Unofficial. This site is an experimental reformatting of data published by NHS England. It is not endorsed by NHS England. Always check the official Data Uses Register before relying on anything here.

Vaccine COVID-19 – CCG - Pseudo

NHS Gloucestershire ICB · Sub ICB Location

Listed under NHS Gloucestershire Integrated Care Board.

Expired The latest version ended on 30 November 2022. The September 2026 register still lists the agreement, but its term has passed.

Reference
DARS-NIC-391600-Q4Y2J
Latest version
v3.3
Term of latest version
8 October 2021 to 30 November 2022
Start date
1 September 2020
Data controller
Sole Data Controller
Commercial purposes
No
Sublicensing
No
Files released to date
0

Why the data was released

Objective for processing

A letter has been issued to the Data Controller to amend the terms of this data sharing agreement.

The amendments to the agreement are as follows:

• The removal of CV19: Regulation 3 (4) of the Health Service (Control of Patient Information) Regulations 2002 as the legal basis for dissemination. The data is no longer described as “confidential”.

• The change of GDPR Article 6 legal basis from

- Article 6 (1) (c)

to

- Article 6 (1) (e)

• The extension of the DSA end date to 30/11/2022

The letter has been issued to ensure data continues to flow to support commissioning and allow all parties to work on the new agreements required to support new Integrated Care Board data sharing agreement.

NHS Digital has been provided with the necessary powers to support the Secretary of State’s response to COVID-19 under the COVID-19 Public Health Directions 2020 (COVID-19 Directions) and support various COVID-19 purposes, the data shared under this agreement can be used for these specified purposes except where they would require the reidentification of individuals.

COVID Vaccine data

NHS England and NHS Digital have agreed that NHS Digital should become a joint controller of the Vaccine Data with NHS England under the COVID-19 Public Health (NHS England) Directions 2020 (COVID-19 Directions) to facilitate the analysis, linkage and dissemination of the Vaccine Data to requestors who have an appropriate legal basis to process it.

There is high demand from CCGs for the Vaccine Data which will help them;

- Understand vaccine categories and success of population roll out in their respective areas, required for weekly report to NHSE/Cabinet office

- Understand and decide whether new vaccine sites are required and stock control of vaccines to ensure immediate delivery/deploy to appropriate patients.

- Moderate and manage readmissions post vaccine e.g. how many patients are being re-admitted post vaccination

- Monitor secondary care Shielded patient activity post-vaccination.

- Identifying areas of low vaccine take-up and work directly with local communities and community leaders to address concerns.

- Ensure vulnerable individuals and groups are identified and supported through the vaccination process to ensure the maximum possible vaccination uptake.

NHS Digital has agreed to share the data with the recipients and their processors for the purpose of supporting the recipients in their local response to the COVID-19 emergency as part of the national response to the COVID-19 pandemic.

The Vaccine Data will include;

- Patient demographics

- Source organisation (where the vaccination data originated)

- Vaccination appointment and outcome details

- Vaccine batch details

LINKAGE

The data may only be linked by the Data Controller or their respective Data Processor, to other pseudonymised datasets which it holds under a current data sharing agreement only where such data is provided for the purposes of general commissioning by NHS Digital. The Health Service Control of Patient Information Regulations (COPI) will also apply to any data linked to the data under this agreement.

The linked data may only be used for purposes stipulated within this agreement and may only be held and used whilst both data sharing agreements are live and in date. Using the linked data for any other purposes, including non-COVID-19 purposes would be considered a breach of this agreement.

RE-IDENTIFICATION

Reidentification of individuals under the vaccination dataset is permitted but only for the purposes of direct care and is strictly limited to direct health care professionals or local authority direct care staff only with a legitimate relationship to the patient. All re-identification requests will be processed and authorised by the DSCRO on a case by case basis.

LEGAL BASIS FOR PROCESSING DATA:

Legal Basis for NHS Digital to Disseminate the Data:

NHS Digital is able to disseminate data with the Recipients for the agreed purposes under a notice issued to NHS Digital by the Secretary of State for Health and Social Care under Regulation 3(4) of the Health Service Control of Patient Information Regulations (COPI) dated 17 March 2020 (the NHSD COPI Notice).

The Recipients are health organisations covered by Regulation 3(3) of COPI and the agreed purposes (paragraphs 2.2.2-2.2.4 of the COVID-19 Directions, as stated below in section 5a) for which the disseminated data is being shared are covered by Regulation 3(1) of COPI.

Under the Health and Social Care Act, NHS Digital is relying on section 261(5)(d) – necessary or expedient to share the disseminated data with the Recipients for the agreed purposes.

Legal Basis for Processing:

The Recipients are able to receive and process the disseminated data under a notice issued to the Recipients by the Secretary of State for Health and Social Care under Regulation 3(4) of COPI dated 20th March (the Recipient COPI Notice section 2).

The Secretary of State has issued notices under the Health Service Control of Patient Information Regulations 2002 requiring the following organisations to process information:

Health organisations

“Health Organisations” defined below under Regulation 3(3) of COPI includes CCGs for the reasons explained below. These are clinically led statutory NHS bodies responsible for the planning and commissioning of health care services for their local area

The Secretary of State for Health and Social Care has issued NHS Digital with a Notice under Regulation 3(4) of the National Health Service (Control of Patient Information Regulations) 2002 (COPI) to require NHS Digital to share confidential patient information with organisations permitted to process confidential information under Regulation 3(3) of COPI. These include:

• persons employed or engaged for the purposes of the health service

Under Section 26 of the Health and Social Care Act 2012, CCG’s have a duty to provide and manage health services for the population.

Regulation 7 of COPI includes certain limitations. The request has considered these limitations, considering data minimisation, access controls and technical and organisational measures.

Under GDPR, the Recipients can rely on Article 6(1)(c) – Legal Obligation to receive and process the Disclosed Data from NHS Digital for the Agreed Purposes under the Recipient COPI Notice. As this is health information and therefore special category personal data the Recipients can also rely on Article 9(2)(h) – preventative or occupational medicine and para 6 of Schedule 1 DPA – statutory purpose.

Processing activities

PROCESSING CONDITIONS:

Data must only be used for the purposes stipulated within this Data Sharing Agreement. Any additional disclosure / publication will require further approval from NHS Digital.

Data Processors must only act upon specific instructions from the Data Controller.

All access to data is managed under Role-Based Access Controls. Users can only access data authorised by their role and the tasks that they are required to undertake.

Patient level data will not be linked other than as specifically detailed within this Data Sharing Agreement.

NHS Digital reminds all organisations party to this agreement of the need to comply with the Data Sharing Framework Contract requirements, including those regarding the use (and purposes of that use) by “Personnel” (as defined within the Data Sharing Framework Contract i.e.: employees, agents and contractors of the Data Recipient who may have access to that data).

The Recipients will take all required security measures to protect the disseminated data and they will not generate copies of their cuts of the disseminated data unless this is strictly necessary. Where this is necessary, the Recipients will keep a log of all copies of the disseminated data and who is controlling them and ensure these are updated and destroyed securely.

Onward sharing of patient level data is not permitted under this agreement. Only aggregated reports with small number suppression can be shared externally.

The data disseminated will only be used for COVID-19 purposes as described in this DSA, any other purpose is excluded.

SEGREGATION:

Where the Data Processor and/or the Data Controller hold both identifiable and pseudonymised data, the data will be held separately so data cannot be linked.

AUDIT

All access to data is auditable by NHS Digital in accordance with the Data Sharing Framework Contract and NHS Digital terms.

Under the Local Audit and Accountability Act 2014, section 35, Secretary of State has power to audit all data that has flowed, including under COPI.

DATA MINIMISATION:

Data Minimisation in relation to the data sets listed within the application are listed below:

• Patients who are normally registered and/or resident within the CCG region (including historical activity where the patient was previously registered or resident in another commissioner area).

and/or

• Patients treated by a provider where the CCG is the host/co-ordinating commissioner and/or has the primary responsibility for the provider services in the local health economy.

and/or

• Activity identified by the provider and recorded as such within national systems (such as SUS+) as for the attention of the CCG.

The Data Services for Commissioners Regional Office (DSCRO) obtains the COVID Vaccine Data data sets:

Pseudonymisation is completed within the DSCRO and is then disseminated as follows:

1. Pseudonymised COVID Vaccine Data Set data is securely transferred from the DSCRO to the Data Controller / Processor

2. Aggregation of required data will be completed by the Controller (or the Processor as instructed by the Controller).

3. Patient level data may not be shared by the Controller (or any of its processors).

Expected output

• Reports for NHSE/Cabinet Office on the success of Vaccine rollout

• Identification of areas of low vaccine take up leading to work with local communities to address concerns

For avoidance of doubt these are pseudonymised patient cohorts, not identifiable.

Expected measurable benefits

• Controlling and helping to prevent the spread of the virus

• Maintaining the high percentage of the population receiving the vaccination

Benefits reported so far

The CCG is unable to evidence any achieved yielded benefits as of yet as they have not been able to process the data for a substantial amount of time.

Datasets on the latest version

Legal basis for provision: CV19: Regulation 3 (4) of the Health Service (Control of Patient Information) Regulations 2002; Health and Social Care Act 2012 - s261(5)(d)

Datasets approved under DARS-NIC-391600-Q4Y2J-v3.3
DatasetType of dataSensitivity FrequencyConfidential data
COVID-19 Vaccination Status Anonymised - ICO Code Compliant Sensitive Frequent Adhoc Flow Statutory exemption to flow confidential data without consent

Files released

Files released counts only files released externally by DARS. Access granted in NHS England's own systems, such as its Secure Data Environment, is not included.

No files recorded as released under this agreement.

Version history

The register lists each renewal of this agreement as a separate row. This site has 4 versions.

DARS-NIC-391600-Q4Y2J-v3.3 8 October 2021 to 30 November 2022
Title
Vaccine COVID-19 – CCG - Pseudo
Commercial
No
Sublicensing
No
Datasets
1
Files released
0

Datasets: COVID-19 Vaccination Status

What changed from DARS-NIC-391600-Q4Y2J-v2.2

Text removed is struck through; text added is underlined. Unchanged paragraphs are summarised rather than repeated.

Fields changed from DARS-NIC-391600-Q4Y2J-v2.2
FieldWasBecame
TitleEthnicity/Vaccine COVID-19 – CCG - PseudoVaccine COVID-19 – CCG - Pseudo
Start date2021-09-102021-10-08
End date2022-03-312022-11-30

Datasets: − COVID-19 Ethnic Category Data Set

Objective for processing

A letter has been issued to the Data Controller to amend the terms of this data sharing agreement. The amendments to the agreement are as follows: • The removal of CV19: Regulation 3 (4) of the Health Service (Control of Patient Information) Regulations 2002 as the legal basis for dissemination. The data is no longer described as “confidential”. • The change of GDPR Article 6 legal basis from - Article 6 (1) (c) to - Article 6 (1) (e) • The extension of the DSA end date to 30/11/2022 The letter has been issued to ensure data continues to flow to support commissioning and allow all parties to work on the new agreements required to support new Integrated Care Board data sharing agreement. [16 paragraphs unchanged] COVID-19 Ethnic Category Data Set NHS Digital has created a small stand-alone dataset known as the COVID-19 Ethnic Category Data Set. This data set is created using ethnic category data from the General Practice Extraction Service (GPES) Data for Pandemic Planning and Research (COVID-19) (GDPPR) and Hospital Episodes Statistics (HES). By combining GDPPR ethnic category data with the latest available ethnicity data in HES, NHS Digital can substantively increase coverage in ethnic category data and therefore add strength to the GDPPR dataset when linked. [20 paragraphs unchanged]

Processing activities

[21 paragraphs unchanged] The Data Services for Commissioners Regional Office (DSCRO) obtains the following COVID Vaccine Data data sets: - COVID Vaccine Data - COVID-19 Ethnic Category Data Set [1 paragraph unchanged] 1. Pseudonymised COVID Vaccine and COVID-19 Ethnic Category Data Set data is securely transferred from the DSCRO to the Data Controller / Processor [2 paragraphs unchanged]

Unchanged: Expected output, Expected measurable benefits, Benefits reported.

DARS-NIC-391600-Q4Y2J-v2.2 10 September 2021 to 31 March 2022
Title
Ethnicity/Vaccine COVID-19 – CCG - Pseudo
Commercial
No
Sublicensing
No
Datasets
2
Files released
0

Datasets: COVID-19 Ethnic Category Data Set; COVID-19 Vaccination Status

What changed from DARS-NIC-391600-Q4Y2J-v1.2

Text removed is struck through; text added is underlined. Unchanged paragraphs are summarised rather than repeated.

Fields changed from DARS-NIC-391600-Q4Y2J-v1.2
FieldWasBecame
TitleGDPPR COVID-19 – CCG - PseudoEthnicity/Vaccine COVID-19 – CCG - Pseudo
Start date2020-09-012021-09-10
End date2021-09-302022-03-31

Datasets: + COVID-19 Ethnic Category Data Set; + COVID-19 Vaccination Status · − COVID-19 General Practice Extraction Service (GPES) Data for Pandemic Planning and Research (GDPPR)

Objective for processing

[1 paragraph unchanged] GPES data for pandemic planning and research (GDPPR COVID 19) COVID Vaccine data To support the response to the outbreak, NHS Digital has been legally directed to collect and analyse healthcare information about patients from their GP record for the duration of the COVID-19 emergency period under the COVID-19 Directions. NHS England and NHS Digital have agreed that NHS Digital should become a joint controller of the Vaccine Data with NHS England under the COVID-19 Public Health (NHS England) Directions 2020 (COVID-19 Directions) to facilitate the analysis, linkage and dissemination of the Vaccine Data to requestors who have an appropriate legal basis to process it. The data which NHS Digital has collected and is providing under this agreement includes coded health data, which is held in a patient’s GP record, such as details of: There is high demand from CCGs for the Vaccine Data which will help them; • diagnoses and findings - Understand vaccine categories and success of population roll out in their respective areas, required for weekly report to NHSE/Cabinet office • medications and other prescribed items - Understand and decide whether new vaccine sites are required and stock control of vaccines to ensure immediate delivery/deploy to appropriate patients. • investigations, tests and results - Moderate and manage readmissions post vaccine e.g. how many patients are being re-admitted post vaccination • treatments and outcomes - Monitor secondary care Shielded patient activity post-vaccination. • vaccinations and immunisations - Identifying areas of low vaccine take-up and work directly with local communities and community leaders to address concerns. Details of any sensitive SNOMED codes included in the GDPPR data set can be found in the Reference Data and GDPPR COVID 19 user guides hosted on the NHS Digital website. SNOMED codes are included in GDPPR data. - Ensure vulnerable individuals and groups are identified and supported through the vaccination process to ensure the maximum possible vaccination uptake. There are no free text record entries in the data. NHS Digital has agreed to share the data with the recipients and their processors for the purpose of supporting the recipients in their local response to the COVID-19 emergency as part of the national response to the COVID-19 pandemic. The Controller will use the pseudonymised GDPPR COVID 19 data to provide intelligence to support their local response to the COVID-19 emergency. The data is analysed so that health care provision can be planned to support the needs of the population within the CCG area for the COVID-19 purposes. The Vaccine Data will include; Such uses of the data include but are not limited to: - Patient demographics • Analysis of missed appointments - Analysis of local missed/delayed referrals due to the COVID-19 crisis to estimate the potential impact and to estimate when ‘normal’ health and care services may resume, linked to Paragraph 2.2.3 of the COVID-19 Directions. - Source organisation (where the vaccination data originated) • Patient risk stratification and predictive modelling - to highlight patients at risk of requiring hospital admission due to COVID-19, computed using algorithms executed against linked de-identified data, and identification of future service delivery models linked to Paragraph 2.2.2 of the COVID-19 Directions. As with all risk stratification, this would lead to the identification of the characteristics of a cohort that could subsequently, and separately, be used to identify individuals for intervention. However the identification of individuals will not be done as part of this data sharing agreement, and the data shared under this agreement will not be reidentified. - Vaccination appointment and outcome details • Resource Allocation - In order to assess system wide impact of COVID-19, the GDPPR COVID 19 data will allow reallocation of resources to the worst hit localities using their expertise in scenario planning, clinical impact and assessment of workforce needs, linked to Paragraph 2.2.4 of the COVID-19 Directions: - Vaccine batch details The data may only be linked by the Data Controller or their respective Data Processor, to other pseudonymised datasets which it holds under a current data sharing agreement only where such data is provided for the purposes of general commissioning by NHS Digital. The Health Service Control of Patient Information Regulations (COPI) will also apply to any data linked to the GDPPR data. COVID-19 Ethnic Category Data Set The linked data may only be used for purposes stipulated within this agreement and may only be held and used whilst both data sharing agreements are live and in date. Using the linked data for any other purposes, including non-COVID-19 purposes would be considered a breach of this agreement. Reidentification of individuals is not permitted under this DSA. NHS Digital has created a small stand-alone dataset known as the COVID-19 Ethnic Category Data Set. This data set is created using ethnic category data from the General Practice Extraction Service (GPES) Data for Pandemic Planning and Research (COVID-19) (GDPPR) and Hospital Episodes Statistics (HES). By combining GDPPR ethnic category data with the latest available ethnicity data in HES, NHS Digital can substantively increase coverage in ethnic category data and therefore add strength to the GDPPR dataset when linked. LINKAGE The data may only be linked by the Data Controller or their respective Data Processor, to other pseudonymised datasets which it holds under a current data sharing agreement only where such data is provided for the purposes of general commissioning by NHS Digital. The Health Service Control of Patient Information Regulations (COPI) will also apply to any data linked to the data under this agreement. The linked data may only be used for purposes stipulated within this agreement and may only be held and used whilst both data sharing agreements are live and in date. Using the linked data for any other purposes, including non-COVID-19 purposes would be considered a breach of this agreement. RE-IDENTIFICATION Reidentification of individuals under the vaccination dataset is permitted but only for the purposes of direct care and is strictly limited to direct health care professionals or local authority direct care staff only with a legitimate relationship to the patient. All re-identification requests will be processed and authorised by the DSCRO on a case by case basis. [15 paragraphs unchanged]

Processing activities

[8 paragraphs unchanged] The data disseminated will only be used for COVID-19 GDPPR purposes as described in this DSA, any other purpose is excluded. [13 paragraphs unchanged] - GDPPR COVID 19 Vaccine Data - COVID-19 Ethnic Category Data Set [1 paragraph unchanged] 1. Pseudonymised GDPPR COVID 19 Vaccine and COVID-19 Ethnic Category Data Set data is securely transferred from the DSCRO to the Data Controller / Processor [2 paragraphs unchanged]

Expected output

• Operational planning to predict likely demand on primary, community and acute service for vulnerable patients due to the impact of COVID-19 • Reports for NHSE/Cabinet Office on the success of Vaccine rollout • Analysis of resource allocation • Identification of areas of low vaccine take up leading to work with local communities to address concerns • Investigating and monitoring the effects of COVID-19 • Patient Stratification in relation to COVID-19, such as: o Patients at highest risk of admission o Frail and elderly o Patients that are currently in hospital o Patients with prescriptions related to COVID-19 o Patients recently Discharged from hospital [1 paragraph unchanged]

Expected measurable benefits

• Manage demand and capacity • Reallocation of resources • Bring in additional workforce support • Assists commissioners to make better decisions to support patients • Identifying COVID-19 trends and risks to public health • Enables CCGs to provide guidance and develop policies to respond to the outbreak [1 paragraph unchanged] • Maintaining the high percentage of the population receiving the vaccination

Benefits reported

Not stated in the previous version; added here.

The CCG is unable to evidence any achieved yielded benefits as of yet as they have not been able to process the data for a substantial amount of time.

Objective for processing

NHS Digital has been provided with the necessary powers to support the Secretary of State’s response to COVID-19 under the COVID-19 Public Health Directions 2020 (COVID-19 Directions) and support various COVID-19 purposes, the data shared under this agreement can be used for these specified purposes except where they would require the reidentification of individuals.

COVID Vaccine data

NHS England and NHS Digital have agreed that NHS Digital should become a joint controller of the Vaccine Data with NHS England under the COVID-19 Public Health (NHS England) Directions 2020 (COVID-19 Directions) to facilitate the analysis, linkage and dissemination of the Vaccine Data to requestors who have an appropriate legal basis to process it.

There is high demand from CCGs for the Vaccine Data which will help them;

- Understand vaccine categories and success of population roll out in their respective areas, required for weekly report to NHSE/Cabinet office

- Understand and decide whether new vaccine sites are required and stock control of vaccines to ensure immediate delivery/deploy to appropriate patients.

- Moderate and manage readmissions post vaccine e.g. how many patients are being re-admitted post vaccination

- Monitor secondary care Shielded patient activity post-vaccination.

- Identifying areas of low vaccine take-up and work directly with local communities and community leaders to address concerns.

- Ensure vulnerable individuals and groups are identified and supported through the vaccination process to ensure the maximum possible vaccination uptake.

NHS Digital has agreed to share the data with the recipients and their processors for the purpose of supporting the recipients in their local response to the COVID-19 emergency as part of the national response to the COVID-19 pandemic.

The Vaccine Data will include;

- Patient demographics

- Source organisation (where the vaccination data originated)

- Vaccination appointment and outcome details

- Vaccine batch details

COVID-19 Ethnic Category Data Set

NHS Digital has created a small stand-alone dataset known as the COVID-19 Ethnic Category Data Set. This data set is created using ethnic category data from the General Practice Extraction Service (GPES) Data for Pandemic Planning and Research (COVID-19) (GDPPR) and Hospital Episodes Statistics (HES). By combining GDPPR ethnic category data with the latest available ethnicity data in HES, NHS Digital can substantively increase coverage in ethnic category data and therefore add strength to the GDPPR dataset when linked.

LINKAGE

The data may only be linked by the Data Controller or their respective Data Processor, to other pseudonymised datasets which it holds under a current data sharing agreement only where such data is provided for the purposes of general commissioning by NHS Digital. The Health Service Control of Patient Information Regulations (COPI) will also apply to any data linked to the data under this agreement.

The linked data may only be used for purposes stipulated within this agreement and may only be held and used whilst both data sharing agreements are live and in date. Using the linked data for any other purposes, including non-COVID-19 purposes would be considered a breach of this agreement.

RE-IDENTIFICATION

Reidentification of individuals under the vaccination dataset is permitted but only for the purposes of direct care and is strictly limited to direct health care professionals or local authority direct care staff only with a legitimate relationship to the patient. All re-identification requests will be processed and authorised by the DSCRO on a case by case basis.

LEGAL BASIS FOR PROCESSING DATA:

Legal Basis for NHS Digital to Disseminate the Data:

NHS Digital is able to disseminate data with the Recipients for the agreed purposes under a notice issued to NHS Digital by the Secretary of State for Health and Social Care under Regulation 3(4) of the Health Service Control of Patient Information Regulations (COPI) dated 17 March 2020 (the NHSD COPI Notice).

The Recipients are health organisations covered by Regulation 3(3) of COPI and the agreed purposes (paragraphs 2.2.2-2.2.4 of the COVID-19 Directions, as stated below in section 5a) for which the disseminated data is being shared are covered by Regulation 3(1) of COPI.

Under the Health and Social Care Act, NHS Digital is relying on section 261(5)(d) – necessary or expedient to share the disseminated data with the Recipients for the agreed purposes.

Legal Basis for Processing:

The Recipients are able to receive and process the disseminated data under a notice issued to the Recipients by the Secretary of State for Health and Social Care under Regulation 3(4) of COPI dated 20th March (the Recipient COPI Notice section 2).

The Secretary of State has issued notices under the Health Service Control of Patient Information Regulations 2002 requiring the following organisations to process information:

Health organisations

“Health Organisations” defined below under Regulation 3(3) of COPI includes CCGs for the reasons explained below. These are clinically led statutory NHS bodies responsible for the planning and commissioning of health care services for their local area

The Secretary of State for Health and Social Care has issued NHS Digital with a Notice under Regulation 3(4) of the National Health Service (Control of Patient Information Regulations) 2002 (COPI) to require NHS Digital to share confidential patient information with organisations permitted to process confidential information under Regulation 3(3) of COPI. These include:

• persons employed or engaged for the purposes of the health service

Under Section 26 of the Health and Social Care Act 2012, CCG’s have a duty to provide and manage health services for the population.

Regulation 7 of COPI includes certain limitations. The request has considered these limitations, considering data minimisation, access controls and technical and organisational measures.

Under GDPR, the Recipients can rely on Article 6(1)(c) – Legal Obligation to receive and process the Disclosed Data from NHS Digital for the Agreed Purposes under the Recipient COPI Notice. As this is health information and therefore special category personal data the Recipients can also rely on Article 9(2)(h) – preventative or occupational medicine and para 6 of Schedule 1 DPA – statutory purpose.

Expected output

• Reports for NHSE/Cabinet Office on the success of Vaccine rollout

• Identification of areas of low vaccine take up leading to work with local communities to address concerns

For avoidance of doubt these are pseudonymised patient cohorts, not identifiable.

Benefits reported

The CCG is unable to evidence any achieved yielded benefits as of yet as they have not been able to process the data for a substantial amount of time.

DARS-NIC-391600-Q4Y2J-v1.2 1 September 2020 to 30 September 2021
Title
GDPPR COVID-19 – CCG - Pseudo
Commercial
No
Sublicensing
No
Datasets
1
Files released
0

Datasets: COVID-19 General Practice Extraction Service (GPES) Data for Pandemic Planning and Research (GDPPR)

What changed from DARS-NIC-391600-Q4Y2J-v0.2

Text removed is struck through; text added is underlined. Unchanged paragraphs are summarised rather than repeated.

Fields changed from DARS-NIC-391600-Q4Y2J-v0.2
FieldWasBecame
End date2021-03-312021-09-30

Benefits reported

Stated in the previous version and removed here.

Yielded Benefits is not a requirement for new applications.

Unchanged: Objective for processing, Processing activities, Expected output, Expected measurable benefits.

Objective for processing

NHS Digital has been provided with the necessary powers to support the Secretary of State’s response to COVID-19 under the COVID-19 Public Health Directions 2020 (COVID-19 Directions) and support various COVID-19 purposes, the data shared under this agreement can be used for these specified purposes except where they would require the reidentification of individuals.

GPES data for pandemic planning and research (GDPPR COVID 19)

To support the response to the outbreak, NHS Digital has been legally directed to collect and analyse healthcare information about patients from their GP record for the duration of the COVID-19 emergency period under the COVID-19 Directions.

The data which NHS Digital has collected and is providing under this agreement includes coded health data, which is held in a patient’s GP record, such as details of:

• diagnoses and findings

• medications and other prescribed items

• investigations, tests and results

• treatments and outcomes

• vaccinations and immunisations

Details of any sensitive SNOMED codes included in the GDPPR data set can be found in the Reference Data and GDPPR COVID 19 user guides hosted on the NHS Digital website. SNOMED codes are included in GDPPR data.

There are no free text record entries in the data.

The Controller will use the pseudonymised GDPPR COVID 19 data to provide intelligence to support their local response to the COVID-19 emergency. The data is analysed so that health care provision can be planned to support the needs of the population within the CCG area for the COVID-19 purposes.

Such uses of the data include but are not limited to:

• Analysis of missed appointments - Analysis of local missed/delayed referrals due to the COVID-19 crisis to estimate the potential impact and to estimate when ‘normal’ health and care services may resume, linked to Paragraph 2.2.3 of the COVID-19 Directions.

• Patient risk stratification and predictive modelling - to highlight patients at risk of requiring hospital admission due to COVID-19, computed using algorithms executed against linked de-identified data, and identification of future service delivery models linked to Paragraph 2.2.2 of the COVID-19 Directions. As with all risk stratification, this would lead to the identification of the characteristics of a cohort that could subsequently, and separately, be used to identify individuals for intervention. However the identification of individuals will not be done as part of this data sharing agreement, and the data shared under this agreement will not be reidentified.

• Resource Allocation - In order to assess system wide impact of COVID-19, the GDPPR COVID 19 data will allow reallocation of resources to the worst hit localities using their expertise in scenario planning, clinical impact and assessment of workforce needs, linked to Paragraph 2.2.4 of the COVID-19 Directions:

The data may only be linked by the Data Controller or their respective Data Processor, to other pseudonymised datasets which it holds under a current data sharing agreement only where such data is provided for the purposes of general commissioning by NHS Digital. The Health Service Control of Patient Information Regulations (COPI) will also apply to any data linked to the GDPPR data.

The linked data may only be used for purposes stipulated within this agreement and may only be held and used whilst both data sharing agreements are live and in date. Using the linked data for any other purposes, including non-COVID-19 purposes would be considered a breach of this agreement. Reidentification of individuals is not permitted under this DSA.

LEGAL BASIS FOR PROCESSING DATA:

Legal Basis for NHS Digital to Disseminate the Data:

NHS Digital is able to disseminate data with the Recipients for the agreed purposes under a notice issued to NHS Digital by the Secretary of State for Health and Social Care under Regulation 3(4) of the Health Service Control of Patient Information Regulations (COPI) dated 17 March 2020 (the NHSD COPI Notice).

The Recipients are health organisations covered by Regulation 3(3) of COPI and the agreed purposes (paragraphs 2.2.2-2.2.4 of the COVID-19 Directions, as stated below in section 5a) for which the disseminated data is being shared are covered by Regulation 3(1) of COPI.

Under the Health and Social Care Act, NHS Digital is relying on section 261(5)(d) – necessary or expedient to share the disseminated data with the Recipients for the agreed purposes.

Legal Basis for Processing:

The Recipients are able to receive and process the disseminated data under a notice issued to the Recipients by the Secretary of State for Health and Social Care under Regulation 3(4) of COPI dated 20th March (the Recipient COPI Notice section 2).

The Secretary of State has issued notices under the Health Service Control of Patient Information Regulations 2002 requiring the following organisations to process information:

Health organisations

“Health Organisations” defined below under Regulation 3(3) of COPI includes CCGs for the reasons explained below. These are clinically led statutory NHS bodies responsible for the planning and commissioning of health care services for their local area

The Secretary of State for Health and Social Care has issued NHS Digital with a Notice under Regulation 3(4) of the National Health Service (Control of Patient Information Regulations) 2002 (COPI) to require NHS Digital to share confidential patient information with organisations permitted to process confidential information under Regulation 3(3) of COPI. These include:

• persons employed or engaged for the purposes of the health service

Under Section 26 of the Health and Social Care Act 2012, CCG’s have a duty to provide and manage health services for the population.

Regulation 7 of COPI includes certain limitations. The request has considered these limitations, considering data minimisation, access controls and technical and organisational measures.

Under GDPR, the Recipients can rely on Article 6(1)(c) – Legal Obligation to receive and process the Disclosed Data from NHS Digital for the Agreed Purposes under the Recipient COPI Notice. As this is health information and therefore special category personal data the Recipients can also rely on Article 9(2)(h) – preventative or occupational medicine and para 6 of Schedule 1 DPA – statutory purpose.

Expected output

• Operational planning to predict likely demand on primary, community and acute service for vulnerable patients due to the impact of COVID-19

• Analysis of resource allocation

• Investigating and monitoring the effects of COVID-19

• Patient Stratification in relation to COVID-19, such as:

o Patients at highest risk of admission

o Frail and elderly

o Patients that are currently in hospital

o Patients with prescriptions related to COVID-19

o Patients recently Discharged from hospital

For avoidance of doubt these are pseudonymised patient cohorts, not identifiable.

DARS-NIC-391600-Q4Y2J-v0.2 1 September 2020 to 31 March 2021
Title
GDPPR COVID-19 – CCG - Pseudo
Commercial
No
Sublicensing
No
Datasets
1
Files released
0

Datasets: COVID-19 General Practice Extraction Service (GPES) Data for Pandemic Planning and Research (GDPPR)

Objective for processing

NHS Digital has been provided with the necessary powers to support the Secretary of State’s response to COVID-19 under the COVID-19 Public Health Directions 2020 (COVID-19 Directions) and support various COVID-19 purposes, the data shared under this agreement can be used for these specified purposes except where they would require the reidentification of individuals.

GPES data for pandemic planning and research (GDPPR COVID 19)

To support the response to the outbreak, NHS Digital has been legally directed to collect and analyse healthcare information about patients from their GP record for the duration of the COVID-19 emergency period under the COVID-19 Directions.

The data which NHS Digital has collected and is providing under this agreement includes coded health data, which is held in a patient’s GP record, such as details of:

• diagnoses and findings

• medications and other prescribed items

• investigations, tests and results

• treatments and outcomes

• vaccinations and immunisations

Details of any sensitive SNOMED codes included in the GDPPR data set can be found in the Reference Data and GDPPR COVID 19 user guides hosted on the NHS Digital website. SNOMED codes are included in GDPPR data.

There are no free text record entries in the data.

The Controller will use the pseudonymised GDPPR COVID 19 data to provide intelligence to support their local response to the COVID-19 emergency. The data is analysed so that health care provision can be planned to support the needs of the population within the CCG area for the COVID-19 purposes.

Such uses of the data include but are not limited to:

• Analysis of missed appointments - Analysis of local missed/delayed referrals due to the COVID-19 crisis to estimate the potential impact and to estimate when ‘normal’ health and care services may resume, linked to Paragraph 2.2.3 of the COVID-19 Directions.

• Patient risk stratification and predictive modelling - to highlight patients at risk of requiring hospital admission due to COVID-19, computed using algorithms executed against linked de-identified data, and identification of future service delivery models linked to Paragraph 2.2.2 of the COVID-19 Directions. As with all risk stratification, this would lead to the identification of the characteristics of a cohort that could subsequently, and separately, be used to identify individuals for intervention. However the identification of individuals will not be done as part of this data sharing agreement, and the data shared under this agreement will not be reidentified.

• Resource Allocation - In order to assess system wide impact of COVID-19, the GDPPR COVID 19 data will allow reallocation of resources to the worst hit localities using their expertise in scenario planning, clinical impact and assessment of workforce needs, linked to Paragraph 2.2.4 of the COVID-19 Directions:

The data may only be linked by the Data Controller or their respective Data Processor, to other pseudonymised datasets which it holds under a current data sharing agreement only where such data is provided for the purposes of general commissioning by NHS Digital. The Health Service Control of Patient Information Regulations (COPI) will also apply to any data linked to the GDPPR data.

The linked data may only be used for purposes stipulated within this agreement and may only be held and used whilst both data sharing agreements are live and in date. Using the linked data for any other purposes, including non-COVID-19 purposes would be considered a breach of this agreement. Reidentification of individuals is not permitted under this DSA.

LEGAL BASIS FOR PROCESSING DATA:

Legal Basis for NHS Digital to Disseminate the Data:

NHS Digital is able to disseminate data with the Recipients for the agreed purposes under a notice issued to NHS Digital by the Secretary of State for Health and Social Care under Regulation 3(4) of the Health Service Control of Patient Information Regulations (COPI) dated 17 March 2020 (the NHSD COPI Notice).

The Recipients are health organisations covered by Regulation 3(3) of COPI and the agreed purposes (paragraphs 2.2.2-2.2.4 of the COVID-19 Directions, as stated below in section 5a) for which the disseminated data is being shared are covered by Regulation 3(1) of COPI.

Under the Health and Social Care Act, NHS Digital is relying on section 261(5)(d) – necessary or expedient to share the disseminated data with the Recipients for the agreed purposes.

Legal Basis for Processing:

The Recipients are able to receive and process the disseminated data under a notice issued to the Recipients by the Secretary of State for Health and Social Care under Regulation 3(4) of COPI dated 20th March (the Recipient COPI Notice section 2).

The Secretary of State has issued notices under the Health Service Control of Patient Information Regulations 2002 requiring the following organisations to process information:

Health organisations

“Health Organisations” defined below under Regulation 3(3) of COPI includes CCGs for the reasons explained below. These are clinically led statutory NHS bodies responsible for the planning and commissioning of health care services for their local area

The Secretary of State for Health and Social Care has issued NHS Digital with a Notice under Regulation 3(4) of the National Health Service (Control of Patient Information Regulations) 2002 (COPI) to require NHS Digital to share confidential patient information with organisations permitted to process confidential information under Regulation 3(3) of COPI. These include:

• persons employed or engaged for the purposes of the health service

Under Section 26 of the Health and Social Care Act 2012, CCG’s have a duty to provide and manage health services for the population.

Regulation 7 of COPI includes certain limitations. The request has considered these limitations, considering data minimisation, access controls and technical and organisational measures.

Under GDPR, the Recipients can rely on Article 6(1)(c) – Legal Obligation to receive and process the Disclosed Data from NHS Digital for the Agreed Purposes under the Recipient COPI Notice. As this is health information and therefore special category personal data the Recipients can also rely on Article 9(2)(h) – preventative or occupational medicine and para 6 of Schedule 1 DPA – statutory purpose.

Expected output

• Operational planning to predict likely demand on primary, community and acute service for vulnerable patients due to the impact of COVID-19

• Analysis of resource allocation

• Investigating and monitoring the effects of COVID-19

• Patient Stratification in relation to COVID-19, such as:

o Patients at highest risk of admission

o Frail and elderly

o Patients that are currently in hospital

o Patients with prescriptions related to COVID-19

o Patients recently Discharged from hospital

For avoidance of doubt these are pseudonymised patient cohorts, not identifiable.

Benefits reported

Yielded Benefits is not a requirement for new applications.

Register history

When this agreement appeared in, or was edited in, each monthly edition of the register. Built by comparing every edition this site holds, the earliest of which is July 2021.

"Amended in place" means NHS England changed the record without issuing a new version number. The register publishes no changelog for those edits; this site infers them by comparing editions. An edit is attributed to the edition it first appears in, not to the date it was made.

Cite this page

NHS England (2026) Data Uses Register, September 2026 edition, agreement DARS-NIC-391600-Q4Y2J, “Vaccine COVID-19 – CCG - Pseudo”. Read via NHS Data Access Explorer (unofficial), https://healthdatauses.uk/agreements/dars-nic-391600-q4y2j/ (accessed [date]).

This address stays the same, but the page is rebuilt with each monthly edition, so the citation names the edition it shows. Every edition's data is kept in the facts store.

Source: datausesregister_september2026.xlsx, September 2026 edition of the NHS England Data Uses Register. Search that workbook for DARS-NIC-391600-Q4Y2J to see the original rows.