Data management policy
| Policy title | Dental Community Interest Company (CIC) Data Management Policy |
| Version number | |
| Effective from date | March 2024 |
| Applicable to | All staff employed by the University of Suffolk Dental Community Interest Company |
| Owner | Dental Community Interest Company (CIC) |
| Date EIA completed | |
| Approving Committee(s) | Dental Project Board |
| Date of approval | |
| Review date | October 2024 |
University of Suffolk
Data Management Policy
Purpose
This document explains the University of Suffolk Dental Community Interest Company (hereafter known as” Dental CIC”) policy on data protection and data security and is based on the following principles:
- The Dental CIC will comply with all relevant legislation, particularly the Data Protection Act 2018 and the UK General Data Protection Regulations (“GDPR”).
- Ensuring compliance is a corporate responsibility of the Dental CIC requiring the active involvement of, and appreciation by, all staff at all levels of the organisation. The Dental CIC will provide support and services to enable staff handling personal data to remain compliant with the legislation and the Dental CIC’s requirements in respect of data security.
About the Policy
At the Dental CIC personal data from a wide range of individuals is collected, analysed, stored, shared, transferred, processed and at the end of the retention period, destroyed . Personal data used in this way is from staff, patients and visitors.. Maintaining the security and privacy of their personal data is essential. This policy sets out the Dental CIC requirements as Data Controller when processing Personal Data
This Policy has been approved by CEO/Board of Dental CIC and the University of Suffolk Data Governance and Digital & IT teams. This is subject to review every year. Review will take place earlier where changes in legislation require such review.
A Dental CIC Data User is defined as staff and others who have access to and use Personal Data on behalf of the Dental CIC. All Dental CIC Data Users must
- comply with this Policy when processing Personal Data on behalf of the Dental CIC
- recognise that they have a role to play in ensuring that the Dental CIC maintains the trust and confidence of the individuals about whom the Dental CIC processes personal data (including it’s own staff)
- comply with legal obligations and protect the Dental CIC’s reputation
Disciplinary action can be taken against those who do not comply, particularly in cases when there has been deliberate, wilful or negligent disregard of the Policy and Dental CIC requirements.
The Dental CIC has policies in place, including this Policy, which are designed to protect the accuracy, integrity and confidentiality of personal data and to ensure that individuals are able to exercise their rights. Appendix 1 provides more information about these other policies.
Key words are defined in the Glossary of Terms in Appendix 2.
If you do not feel confident in your knowledge or understanding of this Policy, or you have concerns regarding the implementation of this Policy, you should raise this with the Data Protection Officer to seek advice:
Data Protection Officer – datagovernance@uos.ac.uk or 01473 338240
Training
All staff involved in the Dental CIC will undertake appropriate GDPR training, using a training package provided through iLearn. New members of staff must complete this module as part of their induction. It is the responsibility of managers to ensure that their staff complete the required training, including any additional training required, both as part of their induction and biennially thereafter, a copy of training record will be available via iLearn. It is also the responsibility of managers to follow up any incomplete training.
Data Protection Principles
The GDPR sets out principles that the Dental CIC must observe and comply with when processing Personal Data. The GDPR requires that personal data shall:
- be processed lawfully, fairly and in a transparent manner
- be collected only for specified, explicit and legitimate purposes
- be adequate, relevant and limited to what is necessary in relation to the purposes for which it is to be processed
- be accurate and, where necessary, kept up to date
- not be kept in a form which permits identification of data subjects for longer than is necessary for the purposes for which the data is processed
- be processed in a manner than ensures its security using appropriate technical and organisational measures to protect against unauthorised or unlawful processing and against accident loss, destruction or damage
- not be transferred to a country outside of the European Economic Area (EEA) without appropriate safeguards being in place
Further information on the Data Protection Principles can be found on the Information Commissioner’s website (ICO – Data Protection Principles).
The Dental CIC and its staff who process or use personal data must be able to demonstrate compliance with all of the above principles.
Accountability and Governance
The Dental CIC is responsible for, and must be able to demonstrate, compliance with the GDPR and data protection.
There are several actions the Dental CIC, and its Data Users, can and, in some cases, must take to meet this data protection principle, including:
- Implementation of Data Management Policy
- Taking a ‘data protection by design and default’ approach
- Ensuring that written contracts are in place with organisations that process personal data on the Dental CIC’s behalf
- Maintaining documentation of all Dental CIC processing activities
- Implementing appropriate security measures
- Recording and, where required, reporting personal data breaches
- Carrying out data protection impact assessments (DPIAs) where the use of personal data is likely to result in a high risk to individuals’ interests
- Appointment of a Data Protection Officer
- Adherence to relevant codes of conduct and signing up to certification schemes
Registering with the Information Commissioner’s Office (ICO) as a Data Controller
As an organisation that processes personal and special category data, the Dental CIC is required to register with the ICO. The ICO publishes contact details for the Dental CIC and the Dental CIC Data Protection Officer, fee information, any trading names used by the Dental CIC and the data protection registration number given by the ICO ZB628668 as a public authority data controller.
Data Protection Officer
The Dental CIC Data Protection Officer, supported by the University of Suffolk Data Governance Team advises the Dental CIC on data protection law, monitors compliance, provides advice to Data Users, and ensures that guidance, training and resources are available to Data Users. The Data Protection Officer is the point of contact for individuals wishing to exercise their rights in relation to their data, and for any contact with the ICO. Contact details for the Data Protection Officer and their team who deal with general queries and Subject Access Requests are as follows:
Data Protection Officer datagovernance@uos.ac.uk
01473 338240
Legal basis for processing
Whenever the Dental CIC processes personal data there must be a valid lawful basis for that processing. There are six potentially applicable lawful bases for general processing of Personal Data and ten lawful bases for processing Special Category Data. If Special Category Data is being processed, both a lawful basis for general processing and an additional condition for processing this type of data must be identified. These are listed in full in Appendix 3 and Appendix 5.
In practice, for many of the Dental CIC’s activities it will rely on the legal basis that;
We have your consent – this must be freely given, specific, informed and unambiguous. This would apply to cookies collected on the Dental CIC website.
We need it to perform a public task – a public body, such as an NHS organisation or Care Quality Commission (CQC) registered social care organisation, is required to undertake particular activities by law. See this list for the most likely laws that apply when using and sharing information in health and care.
Storing Personal Information
Your information is securely stored for the time periods specified in the Records Management Code of Practice and our own data retention schedules. We will then dispose of the information as recommended by the Records Management Code for example we will:
- securely dispose of your information by deleting data at the end of the retention period and wiping hard drives to legal standards of destruction.
Profiling and Automated Decision Making
The ICO has produced guidance (Automated decision-making and profiling) on Profiling and Automated Decision Making which is available on its website and should be taken into account before considering any activity or task which involves Profiling or Automated Decision Making.
Before starting a task or activity which involves Profiling or Automated Decision Making, the following steps must be carried out:
- A Data Protection Impact Assessment (DPIA) must be carried out. The Data Protection Officer must be informed and consulted as part of that exercise
- A Privacy Notice must inform individuals if their data will be used for solely automated decision-making processes with legal or similarly significant effects. This must explicitly set out the Data Subject’s rights. The Privacy Notice should be approved by the Data Protection Officer
- The DPIA must be kept under regular review, and records of those reviews must be retained
Data Protection by Design and Data Privacy Impact Assessments (DPIAs)
An aspect of the accountability and governance data protection principle, the Dental CIC must ensure that consideration is given to the protection of data from design through the life cycle of the process or system.
It is therefore the responsibility of any Dental CIC staff member introducing or designing a new process or system, to take account of the data protection principles and ensure that data protection laws are complied with and can be demonstrated.
A DPIA enables Data Users to identify and minimise the data protection risks of a project. A DPIA must be completed for any data processing that is likely to result in a high risk to individuals. It is also good practice to complete a DPIA for major projects which will require the processing of personal data.
A DPIA should:
- Provide a description of the nature, scope, context and purposes of the processing
- Assess necessity, proportionality and compliance measures
- Identify and assess risks to individuals
- Identify additional measures required to mitigate the risks
Further information about DPIAs is available on the ICO website (ICO – Data Protection Impact Assessments).
DPIAs should be shared with the Dental CIC Data Protection Officer prior to sign-off and commencement of the project.
Security
Purpose
This Data Security Policy outlines the procedures and guidelines for safeguarding, managing, and storing sensitive information at the Dental CIC. Its primary aim is to ensure the confidentiality, integrity, and availability of data, in compliance with all relevant laws and regulations.
Scope
This policy applies to all staff, contractors, and any individual or entity accessing or handling Dental CIC data, systems, or networks.
Data Classification
- Sensitive Data: Information classified as sensitive includes, but is not limited to, personally identifiable data, financial data, health records, intellectual property, and any data covered under legal, contractual, or regulatory requirements.
- Internal Data: Information not publicly available but not classified as sensitive.
- Public Data: Information that can be freely shared without restrictions.
Responsibilities
- Dental CIC: Responsible for overseeing the implementation, compliance, and regular review of this policy.
- Data Owners: Dental CIC senior staff and Dental CIC Caldicott Guardian, responsible for defining data classifications, access levels, and ensuring appropriate protection measures.
- Digital and Network Provider: Responsible for maintaining secure systems, networks, providing technical support, and enforcing security measures.
- Users: Required to adhere to this policy, including securing access credentials, reporting security incidents, and following best practices for data protection.
Data Security Measures
- Access Control: Grant access to data on a need-to-know basis. Use strong authentication methods, including passwords, multi-factor authentication (MFA), and least privilege principles.
- Encryption: Encrypt sensitive data in transit and at rest using industry-standard encryption algorithms.
- Data Handling: Ensure secure handling, transmission, and storage of sensitive information. Ensure no storing of sensitive data on personal devices unless encrypted and authorised.
- Security Awareness Training: Regularly train and educate staff, students, and relevant parties on data security best practices and policies.
- Incident Response Plan: Develop and maintain a comprehensive incident response plan to address data breaches, including reporting procedures, containment, and recovery.
- Regular Audits and Assessments: Conduct periodic security audits, risk assessments, and vulnerability scans to identify and mitigate potential threats.
Compliance and Legal Obligations
- Adhere to all relevant data protection laws and regulations, including the General Data Protection Regulation (GDPR), Data Protection Act, and any other applicable legislation.
- Obtain necessary consents and permissions before collecting, processing, or sharing personal data.
Promptly report any suspected or actual data security incidents, breaches, or violations to the Data governance team who will liaise with the Digital and Network provider and the designated authorities.
Individuals Rights
In accordance with the GDPR and the Data Protection Act 2018 every Data Subject has the following rights:
- The right to be informed about how their personal data may be processed
- The right of access to their personal data held by Dental CIC
- The right to rectification if their personal data is inaccurate or incomplete
- The right to request deletion or removal of personal data where there is no compelling reason for its continued processing
- The right to restrict processing in certain circumstances
- The right to data portability which allows individuals to obtain and reuse their personal data for their own purposes across different services
- The right to object to processing in certain circumstances
- Rights in relation to automated decision making and profiling
More information about the rights of individuals can be found on the ICO website (ICO – Individual Rights).
Information about submitting a Subject Access Request or Freedom of Information request to the Dental CIC can be found on the Dental CIC website or by contacting datagovernance@uos.ac.uk
The Dental CIC must respond to any requests from Data Subjects wishing to exercise these rights within strict time limits. Therefore, all requests from individuals wishing to exercise rights must be forwarded to the Dental CIC Data Protection Officer immediately on datagovernance@uos.ac.uk. Similarly, staff must prioritise requests from the Dental CIC Data Protection Officer and their team to assist with processing a Data Subject request, to ensure compliance with Data Protection Laws.
Data Breach Management
Everyone is responsible for ensuring that data security breaches are avoided; where one does occur, you should report it immediately to the Dental CIC Operational Manager via email to C.Maskall@UOS.AC.UK and to the Data Governance team on datagovernance@uos.ac.uk or 01473 338240.
Personal data breaches can include:
- Access by an unauthorised third party
- Deliberate or accidental action (or inaction) by a controller or processor
- Sending personal data to an incorrect recipient
- Computing devices containing personal data being lost or stolen
- Alteration of personal data without permission
- Loss of availability of personal data
Some types of breach must be reported to the ICO by the Dental CIC Data Protection Officer within 72 hours. The sooner the breach is reported, the sooner action can be taken and the greater the opportunity to limit any potential damage which might be caused by the incident.
The Dental CIC Data Protection Officer will determine whether it is necessary to report the personal data breach to either the ICO for the affected Data Subjects, or necessary third parties.
The general procedure in the case of a Dental CIC data security breach will follow ICO guidelines and focus on the completion of the four stages of breach management:
- Containment and recovery
- Assessment of on-going risk
- Notification of breach
- Evaluation and response
It is the responsibility of the Dental CIC Data Protection Officer and Data Governance team to ensure that a record of all Dental CIC breaches, regardless of whether they are required to be reported to the ICO is retained and that the Chief Operating Officer and Dental CIC Chief Executive Officer is informed of reportable instances.
Annual Reporting
The Dental CIC will provide an annual report on information, CQC compliance, governance, completion of NHS Data protection and Security toolkit assessment as well as NHS Digital Technology Assessment Criteria to the Dental CIC Board.
Queries, Concerns and Complaints
Any queries, concerns, or complaints about the processing of Personal Data by Dental CIC or in relation to the exercise of any Data Subject rights should be directed to the Dental CIC Data Protection Officer in the first instance on datagovernance@uos.ac.uk
Any person who is not satisfied with the way the University has handled Personal Data or a request to exercise Data Subject rights may complain to the ICO (ICO).
Responsibilities
Within this policy, the following post-holders have these responsibilities:
| Responsibility | Owner |
| Administration of Dental CIC subject access requests, response to data protection enquiries from staff and students | Data Governance Team and Dental CIC Data Protection Officer |
| Initial investigation and management of Dental CIC data security breaches | Operational Manager, Data Governance Team and Dental CIC Data Protection Officer |
| Overall responsibility for Data Management Policy, authorisation of actions related to data security breaches, management and oversight of the Dental CIC, raising awareness of data protection across the Dental CIC, and the provision of training and information for staff and students | Operational Manager and Dental CIC Data Protection Officer |
| Overall responsibility for those aspects of data security relating to Dental CIC information technology systems | Operational Manager and Digital and Network Provider |
| Strategic liaison regarding data protection and data security with the Dental CIC Board | Operational Manager and Dental CIC Data Protection Officer |
| Institutional approval of Data Protection Policy | Dental CIC Board |
| Personal data to be handled in line with the Dental CIC Data Protection Policy, best practice and data protection legislation | Staff and students handling personal data |
APPENDICES
Appendix 1: Policies
University of Suffolk Data Management Policy
Code of Practice for Managing Freedom of Information Requests
Dental CIC Privacy Notice
Employees and Other Workers Privacy Notice
Privacy Notice for Candidates and Applicants
Appendix 2: Glossary of Terms
| Automated Decision-Making | A decision made by automated means without any human involvement |
| Consent | Agreement, which is freely given, specific, informed and unambiguous |
| Criminal Offences Data | Data relating to criminal convictions and offences or related security measures. |
| Data Breach | The destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. This means that a breach is more than just losing personal data |
| Data Controller | The person or organisation that determines when, why and how to process personal data |
| Data Privacy Impact Assessment | A standard assessment used to identify and reduce risks of a data processing activity |
| Data Processor | Any person, company or organisation (other than an employee of the data controller) who processes personal data on behalf of a Data Controller |
| Data Protection Officer (DPO) | An internal, statutory role, required to monitor and promote compliance with data protection legislation |
| Data Protection Laws | Any law which relates to the protection of individuals with regards to the processing of Personal Data including Regulation (EU) 2016/679 (known as the General Data Protection Regulation or GDPR), the Data Protection Act 2018 and all legislation enacted in the UK in respect of the protection of personal data, and any code of practice or guidance published by the Information Commissioner’s Office. |
| Data Retention | Data retention principles are set out in the University’s privacy notices on the website. |
| Data Subject | Any living, identified or identifiable individual about whom we hold Personal Data |
| Data Users | Staff, students and others who have access to and use Personal Data on behalf of the University |
| Individuals Rights | The rights granted to Data Subjects by the applicable data protection legislation, including the right of access to their Personal Data, the right to correct it, and the right to deletion |
| Personal Data | Any information identifying a Data Subject or from which we could identify a Data Subject. Personal Data includes ‘Special Categories’ of sensitive personal data and Pseudonymised Data but not anonymised data (data where any identifying elements have been removed) |
| Special Categories of Personal Data | A subset of Personal Data, being any information revealing racial or ethnic origin, political opinions, religious or similar beliefs, trade union membership, physical or mental health conditions, sexual life or sexual orientation, biometric or genetic data, and Personal Data relating to criminal offences and convictions |
| Processing or Process | Any activity that involve the use of Personal Data, whether manual or electronic, including obtaining, recording or holding the data, organising, amending, transferring, retrieving, using, disclosing, erasing or destroying it |
| Privacy Notices | Separate notices setting out information that may be provided to Data Subjects when the University collects information about them. These notices may apply to a specific group of individuals, for example employees or they may cover a specific purpose, for example filming on campus |
| Pseudonymised Data | Data which has been modified to replace information that directly or indirectly identifies an individual with artificial identifiers or pseudonyms so that the person, to whom the data relates, cannot be identified without the use of additional information which is kept separately and secure |
| Third Party | Anyone other than the Data Subject and the Data Controller |
| Recruitment privacy notices | This privacy notice explains how we collect, use and store personal information about you in the context of applying for employment with us and our recruitment process. It explains the circumstances where we may also have to share personal information. |
Appendix 3: Legal bases for processing
Processing shall be lawful only if and to the extent that at least one of the following applies:
- The Data Subject has given consent to the processing of his or her personal data for one or more specific purposes.
- Processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the Data Subject prior to entering into a contract.
- Processing is necessary for compliance with a legal obligation to which the Data Controller is subject.
- Processing is necessary in order to protect the vital interests of the Data Subject or of another natural person.
- Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Data Controller.
- Processing is necessary for the purposes of the legitimate interests pursued by the Data Controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the Data Subject which require protection of personal data, in particular where the Data Subject is a child. (This does not apply to processing carried out by public authorities, such as Universities, in the performance of their public tasks).
There are 10 legal bases on which Special Category Personal Data may be processed:
- The Data Subject has given explicit consent to the processing of those personal data for one or more specified purposes.
- Processing is necessary for the purposes of carrying out the obligations and rights of the Data Controller or of the Data Subject in the field of employment and social security (subject to the Data Protection Act 2018).
- Processing is necessary to protect the vital interests of the Data Subject or of another natural person where the data subject is physically or legally incapable of giving consent.
- Processing is carried out in the course of its legitimate activities with appropriate safeguards by a foundation, association or any other not-for-profit body with a political, philosophical, religious or trade union aim and on condition that the processing relates solely to the members or to former members of the body or to persons who have regular contact with it in connection with its purposes and that the personal data are not disclosed outside that body without the consent of the Data Subjects; 12 Revised Data Protection Policy 27.06.2018.
- Processing relates to personal data which are manifestly made public by the Data Subject.
- Processing is necessary for the establishment, exercise or defence of legal claims or whenever courts are acting in their judicial capacity.
- Processing is necessary for reasons of substantial public interest, on the basis of Union or Member State law which shall be proportionate to the aim pursued, respect the essence of the right to data protection and provide for suitable and specific measures to safeguard the fundamental rights and the interests of the Data Subject.
- Processing is necessary for the purposes of preventive or occupational medicine, for the assessment of the working capacity of the employee, medical diagnosis, the provision of health or social care or treatment or the management of health or social care systems and services on the basis of Union or Member State law or pursuant to contract with a health professional and subject to safeguards.
- Processing is necessary for reasons of public interest in the area of public health, such as protecting against serious cross-border threats to health or ensuring high standards of quality and safety of health care and of medicinal products or medical devices, on the basis of Union or Member State law which provides for suitable and specific measures to safeguard the rights and freedoms of the Data Subject, in particular professional secrecy; L 119/38 EN Official Journal of the European Union 4.5.2016.
- Processing is necessary for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes, respect the essence of the right to data protection and provide for suitable and specific measures to safeguard the fundamental rights and the interests of the Data Subject.
Appendix 4: Sources of information, guidance and advice
Data Protection Officer (DPO) datagovernance@uos.ac.uk
01473 338240
Dental CIC Operational Manager- Chrystal Maskall- C.Maskall@UOS.AC.UK
Data Protection Resources:
- ICO resources (https://ico.org.uk/)
- Laws that health and care organisations rely on when using your information [https://transform.england.nhs.uk/information-governance/the-laws-that-health-and-care-organisations-rely-on-when-using-your-information/ ]
- National Data Opt-Out [https://digital.nhs.uk/services/national-data-opt-out/compliance-with-the-national-data-opt-out]
- NHS Data Security and Protection Toolkit [https://www.dsptoolkit.nhs.uk/]
- NHS Digital Technology Assessment Criteria [https://transform.england.nhs.uk/key-tools-and-info/digital-technology-assessment-criteria-dtac/]
- Use and share information with confidence – NHS Transformation Directorate (england.nhs.uk)
Appendix 5: Lawful basis for processing special category data
Under UK GDPR, the lawful basis we rely on for using information that is more sensitive (special category):
To provide and manage health or social care (with a basis in law). See this list for the most likely laws that apply when using and sharing information in health and care.
To manage public health (with a basis in law). See this list for the most likely laws that apply when using and sharing information in health and care.
Common law duty of confidentiality
In our use of health and care information, we satisfy the common law duty of confidentiality because:
- you have provided us with your consent (we have taken it as implied to provide you with care, or you have given it explicitly for other uses)
- we have a legal requirement to collect, share and use the data
- for specific individual cases, we have assessed that the public interest to share the data overrides the public interest served by protecting the duty of confidentiality (for example sharing information with the police to support the detection or prevention of serious crime). This will always be considered on a case by case basis, with careful assessment of whether it is appropriate to share the particular information, balanced against the public interest in maintaining a confidential health service
National data opt-out
- we are applying the national data opt-out because we are using confidential patient information for planning or research purposes
The information collected about you when you use health and care services can also be used and provided to other organisations for purposes beyond your individual care, for instance to help with:
- improving the quality and standards of care provided
- monitoring safety
This may only take place when there is a clear lawful basis to use this information. All these uses help to provide better health and care for you, your family and future generations. Confidential health and care information is only used like this when allowed by law.
You have a choice about whether you want your confidential information to be used in this way. If you are happy with this use of information you do not need to do anything. If you do choose to opt out your confidential information will still be used to support your individual care.
To find out more or to register your choice to opt out, please visit www.nhs.uk/your-nhs-data-matters.
You can change your mind about your choice at any time.
