GDPPR/Ethnicity/Vaccine COVID-19 – CCG - Pseudo
NHS Sussex ICB · Sub ICB Location
Listed under NHS Surrey and Sussex Integrated Care Board.
Expired The latest version ended on 30 November 2022. The September 2026 register still lists the agreement, but its term has passed.
- Reference
- DARS-NIC-387074-L1X5J
- Latest version
- v3.2
- Term of latest version
- 4 March 2022 to 30 November 2022
- Start date
- 19 August 2020
- Data controller
- Joint Data Controller
- Commercial purposes
- No
- Sublicensing
- No
- Files released to date
- 0
Data controllers
- NHS Sussex ICB (named in the register 3 times, as different sub-ICB locations)
Why the data was released
Objective for processing
A letter has been issued to the Data Controller to amend the terms of this data sharing agreement.
The amendments to the agreement are as follows:
• The removal of CV19: Regulation 3 (4) of the Health Service (Control of Patient Information) Regulations 2002 as the legal basis for dissemination. The data is no longer described as “confidential”.
• The change of GDPR Article 6 legal basis from
- Article 6 (1) (c)
to
- Article 6 (1) (e)
• The extension of the DSA end date to 30/11/2022
The letter has been issued to ensure data continues to flow to support commissioning and allow all parties to work on the new agreements required to support new Integrated Care Board data sharing agreement.
NHS Digital has been provided with the necessary powers to support the Secretary of State’s response to COVID-19 under the COVID-19 Public Health Directions 2020 (COVID-19 Directions) and support various COVID-19 purposes, the data shared under this agreement can be used for these specified purposes except where they would require the reidentification of individuals.
GPES data for pandemic planning and research (GDPPR COVID 19)
To support the response to the outbreak, NHS Digital has been legally directed to collect and analyse healthcare information about patients from their GP record for the duration of the COVID-19 emergency period under the COVID-19 Directions.
The data which NHS Digital has collected and is providing under this agreement includes coded health data, which is held in a patient’s GP record, such as details of:
• diagnoses and findings
• medications and other prescribed items
• investigations, tests and results
• treatments and outcomes
• vaccinations and immunisations
Details of any sensitive SNOMED codes included in the GDPPR data set can be found in the Reference Data and GDPPR COVID 19 user guides hosted on the NHS Digital website. SNOMED codes are included in GDPPR data.
There are no free text record entries in the data.
The Controller will use the pseudonymised GDPPR COVID 19 data to provide intelligence to support their local response to the COVID-19 emergency. The data is analysed so that health care provision can be planned to support the needs of the population within the CCG area for the COVID-19 purposes.
Such uses of the data include but are not limited to:
• Analysis of missed appointments - Analysis of local missed/delayed referrals due to the COVID-19 crisis to estimate the potential impact and to estimate when ‘normal’ health and care services may resume, linked to Paragraph 2.2.3 of the COVID-19 Directions.
• Patient risk stratification and predictive modelling - to highlight patients at risk of requiring hospital admission due to COVID-19, computed using algorithms executed against linked de-identified data, and identification of future service delivery models linked to Paragraph 2.2.2 of the COVID-19 Directions. As with all risk stratification, this would lead to the identification of the characteristics of a cohort that could subsequently, and separately, be used to identify individuals for intervention. However the identification of individuals will not be done as part of this data sharing agreement, and the data shared under this agreement will not be reidentified.
• Resource Allocation - In order to assess system wide impact of COVID-19, the GDPPR COVID 19 data will allow reallocation of resources to the worst hit localities using their expertise in scenario planning, clinical impact and assessment of workforce needs, linked to Paragraph 2.2.4 of the COVID-19 Directions.
COVID Vaccine data
NHS England and NHS Digital have agreed that NHS Digital should become a joint controller of the Vaccine Data with NHS England under the COVID-19 Public Health (NHS England) Directions 2020 (COVID-19 Directions) to facilitate the analysis, linkage and dissemination of the Vaccine Data to requestors who have an appropriate legal basis to process it.
There is high demand from CCGs for the Vaccine Data which will help them;
- Understand vaccine categories and success of population roll out in their respective areas, required for weekly report to NHSE/Cabinet office
- Understand and decide whether new vaccine sites are required and stock control of vaccines to ensure immediate delivery/deploy to appropriate patients.
- Moderate and manage readmissions post vaccine e.g. how many patients are being re-admitted post vaccination
- Monitor secondary care Shielded patient activity post-vaccination.
- Identifying areas of low vaccine take-up and work directly with local communities and community leaders to address concerns.
- Ensure vulnerable individuals and groups are identified and supported through the vaccination process to ensure the maximum possible vaccination uptake.
NHS Digital has agreed to share the data with the recipients and their processors for the purpose of supporting the recipients in their local response to the COVID-19 emergency as part of the national response to the COVID-19 pandemic.
The Vaccine Data will include;
- Patient demographics
- Source organisation (where the vaccination data originated)
- Vaccination appointment and outcome details
- Vaccine batch details
COVID-19 Ethnic Category Data Set
NHS Digital has created a small stand-alone dataset known as the COVID-19 Ethnic Category Data Set. This data set is created using ethnic category data from the General Practice Extraction Service (GPES) Data for Pandemic Planning and Research (COVID-19) (GDPPR) and Hospital Episodes Statistics (HES). By combining GDPPR ethnic category data with the latest available ethnicity data in HES, NHS Digital can substantively increase coverage in ethnic category data and therefore add strength to the GDPPR dataset when linked.
LINKAGE
The data may only be linked by the Data Controller or their respective Data Processor, to other pseudonymised datasets which it holds under a current data sharing agreement only where such data is provided for the purposes of general commissioning by NHS Digital. The Health Service Control of Patient Information Regulations (COPI) will also apply to any data linked to the data under this agreement.
The linked data may only be used for purposes stipulated within this agreement and may only be held and used whilst both data sharing agreements are live and in date. Using the linked data for any other purposes, including non-COVID-19 purposes would be considered a breach of this agreement.
RE-IDENTIFICATION
Reidentification of individuals under the GDPPR data is not permitted under this DSA.
Reidentification of individuals under the vaccination dataset is permitted but only for the purposes of direct care and is strictly limited to direct health care professionals or local authority direct care staff only with a legitimate relationship to the patient. All re-identification requests will be processed and authorised by the DSCRO on a case by case basis.
LEGAL BASIS FOR PROCESSING DATA:
Legal Basis for NHS Digital to Disseminate the Data:
NHS Digital is able to disseminate data with the Recipients for the agreed purposes under a notice issued to NHS Digital by the Secretary of State for Health and Social Care under Regulation 3(4) of the Health Service Control of Patient Information Regulations (COPI) dated 17 March 2020 (the NHSD COPI Notice).
The Recipients are health organisations covered by Regulation 3(3) of COPI and the agreed purposes (paragraphs 2.2.2-2.2.4 of the COVID-19 Directions, as stated below in section 5a) for which the disseminated data is being shared are covered by Regulation 3(1) of COPI.
Under the Health and Social Care Act, NHS Digital is relying on section 261(5)(d) – necessary or expedient to share the disseminated data with the Recipients for the agreed purposes.
Legal Basis for Processing:
The Recipients are able to receive and process the disseminated data under a notice issued to the Recipients by the Secretary of State for Health and Social Care under Regulation 3(4) of COPI dated 20th March (the Recipient COPI Notice section 2).
The Secretary of State has issued notices under the Health Service Control of Patient Information Regulations 2002 requiring the following organisations to process information:
Health organisations
“Health Organisations” defined below under Regulation 3(3) of COPI includes CCGs for the reasons explained below. These are clinically led statutory NHS bodies responsible for the planning and commissioning of health care services for their local area
The Secretary of State for Health and Social Care has issued NHS Digital with a Notice under Regulation 3(4) of the National Health Service (Control of Patient Information Regulations) 2002 (COPI) to require NHS Digital to share confidential patient information with organisations permitted to process confidential information under Regulation 3(3) of COPI. These include:
• persons employed or engaged for the purposes of the health service
Under Section 26 of the Health and Social Care Act 2012, CCG’s have a duty to provide and manage health services for the population.
Regulation 7 of COPI includes certain limitations. The request has considered these limitations, considering data minimisation, access controls and technical and organisational measures.
Under GDPR, the Recipients can rely on Article 6(1)(c) – Legal Obligation to receive and process the Disclosed Data from NHS Digital for the Agreed Purposes under the Recipient COPI Notice. As this is health information and therefore special category personal data the Recipients can also rely on Article 9(2)(h) – preventative or occupational medicine and para 6 of Schedule 1 DPA – statutory purpose.
Processing activities
PROCESSING CONDITIONS:
Data must only be used for the purposes stipulated within this Data Sharing Agreement. Any additional disclosure / publication will require further approval from NHS Digital.
Data Processors must only act upon specific instructions from the Data Controller.
All access to data is managed under Role-Based Access Controls. Users can only access data authorised by their role and the tasks that they are required to undertake.
Patient level data will not be linked other than as specifically detailed within this Data Sharing Agreement.
NHS Digital reminds all organisations party to this agreement of the need to comply with the Data Sharing Framework Contract requirements, including those regarding the use (and purposes of that use) by “Personnel” (as defined within the Data Sharing Framework Contract i.e.: employees, agents and contractors of the Data Recipient who may have access to that data).
The Recipients will take all required security measures to protect the disseminated data and they will not generate copies of their cuts of the disseminated data unless this is strictly necessary. Where this is necessary, the Recipients will keep a log of all copies of the disseminated data and who is controlling them and ensure these are updated and destroyed securely.
Onward sharing of patient level data is not permitted under this agreement. Only aggregated reports with small number suppression can be shared externally.
The data disseminated will only be used for COVID-19 purposes as described in this DSA, any other purpose is excluded.
SEGREGATION:
Where the Data Processor and/or the Data Controller hold both identifiable and pseudonymised data, the data will be held separately so data cannot be linked.
AUDIT
All access to data is auditable by NHS Digital in accordance with the Data Sharing Framework Contract and NHS Digital terms.
Under the Local Audit and Accountability Act 2014, section 35, Secretary of State has power to audit all data that has flowed, including under COPI.
DATA MINIMISATION:
Data Minimisation in relation to the data sets listed within the application are listed below:
• Patients who are normally registered and/or resident within the CCG region (including historical activity where the patient was previously registered or resident in another commissioner area).
and/or
• Patients treated by a provider where the CCG is the host/co-ordinating commissioner and/or has the primary responsibility for the provider services in the local health economy.
and/or
• Activity identified by the provider and recorded as such within national systems (such as SUS+) as for the attention of the CCG.
The Data Services for Commissioners Regional Office (DSCRO) obtains the following data sets:
- GDPPR COVID 19 Data
- COVID Vaccine Data
- COVID-19 Ethnic Category Data Set
Pseudonymisation is completed within the DSCRO and is then disseminated as follows:
1. Pseudonymised GDPPR COVID 19, COVID Vaccine and COVID-19 Ethnic Category Data Set data is securely transferred from the DSCRO to the Data Controller / Processor
2. Aggregation of required data will be completed by the Controller (or the Processor as instructed by the Controller).
3. Patient level data may not be shared by the Controller (or any of its processors).
Expected output
• Operational planning to predict likely demand on primary, community and acute service for vulnerable patients due to the impact of COVID-19
• Analysis of resource allocation
• Investigating and monitoring the effects of COVID-19
• Patient Stratification in relation to COVID-19, such as:
o Patients at highest risk of admission
o Frail and elderly
o Patients that are currently in hospital
o Patients with prescriptions related to COVID-19
o Patients recently Discharged from hospital
• Reports for NHSE/Cabinet Office on the success of Vaccine rollout
• Identification of areas of low vaccine take up leading to work with local communities to address concerns
For avoidance of doubt these are pseudonymised patient cohorts, not identifiable.
Expected measurable benefits
• Manage demand and capacity
• Reallocation of resources
• Bring in additional workforce support
• Assists commissioners to make better decisions to support patients
• Identifying COVID-19 trends and risks to public health
• Enables CCGs to provide guidance and develop policies to respond to the outbreak
• Controlling and helping to prevent the spread of the virus
• Maintaining the high percentage of the population receiving the vaccination
Benefits reported so far
The CCGs have produced an annual report in which they describe the key achievements and developments, including those for pandemic response, for which processing NHS Digital data has contributed. These can be found at:
https://www.brightonandhoveccg.nhs.uk/wp-content/uploads/sites/5/2021/06/NHS-Brighton-and-Hove-CCG-Annual-Report-2020-21-website-version.pdf
https://www.westsussexccg.nhs.uk/wp-content/uploads/sites/4/2021/06/NHS-West-Sussex-CCG-Annual-Report-2020-21-website-version.pdf
https://www.eastsussexccg.nhs.uk/wp-content/uploads/sites/3/2021/06/NHS-East-Sussex-CCG-Annual-Report-2020-21-website-version.pdf
Datasets on the latest version
Legal basis for provision: CV19: Regulation 3 (4) of the Health Service (Control of Patient Information) Regulations 2002; Health and Social Care Act 2012 - s261(5)(d)
| Dataset | Type of data | Sensitivity | Frequency | Confidential data |
|---|---|---|---|---|
| COVID-19 Ethnic Category Data Set | Anonymised - ICO Code Compliant | Sensitive | Frequent Adhoc Flow | Statutory exemption to flow confidential data without consent |
| COVID-19 General Practice Extraction Service (GPES) Data for Pandemic Planning and Research (GDPPR) | Anonymised - ICO Code Compliant | Sensitive | Frequent Adhoc Flow | Statutory exemption to flow confidential data without consent |
| COVID-19 Vaccination Status | Anonymised - ICO Code Compliant | Sensitive | Frequent Adhoc Flow | Statutory exemption to flow confidential data without consent |
Files released
Files released counts only files released externally by DARS. Access granted in NHS England's own systems, such as its Secure Data Environment, is not included.
No files recorded as released under this agreement.
Version history
The register lists each renewal of this agreement as a separate row. This site has 4 versions.
DARS-NIC-387074-L1X5J-v3.2 4 March 2022 to 30 November 2022
- Title
- GDPPR/Ethnicity/Vaccine COVID-19 – CCG - Pseudo
- Commercial
- No
- Sublicensing
- No
- Datasets
- 3
- Files released
- 0
Datasets: COVID-19 Ethnic Category Data Set; COVID-19 General Practice Extraction Service (GPES) Data for Pandemic Planning and Research (GDPPR); COVID-19 Vaccination Status
What changed from DARS-NIC-387074-L1X5J-v2.2
Text removed is struck through; text added is underlined. Unchanged paragraphs are summarised rather than repeated.
| Field | Was | Became |
|---|---|---|
| Start date | 2022-03-04 | |
| End date | 2022-11-30 |
Objective for processing
A letter has been issued to the Data Controller to amend the terms of this data sharing agreement. The amendments to the agreement are as follows: • The removal of CV19: Regulation 3 (4) of the Health Service (Control of Patient Information) Regulations 2002 as the legal basis for dissemination. The data is no longer described as “confidential”. • The change of GDPR Article 6 legal basis from - Article 6 (1) (c) to - Article 6 (1) (e) • The extension of the DSA end date to 30/11/2022 The letter has been issued to ensure data continues to flow to support commissioning and allow all parties to work on the new agreements required to support new Integrated Care Board data sharing agreement. [54 paragraphs unchanged]
Benefits reported
The CCG is unable to evidence any achieved yielded benefits as of yet as they have not been able to process the data for a substantial amount of time.
The CCGs have produced an annual report in which they describe the key achievements and developments, including those for pandemic response, for which processing NHS Digital data has contributed. These can be found at:
https://www.brightonandhoveccg.nhs.uk/wp-content/uploads/sites/5/2021/06/NHS-Brighton-and-Hove-CCG-Annual-Report-2020-21-website-version.pdf
https://www.westsussexccg.nhs.uk/wp-content/uploads/sites/4/2021/06/NHS-West-Sussex-CCG-Annual-Report-2020-21-website-version.pdf
https://www.eastsussexccg.nhs.uk/wp-content/uploads/sites/3/2021/06/NHS-East-Sussex-CCG-Annual-Report-2020-21-website-version.pdf
Unchanged: Processing activities, Expected output, Expected measurable benefits.
DARS-NIC-387074-L1X5J-v2.2 10 September 2021 to 31 March 2022
- Title
- GDPPR/Ethnicity/Vaccine COVID-19 – CCG - Pseudo
- Commercial
- No
- Sublicensing
- No
- Datasets
- 3
- Files released
- 0
Datasets: COVID-19 Ethnic Category Data Set; COVID-19 General Practice Extraction Service (GPES) Data for Pandemic Planning and Research (GDPPR); COVID-19 Vaccination Status
What changed from DARS-NIC-387074-L1X5J-v1.2
Text removed is struck through; text added is underlined. Unchanged paragraphs are summarised rather than repeated.
| Field | Was | Became |
|---|---|---|
| Title | GDPPR/Ethnicity/Vaccine COVID-19 – CCG - Pseudo | |
| Start date | 2021-09-10 | |
| End date | 2022-03-31 |
Datasets: + COVID-19 Ethnic Category Data Set; + COVID-19 Vaccination Status
Objective for processing
[15 paragraphs unchanged]
• Resource Allocation - In order to assess system wide impact of
[24 words unchanged]
and assessment of workforce needs, linked to Paragraph 2.2.4 of the COVID-19
Directions:
Directions.
The data may only be linked by the Data Controller or their respective Data Processor, to other pseudonymised datasets which it holds under a current data sharing agreement only where such data is provided for the purposes of general commissioning by NHS Digital. The Health Service Control of Patient Information Regulations (COPI) will also apply to any data linked to the GDPPR data.
COVID Vaccine data
The linked data may only be used for purposes stipulated within this agreement and may only be held and used whilst both data sharing agreements are live and in date. Using the linked data for any other purposes, including non-COVID-19 purposes would be considered a breach of this agreement. Reidentification of individuals is not permitted under this DSA.
NHS England and NHS Digital have agreed that NHS Digital should become a joint controller of the Vaccine Data with NHS England under the COVID-19 Public Health (NHS England) Directions 2020 (COVID-19 Directions) to facilitate the analysis, linkage and dissemination of the Vaccine Data to requestors who have an appropriate legal basis to process it.
There is high demand from CCGs for the Vaccine Data which will help them;
- Understand vaccine categories and success of population roll out in their respective areas, required for weekly report to NHSE/Cabinet office
- Understand and decide whether new vaccine sites are required and stock control of vaccines to ensure immediate delivery/deploy to appropriate patients.
- Moderate and manage readmissions post vaccine e.g. how many patients are being re-admitted post vaccination
- Monitor secondary care Shielded patient activity post-vaccination.
- Identifying areas of low vaccine take-up and work directly with local communities and community leaders to address concerns.
- Ensure vulnerable individuals and groups are identified and supported through the vaccination process to ensure the maximum possible vaccination uptake.
NHS Digital has agreed to share the data with the recipients and their processors for the purpose of supporting the recipients in their local response to the COVID-19 emergency as part of the national response to the COVID-19 pandemic.
The Vaccine Data will include;
- Patient demographics
- Source organisation (where the vaccination data originated)
- Vaccination appointment and outcome details
- Vaccine batch details
COVID-19 Ethnic Category Data Set
NHS Digital has created a small stand-alone dataset known as the COVID-19 Ethnic Category Data Set. This data set is created using ethnic category data from the General Practice Extraction Service (GPES) Data for Pandemic Planning and Research (COVID-19) (GDPPR) and Hospital Episodes Statistics (HES). By combining GDPPR ethnic category data with the latest available ethnicity data in HES, NHS Digital can substantively increase coverage in ethnic category data and therefore add strength to the GDPPR dataset when linked.
LINKAGE
The data may only be linked by the Data Controller or their respective Data Processor, to other pseudonymised datasets which it holds under a current data sharing agreement only where such data is provided for the purposes of general commissioning by NHS Digital. The Health Service Control of Patient Information Regulations (COPI) will also apply to any data linked to the data under this agreement.
The linked data may only be used for purposes stipulated within this agreement and may only be held and used whilst both data sharing agreements are live and in date. Using the linked data for any other purposes, including non-COVID-19 purposes would be considered a breach of this agreement.
RE-IDENTIFICATION
Reidentification of individuals under the GDPPR data is not permitted under this DSA.
Reidentification of individuals under the vaccination dataset is permitted but only for the purposes of direct care and is strictly limited to direct health care professionals or local authority direct care staff only with a legitimate relationship to the patient. All re-identification requests will be processed and authorised by the DSCRO on a case by case basis.
[15 paragraphs unchanged]
Processing activities
[8 paragraphs unchanged]
The data disseminated will only be used for COVID-19
GDPPR
purposes as described in this DSA, any other purpose is excluded.
[14 paragraphs unchanged]
- COVID Vaccine Data
- COVID-19 Ethnic Category Data Set
[1 paragraph unchanged]
1. Pseudonymised GDPPR COVID
19
19, COVID Vaccine and COVID-19 Ethnic Category Data Set
data is securely transferred from the DSCRO to the Data Controller / Processor
[2 paragraphs unchanged]
Expected output
[9 paragraphs unchanged] • Reports for NHSE/Cabinet Office on the success of Vaccine rollout • Identification of areas of low vaccine take up leading to work with local communities to address concerns [1 paragraph unchanged]
Expected measurable benefits
[7 paragraphs unchanged] • Maintaining the high percentage of the population receiving the vaccination
Benefits reported
Not stated in the previous version; added here.
The CCG is unable to evidence any achieved yielded benefits as of yet as they have not been able to process the data for a substantial amount of time.
Objective for processing
NHS Digital has been provided with the necessary powers to support the Secretary of State’s response to COVID-19 under the COVID-19 Public Health Directions 2020 (COVID-19 Directions) and support various COVID-19 purposes, the data shared under this agreement can be used for these specified purposes except where they would require the reidentification of individuals.
GPES data for pandemic planning and research (GDPPR COVID 19)
To support the response to the outbreak, NHS Digital has been legally directed to collect and analyse healthcare information about patients from their GP record for the duration of the COVID-19 emergency period under the COVID-19 Directions.
The data which NHS Digital has collected and is providing under this agreement includes coded health data, which is held in a patient’s GP record, such as details of:
• diagnoses and findings
• medications and other prescribed items
• investigations, tests and results
• treatments and outcomes
• vaccinations and immunisations
Details of any sensitive SNOMED codes included in the GDPPR data set can be found in the Reference Data and GDPPR COVID 19 user guides hosted on the NHS Digital website. SNOMED codes are included in GDPPR data.
There are no free text record entries in the data.
The Controller will use the pseudonymised GDPPR COVID 19 data to provide intelligence to support their local response to the COVID-19 emergency. The data is analysed so that health care provision can be planned to support the needs of the population within the CCG area for the COVID-19 purposes.
Such uses of the data include but are not limited to:
• Analysis of missed appointments - Analysis of local missed/delayed referrals due to the COVID-19 crisis to estimate the potential impact and to estimate when ‘normal’ health and care services may resume, linked to Paragraph 2.2.3 of the COVID-19 Directions.
• Patient risk stratification and predictive modelling - to highlight patients at risk of requiring hospital admission due to COVID-19, computed using algorithms executed against linked de-identified data, and identification of future service delivery models linked to Paragraph 2.2.2 of the COVID-19 Directions. As with all risk stratification, this would lead to the identification of the characteristics of a cohort that could subsequently, and separately, be used to identify individuals for intervention. However the identification of individuals will not be done as part of this data sharing agreement, and the data shared under this agreement will not be reidentified.
• Resource Allocation - In order to assess system wide impact of COVID-19, the GDPPR COVID 19 data will allow reallocation of resources to the worst hit localities using their expertise in scenario planning, clinical impact and assessment of workforce needs, linked to Paragraph 2.2.4 of the COVID-19 Directions.
COVID Vaccine data
NHS England and NHS Digital have agreed that NHS Digital should become a joint controller of the Vaccine Data with NHS England under the COVID-19 Public Health (NHS England) Directions 2020 (COVID-19 Directions) to facilitate the analysis, linkage and dissemination of the Vaccine Data to requestors who have an appropriate legal basis to process it.
There is high demand from CCGs for the Vaccine Data which will help them;
- Understand vaccine categories and success of population roll out in their respective areas, required for weekly report to NHSE/Cabinet office
- Understand and decide whether new vaccine sites are required and stock control of vaccines to ensure immediate delivery/deploy to appropriate patients.
- Moderate and manage readmissions post vaccine e.g. how many patients are being re-admitted post vaccination
- Monitor secondary care Shielded patient activity post-vaccination.
- Identifying areas of low vaccine take-up and work directly with local communities and community leaders to address concerns.
- Ensure vulnerable individuals and groups are identified and supported through the vaccination process to ensure the maximum possible vaccination uptake.
NHS Digital has agreed to share the data with the recipients and their processors for the purpose of supporting the recipients in their local response to the COVID-19 emergency as part of the national response to the COVID-19 pandemic.
The Vaccine Data will include;
- Patient demographics
- Source organisation (where the vaccination data originated)
- Vaccination appointment and outcome details
- Vaccine batch details
COVID-19 Ethnic Category Data Set
NHS Digital has created a small stand-alone dataset known as the COVID-19 Ethnic Category Data Set. This data set is created using ethnic category data from the General Practice Extraction Service (GPES) Data for Pandemic Planning and Research (COVID-19) (GDPPR) and Hospital Episodes Statistics (HES). By combining GDPPR ethnic category data with the latest available ethnicity data in HES, NHS Digital can substantively increase coverage in ethnic category data and therefore add strength to the GDPPR dataset when linked.
LINKAGE
The data may only be linked by the Data Controller or their respective Data Processor, to other pseudonymised datasets which it holds under a current data sharing agreement only where such data is provided for the purposes of general commissioning by NHS Digital. The Health Service Control of Patient Information Regulations (COPI) will also apply to any data linked to the data under this agreement.
The linked data may only be used for purposes stipulated within this agreement and may only be held and used whilst both data sharing agreements are live and in date. Using the linked data for any other purposes, including non-COVID-19 purposes would be considered a breach of this agreement.
RE-IDENTIFICATION
Reidentification of individuals under the GDPPR data is not permitted under this DSA.
Reidentification of individuals under the vaccination dataset is permitted but only for the purposes of direct care and is strictly limited to direct health care professionals or local authority direct care staff only with a legitimate relationship to the patient. All re-identification requests will be processed and authorised by the DSCRO on a case by case basis.
LEGAL BASIS FOR PROCESSING DATA:
Legal Basis for NHS Digital to Disseminate the Data:
NHS Digital is able to disseminate data with the Recipients for the agreed purposes under a notice issued to NHS Digital by the Secretary of State for Health and Social Care under Regulation 3(4) of the Health Service Control of Patient Information Regulations (COPI) dated 17 March 2020 (the NHSD COPI Notice).
The Recipients are health organisations covered by Regulation 3(3) of COPI and the agreed purposes (paragraphs 2.2.2-2.2.4 of the COVID-19 Directions, as stated below in section 5a) for which the disseminated data is being shared are covered by Regulation 3(1) of COPI.
Under the Health and Social Care Act, NHS Digital is relying on section 261(5)(d) – necessary or expedient to share the disseminated data with the Recipients for the agreed purposes.
Legal Basis for Processing:
The Recipients are able to receive and process the disseminated data under a notice issued to the Recipients by the Secretary of State for Health and Social Care under Regulation 3(4) of COPI dated 20th March (the Recipient COPI Notice section 2).
The Secretary of State has issued notices under the Health Service Control of Patient Information Regulations 2002 requiring the following organisations to process information:
Health organisations
“Health Organisations” defined below under Regulation 3(3) of COPI includes CCGs for the reasons explained below. These are clinically led statutory NHS bodies responsible for the planning and commissioning of health care services for their local area
The Secretary of State for Health and Social Care has issued NHS Digital with a Notice under Regulation 3(4) of the National Health Service (Control of Patient Information Regulations) 2002 (COPI) to require NHS Digital to share confidential patient information with organisations permitted to process confidential information under Regulation 3(3) of COPI. These include:
• persons employed or engaged for the purposes of the health service
Under Section 26 of the Health and Social Care Act 2012, CCG’s have a duty to provide and manage health services for the population.
Regulation 7 of COPI includes certain limitations. The request has considered these limitations, considering data minimisation, access controls and technical and organisational measures.
Under GDPR, the Recipients can rely on Article 6(1)(c) – Legal Obligation to receive and process the Disclosed Data from NHS Digital for the Agreed Purposes under the Recipient COPI Notice. As this is health information and therefore special category personal data the Recipients can also rely on Article 9(2)(h) – preventative or occupational medicine and para 6 of Schedule 1 DPA – statutory purpose.
Expected output
• Operational planning to predict likely demand on primary, community and acute service for vulnerable patients due to the impact of COVID-19
• Analysis of resource allocation
• Investigating and monitoring the effects of COVID-19
• Patient Stratification in relation to COVID-19, such as:
o Patients at highest risk of admission
o Frail and elderly
o Patients that are currently in hospital
o Patients with prescriptions related to COVID-19
o Patients recently Discharged from hospital
• Reports for NHSE/Cabinet Office on the success of Vaccine rollout
• Identification of areas of low vaccine take up leading to work with local communities to address concerns
For avoidance of doubt these are pseudonymised patient cohorts, not identifiable.
Benefits reported
The CCG is unable to evidence any achieved yielded benefits as of yet as they have not been able to process the data for a substantial amount of time.
DARS-NIC-387074-L1X5J-v1.2 16 February 2021 to 30 September 2021
- Title
- GDPPR COVID-19 – CCG - Pseudo
- Commercial
- No
- Sublicensing
- No
- Datasets
- 1
- Files released
- 0
Datasets: COVID-19 General Practice Extraction Service (GPES) Data for Pandemic Planning and Research (GDPPR)
What changed from DARS-NIC-387074-L1X5J-v0.2
Text removed is struck through; text added is underlined. Unchanged paragraphs are summarised rather than repeated.
| Field | Was | Became |
|---|---|---|
| Start date | 2021-02-16 | |
| End date | 2021-09-30 |
Benefits reported
Stated in the previous version and removed here.
Yielded Benefits is not a requirement for new applications.
Unchanged: Objective for processing, Processing activities, Expected output, Expected measurable benefits.
Objective for processing
NHS Digital has been provided with the necessary powers to support the Secretary of State’s response to COVID-19 under the COVID-19 Public Health Directions 2020 (COVID-19 Directions) and support various COVID-19 purposes, the data shared under this agreement can be used for these specified purposes except where they would require the reidentification of individuals.
GPES data for pandemic planning and research (GDPPR COVID 19)
To support the response to the outbreak, NHS Digital has been legally directed to collect and analyse healthcare information about patients from their GP record for the duration of the COVID-19 emergency period under the COVID-19 Directions.
The data which NHS Digital has collected and is providing under this agreement includes coded health data, which is held in a patient’s GP record, such as details of:
• diagnoses and findings
• medications and other prescribed items
• investigations, tests and results
• treatments and outcomes
• vaccinations and immunisations
Details of any sensitive SNOMED codes included in the GDPPR data set can be found in the Reference Data and GDPPR COVID 19 user guides hosted on the NHS Digital website. SNOMED codes are included in GDPPR data.
There are no free text record entries in the data.
The Controller will use the pseudonymised GDPPR COVID 19 data to provide intelligence to support their local response to the COVID-19 emergency. The data is analysed so that health care provision can be planned to support the needs of the population within the CCG area for the COVID-19 purposes.
Such uses of the data include but are not limited to:
• Analysis of missed appointments - Analysis of local missed/delayed referrals due to the COVID-19 crisis to estimate the potential impact and to estimate when ‘normal’ health and care services may resume, linked to Paragraph 2.2.3 of the COVID-19 Directions.
• Patient risk stratification and predictive modelling - to highlight patients at risk of requiring hospital admission due to COVID-19, computed using algorithms executed against linked de-identified data, and identification of future service delivery models linked to Paragraph 2.2.2 of the COVID-19 Directions. As with all risk stratification, this would lead to the identification of the characteristics of a cohort that could subsequently, and separately, be used to identify individuals for intervention. However the identification of individuals will not be done as part of this data sharing agreement, and the data shared under this agreement will not be reidentified.
• Resource Allocation - In order to assess system wide impact of COVID-19, the GDPPR COVID 19 data will allow reallocation of resources to the worst hit localities using their expertise in scenario planning, clinical impact and assessment of workforce needs, linked to Paragraph 2.2.4 of the COVID-19 Directions:
The data may only be linked by the Data Controller or their respective Data Processor, to other pseudonymised datasets which it holds under a current data sharing agreement only where such data is provided for the purposes of general commissioning by NHS Digital. The Health Service Control of Patient Information Regulations (COPI) will also apply to any data linked to the GDPPR data.
The linked data may only be used for purposes stipulated within this agreement and may only be held and used whilst both data sharing agreements are live and in date. Using the linked data for any other purposes, including non-COVID-19 purposes would be considered a breach of this agreement. Reidentification of individuals is not permitted under this DSA.
LEGAL BASIS FOR PROCESSING DATA:
Legal Basis for NHS Digital to Disseminate the Data:
NHS Digital is able to disseminate data with the Recipients for the agreed purposes under a notice issued to NHS Digital by the Secretary of State for Health and Social Care under Regulation 3(4) of the Health Service Control of Patient Information Regulations (COPI) dated 17 March 2020 (the NHSD COPI Notice).
The Recipients are health organisations covered by Regulation 3(3) of COPI and the agreed purposes (paragraphs 2.2.2-2.2.4 of the COVID-19 Directions, as stated below in section 5a) for which the disseminated data is being shared are covered by Regulation 3(1) of COPI.
Under the Health and Social Care Act, NHS Digital is relying on section 261(5)(d) – necessary or expedient to share the disseminated data with the Recipients for the agreed purposes.
Legal Basis for Processing:
The Recipients are able to receive and process the disseminated data under a notice issued to the Recipients by the Secretary of State for Health and Social Care under Regulation 3(4) of COPI dated 20th March (the Recipient COPI Notice section 2).
The Secretary of State has issued notices under the Health Service Control of Patient Information Regulations 2002 requiring the following organisations to process information:
Health organisations
“Health Organisations” defined below under Regulation 3(3) of COPI includes CCGs for the reasons explained below. These are clinically led statutory NHS bodies responsible for the planning and commissioning of health care services for their local area
The Secretary of State for Health and Social Care has issued NHS Digital with a Notice under Regulation 3(4) of the National Health Service (Control of Patient Information Regulations) 2002 (COPI) to require NHS Digital to share confidential patient information with organisations permitted to process confidential information under Regulation 3(3) of COPI. These include:
• persons employed or engaged for the purposes of the health service
Under Section 26 of the Health and Social Care Act 2012, CCG’s have a duty to provide and manage health services for the population.
Regulation 7 of COPI includes certain limitations. The request has considered these limitations, considering data minimisation, access controls and technical and organisational measures.
Under GDPR, the Recipients can rely on Article 6(1)(c) – Legal Obligation to receive and process the Disclosed Data from NHS Digital for the Agreed Purposes under the Recipient COPI Notice. As this is health information and therefore special category personal data the Recipients can also rely on Article 9(2)(h) – preventative or occupational medicine and para 6 of Schedule 1 DPA – statutory purpose.
Expected output
• Operational planning to predict likely demand on primary, community and acute service for vulnerable patients due to the impact of COVID-19
• Analysis of resource allocation
• Investigating and monitoring the effects of COVID-19
• Patient Stratification in relation to COVID-19, such as:
o Patients at highest risk of admission
o Frail and elderly
o Patients that are currently in hospital
o Patients with prescriptions related to COVID-19
o Patients recently Discharged from hospital
For avoidance of doubt these are pseudonymised patient cohorts, not identifiable.
DARS-NIC-387074-L1X5J-v0.2 19 August 2020 to 31 March 2021
- Title
- GDPPR COVID-19 – CCG - Pseudo
- Commercial
- No
- Sublicensing
- No
- Datasets
- 1
- Files released
- 0
Datasets: COVID-19 General Practice Extraction Service (GPES) Data for Pandemic Planning and Research (GDPPR)
Objective for processing
NHS Digital has been provided with the necessary powers to support the Secretary of State’s response to COVID-19 under the COVID-19 Public Health Directions 2020 (COVID-19 Directions) and support various COVID-19 purposes, the data shared under this agreement can be used for these specified purposes except where they would require the reidentification of individuals.
GPES data for pandemic planning and research (GDPPR COVID 19)
To support the response to the outbreak, NHS Digital has been legally directed to collect and analyse healthcare information about patients from their GP record for the duration of the COVID-19 emergency period under the COVID-19 Directions.
The data which NHS Digital has collected and is providing under this agreement includes coded health data, which is held in a patient’s GP record, such as details of:
• diagnoses and findings
• medications and other prescribed items
• investigations, tests and results
• treatments and outcomes
• vaccinations and immunisations
Details of any sensitive SNOMED codes included in the GDPPR data set can be found in the Reference Data and GDPPR COVID 19 user guides hosted on the NHS Digital website. SNOMED codes are included in GDPPR data.
There are no free text record entries in the data.
The Controller will use the pseudonymised GDPPR COVID 19 data to provide intelligence to support their local response to the COVID-19 emergency. The data is analysed so that health care provision can be planned to support the needs of the population within the CCG area for the COVID-19 purposes.
Such uses of the data include but are not limited to:
• Analysis of missed appointments - Analysis of local missed/delayed referrals due to the COVID-19 crisis to estimate the potential impact and to estimate when ‘normal’ health and care services may resume, linked to Paragraph 2.2.3 of the COVID-19 Directions.
• Patient risk stratification and predictive modelling - to highlight patients at risk of requiring hospital admission due to COVID-19, computed using algorithms executed against linked de-identified data, and identification of future service delivery models linked to Paragraph 2.2.2 of the COVID-19 Directions. As with all risk stratification, this would lead to the identification of the characteristics of a cohort that could subsequently, and separately, be used to identify individuals for intervention. However the identification of individuals will not be done as part of this data sharing agreement, and the data shared under this agreement will not be reidentified.
• Resource Allocation - In order to assess system wide impact of COVID-19, the GDPPR COVID 19 data will allow reallocation of resources to the worst hit localities using their expertise in scenario planning, clinical impact and assessment of workforce needs, linked to Paragraph 2.2.4 of the COVID-19 Directions:
The data may only be linked by the Data Controller or their respective Data Processor, to other pseudonymised datasets which it holds under a current data sharing agreement only where such data is provided for the purposes of general commissioning by NHS Digital. The Health Service Control of Patient Information Regulations (COPI) will also apply to any data linked to the GDPPR data.
The linked data may only be used for purposes stipulated within this agreement and may only be held and used whilst both data sharing agreements are live and in date. Using the linked data for any other purposes, including non-COVID-19 purposes would be considered a breach of this agreement. Reidentification of individuals is not permitted under this DSA.
LEGAL BASIS FOR PROCESSING DATA:
Legal Basis for NHS Digital to Disseminate the Data:
NHS Digital is able to disseminate data with the Recipients for the agreed purposes under a notice issued to NHS Digital by the Secretary of State for Health and Social Care under Regulation 3(4) of the Health Service Control of Patient Information Regulations (COPI) dated 17 March 2020 (the NHSD COPI Notice).
The Recipients are health organisations covered by Regulation 3(3) of COPI and the agreed purposes (paragraphs 2.2.2-2.2.4 of the COVID-19 Directions, as stated below in section 5a) for which the disseminated data is being shared are covered by Regulation 3(1) of COPI.
Under the Health and Social Care Act, NHS Digital is relying on section 261(5)(d) – necessary or expedient to share the disseminated data with the Recipients for the agreed purposes.
Legal Basis for Processing:
The Recipients are able to receive and process the disseminated data under a notice issued to the Recipients by the Secretary of State for Health and Social Care under Regulation 3(4) of COPI dated 20th March (the Recipient COPI Notice section 2).
The Secretary of State has issued notices under the Health Service Control of Patient Information Regulations 2002 requiring the following organisations to process information:
Health organisations
“Health Organisations” defined below under Regulation 3(3) of COPI includes CCGs for the reasons explained below. These are clinically led statutory NHS bodies responsible for the planning and commissioning of health care services for their local area
The Secretary of State for Health and Social Care has issued NHS Digital with a Notice under Regulation 3(4) of the National Health Service (Control of Patient Information Regulations) 2002 (COPI) to require NHS Digital to share confidential patient information with organisations permitted to process confidential information under Regulation 3(3) of COPI. These include:
• persons employed or engaged for the purposes of the health service
Under Section 26 of the Health and Social Care Act 2012, CCG’s have a duty to provide and manage health services for the population.
Regulation 7 of COPI includes certain limitations. The request has considered these limitations, considering data minimisation, access controls and technical and organisational measures.
Under GDPR, the Recipients can rely on Article 6(1)(c) – Legal Obligation to receive and process the Disclosed Data from NHS Digital for the Agreed Purposes under the Recipient COPI Notice. As this is health information and therefore special category personal data the Recipients can also rely on Article 9(2)(h) – preventative or occupational medicine and para 6 of Schedule 1 DPA – statutory purpose.
Expected output
• Operational planning to predict likely demand on primary, community and acute service for vulnerable patients due to the impact of COVID-19
• Analysis of resource allocation
• Investigating and monitoring the effects of COVID-19
• Patient Stratification in relation to COVID-19, such as:
o Patients at highest risk of admission
o Frail and elderly
o Patients that are currently in hospital
o Patients with prescriptions related to COVID-19
o Patients recently Discharged from hospital
For avoidance of doubt these are pseudonymised patient cohorts, not identifiable.
Benefits reported
Yielded Benefits is not a requirement for new applications.
Register history
When this agreement appeared in, or was edited in, each monthly edition of the register. Built by comparing every edition this site holds, the earliest of which is July 2021.
-
July 2021 —
already listed in the earliest edition this site holds, so it may be older. 2 versions: DARS-NIC-387074-L1X5J-v0.2, DARS-NIC-387074-L1X5J-v1.2
-
November 2021
1 version added: DARS-NIC-387074-L1X5J-v2.2
-
June 2022
1 version added: DARS-NIC-387074-L1X5J-v3.2
-
July 2022
Amended DARS-NIC-387074-L1X5J-v3.2
- End date:
31 May 2022→ 30 November 2022 - Objective for processing:
reworded
Show the change
A letter has been issued to the Data Controller to amend the terms of this data sharing agreement. The amendments to the agreement are as follows: • The removal of CV19: Regulation 3 (4) of the Health Service (Control of Patient Information) Regulations 2002 as the legal basis for dissemination. The data is no longer described as “confidential”. • The change of GDPR Article 6 legal basis from - Article 6 (1) (c) to - Article 6 (1) (e) • The extension of the DSA end date to 30/11/2022 The letter has been issued to ensure data continues to flow to support commissioning and allow all parties to work on the new agreements required to support new Integrated Care Board data sharing agreement. [54 paragraphs unchanged]
- End date:
-
October 2022
Succeeded Applicant organisation: NHS Brighton and Hove CCG succeeded by NHS Sussex ICB from 1 July 2022, according to NHS ODS. Not counted as a change.Succeeded Data controllers: NHS Brighton and Hove CCG succeeded by NHS Sussex ICB from 1 July 2022, according to NHS ODS. Not counted as a change.Succeeded Data controllers: NHS East Sussex CCG succeeded by NHS Sussex ICB from 1 July 2022, according to NHS ODS. Not counted as a change.Succeeded Data controllers: NHS West Sussex CCG succeeded by NHS Sussex ICB from 1 July 2022, according to NHS ODS. Not counted as a change.
"Amended in place" means NHS England changed the record without issuing a new version number. The register publishes no changelog for those edits; this site infers them by comparing editions. An edit is attributed to the edition it first appears in, not to the date it was made.
Cite this page
NHS England (2026) Data Uses Register, September 2026 edition, agreement DARS-NIC-387074-L1X5J, “GDPPR/Ethnicity/Vaccine COVID-19 – CCG - Pseudo”. Read via NHS Data Access Explorer (unofficial), https://healthdatauses.uk/agreements/dars-nic-387074-l1x5j/ (accessed [date]).
This address stays the same, but the page is rebuilt with each monthly edition, so the citation names the edition it shows. Every edition's data is kept in the facts store.
Source: datausesregister_september2026.xlsx, September 2026 edition of the NHS England Data Uses Register. Search that workbook for DARS-NIC-387074-L1X5J to see the original rows.