SUS-COVID vaccination datasets for MHRA surveillance through CPRD
Clinical Practice Research Datalink (CPRD) · Research
In term In term in the September 2026 edition: the latest version runs to 6 February 2027.
- Reference
- DARS-NIC-424723-D5Q9W
- Current version
- v4.2
- Term of current version
- 7 February 2025 to 6 February 2027
- Start date
- 11 February 2021
- Data controller
- Sole Data Controller
- Commercial purposes
- No
- Sublicensing
- No
- Files released to date
- 0
Data controllers
Why the data was released
Objective for processing
The Medicines and Healthcare products Regulatory Agency (MHRA) requires NHS England data to carry out essential regulation of the CV19 vaccination roll out. This measure is being put in place until the flow of this data is captured in the routine GP data flows to the MHRA. The data supplied under this agreement will be used solely for this purpose.
The controller for UK GDPR purposes is the Department of Health and Social Care (DHSC); the legal signatory for this agreement (and for the overarching DSFC) is the Secretary of State for Health and Social Care (acting as part of the Crown), acting through the Clinical Practice Research Datalink centre (hereinafter referred to as CPRD) within the Medicines and Healthcare products Regulatory Agency (the agency); and the licensee is CPRD as a part of the MHRA, not the wider DHSC.
The Clinical Practice Research Datalink (CPRD) is a centre of the Medicines and Healthcare products Regulatory Agency (MHRA), an executive agency of the Department of Health and Social Care (DHSC). The agency regulates medicines (including vaccines), medical devices and blood components for transfusion in the UK and the agency acts as an Executive agency.
The Clinical Practice Research Datalink (CPRD) is a government not for profit research organisation, jointly supported by the Medicines and Healthcare products Regulatory Agency (MHRA) and the National Institute of Health Research (NIHR), supplying anonymised health data for studies to safeguard and improve patient and public health. For more than 30 years, CPRD data have supported vital research into health care delivery, drug safety, effectiveness of medicines and risk factors for disease. It currently receives data and linkage services from NHS England under a separate DSA (DARS-NIC-15625-T8K6L) for public health research.
These flows of COVID-related data are required for an additional 12 months (this is in addition to the data already provided), possibly longer. The position will be reviewed to assess if there is sufficient up to date data. Currently GP system providers are not able to routinely integrate the SUS data into their own systems.
Specifically with reference to this agreement MHRA are acting as a processor on NHS England's behalf in relation to three data flows for COVID-19 vaccine surveillance:
1) COVID-19 Vaccination Dataset - from NHS England (not covered by this agreement)
2) COVID-19 Vaccination Adverse Reactions Dataset - from NHS England (Not covered by this agreement)
3) Minimal bespoke extract from SUS Dataset (Minimal SUS Dataset for COVID-19 Surveillance) - for COVID-19 Surveillance (Purpose of this agreement)
Because of the rapid rollout of the vaccination programme, the GP suppliers had no immediate way of integrating COVID vaccine data from points 1 and 2 into their systems, hence the separate feed to CPRD. Over time, as the vaccine became more routine e.g. like flu and as GP System vendors updated their systems, MHRA would have expected datasets 1 and 2 to be integrated into the electronic health record (EHR) as standard and therefore that data would flow to CPRD via MHRA’s usual channels. Dataset 3, SUS, is controlled by NHS England and comes from a hospital setting and therefore MHRA never expected this to be integrated into the primary care EHR data.
The lawful basis for processing data under GDPR has been reviewed against the guidance provided by IGARD and been assessed as acceptable by NHS England. As per GDPR Article 6(1)(e) “processing is necessary for the performance of a task in the public interest or in the exercise of official authority vested in the controller” the Clinical Practice Research Datalink (CPRD is a function of the Medicines and Healthcare products Regulatory Agency (MHRA) which is a function of Department of Health and Social Care which is a public authority as per the FOI Act 2000 Part 1, section 3. Under Section 8 of the Data Protection Act 2018 CPRD are a function of a government department and provide the England-wide NHS observational and interventional research service. NHS England are satisfied that this request is appropriate, necessary and proportionate for the performance of the task described in the Purpose statement and that there is no other reasonable means for the data processor to achieve their purpose that is less intrusive to the data subjects.
The processing of Health Data, as a Special Category of Personal Data, as per GDPR Article 9(2)(i)” Processing is necessary for reasons of public interest in the area of public health, such as protecting against serious cross-border threats to health or ensuring high standards of quality and safety of health care and of medicinal products or medical devices, on the basis of Union or Member State law which provides for suitable and specific measures to safeguard the rights and freedoms of the data subject, in particular professional secrecy” as the processing is necessary for reasons of public interest in the area of public health (to monitor the new COVID-19 vaccines) and will be carried out under the responsibility of health professionals.
Data are being processed under the following functions within the statutory purpose;
• The Human Medicines Regulations 2012: S178c ‘take all appropriate measures to obtain accurate and verifiable data for the scientific evaluation of suspected adverse reaction reports’ and S179 ‘Obligation on licensing authority to operate pharmacovigilance system’
• MHRA as licensing authority: under Medicines and Healthcare products Regulatory Agency Trading Fund Order 2003 (SI 2003/1076), made under the Government Trading Funds Act 1973
The Agency performs the functions of the Secretary of State under UK legislation relating to medicines, medical devices and blood, amongst other things. From 1 April 2013, the Agency also performs the functions of the Secretary of State in relation to biological substances conferred under section 57 of the Health and Social Care Act 2012. These functions, which relate to ensuring the quality of biological medicines, were previously carried out by the Health Protection Agency through the non-statutory body, the National Institute of Biological Standards and Control (NIBSC). The NIBSC continues to deliver these functions as part of the Agency on behalf of the Secretary of State
Processing activities
There are to be three distinct dataflows - data will flow from NHS England to MHRA who are acting as a processor on NHS England's behalf:
1) COVID-19 Vaccination Dataset - from NHS England (not covered by this agreement)
2) COVID-19 Vaccination Adverse Reactions Dataset - from NHS England (Not covered by this agreement)
3) Minimal bespoke extract from SUS Dataset (Minimal SUS Dataset for COVID-19 Surveillance) - for COVID-19 Surveillance (Purpose of this agreement)
These datasets are to be restricted to the standard CPRD GP Cohort as per DARS-NIC-15625-T8K6L and updates are to be processed daily through MESH (see below).
For the first two dataflows, NHS England are already providing daily updates which will effect linkage to the CPRD cohort (discarding unmatched entries) and replacing identifiers with the usually CPRD GP_ID and GP_Practice_ID (ODS code). The resultant two files are already provided to CPRD via MESH (see below).
For the third dataflow (the purpose of this agreement) NHS England will apply the appropriate extract criteria to SUS to generate a daily update and apply the same matching top the CPRD cohort and the replacement of identifiers with the usual GP_IDs. Type 1 Opt-outs are applied to data by NHS England.
The GP_ID is the pseudonym for each patient in the record which the system provider sends to NHS England and CPRD. CPRD will then re-pseudonymise the GP_ID to a CPRD ID as part of its quality check and transformation when bringing the data inhouse. The GP_ID is only used in the data delivery stage and at the linkage stage- it is part of the standard process for data transfer and linkage.
CPRD will then link these datasets with CPRD primary-care data already received from GP practices and supply a restricted dataset to the Vigilance and Risk Management of Medicines (VRMM) section of the MHRA - the sole ultimate data recipient for this data flow to support their vaccine surveillance requirements.
There is no requirement to be able to sub-licence this data for research purposes as use will be limited to use within MHRA for its statutory duty to monitor the safety and effectiveness of medicines.
There are already established three MESH accounts for each of the three dataflows: VACCINATIONS_DAILY_1, ADVERSE_REACTIONS_DAILY_1, and SUS_EXTRACTS (one for each of the flows above, respectively)
SUS+ Disclosure Control / small number suppression
In order to protect patient confidentiality, when presenting results calculated from SUS+ record level data, outputs will contain only aggregate level data with small numbers suppressed in line with HES analysis guide. When publishing SUS+ data, users must make sure that cell values from 1 to 7 are suppressed at a local level to prevent possible identification of individuals from small counts within the table. Zeros (0) do not need to be suppressed. All other counts will be rounded to the nearest 5.
Sungard Availability Services Ltd are recorded as data storage addresses as for the purposes of this application. Sungard Availability Services Ltd is the primary data centre store and is considered to be the initial back-up and recovery. They are not involved in processing of the data in any way (Sungard Availability Services Ltd provide a facilities management and site management service). CPRD has confirmed that Sungard Availability Services Ltd does not have access to the server (neither administrative nor user rights). Therefore, any access to the data held under this agreement would be considered a breach of the agreement. This includes granting of access to the database[s] containing the data.
NTT Data UK Limited supply IT infrastructure for Medicines and Healthcare Products Regulatory Agency and are therefore listed as data processors. They supply support to the system, but do not access data. Therefore, any access to the data held under this agreement would be considered a breach of the agreement. This includes granting of access to the database[s] containing the data.
No processing of record level data will take place at any locations not stipulated in the agreement. Any changes to this must be enacted through an amendment to the agreement.
Expected output
Statutory & effective surveillance of new COVID vaccines - until normal dataflows from GP systems can be used.
Reports produced for the yellow card scheme and contributes to the vaccine safety surveillance.
Expected measurable benefits
Effective monitoring of the safety and quality of new COVID vaccines - until normal dataflows can be used. Avoidance of deaths or hospitalisation by enabling the provision of effective vaccines and detecting possible adverse reactions.
Access to new data remains essential for surveillance of the booster and Under18 vaccination programmes and fits under CPRDs surveillance requirements.
Given the scale of a COVID-19 mass immunisation programme, with many millions of doses of one or more novel vaccines administered across the UK over a relatively short time period, vigilance needs to be continuous, proactive and as near real-time as is possible. The importance of this is two-fold.
It needs to be very quickly established if any serious events which are temporally-related to vaccination are merely a coincidental association, and to do this in a robust, evidence-based way so that public confidence in a vaccine is not eroded unnecessarily. Indeed, such associations may be more likely whilst we are still in the midst of a national epidemic, and because most of the millions of people offered the vaccine in the early phase of a vaccination campaign will be elderly and/or have underlying medical conditions, which increases the likelihood of unrelated illnesses occurring soon after vaccination.
The Medicines and Healthcare products Regulatory Agency (MHRA) is the executive Agency of the Department of Health and Social Care that acts to protect and promote public health and patient safety, by ensuring that medicines and medical devices meet appropriate standards of safety, quality and efficacy.
The MHRA is responsible for monitoring these vaccines on an ongoing basis to ensure their benefits continue to outweigh any risks. This is a requirement for all authorised medicines and vaccines in the UK. This monitoring strategy is continuous, proactive and based on a wide range of information sources, with a dedicated team of scientists reviewing information daily to look for safety issues or unexpected rare events.
The Data is also expected to be of relevance to the UK Covid-19 inquiry. There is therefore a need for continued retention of the Data.
Benefits reported so far
The Data provided by NHS England has been used for the Statutory & effective monitoring of new COVID vaccines based on the duty of MHRA.
The data received to date has been critical in the surveillance of COVID-19 vaccinations, in particular in relation to assessment of issues such as myopericarditis with mRNA vaccines and menstrual disorders across all the vaccines used in the UK, in addition to its use in rapid cycle analysis for Adverse Events of Special Interest (AESIs).
The data has been used to rapidly detect, confirm, characterise and quantify any new risks that were not detected in clinical trials, to weigh these against the expected benefits and take any necessary action to minimise risks to individuals.
In May 2020, the Commission on Human Medicines established an Expert Working Group (EWG) to advise the Medicines and Healthcare products Regulatory Agency (MHRA) on its safety monitoring strategy for COVID-19 vaccine(s).
The EWG held four meetings from May to October 2020, during which it considered proposals and methodologies for MHRA-led vigilance activities. Based on this advice, the MHRA has developed, and now has in place, a four-stranded approach to vigilance, which is summarised in this report- https://www.gov.uk/government/publications/report-of-the-commission-on-human-medicines-expert-working-group-on-covid-19-vaccine-safety-surveillance/report-of-the-commission-on-human-medicines-expert-working-group-on-covid-19-vaccine-safety-surveillance
More information can also be found on the Coronavirus vaccine - weekly summary of Yellow Card reporting- https://www.gov.uk/government/publications/coronavirus-covid-19-vaccine-adverse-reactions/coronavirus-vaccine-summary-of-yellow-card-reporting
As of 23rd August 2022, 53 million people received a first dose of COVID-19 vaccine, 50 million received a second dose and 40 million received a third or booster dose. The MHRA continually monitors the safety of the COVID 19 vaccines through a comprehensive COVID-19 Vaccine Surveillance Strategy. This monitoring strategy is proactive and based on a wide range of information sources, including the data covered in this agreement with a dedicated team of scientists continually reviewing information to look for safety issues or any unexpected, rare events. As with all vaccines and medicines, the safety of COVID-19 vaccines is continuously monitored, and benefits and possible risks remain under review.
31/01/2024 UPDATE:
This data is received by CPRD to enable the Medicines and Healthcare products Regulatory Agency (MHRA) to carry out essential regulation of the Covid-19 vaccination roll out. The data has been used to date by CPRD to link with the CPRD primary-care data already received from GP practices and supply a restricted dataset to the Vigilance and Risk Management of Medicine (VRMM) section of the MHRA to support their vaccine surveillance requirements.
The data provided by NHS England has been used for the Statutory & effective monitoring of new COVID vaccines based on the duty of MHRA. The data received to date has been critical in the surveillance of COVID-19 vaccinations, in particular in relation to assessment of issues such as myopericarditis with mRNA vaccines and menstrual disorders across all the vaccines used in the UK, in addition to its use in rapid cycle analysis for Adverse Events of Special Interest (AESIs). The data has been used to rapidly detect, confirm, characterise and quantify any new risks that were not detected in clinical trials, to weigh these against the expected benefits and take any necessary action to minimise risks to individuals.
Datasets on the current version
Legal basis for provision: Health and Social Care Act 2012 – s261(2)(a)
| Dataset | Type of data | Sensitivity | Frequency | Confidential data |
|---|---|---|---|---|
| Minimal SUS Dataset for COVID-19 Surveillance | Anonymised - ICO Code Compliant | Sensitive | One-Off | Does not include the flow of confidential data |
Files released
Files released counts only files released externally by DARS. Access granted in NHS England's own systems, such as its Secure Data Environment, is not included.
No files recorded as released under this agreement.
Version history
The register lists each renewal of this agreement as a separate row. This site has 5 versions.
DARS-NIC-424723-D5Q9W-v4.2 7 February 2025 to 6 February 2027
- Title
- SUS-COVID vaccination datasets for MHRA surveillance through CPRD
- Commercial
- No
- Sublicensing
- No
- Datasets
- 1
- Files released
- 0
Datasets: Minimal SUS Dataset for COVID-19 Surveillance
What changed from DARS-NIC-424723-D5Q9W-v3.4
Text removed is struck through; text added is underlined. Unchanged paragraphs are summarised rather than repeated.
| Field | Was | Became |
|---|---|---|
| Start date | 2025-02-07 | |
| End date | 2027-02-06 |
Objective for processing
This agreement is requesting a continuation of a daily flow of data from NHS England to enable the
The
Medicines and Healthcare products Regulatory Agency (MHRA)
requires NHS England data
to carry out essential regulation of the CV19 vaccination roll out. This
[24 words unchanged]
data supplied under this agreement will be used solely for this purpose.
The controller for
UK
GDPR purposes is the Department of Health and Social Care (DHSC); the
[52 words unchanged]
is CPRD as a part of the MHRA, not the wider DHSC.
[14 paragraphs unchanged]
Expected measurable benefits
[6 paragraphs unchanged] The Data is also expected to be of relevance to the UK Covid-19 inquiry. There is therefore a need for continued retention of the Data.
Benefits reported
[7 paragraphs unchanged]
31/01/2024
UPDATE
UPDATE:
[2 paragraphs unchanged]
Unchanged: Processing activities, Expected output.
DARS-NIC-424723-D5Q9W-v3.4 11 February 2024 to 10 February 2025
- Title
- SUS-COVID vaccination datasets for MHRA surveillance through CPRD
- Commercial
- No
- Sublicensing
- No
- Datasets
- 1
- Files released
- 0
Datasets: Minimal SUS Dataset for COVID-19 Surveillance
What changed from DARS-NIC-424723-D5Q9W-v2.2
Text removed is struck through; text added is underlined. Unchanged paragraphs are summarised rather than repeated.
| Field | Was | Became |
|---|---|---|
| Start date | 2024-02-11 | |
| End date | 2025-02-10 |
Benefits reported
[7 paragraphs unchanged] 31/01/2024 UPDATE This data is received by CPRD to enable the Medicines and Healthcare products Regulatory Agency (MHRA) to carry out essential regulation of the Covid-19 vaccination roll out. The data has been used to date by CPRD to link with the CPRD primary-care data already received from GP practices and supply a restricted dataset to the Vigilance and Risk Management of Medicine (VRMM) section of the MHRA to support their vaccine surveillance requirements. The data provided by NHS England has been used for the Statutory & effective monitoring of new COVID vaccines based on the duty of MHRA. The data received to date has been critical in the surveillance of COVID-19 vaccinations, in particular in relation to assessment of issues such as myopericarditis with mRNA vaccines and menstrual disorders across all the vaccines used in the UK, in addition to its use in rapid cycle analysis for Adverse Events of Special Interest (AESIs). The data has been used to rapidly detect, confirm, characterise and quantify any new risks that were not detected in clinical trials, to weigh these against the expected benefits and take any necessary action to minimise risks to individuals.
Changed only in punctuation, spacing or capitalisation: Processing activities.
Unchanged: Objective for processing, Expected output, Expected measurable benefits.
Objective for processing
This agreement is requesting a continuation of a daily flow of data from NHS England to enable the Medicines and Healthcare products Regulatory Agency (MHRA) to carry out essential regulation of the CV19 vaccination roll out. This measure is being put in place until the flow of this data is captured in the routine GP data flows to the MHRA. The data supplied under this agreement will be used solely for this purpose.
The controller for GDPR purposes is the Department of Health and Social Care (DHSC); the legal signatory for this agreement (and for the overarching DSFC) is the Secretary of State for Health and Social Care (acting as part of the Crown), acting through the Clinical Practice Research Datalink centre (hereinafter referred to as CPRD) within the Medicines and Healthcare products Regulatory Agency (the agency); and the licensee is CPRD as a part of the MHRA, not the wider DHSC.
The Clinical Practice Research Datalink (CPRD) is a centre of the Medicines and Healthcare products Regulatory Agency (MHRA), an executive agency of the Department of Health and Social Care (DHSC). The agency regulates medicines (including vaccines), medical devices and blood components for transfusion in the UK and the agency acts as an Executive agency.
The Clinical Practice Research Datalink (CPRD) is a government not for profit research organisation, jointly supported by the Medicines and Healthcare products Regulatory Agency (MHRA) and the National Institute of Health Research (NIHR), supplying anonymised health data for studies to safeguard and improve patient and public health. For more than 30 years, CPRD data have supported vital research into health care delivery, drug safety, effectiveness of medicines and risk factors for disease. It currently receives data and linkage services from NHS England under a separate DSA (DARS-NIC-15625-T8K6L) for public health research.
These flows of COVID-related data are required for an additional 12 months (this is in addition to the data already provided), possibly longer. The position will be reviewed to assess if there is sufficient up to date data. Currently GP system providers are not able to routinely integrate the SUS data into their own systems.
Specifically with reference to this agreement MHRA are acting as a processor on NHS England's behalf in relation to three data flows for COVID-19 vaccine surveillance:
1) COVID-19 Vaccination Dataset - from NHS England (not covered by this agreement)
2) COVID-19 Vaccination Adverse Reactions Dataset - from NHS England (Not covered by this agreement)
3) Minimal bespoke extract from SUS Dataset (Minimal SUS Dataset for COVID-19 Surveillance) - for COVID-19 Surveillance (Purpose of this agreement)
Because of the rapid rollout of the vaccination programme, the GP suppliers had no immediate way of integrating COVID vaccine data from points 1 and 2 into their systems, hence the separate feed to CPRD. Over time, as the vaccine became more routine e.g. like flu and as GP System vendors updated their systems, MHRA would have expected datasets 1 and 2 to be integrated into the electronic health record (EHR) as standard and therefore that data would flow to CPRD via MHRA’s usual channels. Dataset 3, SUS, is controlled by NHS England and comes from a hospital setting and therefore MHRA never expected this to be integrated into the primary care EHR data.
The lawful basis for processing data under GDPR has been reviewed against the guidance provided by IGARD and been assessed as acceptable by NHS England. As per GDPR Article 6(1)(e) “processing is necessary for the performance of a task in the public interest or in the exercise of official authority vested in the controller” the Clinical Practice Research Datalink (CPRD is a function of the Medicines and Healthcare products Regulatory Agency (MHRA) which is a function of Department of Health and Social Care which is a public authority as per the FOI Act 2000 Part 1, section 3. Under Section 8 of the Data Protection Act 2018 CPRD are a function of a government department and provide the England-wide NHS observational and interventional research service. NHS England are satisfied that this request is appropriate, necessary and proportionate for the performance of the task described in the Purpose statement and that there is no other reasonable means for the data processor to achieve their purpose that is less intrusive to the data subjects.
The processing of Health Data, as a Special Category of Personal Data, as per GDPR Article 9(2)(i)” Processing is necessary for reasons of public interest in the area of public health, such as protecting against serious cross-border threats to health or ensuring high standards of quality and safety of health care and of medicinal products or medical devices, on the basis of Union or Member State law which provides for suitable and specific measures to safeguard the rights and freedoms of the data subject, in particular professional secrecy” as the processing is necessary for reasons of public interest in the area of public health (to monitor the new COVID-19 vaccines) and will be carried out under the responsibility of health professionals.
Data are being processed under the following functions within the statutory purpose;
• The Human Medicines Regulations 2012: S178c ‘take all appropriate measures to obtain accurate and verifiable data for the scientific evaluation of suspected adverse reaction reports’ and S179 ‘Obligation on licensing authority to operate pharmacovigilance system’
• MHRA as licensing authority: under Medicines and Healthcare products Regulatory Agency Trading Fund Order 2003 (SI 2003/1076), made under the Government Trading Funds Act 1973
The Agency performs the functions of the Secretary of State under UK legislation relating to medicines, medical devices and blood, amongst other things. From 1 April 2013, the Agency also performs the functions of the Secretary of State in relation to biological substances conferred under section 57 of the Health and Social Care Act 2012. These functions, which relate to ensuring the quality of biological medicines, were previously carried out by the Health Protection Agency through the non-statutory body, the National Institute of Biological Standards and Control (NIBSC). The NIBSC continues to deliver these functions as part of the Agency on behalf of the Secretary of State
Expected output
Statutory & effective surveillance of new COVID vaccines - until normal dataflows from GP systems can be used.
Reports produced for the yellow card scheme and contributes to the vaccine safety surveillance.
Benefits reported
The data provided by NHS England has been used for the Statutory & effective monitoring of new COVID vaccines based on the duty of MHRA.
The data received to date has been critical in the surveillance of COVID-19 vaccinations, in particular in relation to assessment of issues such as myopericarditis with mRNA vaccines and menstrual disorders across all the vaccines used in the UK, in addition to its use in rapid cycle analysis for Adverse Events of Special Interest (AESIs).
The data has been used to rapidly detect, confirm, characterise and quantify any new risks that were not detected in clinical trials, to weigh these against the expected benefits and take any necessary action to minimise risks to individuals.
In May 2020, the Commission on Human Medicines established an Expert Working Group (EWG) to advise the Medicines and Healthcare products Regulatory Agency (MHRA) on its safety monitoring strategy for COVID-19 vaccine(s).
The EWG held four meetings from May to October 2020, during which it considered proposals and methodologies for MHRA-led vigilance activities. Based on this advice, the MHRA has developed, and now has in place, a four-stranded approach to vigilance, which is summarised in this report- https://www.gov.uk/government/publications/report-of-the-commission-on-human-medicines-expert-working-group-on-covid-19-vaccine-safety-surveillance/report-of-the-commission-on-human-medicines-expert-working-group-on-covid-19-vaccine-safety-surveillance
More information can also be found on the Coronavirus vaccine - weekly summary of Yellow Card reporting- https://www.gov.uk/government/publications/coronavirus-covid-19-vaccine-adverse-reactions/coronavirus-vaccine-summary-of-yellow-card-reporting
As of 23rd August 2022, 53 million people received a first dose of COVID-19 vaccine, 50 million received a second dose and 40 million received a third or booster dose. The MHRA continually monitors the safety of the COVID 19 vaccines through a comprehensive COVID-19 Vaccine Surveillance Strategy. This monitoring strategy is proactive and based on a wide range of information sources, including the data covered in this agreement with a dedicated team of scientists continually reviewing information to look for safety issues or any unexpected, rare events. As with all vaccines and medicines, the safety of COVID-19 vaccines is continuously monitored, and benefits and possible risks remain under review.
31/01/2024 UPDATE
This data is received by CPRD to enable the Medicines and Healthcare products Regulatory Agency (MHRA) to carry out essential regulation of the Covid-19 vaccination roll out. The data has been used to date by CPRD to link with the CPRD primary-care data already received from GP practices and supply a restricted dataset to the Vigilance and Risk Management of Medicine (VRMM) section of the MHRA to support their vaccine surveillance requirements.
The data provided by NHS England has been used for the Statutory & effective monitoring of new COVID vaccines based on the duty of MHRA. The data received to date has been critical in the surveillance of COVID-19 vaccinations, in particular in relation to assessment of issues such as myopericarditis with mRNA vaccines and menstrual disorders across all the vaccines used in the UK, in addition to its use in rapid cycle analysis for Adverse Events of Special Interest (AESIs). The data has been used to rapidly detect, confirm, characterise and quantify any new risks that were not detected in clinical trials, to weigh these against the expected benefits and take any necessary action to minimise risks to individuals.
DARS-NIC-424723-D5Q9W-v2.2 11 February 2023 to 10 February 2024
- Title
- SUS-COVID vaccination datasets for MHRA surveillance through CPRD
- Commercial
- No
- Sublicensing
- No
- Datasets
- 1
- Files released
- 0
Datasets: Minimal SUS Dataset for COVID-19 Surveillance
What changed from DARS-NIC-424723-D5Q9W-v1.3
Text removed is struck through; text added is underlined. Unchanged paragraphs are summarised rather than repeated.
| Field | Was | Became |
|---|---|---|
| Start date | 2023-02-11 | |
| End date | 2024-02-10 | |
| Minimal SUS Dataset for COVID-19 Surveillance: legal basis | Health and Social Care Act 2012 – s261(2)(a) |
Objective for processing
This agreement is requesting a continuation of a daily flow of data from NHS
Digital
England
to enable the Medicines and Healthcare products Regulatory Agency (MHRA) to carry
[34 words unchanged]
data supplied under this agreement will be used solely for this purpose.
[2 paragraphs unchanged]
The Clinical Practice Research Datalink (CPRD) is a government not for profit
[57 words unchanged]
factors for disease. It currently receives data and linkage services from NHS
Digital
England
under a separate DSA (DARS-NIC-15625-T8K6L) for public health research.
These flows of COVID-related data are required for an additional 12 months
[14 words unchanged]
be reviewed to assess if there is sufficient up to date data.
Once the
Currently
GP system providers are
not
able to
routinely
integrate
this information
the SUS data
into their own
systems, this data sharing agreement will cease.
systems.
The lawful basis for processing data under GDPR has been reviewed against the guidance provided by IGARD and been assessed as acceptable by NHS Digital. As per GDPR Article 6(1)(e) “processing is necessary for the performance of a task in the public interest or in the exercise of official authority vested in the controller” the Clinical Practice Research Datalink (CPRD is a function of the Medicines and Healthcare products Regulatory Agency (MHRA) which is a function of Department of Health and Social Care which is a public authority as per the FOI Act 2000 Part 1, section 3. Under Section 8 of the Data Protection Act 2018 CPRD are a function of a government department and provide the England-wide NHS observational and interventional research service. NHS Digital are satisfied that this request is appropriate, necessary and proportionate for the performance of the task described in the Purpose statement and that there is no other reasonable means for the data processor to achieve their purpose that is less intrusive to the data subjects.
Specifically with reference to this agreement MHRA are acting as a processor on NHS England's behalf in relation to three data flows for COVID-19 vaccine surveillance:
1) COVID-19 Vaccination Dataset - from NHS England (not covered by this agreement)
2) COVID-19 Vaccination Adverse Reactions Dataset - from NHS England (Not covered by this agreement)
3) Minimal bespoke extract from SUS Dataset (Minimal SUS Dataset for COVID-19 Surveillance) - for COVID-19 Surveillance (Purpose of this agreement)
Because of the rapid rollout of the vaccination programme, the GP suppliers had no immediate way of integrating COVID vaccine data from points 1 and 2 into their systems, hence the separate feed to CPRD. Over time, as the vaccine became more routine e.g. like flu and as GP System vendors updated their systems, MHRA would have expected datasets 1 and 2 to be integrated into the electronic health record (EHR) as standard and therefore that data would flow to CPRD via MHRA’s usual channels. Dataset 3, SUS, is controlled by NHS England and comes from a hospital setting and therefore MHRA never expected this to be integrated into the primary care EHR data.
The lawful basis for processing data under GDPR has been reviewed against the guidance provided by IGARD and been assessed as acceptable by NHS England. As per GDPR Article 6(1)(e) “processing is necessary for the performance of a task in the public interest or in the exercise of official authority vested in the controller” the Clinical Practice Research Datalink (CPRD is a function of the Medicines and Healthcare products Regulatory Agency (MHRA) which is a function of Department of Health and Social Care which is a public authority as per the FOI Act 2000 Part 1, section 3. Under Section 8 of the Data Protection Act 2018 CPRD are a function of a government department and provide the England-wide NHS observational and interventional research service. NHS England are satisfied that this request is appropriate, necessary and proportionate for the performance of the task described in the Purpose statement and that there is no other reasonable means for the data processor to achieve their purpose that is less intrusive to the data subjects.
[5 paragraphs unchanged]
Processing activities
There are to be three distinct dataflows -
first two involve
data
will flow
from NHS England
where NHS Digital provide the data
to MHRA
who are
acting as a processor on NHS England's
behalf and the third data from NHS Digital itself:
behalf:
[4 paragraphs unchanged]
For the first two dataflows, NHS England are already providing daily updates
to NHS Digital,
which will effect linkage to the CPRD cohort (discarding unmatched entries) and
[12 words unchanged]
resultant two files are already provided to CPRD via MESH (see below).
For the third dataflow (the purpose of this agreement)
.
NHS
Digital
England
will apply the appropriate extract criteria to SUS to generate a daily
[14 words unchanged]
identifiers with the usual GP_IDs. Type 1 Opt-outs are applied to data
before the data is transferred to
by
NHS
Digital for linkage.
England.
The GP_ID is the pseudonym for each patient in the record which the system provider sends to NHS
Digital
England
and CPRD. CPRD will then re-pseudonymise the GP_ID to a CPRD ID
[28 words unchanged]
it is part of the standard process for data transfer and linkage.
[4 paragraphs unchanged]
In order to protect patient confidentiality, when presenting results calculated from SUS+
[12 words unchanged]
numbers suppressed in line with HES analysis guide. When publishing SUS+ data,
you
users
must make sure that cell values from 1 to 7 are suppressed
[22 words unchanged]
be suppressed. All other counts will be rounded to the nearest 5.
[3 paragraphs unchanged]
Benefits reported
The data provided by
NHSD
NHS England
has been used for the Statutory & effective monitoring of new COVID vaccines based on the duty of MHRA.
[5 paragraphs unchanged]
As of 23rd August 2022, 53 million people received a first dose of COVID-19 vaccine, 50 million received a second dose and 40 million received a third or booster dose. The MHRA continually monitors the safety of the COVID 19 vaccines through a comprehensive COVID-19 Vaccine Surveillance Strategy. This monitoring strategy is proactive and based on a wide range of information sources, including the data covered in this agreement with a dedicated team of scientists continually reviewing information to look for safety issues or any unexpected, rare events. As with all vaccines and medicines, the safety of COVID-19 vaccines is continuously monitored, and benefits and possible risks remain under review.
Unchanged: Expected output, Expected measurable benefits.
Objective for processing
This agreement is requesting a continuation of a daily flow of data from NHS England to enable the Medicines and Healthcare products Regulatory Agency (MHRA) to carry out essential regulation of the CV19 vaccination roll out. This measure is being put in place until the flow of this data is captured in the routine GP data flows to the MHRA. The data supplied under this agreement will be used solely for this purpose.
The controller for GDPR purposes is the Department of Health and Social Care (DHSC); the legal signatory for this agreement (and for the overarching DSFC) is the Secretary of State for Health and Social Care (acting as part of the Crown), acting through the Clinical Practice Research Datalink centre (hereinafter referred to as CPRD) within the Medicines and Healthcare products Regulatory Agency (the agency); and the licensee is CPRD as a part of the MHRA, not the wider DHSC.
The Clinical Practice Research Datalink (CPRD) is a centre of the Medicines and Healthcare products Regulatory Agency (MHRA), an executive agency of the Department of Health and Social Care (DHSC). The agency regulates medicines (including vaccines), medical devices and blood components for transfusion in the UK and the agency acts as an Executive agency.
The Clinical Practice Research Datalink (CPRD) is a government not for profit research organisation, jointly supported by the Medicines and Healthcare products Regulatory Agency (MHRA) and the National Institute of Health Research (NIHR), supplying anonymised health data for studies to safeguard and improve patient and public health. For more than 30 years, CPRD data have supported vital research into health care delivery, drug safety, effectiveness of medicines and risk factors for disease. It currently receives data and linkage services from NHS England under a separate DSA (DARS-NIC-15625-T8K6L) for public health research.
These flows of COVID-related data are required for an additional 12 months (this is in addition to the data already provided), possibly longer. The position will be reviewed to assess if there is sufficient up to date data. Currently GP system providers are not able to routinely integrate the SUS data into their own systems.
Specifically with reference to this agreement MHRA are acting as a processor on NHS England's behalf in relation to three data flows for COVID-19 vaccine surveillance:
1) COVID-19 Vaccination Dataset - from NHS England (not covered by this agreement)
2) COVID-19 Vaccination Adverse Reactions Dataset - from NHS England (Not covered by this agreement)
3) Minimal bespoke extract from SUS Dataset (Minimal SUS Dataset for COVID-19 Surveillance) - for COVID-19 Surveillance (Purpose of this agreement)
Because of the rapid rollout of the vaccination programme, the GP suppliers had no immediate way of integrating COVID vaccine data from points 1 and 2 into their systems, hence the separate feed to CPRD. Over time, as the vaccine became more routine e.g. like flu and as GP System vendors updated their systems, MHRA would have expected datasets 1 and 2 to be integrated into the electronic health record (EHR) as standard and therefore that data would flow to CPRD via MHRA’s usual channels. Dataset 3, SUS, is controlled by NHS England and comes from a hospital setting and therefore MHRA never expected this to be integrated into the primary care EHR data.
The lawful basis for processing data under GDPR has been reviewed against the guidance provided by IGARD and been assessed as acceptable by NHS England. As per GDPR Article 6(1)(e) “processing is necessary for the performance of a task in the public interest or in the exercise of official authority vested in the controller” the Clinical Practice Research Datalink (CPRD is a function of the Medicines and Healthcare products Regulatory Agency (MHRA) which is a function of Department of Health and Social Care which is a public authority as per the FOI Act 2000 Part 1, section 3. Under Section 8 of the Data Protection Act 2018 CPRD are a function of a government department and provide the England-wide NHS observational and interventional research service. NHS England are satisfied that this request is appropriate, necessary and proportionate for the performance of the task described in the Purpose statement and that there is no other reasonable means for the data processor to achieve their purpose that is less intrusive to the data subjects.
The processing of Health Data, as a Special Category of Personal Data, as per GDPR Article 9(2)(i)” Processing is necessary for reasons of public interest in the area of public health, such as protecting against serious cross-border threats to health or ensuring high standards of quality and safety of health care and of medicinal products or medical devices, on the basis of Union or Member State law which provides for suitable and specific measures to safeguard the rights and freedoms of the data subject, in particular professional secrecy” as the processing is necessary for reasons of public interest in the area of public health (to monitor the new COVID-19 vaccines) and will be carried out under the responsibility of health professionals.
Data are being processed under the following functions within the statutory purpose;
• The Human Medicines Regulations 2012: S178c ‘take all appropriate measures to obtain accurate and verifiable data for the scientific evaluation of suspected adverse reaction reports’ and S179 ‘Obligation on licensing authority to operate pharmacovigilance system’
• MHRA as licensing authority: under Medicines and Healthcare products Regulatory Agency Trading Fund Order 2003 (SI 2003/1076), made under the Government Trading Funds Act 1973
The Agency performs the functions of the Secretary of State under UK legislation relating to medicines, medical devices and blood, amongst other things. From 1 April 2013, the Agency also performs the functions of the Secretary of State in relation to biological substances conferred under section 57 of the Health and Social Care Act 2012. These functions, which relate to ensuring the quality of biological medicines, were previously carried out by the Health Protection Agency through the non-statutory body, the National Institute of Biological Standards and Control (NIBSC). The NIBSC continues to deliver these functions as part of the Agency on behalf of the Secretary of State
Expected output
Statutory & effective surveillance of new COVID vaccines - until normal dataflows from GP systems can be used.
Reports produced for the yellow card scheme and contributes to the vaccine safety surveillance.
Benefits reported
The data provided by NHS England has been used for the Statutory & effective monitoring of new COVID vaccines based on the duty of MHRA.
The data received to date has been critical in the surveillance of COVID-19 vaccinations, in particular in relation to assessment of issues such as myopericarditis with mRNA vaccines and menstrual disorders across all the vaccines used in the UK, in addition to its use in rapid cycle analysis for Adverse Events of Special Interest (AESIs).
The data has been used to rapidly detect, confirm, characterise and quantify any new risks that were not detected in clinical trials, to weigh these against the expected benefits and take any necessary action to minimise risks to individuals.
In May 2020, the Commission on Human Medicines established an Expert Working Group (EWG) to advise the Medicines and Healthcare products Regulatory Agency (MHRA) on its safety monitoring strategy for COVID-19 vaccine(s).
The EWG held four meetings from May to October 2020, during which it considered proposals and methodologies for MHRA-led vigilance activities. Based on this advice, the MHRA has developed, and now has in place, a four-stranded approach to vigilance, which is summarised in this report- https://www.gov.uk/government/publications/report-of-the-commission-on-human-medicines-expert-working-group-on-covid-19-vaccine-safety-surveillance/report-of-the-commission-on-human-medicines-expert-working-group-on-covid-19-vaccine-safety-surveillance
More information can also be found on the Coronavirus vaccine - weekly summary of Yellow Card reporting- https://www.gov.uk/government/publications/coronavirus-covid-19-vaccine-adverse-reactions/coronavirus-vaccine-summary-of-yellow-card-reporting
As of 23rd August 2022, 53 million people received a first dose of COVID-19 vaccine, 50 million received a second dose and 40 million received a third or booster dose. The MHRA continually monitors the safety of the COVID 19 vaccines through a comprehensive COVID-19 Vaccine Surveillance Strategy. This monitoring strategy is proactive and based on a wide range of information sources, including the data covered in this agreement with a dedicated team of scientists continually reviewing information to look for safety issues or any unexpected, rare events. As with all vaccines and medicines, the safety of COVID-19 vaccines is continuously monitored, and benefits and possible risks remain under review.
DARS-NIC-424723-D5Q9W-v1.3 11 February 2022 to 10 February 2023
- Title
- SUS-COVID vaccination datasets for MHRA surveillance through CPRD
- Commercial
- No
- Sublicensing
- No
- Datasets
- 1
- Files released
- 0
Datasets: Minimal SUS Dataset for COVID-19 Surveillance
What changed from DARS-NIC-424723-D5Q9W-v0.5
Text removed is struck through; text added is underlined. Unchanged paragraphs are summarised rather than repeated.
| Field | Was | Became |
|---|---|---|
| Start date | 2022-02-11 | |
| End date | 2023-02-10 | |
| Minimal SUS Dataset for COVID-19 Surveillance: legal basis | Health and Social Care Act 2012 – s261(2)(b)(ii) | |
| Minimal SUS Dataset for COVID-19 Surveillance: type of data | Anonymised - ICO Code Compliant | |
| Minimal SUS Dataset for COVID-19 Surveillance: common law duty of confidentiality | Does not include the flow of confidential data |
Objective for processing
This agreement is requesting
a continuation of
a daily flow of data from NHS Digital to enable the Medicines and Healthcare products Regulatory Agency (MHRA) to carry
our
out
essential regulation of the CV19 vaccination roll out. This measure is being
[21 words unchanged]
data supplied under this agreement will be used solely for this purpose.
[3 paragraphs unchanged]
These flows of COVID-related data are likely to be needed for approximately 12 months, possibly longer, though it is hoped not, as flows through GP systems providers should be available by then. The position will be reviewed post Summer 2021 once the overall position is clearer.
These flows of COVID-related data are required for an additional 12 months (this is in addition to the data already provided), possibly longer. The position will be reviewed to assess if there is sufficient up to date data. Once the GP system providers are able to integrate this information into their own systems, this data sharing agreement will cease.
[1 paragraph unchanged]
As CPRD will be
The
processing
of
Health Data,
which is
as
a Special Category of Personal Data, as per GDPR Article 9(2)(i)” Processing
[59 words unchanged]
rights and freedoms of the data subject, in particular professional secrecy” as
CPRD have confirmed that
the processing is necessary for reasons of public interest in the area of public health
(effectively
(to
monitor the new COVID-19 vaccines) and will be carried out under the responsibility of health professionals.
Data are being processed under the following functions within
their
the
statutory purpose;
[3 paragraphs unchanged]
Processing activities
[6 paragraphs unchanged]
For the third dataflow (the purpose of this agreement) . NHS Digital
[19 words unchanged]
the CPRD cohort and the replacement of identifiers with the usual GP_IDs.
Type 1 Opt-outs are applied to data before the data is transferred to NHS Digital for linkage.
The GP_ID is the pseudonym for each patient in the record which the system provider sends to NHS Digital and CPRD. CPRD will then re-pseudonymise the GP_ID to a CPRD ID as part of its quality check and transformation when bringing the data inhouse. The GP_ID is only used in the data delivery stage and at the linkage stage- it is part of the standard process for data transfer and linkage.
[5 paragraphs unchanged]
Sungard Availability Services
Ltd/Crown Hosting Data Centres
Ltd are recorded as data storage addresses as for the purposes of
[38 words unchanged]
provide a facilities management and site management service). CPRD has confirmed that
neither Crown Hosting Data Centres Ltd nor
Sungard Availability Services Ltd
does not
have access to the server (neither administrative nor user rights). Therefore, any
[15 words unchanged]
agreement. This includes granting of access to the database[s] containing the data.
[1 paragraph unchanged]
No processing of record level data will take place at any locations not stipulated in the agreement. Any changes to this must be enacted through an amendment to the agreement.
Expected output
Statutory & effective
monitoring
surveillance
of new COVID vaccines - until normal dataflows from GP systems can be used.
This will start as soon as dataflows can be arranged. This is an URGENT requirement.
Reports produced for the yellow card scheme and contributes to the vaccine safety surveillance.
Expected measurable benefits
Effective monitoring of the
safey
safety
and quality of new COVID vaccines - until normal dataflows can be
[6 words unchanged]
by enabling the provision of effective vaccines and detecting possible adverse reactions.
Access to new data remains essential for surveillance of the booster and Under18 vaccination programmes and fits under CPRDs surveillance requirements.
Given the scale of a COVID-19 mass immunisation programme, with many millions of doses of one or more novel vaccines administered across the UK over a relatively short time period, vigilance needs to be continuous, proactive and as near real-time as is possible. The importance of this is two-fold.
It needs to be very quickly established if any serious events which are temporally-related to vaccination are merely a coincidental association, and to do this in a robust, evidence-based way so that public confidence in a vaccine is not eroded unnecessarily. Indeed, such associations may be more likely whilst we are still in the midst of a national epidemic, and because most of the millions of people offered the vaccine in the early phase of a vaccination campaign will be elderly and/or have underlying medical conditions, which increases the likelihood of unrelated illnesses occurring soon after vaccination.
The Medicines and Healthcare products Regulatory Agency (MHRA) is the executive Agency of the Department of Health and Social Care that acts to protect and promote public health and patient safety, by ensuring that medicines and medical devices meet appropriate standards of safety, quality and efficacy.
The MHRA is responsible for monitoring these vaccines on an ongoing basis to ensure their benefits continue to outweigh any risks. This is a requirement for all authorised medicines and vaccines in the UK. This monitoring strategy is continuous, proactive and based on a wide range of information sources, with a dedicated team of scientists reviewing information daily to look for safety issues or unexpected rare events.
Benefits reported
Yielded Benefits is not a requirement for new applications.
The data provided by NHSD has been used for the Statutory & effective monitoring of new COVID vaccines based on the duty of MHRA.
The data received to date has been critical in the surveillance of COVID-19 vaccinations, in particular in relation to assessment of issues such as myopericarditis with mRNA vaccines and menstrual disorders across all the vaccines used in the UK, in addition to its use in rapid cycle analysis for Adverse Events of Special Interest (AESIs).
The data has been used to rapidly detect, confirm, characterise and quantify any new risks that were not detected in clinical trials, to weigh these against the expected benefits and take any necessary action to minimise risks to individuals.
In May 2020, the Commission on Human Medicines established an Expert Working Group (EWG) to advise the Medicines and Healthcare products Regulatory Agency (MHRA) on its safety monitoring strategy for COVID-19 vaccine(s).
The EWG held four meetings from May to October 2020, during which it considered proposals and methodologies for MHRA-led vigilance activities. Based on this advice, the MHRA has developed, and now has in place, a four-stranded approach to vigilance, which is summarised in this report- https://www.gov.uk/government/publications/report-of-the-commission-on-human-medicines-expert-working-group-on-covid-19-vaccine-safety-surveillance/report-of-the-commission-on-human-medicines-expert-working-group-on-covid-19-vaccine-safety-surveillance
More information can also be found on the Coronavirus vaccine - weekly summary of Yellow Card reporting- https://www.gov.uk/government/publications/coronavirus-covid-19-vaccine-adverse-reactions/coronavirus-vaccine-summary-of-yellow-card-reporting
Objective for processing
This agreement is requesting a continuation of a daily flow of data from NHS Digital to enable the Medicines and Healthcare products Regulatory Agency (MHRA) to carry out essential regulation of the CV19 vaccination roll out. This measure is being put in place until the flow of this data is captured in the routine GP data flows to the MHRA. The data supplied under this agreement will be used solely for this purpose.
The controller for GDPR purposes is the Department of Health and Social Care (DHSC); the legal signatory for this agreement (and for the overarching DSFC) is the Secretary of State for Health and Social Care (acting as part of the Crown), acting through the Clinical Practice Research Datalink centre (hereinafter referred to as CPRD) within the Medicines and Healthcare products Regulatory Agency (the agency); and the licensee is CPRD as a part of the MHRA, not the wider DHSC.
The Clinical Practice Research Datalink (CPRD) is a centre of the Medicines and Healthcare products Regulatory Agency (MHRA), an executive agency of the Department of Health and Social Care (DHSC). The agency regulates medicines (including vaccines), medical devices and blood components for transfusion in the UK and the agency acts as an Executive agency.
The Clinical Practice Research Datalink (CPRD) is a government not for profit research organisation, jointly supported by the Medicines and Healthcare products Regulatory Agency (MHRA) and the National Institute of Health Research (NIHR), supplying anonymised health data for studies to safeguard and improve patient and public health. For more than 30 years, CPRD data have supported vital research into health care delivery, drug safety, effectiveness of medicines and risk factors for disease. It currently receives data and linkage services from NHS Digital under a separate DSA (DARS-NIC-15625-T8K6L) for public health research.
These flows of COVID-related data are required for an additional 12 months (this is in addition to the data already provided), possibly longer. The position will be reviewed to assess if there is sufficient up to date data. Once the GP system providers are able to integrate this information into their own systems, this data sharing agreement will cease.
The lawful basis for processing data under GDPR has been reviewed against the guidance provided by IGARD and been assessed as acceptable by NHS Digital. As per GDPR Article 6(1)(e) “processing is necessary for the performance of a task in the public interest or in the exercise of official authority vested in the controller” the Clinical Practice Research Datalink (CPRD is a function of the Medicines and Healthcare products Regulatory Agency (MHRA) which is a function of Department of Health and Social Care which is a public authority as per the FOI Act 2000 Part 1, section 3. Under Section 8 of the Data Protection Act 2018 CPRD are a function of a government department and provide the England-wide NHS observational and interventional research service. NHS Digital are satisfied that this request is appropriate, necessary and proportionate for the performance of the task described in the Purpose statement and that there is no other reasonable means for the data processor to achieve their purpose that is less intrusive to the data subjects.
The processing of Health Data, as a Special Category of Personal Data, as per GDPR Article 9(2)(i)” Processing is necessary for reasons of public interest in the area of public health, such as protecting against serious cross-border threats to health or ensuring high standards of quality and safety of health care and of medicinal products or medical devices, on the basis of Union or Member State law which provides for suitable and specific measures to safeguard the rights and freedoms of the data subject, in particular professional secrecy” as the processing is necessary for reasons of public interest in the area of public health (to monitor the new COVID-19 vaccines) and will be carried out under the responsibility of health professionals.
Data are being processed under the following functions within the statutory purpose;
• The Human Medicines Regulations 2012: S178c ‘take all appropriate measures to obtain accurate and verifiable data for the scientific evaluation of suspected adverse reaction reports’ and S179 ‘Obligation on licensing authority to operate pharmacovigilance system’
• MHRA as licensing authority: under Medicines and Healthcare products Regulatory Agency Trading Fund Order 2003 (SI 2003/1076), made under the Government Trading Funds Act 1973
The Agency performs the functions of the Secretary of State under UK legislation relating to medicines, medical devices and blood, amongst other things. From 1 April 2013, the Agency also performs the functions of the Secretary of State in relation to biological substances conferred under section 57 of the Health and Social Care Act 2012. These functions, which relate to ensuring the quality of biological medicines, were previously carried out by the Health Protection Agency through the non-statutory body, the National Institute of Biological Standards and Control (NIBSC). The NIBSC continues to deliver these functions as part of the Agency on behalf of the Secretary of State
Expected output
Statutory & effective surveillance of new COVID vaccines - until normal dataflows from GP systems can be used.
Reports produced for the yellow card scheme and contributes to the vaccine safety surveillance.
Benefits reported
The data provided by NHSD has been used for the Statutory & effective monitoring of new COVID vaccines based on the duty of MHRA.
The data received to date has been critical in the surveillance of COVID-19 vaccinations, in particular in relation to assessment of issues such as myopericarditis with mRNA vaccines and menstrual disorders across all the vaccines used in the UK, in addition to its use in rapid cycle analysis for Adverse Events of Special Interest (AESIs).
The data has been used to rapidly detect, confirm, characterise and quantify any new risks that were not detected in clinical trials, to weigh these against the expected benefits and take any necessary action to minimise risks to individuals.
In May 2020, the Commission on Human Medicines established an Expert Working Group (EWG) to advise the Medicines and Healthcare products Regulatory Agency (MHRA) on its safety monitoring strategy for COVID-19 vaccine(s).
The EWG held four meetings from May to October 2020, during which it considered proposals and methodologies for MHRA-led vigilance activities. Based on this advice, the MHRA has developed, and now has in place, a four-stranded approach to vigilance, which is summarised in this report- https://www.gov.uk/government/publications/report-of-the-commission-on-human-medicines-expert-working-group-on-covid-19-vaccine-safety-surveillance/report-of-the-commission-on-human-medicines-expert-working-group-on-covid-19-vaccine-safety-surveillance
More information can also be found on the Coronavirus vaccine - weekly summary of Yellow Card reporting- https://www.gov.uk/government/publications/coronavirus-covid-19-vaccine-adverse-reactions/coronavirus-vaccine-summary-of-yellow-card-reporting
DARS-NIC-424723-D5Q9W-v0.5 11 February 2021 to 10 February 2022
- Title
- SUS-COVID vaccination datasets for MHRA surveillance through CPRD
- Commercial
- No
- Sublicensing
- No
- Datasets
- 1
- Files released
- 0
Datasets: Minimal SUS Dataset for COVID-19 Surveillance
Objective for processing
This agreement is requesting a daily flow of data from NHS Digital to enable the Medicines and Healthcare products Regulatory Agency (MHRA) to carry our essential regulation of the CV19 vaccination roll out. This measure is being put in place until the flow of this data is captured in the routine GP data flows to the MHRA. The data supplied under this agreement will be used solely for this purpose.
The controller for GDPR purposes is the Department of Health and Social Care (DHSC); the legal signatory for this agreement (and for the overarching DSFC) is the Secretary of State for Health and Social Care (acting as part of the Crown), acting through the Clinical Practice Research Datalink centre (hereinafter referred to as CPRD) within the Medicines and Healthcare products Regulatory Agency (the agency); and the licensee is CPRD as a part of the MHRA, not the wider DHSC.
The Clinical Practice Research Datalink (CPRD) is a centre of the Medicines and Healthcare products Regulatory Agency (MHRA), an executive agency of the Department of Health and Social Care (DHSC). The agency regulates medicines (including vaccines), medical devices and blood components for transfusion in the UK and the agency acts as an Executive agency.
The Clinical Practice Research Datalink (CPRD) is a government not for profit research organisation, jointly supported by the Medicines and Healthcare products Regulatory Agency (MHRA) and the National Institute of Health Research (NIHR), supplying anonymised health data for studies to safeguard and improve patient and public health. For more than 30 years, CPRD data have supported vital research into health care delivery, drug safety, effectiveness of medicines and risk factors for disease. It currently receives data and linkage services from NHS Digital under a separate DSA (DARS-NIC-15625-T8K6L) for public health research.
These flows of COVID-related data are likely to be needed for approximately 12 months, possibly longer, though it is hoped not, as flows through GP systems providers should be available by then. The position will be reviewed post Summer 2021 once the overall position is clearer.
The lawful basis for processing data under GDPR has been reviewed against the guidance provided by IGARD and been assessed as acceptable by NHS Digital. As per GDPR Article 6(1)(e) “processing is necessary for the performance of a task in the public interest or in the exercise of official authority vested in the controller” the Clinical Practice Research Datalink (CPRD is a function of the Medicines and Healthcare products Regulatory Agency (MHRA) which is a function of Department of Health and Social Care which is a public authority as per the FOI Act 2000 Part 1, section 3. Under Section 8 of the Data Protection Act 2018 CPRD are a function of a government department and provide the England-wide NHS observational and interventional research service. NHS Digital are satisfied that this request is appropriate, necessary and proportionate for the performance of the task described in the Purpose statement and that there is no other reasonable means for the data processor to achieve their purpose that is less intrusive to the data subjects.
As CPRD will be processing Health Data, which is a Special Category of Personal Data, as per GDPR Article 9(2)(i)” Processing is necessary for reasons of public interest in the area of public health, such as protecting against serious cross-border threats to health or ensuring high standards of quality and safety of health care and of medicinal products or medical devices, on the basis of Union or Member State law which provides for suitable and specific measures to safeguard the rights and freedoms of the data subject, in particular professional secrecy” as CPRD have confirmed that the processing is necessary for reasons of public interest in the area of public health (effectively monitor the new COVID-19 vaccines) and will be carried out under the responsibility of health professionals.
Data are being processed under the following functions within their statutory purpose;
• The Human Medicines Regulations 2012: S178c ‘take all appropriate measures to obtain accurate and verifiable data for the scientific evaluation of suspected adverse reaction reports’ and S179 ‘Obligation on licensing authority to operate pharmacovigilance system’
• MHRA as licensing authority: under Medicines and Healthcare products Regulatory Agency Trading Fund Order 2003 (SI 2003/1076), made under the Government Trading Funds Act 1973
The Agency performs the functions of the Secretary of State under UK legislation relating to medicines, medical devices and blood, amongst other things. From 1 April 2013, the Agency also performs the functions of the Secretary of State in relation to biological substances conferred under section 57 of the Health and Social Care Act 2012. These functions, which relate to ensuring the quality of biological medicines, were previously carried out by the Health Protection Agency through the non-statutory body, the National Institute of Biological Standards and Control (NIBSC). The NIBSC continues to deliver these functions as part of the Agency on behalf of the Secretary of State
Expected output
Statutory & effective monitoring of new COVID vaccines - until normal dataflows from GP systems can be used.
This will start as soon as dataflows can be arranged. This is an URGENT requirement.
Benefits reported
Yielded Benefits is not a requirement for new applications.
Register history
When this agreement appeared in, or was edited in, each monthly edition of the register. Built by comparing every edition this site holds, the earliest of which is July 2021.
-
July 2021 —
already listed in the earliest edition this site holds, so it may be older. 1 version: DARS-NIC-424723-D5Q9W-v0.5
-
March 2022
1 version added: DARS-NIC-424723-D5Q9W-v1.3
-
December 2022
Register-wide edit DARS-NIC-424723-D5Q9W-v1.3 — Datasets: legal basis: “
s261(1) and” taken out. Made to 639 agreements in this edition, so it is reported once, on the changes page, and not counted as an amendment of this agreement. -
March 2023
1 version added: DARS-NIC-424723-D5Q9W-v2.2
-
May 2023
1 no longer listed: DARS-NIC-424723-D5Q9W-v2.2
-
February 2024
1 version added: DARS-NIC-424723-D5Q9W-v2.2
-
March 2024
1 version added: DARS-NIC-424723-D5Q9W-v3.4
-
March 2025
1 version added: DARS-NIC-424723-D5Q9W-v4.2
Cite this page
NHS England (2026) Data Uses Register, September 2026 edition, agreement DARS-NIC-424723-D5Q9W, “SUS-COVID vaccination datasets for MHRA surveillance through CPRD”. Read via NHS Data Access Explorer (unofficial), https://healthdatauses.uk/agreements/dars-nic-424723-d5q9w/ (accessed [date]).
This address stays the same, but the page is rebuilt with each monthly edition, so the citation names the edition it shows. Every edition's data is kept in the facts store.
Source: datausesregister_september2026.xlsx, September 2026 edition of the NHS England Data Uses Register. Search that workbook for DARS-NIC-424723-D5Q9W to see the original rows.