Who we are
Central East Integrated Care Board (ICB) will secure the provision of health services by taking on the commissioning functions of the previous three ICBs who came together to form Central East ICB, develop and maintain a plan to meet the health needs of our population, set out the strategic direction for our Integrated Care System (ICS) and agree an annual capital resource use plan.
The (ICB) has various roles and responsibilities, a major part of our work involves making sure that:
- contracts are in place with local health service providers;
- routine and emergency NHS services are available to patients;
- those services provide high quality care and value for money; and
- paying those services for the care and treatment they have provided.
This is called “commissioning”. For further information please refer to the ‘About us’ section of the website
Accurate, timely and relevant information is essential for our work to help us to design and plan current and future health and care services, evidence and review our decisions and manage budgets.
What is a privacy notice?
This Privacy Notice tells you about information we collect and hold about you, what we do with it, how we will look after it and who we might share it with.
It covers information we collect directly from you or receive from other individuals or organisations.
This notice is not exhaustive. However, we are happy to provide any additional information or explanation needed using the contact details at the end of this notice.
You have certain legal rights, including a right to have your information processed fairly, lawfully and in a transparent manner, and a right to access any personal information we hold about you. These are just some of the rights provided to you under the UK GDPR and DPA 2018. Below is a list of further rights.
You have the right to privacy and to expect the NHS to keep your information confidential and secure.
If we do hold identifiable information about you, you can ask us to correct any mistakes by contacting us at the address detailed in the Contact Us section below.
You have the right to ask us to stop processing information about you where we are not required to do so by law – although we will first need to explain how this may affect the care you receive.
In some instances, you are allowed to request that your confidential information is not used beyond your own care and treatment and to have your objections considered. If your wishes cannot be followed, you will be told the reason (including the legal basis) for that decision.
If you wish to exercise your right to opt-out, or to speak to somebody to understand the impact this may have, if any, please contact us.
If you wish to know what personal information the ICB holds about you, or to request access to that information, then please contact us.
To protect your confidentiality, you will have to provide proof of who you are.
We are committed to protecting your privacy and will only process personal confidential data in accordance with the UK GDPR and Data Protection Act 2018 (DPA 2018), the Common Law Duty of Confidentiality and the Human Rights Act 1998. The various laws and rules about using and sharing confidential information, with which the ICB will comply, are available in “A guide to confidentiality in health and social care” which is published on the NHS Digital (now merged with NHS England) website.
Central East ICB is a Data Controller under the terms of the UK GDPR/DPA 2018 we are legally responsible for ensuring that whenever we collect, use, hold, obtain, record or share personal confidential data about you, we do it in compliance with data protection legislation.
As NHS Central East ICB is a data controller, we must be registered with the Information Commissioner’s Office (ICO). Our Information Commissioner’s Office registration reference is ZC107760.
Everyone working for the NHS has a legal duty to keep information about you confidential. The NHS Care Record Guarantee and NHS Constitution provide a commitment that all NHS organisations and those providing care on behalf of the NHS will use records about you in ways that respect your rights and promote your health and wellbeing.
All identifiable information that we hold about you will be held securely and confidentially. We use administrative and technical controls to do this. We use strict controls to ensure that only authorised staff are able to see information that identifies you. A limited number of authorised staff have access to information that identifies you, but only where it is appropriate to their role and strictly on a need-to-know basis.
All health and social care organisations are required to provide annual evidence of compliance with applicable laws, regulations and standards through the Data Security and Protection Toolkit (DSPT). Further information regarding Information Governance and the Data Security and Protection Toolkit can be found in Further Definitions and Terms.
All of our staff, contractors and board and committee members receive appropriate and on-going training to ensure they are aware of their personal responsibilities and have contractual obligations to uphold confidentiality, enforceable through disciplinary procedures. All staff are trained to ensure they understand how to recognise and report an incident and the organisation has procedures for investigating, managing and learning lessons from any incidents that occur.
We will only retain information in accordance with the schedules set out in the Records Management Code of Practice Care 2021. The ICB’s Records Management Policies include guidance around the secure destruction of information in line with the Code of Practice.
The ICB has several key roles which support the protection of your data:
Caldicott Guardian – The ICB’s Caldicott Guardian is a senior person responsible for protecting the confidentiality of patient and service-user information and enabling appropriate information sharing. The Guardian actively supports work to enable information sharing where it is appropriate to share and advises on options for lawful and ethical processing of information.
Senior Information Risk Owner (SIRO) – The ICB’s SIRO is an Executive Director with overall responsibility for an organisation’s information risk policy. The SIRO is accountable and responsible for information risk across the organisation. The SIRO ensures that everyone is aware of their personal responsibility to exercise good judgement, and to safeguard and share information appropriately.
Data Protection Officer (DPO) – The ICB’s DPOs assist our organisation to monitor internal compliance, inform and advise on our data protection obligations, provide advice regarding Data Protection Impact Assessments (DPIAs) and acts as a contact point for data subjects and the Information Commissioner’s Office (ICO).
The NHS provides a wide range of services which involve the collection and use of information. Different care settings are considered as either ‘primary care’ or ‘secondary care’.
Primary care settings include GP practices, pharmacists, dentists and some specialised services such as military health services. Secondary care settings include local hospitals, rehabilitative care, urgent and emergency care (including out of hours and NHS 111), community and mental health services.
Throughout this Privacy Notice you will see reference to an organisation called NHS England. They are the national provider of information, data and IT systems for commissioners (such as the ICB), analysts and clinicians in health and social care. NHS England provides information based on identifiable information passed securely to them by Primary and Secondary Care Providers who are legally obliged to provide this information.
Get more information on the way NHS England collects and uses your information.
In the circumstances where we are required to use personal identifiable information we will only do this if:
We have permission from the Secretary of State for Health to use certain confidential patient identifiable information when it is necessary for our work.
- The information is necessary for your direct healthcare, or
- We have received explicit consent from you to use your information for a specific purpose, or
- There is an overriding public interest in using the information:
- in order to safeguard an individual,
- to prevent a serious crime
- in the case of Public Health or other emergencies, to protect the health and safety of others, or
- There is a legal requirement that allows or compels us to use or provide information (e.g. a formal court order or legislation), or
- We have permission from the Secretary of State for Health to use certain confidential patient identifiable information when it is necessary for our work.
Your personal information will only be shared in accordance with your rights under the UK General Data Protection Regulation, Data Protection Act 2018, the Common Law duty of confidentiality, the NHS Constitution and in keeping with professional and NHS Codes of Practice.
NHS England has published a guide to confidentiality in health and social care that explains the various laws and rules about the use and sharing of confidential information.
Safe and effective care is dependent upon relevant information being shared between all those involved in caring for a patient. When an individual agrees to being treated by the wider care team, it creates a direct care relationship between the individual patient and the health and social care professional and their team. All health and adult social care providers are subject to the statutory duty under section 251B of the Health and Social Care Act 2012 to share information about a patient for their direct care. This duty is subject to both the common law duty of confidence and the UK GDPR and Data Protection Act 2018.
For common law purposes, sharing information for direct care is on the basis of “implied consent”, which may also cover administrative purposes where the patient has been informed, or it is otherwise within their reasonable expectations. This means that information is shared without the individual having to give verbal or written agreement each time and only applies within the context of direct care.
Under UK GDPR the lawful basis for the processing of personal data in the delivery of direct care, and for providers’ administrative purposes, will be undertaken using Article 6(1)(e), “processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority”. Personal data in relation to health are special categories of personal data and the processing of this data for direct care or administrative purposes is undertaken using Article 9(2)(h), “…medical diagnosis, the provision of health or social care or treatment or the management of health or social care systems…”
In some circumstances other duties or obligations to share information outweigh confidentiality, and personal information is shared without consent, for example to ensure the safety of a child or vulnerable adult or to report a notifiable disease.
Your information will be used in a de-identified or anonymised form for purposes other than direct care, such as statistical and analytical information needed to assist the ICB, the NHS, Department of Health and health care partners.
Unless your information is being used for direct care or there is a legal requirement to share your information, you have the choice to opt-out. This opt-out is managed through the National Data Opt-Out programme.
You have the right to withhold consent or object to your information being shared, but in some circumstances, this may delay or affect the care you receive. Always consult your GP or relevant health professional before deciding to withhold consent to sharing your information, as they will be able to advise you on the possible outcomes of this decision.
We only collect and use your information for the lawful purposes of administering the business of NHS Central East ICB. We process personal information to enable us to support the provision of healthcare services to patients, maintain our own accounts and records, promote our services, and to support and manage our employees. To enable us to do this effectively we are often required to process personal data i.e. that which identifies a living individual.
There may be times when we need to hold and use certain information about you, for example:
- if we are involved in helping you to resolve a complaint with your GP or other NHS service provider.
- if we fund specialised treatment for you for a particular health condition that is not covered in our local contracts.
- if you are a member of our patient participation group or have asked us to keep you up to date about our work and involved in our engagement and public consultations.
The information we hold about you personally will therefore be with your knowledge and consent.
There may be times when we need to hold and use certain information for purposes such as:
- determining the general health needs of the population.
- ensuring that our services meet future patient needs.
- teaching and training healthcare professionals.
- investigating complaints, legal claims, etc.
- conducting health research and development.
- preparing statistics on NHS performance.
- auditing NHS accounts and service.
- paying your health care provider.
If you do have any concerns about us holding your personal information, then please tell us and we can explain the way this may affect our ability to help and discuss alternative arrangements available to you.
Your information will not be sent outside of the United Kingdom where the laws do not protect your privacy to the same extent as the law in the UK. We will never sell any information about you.
We will only use the minimum amount of information necessary about you. Our records may include relevant information that you have told us, or information provided on your behalf by relatives or those who care for you and know you well, or from health professionals and other staff directly involved in your care and treatment. Our records maybe held on paper or in a computer system. The types of information that we may collect and use include the following:
- Personal Confidential Data: This term describes personal information about identified or identifiable individuals, which should be kept private or secret. For the purposes of this notice ‘personal’ includes the DPA definition of personal data, but it is adapted to include dead as well as living people. ‘Confidential’ includes both information ‘given in confidence’ and ‘that which is owed a duty of confidence’ and is adapted to include ‘sensitive’ as defined in the Data Protection Act. Used interchangeably with ‘confidential’ in this document.
- Pseudonymised Information: This is data that has undergone a technical process that replaces your identifiable information such as a NHS number, postcode, date of birth with a unique identifier, which obscures the ‘real world’ identity of the individual patient to those working with the data.
- Anonymised Information: This is data rendered into a form which does not identify individuals and where there is little or no risk of identification (identification is not likely to take place).
Information in the ICB is held for a specific length of time depending on the type of information it is. The length of time we retain your information for is defined by the NHS retention schedule which can be viewed online here: Records Management Code of Practice for Health and Social Care 2021.
Once information has been reviewed and is no longer required to be kept by a retention period the information will be securely destroyed.
We need to use information in various forms about you and will only use the minimum amount of information necessary for the purpose. Where possible, we will use information that does not identify you. Details of Information collected and used for specific purposes is available.
Although this is not an exhaustive detailed listing, the following ‘Use of information’ section lists key examples of the purposes and rationale for why we collect and process information.
For specific uses of information for the services the ICB undertakes visit the uses of information page.
The national data opt-out was introduced on 25 May 2018, enabling patients to opt out from the use of their data for research or planning purposes, in line with the recommendations of the National Data Guardian in her Review of Data Security, Consent and Opt-Outs.
You can choose to stop your confidential patient information being used for research and planning. You can also make a choice for someone else like your children under the age of 13.
Your choice will only apply to the health and care system in England. This does not apply to health or care services accessed in Scotland, Wales or Northern Ireland.
Get further information and to apply your choice to opt-out.
The ICB aims to meet the highest standards when collecting and using personal information. For this reason, we take any complaints we receive on this subject very seriously.
We encourage people to bring concerns to our attention if they think that our collection or use of information is unfair, misleading or inappropriate. We would also welcome any suggestions for improving our procedures. Contact details for complaints to either Central East ICB or the ICO are below.
Contact Central East ICB
The contact details for our Data Protection Officer (Roz Samuel) and Data Security and IG team are: [email protected].
Address: Central East ICB, Gemini House, Bartholomew’s Walk, Cambridgeshire Business Park, Angel Drove, Ely, Cambridgeshire, CB7 4EA
Caldicott Guardian
Fiona Head, Executive Clinical Director
Deputy Caldicott Guardians
Lesley Deacon; Himani Ramkisson; Sanhita Chakrabarti
You can also contact the Information Commissioner’s Office
Wycliffe House, Water Lane, Wilmslow, Cheshire. SK9 5AF
01625 545745
Further information
Below are links to more information about your rights and the ways that the NHS uses personal information:
- The NHS Care Record Guarantee and the NHS Constitution, which govern the way in which the NHS uses patient confidential information;
- The NHS Digital Guide to Confidentiality in Health and Social Care;
- The National Data Guardian’s Panel advises on the state of Information Governance across the health and social care system in England;
- The Confidentiality Advisory Group is an independent body which provides expert advice to the Health Research Authority (HRA) for on use of confidential patient information for research uses. It also provides advice to the Secretary of State for Health on use of confidential patient information for non-research uses.
- NHS Digital
- Oracle Health | Oracle United Kingdom
- Prescribing Services
- The Information Commissioner’s Office
- National Data Opt-Out
Appendix: Strategic Commissioning Tool: Federated Data Platform (FDP) Product Privacy Notice
Strategic Commissioning Tool: Federated Data Platform (FDP) Product Privacy Notice