Jump to content

Recommended Posts

Posted

We have had a letter from the NHS Child Health Information Service asking for names, dates of birth and addresses for all our pupils to track immunisations. They want termly updates with any changes - which is rather a pain in itself. Due to change in school secretary and GDPR reviews it has been passed to me to look at.

 

Is this all perfectly normal? Anyone know if this is definitely a legal requirement? Not that I think we would not comply, but if it is that makes things straightforward from a data protection point of view.

Posted
We have had a letter from the NHS Child Health Information Service asking for names, dates of birth and addresses for all our pupils to track immunisations. They want termly updates with any changes - which is rather a pain in itself. Due to change in school secretary and GDPR reviews it has been passed to me to look at.

 

Is this all perfectly normal? Anyone know if this is definitely a legal requirement? Not that I think we would not comply, but if it is that makes things straightforward from a data protection point of view.

 

Before anyone else says it

 

Check the source is genuine

 

and get serious advise about Data Protection and who you can share that info with

 

sounds a bit dodgy to me

Posted
Check the source is genuine

I was concerned about that, but the email address is an NHS one and the phone numbers match with those given out for immunisation services on our county council website, so I think the source is genuine.

Posted
"Not that I think we would not comply" - stop - ask yourself, what is the school's legal basis to give those data to any third party? This seems a surprising request, to say the least, both from the POV they should already have those data if it's Public Health England and it's not a school's responsibility (time / cost). There *is* a new NHS child health programme, but no one can just come long and say "send me all your cildren's names and other personal data" and be OK even if it 'sounds legit'. Send nothing, and lots of questions to be asked. Legal basis - yes you need to know the piece of legislation that permits you to. What's the purpose. Where's the documentation. What's the secure transfer mechansim. What's the retention and destruction plan. Where will it be stored. Wil they onwardly share with others. What data will they link it with. What communication materials and privacy policy do they provide for you to give to parents and pupils. How do you deal with refusals?
  • Thanks 2
Posted
Following on from Jen's post ... the first thing to do would be to contact the DPO/SIRO of the trust and ask for confirmation that data is being requested from the Trust and ask for where there is any agreement that the data will be shared.
  • Thanks 1
Posted
.....both from the POV they should already have those data if it's Public Health England

 

If the school nursing team is providing vaccinations in bulk (BCG), they don't know that the Fred Bloggs in 9J who's just about to get his BCG is the same Fred Bloggs born on 01/09/2005 who lives at 29a Acacia Rd and is a patient of Dr Nick at Parkside Surgery in Nuneaton.

 

And anecdotally, the school nursing team (for values of Lincolnshire) is sometime left in the dark by the rest of the NHS.

Posted (edited)

I've just asked our school administrator and we do pass this information to the NHS.... but only after we've obtained written consent from the parents.

 

We do this for height and weight monitoring, hearing tests, sight tests and vaccinations. Separate form every time.

 

This also gives parents the opportunity to tell us if the child had already had a vaccination so they don't get it twice.

Edited by jmak
  • Thanks 1
Posted
This also gives parents the opportunity to tell us if the child had already had a vaccination so they don't get it twice.

 

Which is presumably why the NHS are asking in this instance too. I remember not being vaccinated for something with everyone else at school because my GP had done it when I saw them about something else.

 

The schools may well be the only source of this information. The GPs would know Fred Bloggs born on 01/09/2005 who lives at 29a Acacia Rd and is a patient of Dr Nick at Parkside Surgery in Nuneaton has had that vaccine already, but they don't know which school Fred attends.

 

Of course, all this comes with the slight risk it is assuming parents know what vaccines their children have had...

Posted
Which is presumably why the NHS are asking in this instance too. I remember not being vaccinated for something with everyone else at school because my GP had done it when I saw them about something else.

 

The schools may well be the only source of this information. The GPs would know Fred Bloggs born on 01/09/2005 who lives at 29a Acacia Rd and is a patient of Dr Nick at Parkside Surgery in Nuneaton has had that vaccine already, but they don't know which school Fred attends.

 

Of course, all this comes with the slight risk it is assuming parents know what vaccines their children have had...

Parents' consent is also required for data protection purposes before it can be shared. They need to actively opt in once informed exactly what the data will be used for.
  • Thanks 1
Posted
Parents' consent is also required for data protection purposes before it can be shared. They need to actively opt in once informed exactly what the data will be used for.

 

There are exceptions to that, which cover the learning resources we all use, e.g. Google Apps, Mathswatch and so forth. Whether those exceptions apply here depends on the exact nature of the relationship between the school and the NHS, and why the data is being requested.

Posted

Damn complicated stuff this, but after establishing that the request was genuinely from the NHS immunisation people, I'd assume that explicit consent was not required. It's covered by the the clause that says

 

... processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller

Posted

While I'd agree that immunisation is in the public interest - I think kids should be refused a place in school until they've had MMR - parents have the right to opt out.

 

Like you say, complicated and you've got a logical case, but I'd still be wary...

Posted
While I'd agree that immunisation is in the public interest - I think kids should be refused a place in school until they've had MMR - parents have the right to opt out.

 

Like you say, complicated and you've got a logical case, but I'd still be wary...

:mod:

 

We won't explore the rights and wrongs of vaccines and school admission in this thread. Please keep it on the topic of the data request.

 

:mod:

Posted
:mod:

 

We won't explore the rights and wrongs of vaccines and school admission in this thread. Please keep it on the topic of the data request.

 

:mod:

Feeling suitably admonished [emoji58]

 

It was clumsy and inappropriate to the thread, but what I was trying to get at is that not everyone's idea of what is in the public interest is the same, so on balance, I would get permission before sharing.

  • Thanks 1
Posted (edited)

Thank you for your responses everyone. Sorry I did not get back to this thread earlier today.

 

"Not that I think we would not comply" - stop

I should have said "necessarily not comply". I meant that if it is not a legal requirement, we might still comply as we do want our children vaccinated, but it is more complicated as we have to work out that legal basis (explicit parent consent?) and the school has to make a decision about whether we should be doing this.

 

 

It is helpful to know that this seems surprising to nearly everyone else. I did talk to the vaccination people yesterday, their answer was not very satisfactory, hence my post above.

They said they wanted the information to be able to send out consent letters for vaccination to the pupil's addresses. They needed us to send regular updates to the information for data protection reasons, to make sure the letters did not go to the wrong place. Now I am thinking, if this is the only reason, why can't we send out the consent letters and get the parents to consent to us sharing data at the same time. That would seem much safer.

 

They were originally suggesting just sending the data by email. When I said that was not satisfactory they said we could use the egress switch secure email system. It seems legitimate, but details like retention period are not listed in their public privacy policy, they are supposed to be in Egress' contract with the NHS.

 

Grumbledook's idea of contacting their data protection officer sounds like a good next step. The privacy policy on the Trust's website just points me to their communications team, so I suppose I shall ring them.

 

 

What's the retention and destruction plan. Where will it be stored. Wil they onwardly share with others. What data will they link it with.

This makes me realise I am not sure of a legal point. Do we have a responsibility to vet the policies of data controllers to whom we transfer data, if the legal basis for that transfer is valid? We clearly have an obligation to check out all these things and get them in a written contract if we are passing the data to a data processor, but what if we are passing to a completely separate data controller (as I think would apply in this case). If the legal basis for the transfer was data subject consent then I suppose that could not be informed unless we gave the subject access to information about retention times etc. But if the legal basis is something like "compliance with a legal obligation" or "protect the vital interests of the data subject", then I am not sure what our obligations are. The controller we are transferring to has a responsibility to inform the data subject about these things, so maybe the responsibility passes to them? Or are we still deemed reckless if we have not checked these things out?

Edited by Jollity
Posted
not everyone's idea of what is in the public interest is the same

 

That's a very valid point, actually. Presumably, initially it is down to the Data Controller to define public interest, and ultimately the ICO to rule on it if someone complains (and thus set precedent for us all)

Posted

As the NHS has very strict rules and data access - based on the Caldicot Principles - I would contact they trusts Caldicot Guardian (they have to have one) and check that they are aware of the sharing of patient address via insecure emails

at the very least they need to know that trust employees are suggesting such things and may not be aware of the risks

  • Thanks 2
  • 9 months later...
Posted

Bit of a Necro but wondered if anyone else was having this come up again? We have had the request from the NHS, it is confirmed, and if we do not share the data it means our school nurse has to do a metric ton of paperwork and data entry. BUT them asking for details on an excel spreadsheet via email seems silly.

 

Now our data person is basically saying a big fat no, we will not share with the NHS, they should talk to the GPs.

 

They have added:

From 25 May 2018 KCHFT has a legal duty to process this information under Article 6 (1) © of the General Data Protection Regulation’s –

processing is necessary for compliance with a legal obligation to which the controller is subject.

 

Article 6 (1) (e) - processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller.

 

What are other schools doing?

Posted

What are other schools doing?

 

Currently pondering the supposedly reassuring "We're super-serious about data protection" emails from the NHS nursing team and seeing everyone in the "To:" field.

  • Thanks 1
  • 2 weeks later...
Posted
From 25 May 2018 KCHFT has a legal duty to process this information under Article 6 (1) © of the General Data Protection Regulation’s –

processing is necessary for compliance with a legal obligation to which the controller is subject

 

We got the same letter. I did eventually get clarification from them that they understood the legal obligation to share the data was under Section 10 of the Children’s Act 2004

Children’s Act 2004:

Section 10:- Co – operation to improve well-being

Subsection 1

· Each children’s services authority in England must make arrangements to promote co-operation between:

o (b) each of the authority’s relevant partners: and

o (c ) such other persons or bodies as the authority considers appropriate, being persons or bodies of any nature who exercise functions or are engaged in activities in relation in the authority’s area.

Subsection 2

· The arrangements are to be made with a view to improving the well-being of children in the authority’s area so far as relating to:

o (a) physical and mental health and emotional well-being

o (e) social and economic well-being

Subsection 4

· Relevant partner:

o The governing body of a maintained school that is maintained by the authority;

o The proprietor of a school approved by the Secretary of State under section 342 of the Education Act 1996 and situated in the authority’s area;

o The proprietor of a city technology college, city college for the technology of the arts or Academy situated in the authority’s area;

o The governing body of an institution within the further education sector the main site of which is situated in the authority’s area;

There seems to be a general duty of cooperation. Interested to hear what other people think, but I think they may have a valid legal basis for requesting the data as a legal duty.

 

However, in Kent at least they really ought to be asking us to share it in a more sensible way. The best I have got from them is that we can encrypt the spreadsheet and send the password to a different email address.

  • Thanks 1
Posted
We got the same letter. I did eventually get clarification from them that they understood the legal obligation to share the data was under Section 10 of the Children’s Act 2004

 

There seems to be a general duty of cooperation. Interested to hear what other people think, but I think they may have a valid legal basis for requesting the data as a legal duty.

 

However, in Kent at least they really ought to be asking us to share it in a more sensible way. The best I have got from them is that we can encrypt the spreadsheet and send the password to a different email address.

Many thanks. That is good to have as our compliance guy is saying don't share as we don't have to. I've had nothing back from the Caldicott Guardian so I think that is a dead end, especially as the number hidden away I eventually found has been redirected to a different department!
Posted

The sharing may be Controller to Controller to allow them to comply with their legal obligations ... however you should complete a DPIA and ask for a copy of theirs so that you are taking due care when sharing data.

If you do share data then it should be transported in a safe and secure manner. If that cannot be guaranteed then you cannot share. There is nothing that’s says *they* have to provide the method of transfer ... you could set up a secure pickup box that they have to use. It may be an inconvenience for them, but you have to be safe and secure.

  • 1 year later...

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...