GDPPR Data Request for Dudley Metropolitan Borough Council
Dudley Metropolitan Borough Council · Local Authority
Expired The latest version ended on 13 October 2023. The September 2026 register still lists the agreement, but its term has passed.
- Reference
- DARS-NIC-387291-B3M4Z
- Latest version
- v2.5
- Term of latest version
- 7 November 2022 to 13 October 2023
- Start date
- 21 December 2020
- Data controller
- Sole Data Controller
- Commercial purposes
- No
- Sublicensing
- No
- Files released to date
- 0
Why the data was released
Objective for processing
NHS Digital has been provided with the necessary powers to support the Secretary of State’s response to COVID-19 under the COVID-19 Public Health Directions 2020 (COVID-19 Directions) and support various COVID-19 purposes, the data shared under this agreement can be used for these specified purposes except where they would require the reidentification of individuals.
GPES data for pandemic planning and research (GDPPR COVID 19)
To support the response to the outbreak, NHS Digital has been legally directed to collect and analyse healthcare information about patients from their GP record for the duration of the COVID-19 emergency period under the COVID-19 Directions.
The data which NHS Digital has collected and is providing under this agreement includes coded health data, which is held in a patient’s GP record, such as details of:
• diagnoses and findings
• medications and other prescribed items
• investigations, tests and results
• treatments and outcomes
• vaccinations and immunisations
Details of any sensitive SNOMED codes included in the GDPPR data set can be found in the Reference Data and GDPPR COVID 19 user guides hosted on the NHS Digital website. SNOMED codes are included in GDPPR data.
There are no free text record entries in the data.
The Controller will use the pseudonymised GDPPR COVID 19 data to provide intelligence to support their local response to the COVID-19 emergency. The data is analysed so that health care provision can be planned to support the needs of the population within the CCG area for the COVID-19 purposes.
Such uses of the data include but are not limited to:
• Analysis of missed appointments - Analysis of local missed/delayed referrals due to the COVID-19 crisis to estimate the potential impact and to estimate when ‘normal’ health and care services may resume, linked to Paragraph 2.2.3 of the COVID-19 Directions.
• Patient risk stratification and predictive modelling - to highlight patients at risk of requiring hospital admission due to COVID-19, computed using algorithms executed against linked de-identified data, and identification of future service delivery models linked to Paragraph 2.2.2 of the COVID-19 Directions. As with all risk stratification, this would lead to the identification of the characteristics of a cohort that could subsequently, and separately, be used to identify individuals for intervention. However the identification of individuals will not be done as part of this data sharing agreement, and the data shared under this agreement will not be reidentified.
• Resource Allocation - In order to assess system wide impact of COVID-19, the GDPPR COVID 19 data will allow reallocation of resources to the worst hit localities using their expertise in scenario planning, clinical impact and assessment of workforce needs, linked to Paragraph 2.2.4 of the COVID-19 Directions.
LINKAGE
The data may only be linked by the Data Controller or their respective Data Processor, to other pseudonymised datasets which it holds under a current data sharing agreement only where such data is provided for the purposes of general commissioning by NHS Digital.
The linked data may only be used for purposes stipulated within this agreement and may only be held and used whilst both data sharing agreements are live and in date. Using the linked data for any other purposes, including non-COVID-19 purposes would be considered a breach of this agreement.
RE-IDENTIFICATION
Reidentification of individuals under the GDPPR data is not permitted under this DSA.
LEGAL BASIS FOR PROCESSING DATA:
Legal Basis for NHS Digital to Disseminate the Data:
Under the Health and Social Care Act, NHS Digital is relying on section 261(5)(d) – necessary or expedient to share the disseminated data with the Recipients for the agreed purposes.
NHS Digital will publish details about the sharing of the disseminated data with the Recipient in its Data Release Register.
Legal Basis for Processing:
Under GDPR, the Recipients can rely on Article 6(1)(e) – Public Task to receive and process the Disclosed Data from NHS Digital for the Agreed Purposes. As this is health information and therefore special category personal data the Recipients can also rely on Article 9(2)(h) –preventative or occupational medicine and para 6 of Schedule 1 DPA – statutory purpose.
Processing activities
PROCESSING CONDITIONS:
Data must only be used for the purposes stipulated within this Data Sharing Agreement. Any additional disclosure / publication will require further approval from NHS Digital.
Data Processors must only act upon specific instructions from the Data Controller.
All access to data is managed under Role-Based Access Controls. Users can only access data authorised by their role and the tasks that they are required to undertake.
Patient level data will not be linked other than as specifically detailed within this Data Sharing Agreement.
NHS Digital reminds all organisations party to this agreement of the need to comply with the Data Sharing Framework Contract requirements, including those regarding the use (and purposes of that use) by “Personnel” (as defined within the Data Sharing Framework Contract i.e.: employees, agents and contractors of the Data Recipient who may have access to that data).
The Recipients will take all required security measures to protect the disseminated data and they will not generate copies of their cuts of the disseminated data unless this is strictly necessary. Where this is necessary, the Recipients will keep a log of all copies of the disseminated data and who is controlling them and ensure these are updated and destroyed securely.
Onward sharing of patient level data is not permitted under this agreement. Only aggregated reports with small number suppression can be shared externally.
The data disseminated will only be used for COVID-19 purposes as described in this DSA, any other purpose is excluded.
SEGREGATION:
Where the Data Processor and/or the Data Controller hold both identifiable and pseudonymised data, the data will be held separately so data cannot be linked.
AUDIT
All access to data is auditable by NHS Digital in accordance with the Data Sharing Framework Contract and NHS Digital terms.
Under the Local Audit and Accountability Act 2014, section 35, Secretary of State has power to audit all data that has flowed.
DATA MINIMISATION:
Data Minimisation in relation to the data sets listed within the application are listed below:
• Patients who are normally registered and/or resident within the LA region (including historical activity where the patient was previously registered or resident in another commissioner area).
The Data Services for Commissioners Regional Office (DSCRO) obtains the following data sets:
- GDPPR COVID 19 Data
Pseudonymisation is completed within the DSCRO and is then disseminated as follows:
1. Pseudonymised GDPPR COVID 19 data is securely transferred from the DSCRO to the Data Controller / Processor
2. Aggregation of required data will be completed by the Controller (or the Processor as instructed by the Controller).
3. Patient level data may not be shared by the Controller (or any of its processors).
Expected output
The outputs will be a range of reports, communications, and analysis created using the data stipulated in this agreement. These outputs will support the council to protect the health of the public in a more effective manner.
These reports will be utilised to work closely with the healthcare partners in the local area including CCGs and Trusts to be able to carry out the public health team's work as effectively as possible.
Local priorities include targeted support for the most vulnerable local members of the public. Current targets include but are not limited to; those living in areas of inequality, the elderly and BAME communities. The data will also provide intelligence to uncover cohorts of individuals that are at risk not currently identified by the council.
Expected measurable benefits
• Operational planning to predict likely demand on primary, community and acute service for vulnerable patients due to the impact of COVID-19
• Analysis of resource allocation
• Investigating and monitoring the effects of COVID-19
• Patient Stratification in relation to COVID-19, such as:
o Patients at highest risk of admission
o Frail and elderly
o Patients that are currently in hospital
o Patients with prescriptions related to COVID-19
o Patients recently Discharged from hospital
Benefits reported so far
The council has also produced quarterly performance reports which detail key indicators of progress in tackling COVID within the council area, of which processing of this data has supported.
https://www.dudley.gov.uk/council-community/performance/
Regular monitoring of the priorities using the GDPPR data has ensured effectiveness is continually under review and there is timely acknowledgement of success as well as emphasising actions where targets are failing.
Analysis from the data has also allowed the council to update it's COVID-19 advice page - https://www.dudley.gov.uk/coronavirus/
Datasets on the latest version
Legal basis for provision: Health and Social Care Act 2012 - s261(5)(d)
| Dataset | Type of data | Sensitivity | Frequency | Confidential data |
|---|---|---|---|---|
| COVID-19 General Practice Extraction Service (GPES) Data for Pandemic Planning and Research (GDPPR) | Anonymised - ICO Code Compliant | Sensitive | Frequent Adhoc Flow | Does not include the flow of confidential data |
Files released
Files released counts only files released externally by DARS. Access granted in NHS England's own systems, such as its Secure Data Environment, is not included.
No files recorded as released under this agreement.
Version history
The register lists each renewal of this agreement as a separate row. This site has 3 versions.
DARS-NIC-387291-B3M4Z-v2.5 7 November 2022 to 13 October 2023
- Title
- GDPPR Data Request for Dudley Metropolitan Borough Council
- Commercial
- No
- Sublicensing
- No
- Datasets
- 1
- Files released
- 0
Datasets: COVID-19 General Practice Extraction Service (GPES) Data for Pandemic Planning and Research (GDPPR)
What changed from DARS-NIC-387291-B3M4Z-v1.1
Text removed is struck through; text added is underlined. Unchanged paragraphs are summarised rather than repeated.
| Field | Was | Became |
|---|---|---|
| Start date | 2022-11-07 | |
| End date | 2023-10-13 | |
| COVID-19 General Practice Extraction Service (GPES) Data for Pandemic Planning and Research (GDPPR): legal basis | Health and Social Care Act 2012 - s261(5)(d) |
Objective for processing
[16 paragraphs unchanged]
COVID-19 Ethnic Category Data Set
NHS Digital has created a small stand-alone dataset known as the COVID-19 Ethnic Category Data Set. This data set is created using ethnic category data from the General Practice Extraction Service (GPES) Data for Pandemic Planning and Research (COVID-19) (GDPPR) and Hospital Episodes Statistics (HES). By combining GDPPR ethnic category data with the latest available ethnicity data in HES, NHS Digital can substantively increase coverage in ethnic category data and therefore add strength to the GDPPR dataset when linked.
[1 paragraph unchanged]
The data may only be linked by the Data Controller or their
[19 words unchanged]
data is provided for the purposes of general commissioning by NHS Digital.
The Health Service Control of Patient Information Regulations (COPI) will also apply to any data linked to the data under this agreement.
[3 paragraphs unchanged]
Reidentification of individuals under the vaccination dataset is permitted but only for the purposes of direct care and is strictly limited to direct health care professionals or local authority direct care staff only with a legitimate relationship to the patient. All re-identification requests will be processed and authorised by the DSCRO on a case by case basis.
[2 paragraphs unchanged]
NHS Digital is able to disseminate data with the Recipients for the agreed purposes under a notice issued to NHS Digital by the Secretary of State for Health and Social Care under Regulation 3(4) of the Health Service Control of Patient Information Regulations (COPI) dated 17 March 2020 (the NHSD COPI Notice).
The Recipients are covered by Regulation 3(3) of COPI and the agreed purposes (paragraphs 2.2.2-2.2.4 of the COVID-19 Directions, as stated below in section 5a) for which the disseminated data is being shared are covered by Regulation 3(1) of COPI.
[3 paragraphs unchanged]
The Recipients are able to receive and process the disseminated data under a notice issued to the Recipients by the Secretary of State for Health and Social Care under Regulation 3(4) of COPI dated 20th March (the Recipient COPI Notice section 2).
Under GDPR, the Recipients can rely on Article 6(1)(e) – Public Task to receive and process the Disclosed Data from NHS Digital for the Agreed Purposes. As this is health information and therefore special category personal data the Recipients can also rely on Article 9(2)(h) –preventative or occupational medicine and para 6 of Schedule 1 DPA – statutory purpose.
The Secretary of State has issued notices under the Health Service Control of Patient Information Regulations 2002 requiring the following organisations to process information:
Local Authorities
The Secretary of State for Health and Social Care has issued NHS Digital with a Notice under Regulation 3(4) of the National Health Service (Control of Patient Information Regulations) 2002 (COPI) to require NHS Digital to share confidential patient information with organisations permitted to process confidential information under Regulation 3(3) of COPI. These include:
• persons employed or engaged for the purposes of the health service
Local Authorities have a legal responsibility under Section 3 of the Care Act 2014 to conduct tasks that are in the public interest to promote integration of care and support with health services.
The health and care system is facing an unprecedented challenge. To ensure that arm’s length bodies and local authorities are able to process and share the data they need to respond to COVID-19 , for example by treating and caring for patients and those at risk, managing the service and identifying patterns and risks.
Under GDPR, the Recipients can rely on Article 6(1)(e) – Public Task to receive and process the Disclosed Data from NHS Digital for the Agreed Purposes under the Recipient COPI Notice. As this is health information and therefore special category personal data the Recipients can also rely on Article 9(2)(h) –preventative or occupational medicine and para 6 of Schedule 1 DPA – statutory purpose.
Processing activities
[13 paragraphs unchanged]
Under the Local Audit and Accountability Act 2014, section 35, Secretary of State has power to audit all data that has
flowed, including under COPI.
flowed.
[3 paragraphs unchanged]
and/or
• Patients treated by a provider where the LA is the host/co-ordinating commissioner and/or has the primary responsibility for the provider services in the local health economy.
and/or
• Activity identified by the provider and recorded as such within national systems (such as SUS+) as for the attention of the LA.
[6 paragraphs unchanged]
Expected output
A
The outputs will be a
range of reports, communications, and analysis
creating
created
using the data stipulated in this agreement. These outputs will support the council to protect the health of the public in a more effective manner.
[2 paragraphs unchanged]
Benefits reported
Not applicable as this is a renewal application, but access to the data was not obtained prior to the expiry date of the previous agreement
The council has also produced quarterly performance reports which detail key indicators of progress in tackling COVID within the council area, of which processing of this data has supported.
https://www.dudley.gov.uk/council-community/performance/
Regular monitoring of the priorities using the GDPPR data has ensured effectiveness is continually under review and there is timely acknowledgement of success as well as emphasising actions where targets are failing.
Analysis from the data has also allowed the council to update it's COVID-19 advice page - https://www.dudley.gov.uk/coronavirus/
Unchanged: Expected measurable benefits.
DARS-NIC-387291-B3M4Z-v1.1 1 October 2021 to 31 March 2022
- Title
- GDPPR Data Request for Dudley Metropolitan Borough Council
- Commercial
- No
- Sublicensing
- No
- Datasets
- 1
- Files released
- 0
Datasets: COVID-19 General Practice Extraction Service (GPES) Data for Pandemic Planning and Research (GDPPR)
What changed from DARS-NIC-387291-B3M4Z-v0.3
Text removed is struck through; text added is underlined. Unchanged paragraphs are summarised rather than repeated.
| Field | Was | Became |
|---|---|---|
| Start date | 2021-10-01 | |
| End date | 2022-03-31 |
Objective for processing
[2 paragraphs unchanged]
To support the response to
COVID-19,
the outbreak,
NHS Digital has been legally directed to collect and analyse healthcare information
[6 words unchanged]
for the duration of the COVID-19 emergency period under the COVID-19 Directions.
[8 paragraphs unchanged]
The Local authority will use the pseudonymised GDPPR data for the following purposes:
The Controller will use the pseudonymised GDPPR COVID 19 data to provide intelligence to support their local response to the COVID-19 emergency. The data is analysed so that health care provision can be planned to support the needs of the population within the CCG area for the COVID-19 purposes.
• Identifying local COVID-19 trends and risks to public health.
Such uses of the data include but are not limited to:
• Monitoring the effects of COVID-19 in the borough.
• Analysis of missed appointments - Analysis of local missed/delayed referrals due to the COVID-19 crisis to estimate the potential impact and to estimate when ‘normal’ health and care services may resume, linked to Paragraph 2.2.3 of the COVID-19 Directions.
• Controlling and helping to prevent the spread of COVID-19.
• Patient risk stratification and predictive modelling - to highlight patients at risk of requiring hospital admission due to COVID-19, computed using algorithms executed against linked de-identified data, and identification of future service delivery models linked to Paragraph 2.2.2 of the COVID-19 Directions. As with all risk stratification, this would lead to the identification of the characteristics of a cohort that could subsequently, and separately, be used to identify individuals for intervention. However the identification of individuals will not be done as part of this data sharing agreement, and the data shared under this agreement will not be reidentified.
• Planning and providing health, social care and other public services to the public.
• Resource Allocation - In order to assess system wide impact of COVID-19, the GDPPR COVID 19 data will allow reallocation of resources to the worst hit localities using their expertise in scenario planning, clinical impact and assessment of workforce needs, linked to Paragraph 2.2.4 of the COVID-19 Directions.
• Helping local government to provide information, guidance and develop policies to respond to COVID-19.
COVID-19 Ethnic Category Data Set
• Monitoring and managing COVID-19.
NHS Digital has created a small stand-alone dataset known as the COVID-19 Ethnic Category Data Set. This data set is created using ethnic category data from the General Practice Extraction Service (GPES) Data for Pandemic Planning and Research (COVID-19) (GDPPR) and Hospital Episodes Statistics (HES). By combining GDPPR ethnic category data with the latest available ethnicity data in HES, NHS Digital can substantively increase coverage in ethnic category data and therefore add strength to the GDPPR dataset when linked.
• To better target COVID-19 responses.
LINKAGE
• Improve the communications to residents.
The data may only be linked by the Data Controller or their respective Data Processor, to other pseudonymised datasets which it holds under a current data sharing agreement only where such data is provided for the purposes of general commissioning by NHS Digital. The Health Service Control of Patient Information Regulations (COPI) will also apply to any data linked to the data under this agreement.
• Improve the understanding of the impact of COVID-19 in the local area.
The linked data may only be used for purposes stipulated within this agreement and may only be held and used whilst both data sharing agreements are live and in date. Using the linked data for any other purposes, including non-COVID-19 purposes would be considered a breach of this agreement.
The data under this agreement is only to be used for the above COVID-19 purposes.
RE-IDENTIFICATION
Reidentification of individuals under the GDPPR data is not permitted under this DSA.
Reidentification of individuals under the vaccination dataset is permitted but only for the purposes of direct care and is strictly limited to direct health care professionals or local authority direct care staff only with a legitimate relationship to the patient. All re-identification requests will be processed and authorised by the DSCRO on a case by case basis.
[15 paragraphs unchanged]
Processing activities
[6 paragraphs unchanged]
The Recipients will
keep the disseminated data in an encrypted form and
take all required security measures to protect the disseminated
data. The Recipients
data and they
will not generate copies
of their cuts
of the disseminated data unless this is strictly necessary. Where
copies are
this is
necessary, the
Council will not share the copy with other organisations and the council
Recipients
will keep a log of all copies of the disseminated
data, the individuals
data and who is
controlling them and ensure these
logs
are updated and destroyed securely.
Patient level data may not be shared onward to any organisation not listed as a data controller or data processor in this Agreement.
Onward sharing of patient level data is not permitted under this agreement. Only aggregated reports with small number suppression can be shared externally.
The data disseminated will only be used for COVID-19
GDPPR
purposes as described in this DSA, any other purpose is excluded.
[7 paragraphs unchanged]
• Patients who are normally registered and/or resident within the
Local Authority
LA
region (including historical activity where the patient was previously registered or resident in another commissioner area).
Microsoft Limited provide Cloud Services for Midlands and Lancashire Commissioning Support Unit and are therefore listed as a data processor. They supply support to the system, but do not access data. Therefore, any access to the data held under this agreement would be considered a breach of the agreement. This includes granting of access to the database[s] containing the data.
and/or
Lima Networks Ltd supply IT infrastructure and are therefore listed as a data processor. They supply support to the system, but do not access data. Therefore, any access to the data held under this agreement would be considered a breach of the agreement. This includes granting of access to the database[s] containing the data.
• Patients treated by a provider where the LA is the host/co-ordinating commissioner and/or has the primary responsibility for the provider services in the local health economy.
and/or
• Activity identified by the provider and recorded as such within national systems (such as SUS+) as for the attention of the LA.
[3 paragraphs unchanged]
1. Pseudonymised GDPPR COVID 19 data is securely transferred from the DSCRO to the
NHS Midlands and Lancashire Commissioning Support Unit.
Data Controller / Processor
2. NHS Midlands and Lancashire Commissioning Support Unit will provide role-based access to the Dudley Metropolitan Borough Council for processing.
2. Aggregation of required data will be completed by the Controller (or the Processor as instructed by the Controller).
3. Dudley Metropolitan Borough Council will then process the data creating aggregated reports and analysis to inform the COVID response. For clarity only aggregated reports with small number suppression can be shared outside of the Council and NHS Midlands and Lancashire Commissioning Support Unit.
3. Patient level data may not be shared by the Controller (or any of its processors).
Expected measurable benefits
This data will provide improved intelligence in combating COVID-19 leading to the below benefits;
• Operational planning to predict likely demand on primary, community and acute service for vulnerable patients due to the impact of COVID-19
• Better understanding of the local trends and risks to public health will allow the council to better target at risk groups and formulate specific targeted responses to those trends as they are reported.
• Analysis of resource allocation
• The increased under standing will help the council to better control and prevent the spread of COVID-19.
• Investigating and monitoring the effects of COVID-19
• The outputs will help the council understand how to better provide public services in the future and to plan for future outbreaks.
• Patient Stratification in relation to COVID-19, such as:
• Local government will have better information to develop policies and guidance in response to COVID-19.
o Patients at highest risk of admission
• Local government will be better placed to communicate specifically to the local population to help implement any guidance and interventions devised.
o Frail and elderly
o Patients that are currently in hospital
o Patients with prescriptions related to COVID-19
o Patients recently Discharged from hospital
Benefits reported
Not applicable as this is new application.
Not applicable as this is a renewal application, but access to the data was not obtained prior to the expiry date of the previous agreement
Unchanged: Expected output.
Objective for processing
NHS Digital has been provided with the necessary powers to support the Secretary of State’s response to COVID-19 under the COVID-19 Public Health Directions 2020 (COVID-19 Directions) and support various COVID-19 purposes, the data shared under this agreement can be used for these specified purposes except where they would require the reidentification of individuals.
GPES data for pandemic planning and research (GDPPR COVID 19)
To support the response to the outbreak, NHS Digital has been legally directed to collect and analyse healthcare information about patients from their GP record for the duration of the COVID-19 emergency period under the COVID-19 Directions.
The data which NHS Digital has collected and is providing under this agreement includes coded health data, which is held in a patient’s GP record, such as details of:
• diagnoses and findings
• medications and other prescribed items
• investigations, tests and results
• treatments and outcomes
• vaccinations and immunisations
Details of any sensitive SNOMED codes included in the GDPPR data set can be found in the Reference Data and GDPPR COVID 19 user guides hosted on the NHS Digital website. SNOMED codes are included in GDPPR data.
There are no free text record entries in the data.
The Controller will use the pseudonymised GDPPR COVID 19 data to provide intelligence to support their local response to the COVID-19 emergency. The data is analysed so that health care provision can be planned to support the needs of the population within the CCG area for the COVID-19 purposes.
Such uses of the data include but are not limited to:
• Analysis of missed appointments - Analysis of local missed/delayed referrals due to the COVID-19 crisis to estimate the potential impact and to estimate when ‘normal’ health and care services may resume, linked to Paragraph 2.2.3 of the COVID-19 Directions.
• Patient risk stratification and predictive modelling - to highlight patients at risk of requiring hospital admission due to COVID-19, computed using algorithms executed against linked de-identified data, and identification of future service delivery models linked to Paragraph 2.2.2 of the COVID-19 Directions. As with all risk stratification, this would lead to the identification of the characteristics of a cohort that could subsequently, and separately, be used to identify individuals for intervention. However the identification of individuals will not be done as part of this data sharing agreement, and the data shared under this agreement will not be reidentified.
• Resource Allocation - In order to assess system wide impact of COVID-19, the GDPPR COVID 19 data will allow reallocation of resources to the worst hit localities using their expertise in scenario planning, clinical impact and assessment of workforce needs, linked to Paragraph 2.2.4 of the COVID-19 Directions.
COVID-19 Ethnic Category Data Set
NHS Digital has created a small stand-alone dataset known as the COVID-19 Ethnic Category Data Set. This data set is created using ethnic category data from the General Practice Extraction Service (GPES) Data for Pandemic Planning and Research (COVID-19) (GDPPR) and Hospital Episodes Statistics (HES). By combining GDPPR ethnic category data with the latest available ethnicity data in HES, NHS Digital can substantively increase coverage in ethnic category data and therefore add strength to the GDPPR dataset when linked.
LINKAGE
The data may only be linked by the Data Controller or their respective Data Processor, to other pseudonymised datasets which it holds under a current data sharing agreement only where such data is provided for the purposes of general commissioning by NHS Digital. The Health Service Control of Patient Information Regulations (COPI) will also apply to any data linked to the data under this agreement.
The linked data may only be used for purposes stipulated within this agreement and may only be held and used whilst both data sharing agreements are live and in date. Using the linked data for any other purposes, including non-COVID-19 purposes would be considered a breach of this agreement.
RE-IDENTIFICATION
Reidentification of individuals under the GDPPR data is not permitted under this DSA.
Reidentification of individuals under the vaccination dataset is permitted but only for the purposes of direct care and is strictly limited to direct health care professionals or local authority direct care staff only with a legitimate relationship to the patient. All re-identification requests will be processed and authorised by the DSCRO on a case by case basis.
LEGAL BASIS FOR PROCESSING DATA:
Legal Basis for NHS Digital to Disseminate the Data:
NHS Digital is able to disseminate data with the Recipients for the agreed purposes under a notice issued to NHS Digital by the Secretary of State for Health and Social Care under Regulation 3(4) of the Health Service Control of Patient Information Regulations (COPI) dated 17 March 2020 (the NHSD COPI Notice).
The Recipients are covered by Regulation 3(3) of COPI and the agreed purposes (paragraphs 2.2.2-2.2.4 of the COVID-19 Directions, as stated below in section 5a) for which the disseminated data is being shared are covered by Regulation 3(1) of COPI.
Under the Health and Social Care Act, NHS Digital is relying on section 261(5)(d) – necessary or expedient to share the disseminated data with the Recipients for the agreed purposes.
NHS Digital will publish details about the sharing of the disseminated data with the Recipient in its Data Release Register.
Legal Basis for Processing:
The Recipients are able to receive and process the disseminated data under a notice issued to the Recipients by the Secretary of State for Health and Social Care under Regulation 3(4) of COPI dated 20th March (the Recipient COPI Notice section 2).
The Secretary of State has issued notices under the Health Service Control of Patient Information Regulations 2002 requiring the following organisations to process information:
Local Authorities
The Secretary of State for Health and Social Care has issued NHS Digital with a Notice under Regulation 3(4) of the National Health Service (Control of Patient Information Regulations) 2002 (COPI) to require NHS Digital to share confidential patient information with organisations permitted to process confidential information under Regulation 3(3) of COPI. These include:
• persons employed or engaged for the purposes of the health service
Local Authorities have a legal responsibility under Section 3 of the Care Act 2014 to conduct tasks that are in the public interest to promote integration of care and support with health services.
The health and care system is facing an unprecedented challenge. To ensure that arm’s length bodies and local authorities are able to process and share the data they need to respond to COVID-19 , for example by treating and caring for patients and those at risk, managing the service and identifying patterns and risks.
Under GDPR, the Recipients can rely on Article 6(1)(e) – Public Task to receive and process the Disclosed Data from NHS Digital for the Agreed Purposes under the Recipient COPI Notice. As this is health information and therefore special category personal data the Recipients can also rely on Article 9(2)(h) –preventative or occupational medicine and para 6 of Schedule 1 DPA – statutory purpose.
Expected output
A range of reports, communications, and analysis creating using the data stipulated in this agreement. These outputs will support the council to protect the health of the public in a more effective manner.
These reports will be utilised to work closely with the healthcare partners in the local area including CCGs and Trusts to be able to carry out the public health team's work as effectively as possible.
Local priorities include targeted support for the most vulnerable local members of the public. Current targets include but are not limited to; those living in areas of inequality, the elderly and BAME communities. The data will also provide intelligence to uncover cohorts of individuals that are at risk not currently identified by the council.
Benefits reported
Not applicable as this is a renewal application, but access to the data was not obtained prior to the expiry date of the previous agreement
DARS-NIC-387291-B3M4Z-v0.3 21 December 2020 to 30 September 2021
- Title
- GDPPR Data Request for Dudley Metropolitan Borough Council
- Commercial
- No
- Sublicensing
- No
- Datasets
- 1
- Files released
- 0
Datasets: COVID-19 General Practice Extraction Service (GPES) Data for Pandemic Planning and Research (GDPPR)
Objective for processing
NHS Digital has been provided with the necessary powers to support the Secretary of State’s response to COVID-19 under the COVID-19 Public Health Directions 2020 (COVID-19 Directions) and support various COVID-19 purposes, the data shared under this agreement can be used for these specified purposes except where they would require the reidentification of individuals.
GPES data for pandemic planning and research (GDPPR COVID 19)
To support the response to COVID-19, NHS Digital has been legally directed to collect and analyse healthcare information about patients from their GP record for the duration of the COVID-19 emergency period under the COVID-19 Directions.
The data which NHS Digital has collected and is providing under this agreement includes coded health data, which is held in a patient’s GP record, such as details of:
• diagnoses and findings
• medications and other prescribed items
• investigations, tests and results
• treatments and outcomes
• vaccinations and immunisations
Details of any sensitive SNOMED codes included in the GDPPR data set can be found in the Reference Data and GDPPR COVID 19 user guides hosted on the NHS Digital website. SNOMED codes are included in GDPPR data.
There are no free text record entries in the data.
The Local authority will use the pseudonymised GDPPR data for the following purposes:
• Identifying local COVID-19 trends and risks to public health.
• Monitoring the effects of COVID-19 in the borough.
• Controlling and helping to prevent the spread of COVID-19.
• Planning and providing health, social care and other public services to the public.
• Helping local government to provide information, guidance and develop policies to respond to COVID-19.
• Monitoring and managing COVID-19.
• To better target COVID-19 responses.
• Improve the communications to residents.
• Improve the understanding of the impact of COVID-19 in the local area.
The data under this agreement is only to be used for the above COVID-19 purposes.
LEGAL BASIS FOR PROCESSING DATA:
Legal Basis for NHS Digital to Disseminate the Data:
NHS Digital is able to disseminate data with the Recipients for the agreed purposes under a notice issued to NHS Digital by the Secretary of State for Health and Social Care under Regulation 3(4) of the Health Service Control of Patient Information Regulations (COPI) dated 17 March 2020 (the NHSD COPI Notice).
The Recipients are covered by Regulation 3(3) of COPI and the agreed purposes (paragraphs 2.2.2-2.2.4 of the COVID-19 Directions, as stated below in section 5a) for which the disseminated data is being shared are covered by Regulation 3(1) of COPI.
Under the Health and Social Care Act, NHS Digital is relying on section 261(5)(d) – necessary or expedient to share the disseminated data with the Recipients for the agreed purposes.
NHS Digital will publish details about the sharing of the disseminated data with the Recipient in its Data Release Register.
Legal Basis for Processing:
The Recipients are able to receive and process the disseminated data under a notice issued to the Recipients by the Secretary of State for Health and Social Care under Regulation 3(4) of COPI dated 20th March (the Recipient COPI Notice section 2).
The Secretary of State has issued notices under the Health Service Control of Patient Information Regulations 2002 requiring the following organisations to process information:
Local Authorities
The Secretary of State for Health and Social Care has issued NHS Digital with a Notice under Regulation 3(4) of the National Health Service (Control of Patient Information Regulations) 2002 (COPI) to require NHS Digital to share confidential patient information with organisations permitted to process confidential information under Regulation 3(3) of COPI. These include:
• persons employed or engaged for the purposes of the health service
Local Authorities have a legal responsibility under Section 3 of the Care Act 2014 to conduct tasks that are in the public interest to promote integration of care and support with health services.
The health and care system is facing an unprecedented challenge. To ensure that arm’s length bodies and local authorities are able to process and share the data they need to respond to COVID-19 , for example by treating and caring for patients and those at risk, managing the service and identifying patterns and risks.
Under GDPR, the Recipients can rely on Article 6(1)(e) – Public Task to receive and process the Disclosed Data from NHS Digital for the Agreed Purposes under the Recipient COPI Notice. As this is health information and therefore special category personal data the Recipients can also rely on Article 9(2)(h) –preventative or occupational medicine and para 6 of Schedule 1 DPA – statutory purpose.
Expected output
A range of reports, communications, and analysis creating using the data stipulated in this agreement. These outputs will support the council to protect the health of the public in a more effective manner.
These reports will be utilised to work closely with the healthcare partners in the local area including CCGs and Trusts to be able to carry out the public health team's work as effectively as possible.
Local priorities include targeted support for the most vulnerable local members of the public. Current targets include but are not limited to; those living in areas of inequality, the elderly and BAME communities. The data will also provide intelligence to uncover cohorts of individuals that are at risk not currently identified by the council.
Benefits reported
Not applicable as this is new application.
Register history
When this agreement appeared in, or was edited in, each monthly edition of the register. Built by comparing every edition this site holds, the earliest of which is July 2021.
-
July 2021 —
already listed in the earliest edition this site holds, so it may be older. 1 version: DARS-NIC-387291-B3M4Z-v0.3
-
January 2022
1 version added: DARS-NIC-387291-B3M4Z-v1.1
-
December 2022
1 version added: DARS-NIC-387291-B3M4Z-v2.5
Cite this page
NHS England (2026) Data Uses Register, September 2026 edition, agreement DARS-NIC-387291-B3M4Z, “GDPPR Data Request for Dudley Metropolitan Borough Council”. Read via NHS Data Access Explorer (unofficial), https://healthdatauses.uk/agreements/dars-nic-387291-b3m4z/ (accessed [date]).
This address stays the same, but the page is rebuilt with each monthly edition, so the citation names the edition it shows. Every edition's data is kept in the facts store.
Source: datausesregister_september2026.xlsx, September 2026 edition of the NHS England Data Uses Register. Search that workbook for DARS-NIC-387291-B3M4Z to see the original rows.