Astrazeneca/Oxford - Re-use of existing data for data validation exercise
University of Oxford · Academic
Expired The latest version ended on 8 September 2021. The September 2026 register still lists the agreement, but its term has passed.
- Reference
- DARS-NIC-480562-G9R5X
- Latest version
- v0.2
- Term of latest version
- 9 July 2021 to 8 September 2021
- Start date
- 9 July 2021
- Data controller
- Joint Data Controller
- Commercial purposes
- Yes
- Sublicensing
- No
- Files released to date
- 0
Data controllers
Why the data was released
Objective for processing
The University of Oxford and AstraZeneca wish to use data currently held by University of Oxford (disseminated under DARS-NIC-381683) to do initial internal development work ahead of receiving a fresh data extract under DARS- NIC-459114. The work will support the preparatory work for the data management of the extract building models and internally validating them against other work that the University of Oxford are involved in / are in the public domain.
DATA CONTROLLERS AND PROCESSORS
The University of Oxford (Oxford's Royal College of GPs (RCGP) Research and Surveillance Centre (RSC)) are Joint Data Controllers with AstraZeneca Limited UK (also known as AstraZeneca Global). The data will only be processed by University of Oxford's Royal College of GPs (RCGP) Research and Surveillance Centre (RSC) and by Momentum Data. University of Oxford have subcontracted a part of the analysis to Momentum Data who will be acting as data processors on the instructions from University of Oxford and AstraZeneca UK Limited.
LEGAL BASIS
The lawful basis for processing data under GDPR has been reviewed and been assessed as acceptable. The University of Oxford process data under Article 6(1)(e): "processing is necessary for the performance of a task in the public interest or in the exercise of official authority vested in the controller" as they are a Public Authority.
AstraZeneca UK Limited process data under Article 6(1)(f): “Legitimate interests: the processing is necessary for your legitimate interests or the legitimate interests of a third party, unless there is a good reason to protect the individual’s personal data which overrides those legitimate interests. (This cannot apply if you are a public authority processing data to perform your official tasks.)”
Additionally, the University of Oxford and AstraZeneca UK Limited process the Special Category Health Data under Article 9(2)(j): "processing is necessary for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes in accordance with Article 89(1) based on Union or Member State law which shall be proportionate to the aim pursued, respect the essence of the right to data protection and provide for suitable and specific measures to safeguard the fundamental rights and the interests of the data subject" as the data are required for research purposes in the public interest.
Processing activities
Date will only be accessed by staff substantively employed by University of Oxford who are a data controller and processor and Momentum Data, who are a data processor. No data will leave the University of Oxford.
The data will be controlled and processed by a group of staff who are all substantive employees of the University of Oxford. Additionally, for the purpose of this study, given the tight turnaround and the urgency in providing these analyses in the interest of public health, University of Oxford have subcontracted a part of the analysis to Momentum Data who will solely be acting as data processors on the instructions from University of Oxford and AstraZeneca (joint data controllers). Analysts from Momentum Data will first have to complete the IG training in order to get access to the secure environment at the University of Oxford. Although acting as data processors, all the analysis and processing will take place within the secure environment at University of Oxford. (ORCHID)
University of Oxford staff are mandated to complete information governance training. The group is made up of analysts, academic fellows, Structure Language Query (SQL) developers, RCGP RSC practice liaison officers, a project manager and a head of department. The team work from secure workstations or secure laptops with encrypted drives within the group’s secure network.
Data will only be accessed by individuals within the RSC who have authorisation. The authorisation process includes:
(1) Contractual requirement to follow IG principles;
(2) Using the email registered with Human Resources to complete IG training and to return the certificate;
(3) Staff email is authorised by the IT department for one year to access the secure network and staff computers are configured to allow this;
(4) At any point the project managers or Head can have access to the secure network turned off.
Momentum will be data processors, however they will only access data within a secure environment via a secure client and can’t download data.
Expected output
No outputs are expected other than preparing databases for the receipt of the extracted data once available via the main research agreements.
Expected measurable benefits
The benefits will be internally initially to ensure that the data managers are ready to work on the extracted data for the Vaccination effectiveness studies as soon as they are available thus enabling the results of the study to be published more rapidly.
Benefits reported so far
Yielded Benefits is not a requirement for new applications.
Datasets on the latest version
Legal basis for provision: Health and Social Care Act 2012 - s261 - 'Other dissemination of information'
| Dataset | Type of data | Sensitivity | Frequency | Confidential data |
|---|---|---|---|---|
| COVID-19 Hospitalization in England Surveillance System | Anonymised - ICO Code Compliant | Non-Sensitive | One-Off | Does not include the flow of confidential data |
| COVID-19 SGSS First Positives (Second Generation Surveillance System) | Anonymised - ICO Code Compliant | Non-Sensitive | One-Off | Does not include the flow of confidential data |
| Secondary Uses Service Payment By Results Accident & Emergency | Anonymised - ICO Code Compliant | Non-Sensitive | One-Off | Does not include the flow of confidential data |
| Secondary Uses Service Payment By Results Episodes | Anonymised - ICO Code Compliant | Non-Sensitive | One-Off | Does not include the flow of confidential data |
| Secondary Uses Service Payment By Results Outpatients | Anonymised - ICO Code Compliant | Non-Sensitive | One-Off | Does not include the flow of confidential data |
| Secondary Uses Service Payment By Results Spells | Anonymised - ICO Code Compliant | Non-Sensitive | One-Off | Does not include the flow of confidential data |
Files released
Files released counts only files released externally by DARS. Access granted in NHS England's own systems, such as its Secure Data Environment, is not included.
No files recorded as released under this agreement.
Version history
The register lists each renewal of this agreement as a separate row. This site has 1 version.
DARS-NIC-480562-G9R5X-v0.2 9 July 2021 to 8 September 2021
- Title
- Astrazeneca/Oxford - Re-use of existing data for data validation exercise
- Commercial
- Yes
- Sublicensing
- No
- Datasets
- 6
- Files released
- 0
Datasets: COVID-19 Hospitalization in England Surveillance System; COVID-19 SGSS First Positives (Second Generation Surveillance System); Secondary Uses Service Payment By Results Accident & Emergency; Secondary Uses Service Payment By Results Episodes; Secondary Uses Service Payment By Results Outpatients; Secondary Uses Service Payment By Results Spells
Register history
When this agreement appeared in, or was edited in, each monthly edition of the register. Built by comparing every edition this site holds.
-
August 2021 —
first listed. 1 version: DARS-NIC-480562-G9R5X-v0.2
-
January 2023
Amended DARS-NIC-480562-G9R5X-v0.2
- Datasets:
+ COVID-19 SGSS First Positives (Second Generation Surveillance System) ·
− COVID-19 Second Generation Surveillance System (SGSS)
- Datasets:
+ COVID-19 SGSS First Positives (Second Generation Surveillance System) ·
"Amended in place" means NHS England changed the record without issuing a new version number. The register publishes no changelog for those edits; this site infers them by comparing editions. An edit is attributed to the edition it first appears in, not to the date it was made.
Cite this page
NHS England (2026) Data Uses Register, September 2026 edition, agreement DARS-NIC-480562-G9R5X, “Astrazeneca/Oxford - Re-use of existing data for data validation exercise”. Read via NHS Data Access Explorer (unofficial), https://healthdatauses.uk/agreements/dars-nic-480562-g9r5x/ (accessed [date]).
This address stays the same, but the page is rebuilt with each monthly edition, so the citation names the edition it shows. Every edition's data is kept in the facts store.
Source: datausesregister_september2026.xlsx, September 2026 edition of the NHS England Data Uses Register. Search that workbook for DARS-NIC-480562-G9R5X to see the original rows.