to you. We may share anonymised statistical information with them for the purpose of improving local services, for example understanding how health conditions spread across our local area compared against other areas.

The law provides some NHS bodies, particularly NHS Digital (formerly the Health and Social Care Information Centre), with ways of collecting and using patient data that cannot identify a person, to help commissioners to design and procure the combination of services that best suit the population they serve.

We may also share information with NHS England and NHS Digital. If you do not want your information to be used for purposes beyond providing your direct care you can choose to opt-out. If you wish to do so, please contact your GP practice and they will mark your choice in your medical record. You can opt out of your data being used for some purposes. You can withdraw your opt-out choice at any time by informing your GP practice. More information is available on NHS Digital Your personal information choices

NHS Digital takes the responsibility for looking after care information very seriously. Please follow links on how we look after information for more detailed documentation.

NHS England recognises the importance of protecting personal and confidential information in all that they do, all that they direct or commission, and takes care to meet its legal duties. Follow the links on the How we use your information page for more details. 

7. Datasets accessed by the CCG

GP Data and Secondary Uses Service (SUS) data (in-patient, out-patient and A&E) may be de-identified and linked so that it can be used to improve healthcare and development and monitor NHS performance. Where data is used for these statistical purposes, stringent measures are taken to ensure individual patients cannot be identified.

When analysing current health services and proposals for developing future services it is sometimes necessary to link separate individual datasets to be able to produce a comprehensive evaluation. This may involve linking primary care GP data with other data such as SUS data. In some cases there may also be a need to link local datasets which could include a range of acute-based services such as radiology, physiotherapy, audiology etc., as well as mental health and community-based services such as Improving Access to Psychological Therapies (IAPT), district nursing, podiatry etc. When carrying out this analysis, the linkage of these datasets is always done using a unique identifier that does not reveal a person’s identity, as the CCG does not have any access to patient identifiable data.

We may also contract with other organisations to process data. These organisations are known as Data Processors. We ensure external data processors that support us are legally and contractually bound to operate and prove security arrangements are in place, where data that could or does identify a person are processed. 

8. Currently, the external data processors we work with include (amongst others):

  • NHS Arden & Greater East Midlands Commissioning Support Unit (AGEM CSU) and
  • OPTUM Commissioning Support Services (OPTUM CSS)

9. Paying Invoices – invoice validation

The validation of invoices is undertaken in line with NHS requirements to ensure that the CCG is paying for treatments relating to its patients only. AGEM CSU receives identifiable data into their Controlled Environment for Finance (CEfF) to securely support the invoice validation process. As Data Processor for the CCG, AGEM CSU is allowed to process Personal Confidential Data (PCD) which is required for invoice validation purposes. This approval is subject to a set of conditions. The legal basis for this processing is under the Health Service (Control of Patient Information) Regulations 2002 (a) also known as ‘section 251 support’) and details of Confidentiality Advisory Group (CAG) approval CAG 7-07(a-c)/2013 are provided at http://www.hra.nhs.uk/?s=register

OPTUM CSS receives pseudonymised information from AGEM CSU and undertake a number of checks to ensure invoices are valid and should be paid for by the CCG. The CCG does no receive or see any patient level information relating to these invoices.

10. What are your rights?

Where information from which you can be identified is held, you have the right to ask to:

• view this or request copies of the records by making a subject access request
• request information is corrected
• have the information updated where it is no longer accurate
• ask us to stop processing information about you where we are not required to do so by law – although we will first need to explain how this may affect the care you receive

11. What safeguards are in place to ensure data that identifies me is secure?

We only use information that may identify you in accordance with the Data Protection Act 1998. The Data Protection Act requires us to process personal data only if there is a legitimate basis for doing so and that any processing must be fair and lawful.
Within the health sector, we also have to follow the common law duty of confidence, which means that where identifiable information about you has been given in confidence, it should be treated as confidential and only shared for the purpose of providing direct healthcare. 

This applies to all of our staff, and they are required to protect your information, inform you of how your information will be used, and allow you to decide if and how your information can be shared. All CCG staff are expected to make sure information is kept confidential and receive annual training on how to do this. This is monitored by the CCG and can be enforced through disciplinary procedures.

We also ensure the information we hold is kept in secure locations, restrict access to information to authorised personnel only, protect personal and confidential information held on equipment such as laptops with encryption (which masks data so that unauthorised users cannot see or make sense of it). 

We ensure external data processors that support us are legally and contractually bound to operate and prove security arrangements are in place where data that could or does identify a person are processed.

The CCG has an Executive Director, Tracy Pilcher (Chief Nurse) responsible for protecting the confidentiality of patient information. This person is called the Caldicott Guardian and can be contacted on This email address is being protected from spambots. You need JavaScript enabled to view it.

The CCG is registered with the Information Commissioner’s Office (ICO) as a data controller and collects data for a variety of purposes. A copy of the registration is available through the ICO website (search by CCG name). 

12. How long do you hold confidential information for?

All records held by the CCG will be kept for the duration specified by national guidance from the Department of Health. 

13. Gaining access to the data we hold about you

The CCG does not directly provide health care services and therefore does not hold personal healthcare records. If you wish to have sight of, or obtain copies of your of your own personal health care records you will need to apply to your GP Practice, the hospital or NHS Organisation which provided your health care.

Every individual has the right to see, or have a copy, of data held that can identify you, with some exceptions. You do not need to give a reason to see your data, but you may be charged a fee.

If you want to access your data you must make the request in writing. Under special circumstances, some information may be withheld.

If you wish to have a copy of the information we hold about you, please note that there may be a charge for this (of up to £50) please contact:

NHS Lincolnshire East CCG, Cross O’ Cliff, Bracebridge Heath, Lincoln LN4 2HN tel: 01522 515 308 

14. Your right to opt out

In some instances, you are allowed to request that your confidential information is not used beyond your own care and treatment and to have your objections considered. If your wishes cannot be followed, you will be told the reasons (including the legal basis) for that decision. This includes situations such as to fulfil our safeguarding obligations and any areas where we have legal obligations to share your information.

If you wish to exercise your right to opt-out, or to speak to somebody to understand what impact this may have, if any, please contact: NHS Lincolnshire East CCG, Cross O’ Cliff, Bracebridge Heath, Lincoln LN4 2HN tel: 01522 515 308

15. What is the right to know?

The Freedom of Information Act 2000 (FOIA) gives people a general right of access to information held by or on behalf of public authorities, promoting a culture of openness and accountability across the public sector.

16. What sort of information can I request?

In theory, you can request any information that we hold, that does not fall under an exemption. You may not ask for information that is covered by the Data Protection Act.

17. How do I make a request for information under the Freedom of Information Act?

Your request must be in writing and can be either posted or emailed to OPTUM CSS at the address detailed below. The service is managed by the team at Optum Commissioning Support Services. 

Email: This email address is being protected from spambots. You need JavaScript enabled to view it. 

For postal requests, please send to the following address: 

Optum Commissioning Support Services
South Kesteven District Council Offices
St. Peter’s Hill
Grantham
Lincolnshire NG31 6PZ.

18. For independent advice about data protection, privacy, data sharing issues and your rights you can contact:

Information Commissioner’s Office
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Telephone: 0303 123 1113 (local rate) or 01625 545 745
Email: This email address is being protected from spambots. You need JavaScript enabled to view it.
ICO website https://ico.org.uk/

19. Website technical details

a. Forms

We do use electronic forms on our website making use of an available ‘forms module’ which has a number of built-in features to help ensure privacy. We also aim to use secure forms where appropriate.

In compliance with EU legislation, the following table lists the use of cookies on this web site:

Cookie Name

Purpose
useTextOnly This is used to store whether you are in textOnly mode or not.
Persistent for three months.
setString This is used to store user preferences for viewing sites in textOnly mode e.g. font-size and colour.
Persistent for one month.
SitekitLogin This is used to store the username and password for ‘remember my login’ feature on extranets.
Persistent for one month.
SKSession This cookie has two functions.
Firstly it serves as a session cookie for extranet users. Without this cookie, an extranet user will have to login to each individual page in the extranet.
It also enables us to track the pages that a user visits while they navigate around the site.
AcceptCookies This is used to store whether you have agreed to receive cookies.
Persistent for one year.
Google Analytics
_utma
_utmb
_utmc
_utmz
These cookies are used to collect information about how visitors use our site. We use the information to compile reports and to help us improve the site. The cookies collect information in an anonymous form, including the number of visitors to the site, where visitors have come to the site from and the pages they visited.

Cookies are small. We do not make use of cookies to collect any private or personally identifiable information. The technical platform of this website uses cookies solely to aid the proper technical functioning of the website. The cookies used contain random strings of characters alongside minimal information about the state and session of the website – which in no way collects or discloses any personal information about you as a visitor.

Cookies are small. We do not make use of cookies to collect any private or personally identifiable information. The technical platform of this website uses cookies solely to aid the proper technical functioning of the website. The cookies used contain random strings of characters alongside minimal information about the state and session of the website – which in no way collects or discloses any personal information about you as a visitor.

If you chose to, for any secure pages of this website, you can elect to save login information in a cookie to facilitate faster login to a private area of this site. A notification is given before any such cookie is dropped, and the process is ultimately within your control. Even where this is used, the cookie still contains minimal authentication information, and does not contain any private or personal data.

Advanced areas of this site may use cookies to store your presentation preferences in a purely technical fashion with no individually identifiable information. Note also our statement on analytics software below – as analytics software also uses cookies to function.

Most web browsers allow some control of most cookies through the browser settings. To find out more about cookies, including how to see what cookies have been set and how to manage and delete them, visit www.allaboutcookies.org.

To opt out of being tracked by Google Analytics across all websites visit http://tools.google.com/dlpage/gaoptout.

20. Data retention policy

Our platform operates with a clear data-retention policy in order to comply with the Privacy Enhancing Technology guidance from the Information Commissioner. This means that data has predefined time limits for storage and is only retained by the system for as long as it is considered useful.

21. Server statistics

Like almost all websites, we have access to server statistics which provide aggregate statistics on bandwidth and server load. This load data is used to manage bandwidth effectively and for billing purposes. It is important for us to collect and monitor this information because we pay for a server bandwidth allowance and are liable for the costs of increases beyond our allowance.

The server statistics are not designed to collect any individually identifiable information and the reports we receive are generally numerical and in graph format.

Alongside the server statistics, our Content Management System, collects information on: popular search terms used on the website, which we have access to in order to arrange our pages better; visitor path information, which we have access to for future design considerations; and download popularity (numerical by month), which we use to organise the file libraries better.

22. Analytics

Like most websites, we make use of analytics software in order to help us understand the trends in popularity of our website and of different sections. We make no use of personally identifiable information in any of the statistical reports we use from this package.

We use an analytics package called Google Analytics who provide details of their privacy policy on the Google website.