Privacy Notice – Healthy Living Fair Processing Notice
Introduction
This document is an extension of our platform Privacy Policy.
This notice applies to you when you choose to register and participate with the Healthy Living for people with type 2 diabetes programme. Changing Health Limited has been commissioned by NHS England (NHSE) to deliver the “Healthy Living for people with type 2 diabetes” Service (the Programme) which aims to deliver structured education for diabetes patients via a digital tool to help to change the behaviours and health of people with type 2 diabetes. For further details of the Programme please use the following link NHS England » Healthy Living for People with Type 2 Diabetes.
Changing Health has been requested by NHSE to process information about you for the Programme and to inform an evaluation of the service. Changing Health will collect information about you from the digital service itself and this notice details the information that is required from you to participate in the Programme and how it will be used. This document should be read in conjunction with the Changing Health digital platform Privacy Policy.
Please note that you need to be over 18 years old to use this service, and a resident in the United Kingdom.
Data controller
NHSE is the Controller of the data and has identified the following lawful basis for processing your personal data for the Programme and evaluation:
- GDPR Article 6 (1) (e) – Processing is necessary for the performance of a public task carried out in the public interest or in the exercise of official authority vested in the controller under the NHS Act 2006 as amended by the Health and Social Care Act 2012, Part 2, Chapter A1.
- GDPR Article 9 (2) (h) – Processing is necessary for the purposes of preventive or occupational medicine, the provision of health or social care or treatment and the management of health or social care systems and services
To satisfy the common law duty of confidentiality, your participation in the Programme will be taken as your consent for processing your data for these purposes.
Information required for the education programme and how it will be used
Type of Personal data | Source of data | Purpose for processing |
---|---|---|
Basic contact details, name, surname, telephone number, email address and postcode | You will enter this yourself if you complete a Self-referral, or the organisation making the referral for you will enter the information. | Contact and communications |
NHS number | This will be obtained from the NHS Digital Personal Demographics Service or the organisation making the referral for you will provide the information. | For the maintenance of accurate healthcare records and the National Diabetes Audit to monitor diabetes education attendance and completion. |
Date of birth | You will enter this yourself if you complete a Self-referral. or the organisation making the referral for you will enter the information. | To ensure eligibility for the programme, as you must be over the age of 18. |
Demographic information including ethnic origin, first language, gender, disability status | You will be asked to input this information. | • A statutory duty to monitor equality of access to the service • Reporting purposes • Service improvements • To respond to individual’s needs |
Health information, including Smoking Status, height at baseline, Weight at baseline, BMI, HbA1c blood tests result at baseline, diabetes type, date of diagnosis | You will enter this yourself if you complete a Self-referral. or the organisation making the referral for you will enter the information. | • To ensure eligibility for the programme • To provide an individual service tailored to individual needs |
Personal goals and achievements, data inputted into our tools and trackers including steps, food content, HbA1c, goals and plans | You will be asked to input this information. | To provide an individual service tailored to individual needs. |
Programme usage data including, type of referral, Number of activities completed, pages visited, personalised emails sent, log ins, browser and device type, type of activities completed, time and frequency of logins | The Digital Platform will generate this information. | To provide an individual service tailored to individual needs and to address any concerns and improve the service. |
Opinions and evaluations of the service that we have provided | You will be asked to input this information. | To provide an individual service tailored to individual needs and to address any concerns and improve the service. |
Communications with the service provider support desk by e-mail or recorded telephone call | You will be asked to input this information. | To investigate or prevent any complaints or incidents raised. |
Programme survey data | You will be asked to input this information. | • To support your success on the programme and share progress with relevant parties • To investigate or prevent any complaints or incidents raised |
Changing Health will collect this information about you to find out if the digital service you receive has resulted in any behaviour or health changes and, under contract to NHSE, is responsible for the recording, processing and securely storing the information you provide via the participant data monitoring form (the main form used to record your information during the Programme), creating your profile, and any information that you input as part of your engagement with the Programme.
Sharing with third parties
Your identifiable personal data will be shared with:
- The organisation who made the original referral (where you have been referred to the programme)
- Your GP practice if you have consented to share your information with them to update your patient record (where you have self-referred to the programme)
- NHS Digital (NHSD):
- To establish your NHS Number – more information below
- To link your data with the National Diabetes Audit Data – more information below
- NHS Digital Data Services for Commissioners Regional Offices (DSCRO’s)
- To remove any identifying details and add a special code through a process called pseudonymisation, to allow your data to be linked to the National Diabetes Audit Data and shared for service monitoring purposes with SCW and NHSE without anyone knowing your identity.
Non-identifiable data will be shared with:
- The University of Manchester – for evaluation of the Programme; more information about this is included below.
- NHSE – for service monitoring and contract management.
NHSE will receive data in relation to the Programme and the contract in place to provide it. NHSE has asked SCW Commissioning Support Unit (SCW) to manage this on their behalf. To undertake contract management, data management and business intelligence services, SCW will access data that does not identify you as it has been pseudonymised by NHSD prior to it being made available.
Programme Evaluation – University of Manchester
An independent evaluation will be undertaken by the University of Manchester to help NHS England understand whether the Healthy Living Programme helps people to manage their type 2 diabetes. This will be completed with the assistance of NHSD sharing data from the National Diabetes Audit and using data collected by Changing Health. Your data will be pseudonymised by Changing Health and NHSD before is it shared with the evaluation team. This means that personal information such as your name and contact details will be removed, some personal information will be replaced with codes that the evaluation team will be provided the definitions for, and you will be assigned a unique identification number that will be used to link the data from Changing Health with the data within the National Diabetes Audit.
Individuals cannot be identified from the information provided by Changing Health or NHSD to the University of Manchester. For more information about the evaluation please visit ARC GM | Diabetes and Pre-Diabetes (nihr.ac.uk)
Information sharing with NHS Digital (NHSD)
Personal Demographics Service
Changing Health will use the Personal Demographics Service to identify your NHS number to:
- Match your usage data to your patient record
- Match your usage data to the National Diabetes Audit (NDA), managed by NHSD
Access to the Personal Demographics Service is strictly monitored; more information can be obtained here Demographics – NHS Digital.
The purpose of this linkage to the NDA is to enable evaluation of the implementation of this project.
Your name, surname, date of birth and postcode will be securely shared with NHSD to match your information to your NHS number. Your NHS number will then be securely shared with Changing Health to add to your participant monitoring data.
National Diabetes Audit (NDA)
Changing Health will share the following identifiable personal data with NHSD for the purposes of matching programme completion data with the NDA to update the audit with structured education programme usage:
- Name
- DOB
- Postcode
- NHS Number
- Structured Education completion status: Accepted or Completed the Programme
More information about the NDA can be found at National Diabetes Audit Programme – NHS Digital
Information sharing with your GP practice
Self-referrals:
Information on your use of the Programme will only be shared with your GP practice if you provide consent to do so on your registration. It will be used to keep your patient record up to date and inform your health care team that you are using the programme to help manage your type 2 diabetes.
The following will be shared:
- Name
- NHS Number
- Postcode
- Status: Accepted or Completed the Programme
Referrals from North West London Know Diabetes Hub:
Information on your use of the Programme will only be shared with your GP practice if you provide consent to do so on your registration. It will be used to keep your patient record up to date and inform your health care team that you are using the programme to help manage your type 2 diabetes.
The following will be shared:
- Name
- NHS Number
- Postcode
- Status: Accepted or Completed the Programme
Referrals from South London Diabetes Book and Learn Hub:
We will confirm if your referral to Healthy Living has been accepted or declined, and when you have completed the Programme.
The following will be shared:
- Name
- NHS Number
- Postcode
- Status: Accepted or Declined, and Completed the Programme
The Diabetes Book and Learn hub will share the structured education status information with your GP to update your health care record.
GP referrals:
We will confirm if your referral to Healthy Living has been accepted or declined, and when you have completed the Programme.
The following will be shared:
- Name
- NHS Number
- Postcode
- Status: Accepted or Declined, and Completed the Programme.
GP Connect
We use a facility called GP Connect to support your direct care. GP Connect makes patient information available to all appropriate clinicians when and where they need it, to support direct patient care, leading to improvements in both care and outcomes.
GP Connect is not used for any purpose other than direct care.
Authorised Clinicians such as GPs, NHS 111 Clinicians, Care Home Nurses (if you are in a Care Home), Secondary Care Trusts, Social Care Clinicians are able to access the GP records of the patients they are treating via a secure NHS Digital service called GP connect.
The NHS 111 service (and other services determined locally e.g. Other GP practices in a Primary Care Network) will be able to book appointments for patients at GP practices and other local services.
Legal basis for sharing this data
In order for your Personal Data to be shared or processed, an appropriate “legal basis” needs to be in place and recorded. The legal bases for direct care via GP Connect is the same as the legal bases for the care you would receive from your own GP, or another healthcare provider:
- for the processing of personal data: Article 6.1 (e) of the UK GDPR: “processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller”.
- for the processing of “Special Category Data” (which includes your medical information): Article 9.2 (h) of the UK GDPR: “processing is necessary for the purposes of preventive or occupational medicine, for the assessment of the working capacity of the employee, medical diagnosis, the provision of health or social care or treatment or the management of health or social care systems and services”.
Your rights
Because the legal bases used for your care using GP Connect are the same as used in other direct care situations, the legal rights you have over this data under UK GDPR will also be the same- these are listed elsewhere in our privacy notice. Find out more about GP Connect
Feedback and Comments
Any feedback or comments submitted to the programme will be reviewed and may be used in future publicity for the programme but will only include your:
- First name
- Location
- Diabetes diagnosis and time since diagnosis
- Feedback or comment
Additional personal identifiable information will only be included as part of the publicity where you have expressly consented to this.
How long your information will be kept for
Subject to the requirements of applicable law (and including in that your deletion right in respect of personal data), your information shall be kept by Changing Health for 1 year following the end of the contract with NHSE. At this point it will be deleted from the digital platform in accordance with the Changing Health data deletion policy. Should you wish to withdraw from the Programme at any time you can delete your account on the digital platform or alternatively request Changing Health to do this for you. This will delete your data from the Changing Health digital platform.
Information security
All organisations involved have policies and procedures in place to make sure only authorised and trained personnel access your information and that your information is handled and stored in a safe and secure way.
If you would like further information in relation to the information security procedures in place, please contact the relevant organisation.
Your rights
You have the right to request access to the identifiable personal information held by the organisations that hold data about you in relation to this Programme; this is more often known as a subject access request. Your GP, the organisation that processed your referral, NHSD and Changing Health will hold your personal data in relation to your participation in this service.
To exercise this right, you should contact the Controller of the record you wish to access. Your GP will hold limited information relating to the Programme but will hold more health information in your medical records. If an organisation has referred you, they may hold information about you in addition to that used for the Programme.
You can view the data that Changing Health hold in your Profile and account information within the platform.
For further information regarding making a request, please contact the relevant organisation.
The University of Manchester and NHS England will not hold identifiable personal data as only data with identifiers removed will be processed by them therefore, they will not be able to identify personal data belonging to you and therefore you are unable to exercise the right of access.
You have the right to request that Changing Health stops processing your personal data for the Programme and can exercise this right by deleting your account. If you do decide to withdraw from the programme, where your data has been shared prior to the withdrawal date it may not be possible to prevent further processing of this information by the organisations that it has been shared with, but a withdrawn status will be applied to your record and shared with them. Where the data processed contains your information but in a way that does not identify you, this data will continue to be processed but will reflect a ‘withdrawn from the Programme status’ and so will no longer be actively processed.
Contact information
If you have any queries about this notice or need further information you can use the details below:
Changing Health Limited, The Catalyst, Newcastle Helix, 3 Science Square, Newcastle upon Tyne, NE4 5TG, help@support.changinghealth.com
NHS England and NHS Improvement, Quarry House, Quarry Hill, Leeds, LS2 7UE NHS England » Contact us
The Information Commissioners Office is the UK’s independent authority set up to uphold information rights in the public interest, promoting openness by public bodies and data privacy for individuals. They can be contacted at Contact us | ICO
Cookies
There are various ways you can restrict the use of specific cookies, for example by changing your browser, privacy or security settings. Some cookies are essential and cannot be restricted or need to be permanently disabled in order for them not to reapply on your next visit. Also disabling certain types of cookies could impact on the functionality of the website itself. Further information in relation to how to amend these settings can usually be found by following the help or FAQs option of your browser or by visiting www.allaboutcookies.org.
For a detailed information about our Cookies Policy please look into our platform Cookies Policy.
There are various ways you can restrict the use of specific cookies, for example by changing your browser, privacy, or security settings. Some cookies are essential and cannot be restricted or need to be permanently disabled for them not to reapply on your next visit. Also disabling certain types of cookies could impact on the functionality of the website itself. Further information in relation to how to amend these settings can usually be found by following the help or FAQs option of your browser or by visiting www.allaboutcookies.org.
For detailed information about the Changing Health Cookies Policy please see Cookies Policy.
This notice was last updated on the 06-05-2022.