Unofficial. This site is an experimental reformatting of data published by NHS England. It is not endorsed by NHS England. Always check the official Data Uses Register before relying on anything here.

NHSE UDAL - CQC

Care Quality Commission (CQC) · Agency/Public Body

Expired The latest version ended on 22 August 2026. The September 2026 register still lists the agreement, but its term has passed.

Reference
DARS-NIC-755472-Y7C7F
Latest version
v0.6
Term of latest version
23 August 2024 to 22 August 2026
Start date
23 August 2024
Data controller
Sole Data Controller
Commercial purposes
No
Sublicensing
No
Files released to date
0

Why the data was released

Objective for processing

This Data Sharing Agreement (DSA) is to establish and facilitate a collaborative initiative between the Care Quality Commission (CQC) and NHS England to conduct a pilot project.

The primary purpose of this project is to evaluate and test the Unified Data Access Layer ("UDAL") as an effective and efficient system for data sharing between CQC and NHS England.

CQC is requesting data that is critical to its regulatory oversight of health and care providers. CQC’s remit is to make sure health and adult social care services provide people with safe, effective, compassionate, high-quality care and CQC encourages them to improve.

Access to these data help to ensure CQC can make use of its wide set of powers to protect people who use regulated services from harm and the risk of harm, and to ensure they receive health and social care services of an appropriate standard. These powers also hold registered providers and managers to account for failures in how the service is provided. CQC's enforcement policy sets out CQC's approach to taking action where CQC identify poor care, or where registered providers and managers do not meet the standards required in the regulations.

The following NHS England Data will be accessed:

• Community Services Data Set (CSDS)

• Emergency Care Data Set (ECDS)

• Hospital Episode Statistics Admitted Patient Care (HES APC)

• Hospital Episode Statistics Critical Care (HES Critical Care)

• Hospital Episode Statistics Outpatients (HES OP)

• Mental Health Services Data Set (MHSDS)

CQC use these data in the following ways:

- to populate indicators within their Data & Insight Unit products and associated dashboards, to support prioritisation of regulatory activity (including inspections) and to inform judgements about the level of quality in services

- towards CQC's statutory role of monitoring the Mental Health Act and protecting the interests of people whose rights are restricted under the Act;

- in thematic reviews and national reporting; for example, the Annual State of Care report and

- to support the development and implementation of CQC’s remit to assess ICSs and Local Authorities (with respect to health and care responsibilities).

The level of data will be:

• Pseudonymised

Local Patient Identifier is required, it is occasionally necessary to identify to a trust examples of their own patients whose care appears problematical 'Local patient identifier' is used as the Token Person ID is not known to the trust.

The Data will be minimised as follows:

• Limited to data between 2014 and latest available.

The lawful basis for processing personal data under the UK GDPR is:

Article 6(1)(e) - processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;

The lawful basis for processing special category data under the UK GDPR is:

Article 9(2)(i) - processing is necessary for reasons of public interest in the area of public health in that CQC’s remit is to make sure that health and adult social care services provide people with safe, effective, compassionate, high-quality care.

As per the Information Commissioner’s Officer (ICO) guidance; if an organisation is relying on Article 9(2)(i), they also need to meet the associated condition in UK law, set out in Part 1 of Schedule 1 of the DPA 2018. For Public health, this condition is met if the processing is necessary for reasons of public interest in the area of public health which for CQCs remit it is.

Microsoft Limited is a processor acting under the instructions of CQC. Microsoft Limited role is limited to cloud storage (Microsoft Azure).

Data will be accessed by:

• Substantive employees of CQC

• Non-substantive employees (Contractors)

Where CQC use non-substantive employees (contractors), CQC include confidentiality clauses within contracts and obliges individuals to complete in-house training on data protection and confidentiality.

Processing activities

No data will flow to NHS England for the purposes of this Data Sharing Agreement (DSA).

NHS England will share data with CQC via the Unified Data Access Layer (UDAL) data share*. UDAL is a data management system within NHS England that enables patient data to be processed and made available for analytical purposes.

*The data will be shared via the "Data Share" Service. This entails a data provider (NHS England UDAL) and a data consumer (CQCs Enterprise data platform), where the provider (NHS England) is in control of who receives data, when it is updated and how frequently.

The Data will be stored on servers at NHS England (UDAL) and CQC (based in the UK)

CQC stores data on the cloud provided by Microsoft Limited.

The Data will be accessed by authorised personnel via remote access.

CQC must confirm and provide evidence upon audit by NHS England that access via any remote device complies with the data security obligations within this DSA and the Data Sharing Framework Contract.

For remote access:

- Remote access will only be from secure locations situated within the territory of use (as further restricted elsewhere within the DSA if so done) stated within this DSA;

- Access controls granting users the minimum level of access required are in place;

- Remote access is only via secure connections (e.g., VPNs or secure protocols) to protect data;

- Multifactor authentication (MFA) is required for remote access;

- Device security, including up-to-date software and operating systems, antivirus software, and enabled firewalls are utilised for the remote access;

- All remote access is undertaken within the scope of the organisation’s DSPT (or other security arrangements as per this DSA) and complies with the organisation’s remote access policy.

The above applies in addition to any condition set out elsewhere within the DSA (e.g. who may carry out processing, and for what purpose).

The Data will not leave the UK at any time.

There will be no attempt to re-identify individuals with the sole exception of trusts using Local Patient Identifier to identify patients whose care appears problematic where strictly necessary.

Data will be stored in a dedicated and separate database ensuring physical separation from identifiable data held by CQC (received via a separate data sharing agreement). The measures in place are established to mitigate the risk of re-identification and ensure compliance with data protection standards.

Suppression methodology:

- Where data is shared with health and care providers, CQC would be sharing their own data with them so there would be no increased risk to confidentiality through the disclosure and the data would be shared under strict controls, with CQC giving a clear direction that the provider should not publish or otherwise onwardly share the data. If, hypothetically, the provider chose to subsequently share/publish the data contrary to CQC’s direction, the individual trust/provider would be making that decision on its own data.

- Where insight reports are subsequently shared with other arms-length bodies, CQC would work with these partners bodies to emphasise they must not be published because of NHS England suppression methodologies.

- For any data shared with care providers or arms-length bodies, CQC will adhere to the following measures to limit identifiability of individuals in the data:

In place of the different NHS England suppression methodologies for HES and MHSDS, CQC will carry out the below process when dealing with publications for circulation internally within CQC or externally with care providers or arms-length bodies partnering CQC:

- Zero allowed, 1-7 suppressed with '*', no rounding of values

- Percentages will be based on raw data; where low number values can be deduced from denominator, percentages will be suppressed.

Expected output

Outputs would be indicators to inform CQC assessment, risk, and contextual information for operational staff. Other outputs to include information for State of Care and other statutory reporting.

The outputs will not contain NHS England Data and will only contain aggregated information with small numbers suppressed as appropriate in line with the relevant disclosure rules for the dataset(s) from which the information was derived.

The outputs will be communicated to relevant recipients through the following dissemination channels:

• Public reports

On-going produced outputs include:

- data indicators that align to CQC's assessment framework for that sector

- bringing together information from people who use services, knowledge from CQC’s inspections and data from CQC’s partners

- outputs and reports indicating where the risk to the quality of care provided is greatest

- monitors change over time for each of the measures

- points to services where the quality may be improving

Outputs are produced on an ongoing basis and shared with the specific provider as well as granting access to key arms-length partners; for example, NHS England. This is aggregate information with small numbers suppressed in line with the suppression rules as specified in processing activities.

Expected measurable benefits

The analysis of these datasets are expected to contribute to evidence-based decision-making for policy-makers, local decision-makers such as doctors, and patients to inform best practice to improve the care, treatment and experience of health care users relevant to the subject matter of the study.

Patients and the wider public will see improvements in the care, treatment, and experience of health care users of services across the NHS.

It is hoped that through publication of findings in appropriate media, the findings of this research will add to the body of evidence that is considered by the bodies, organisations and individual care practitioners charged with making policy decisions for or within the NHS or treatment decisions in relation to specific patients.

Stakeholders will need to act based on the information provided to them to realise the potential improvement opportunities in their respective organisations. For example, care home providers will be able to assess their own performance against best practices.

CQC publishes the State of Care, an annual assessment of health care and social care in England. The report looks at the trends, shares examples of good and outstanding care, and highlights where care needs to improve.

HES, MHSDS, ECDS and associated data are used to determine key performance indicators in the CQC insight products. Each indicator is categorised in one of the core domains that, in total, provide a view on the quality of the provision of care

CQC has a suite of insight products which help the planning and review stages of an inspection that seeks to highlight areas of poor care requiring improvement while also seeking to promote good practice. The products use data (HES and/ or MHSDS as appropriate) both to present an overview of the core business of the trust in terms of activity ʹhelping to determine the specialist requirements of the inspection team - while also including specific metrics (e.g. HES re-admissions as descriptive statistics). CSDS + ECDS will be used for the same purposes to generate similar outputs.

HES and MHSDS and associated data are used in analyses for thematic reviews and in the development of new CQC insight indicators; for example, in reviewing quality of access to care across different ethnicities. CSDS + ECDS will be used for the same purposes to generate similar outputs.

CQC insight and associated dashboards are regularly updated. Outlier analyses are undertaken on a monthly or two-monthly basis. National reporting is a combination of predominantly annual reports as well as topic-specific reports released on a one-off basis.

Where CQC identifies poor care, or where the standards of registration are not being met, CQC can use its enforcement policy as described above. Such action is targeted to drive improvements or, in extreme cases, protect the public from access to poor quality services.

Benefits reported so far

Yielded Benefits is not a requirement for new applications.

Datasets on the latest version

Legal basis for provision: Health and Social Care Act 2012 – s261(2)(a)

Datasets approved under DARS-NIC-755472-Y7C7F-v0.6
DatasetType of dataSensitivity FrequencyConfidential data
Community Services Data Set (CSDS) Anonymised - ICO Code Compliant Sensitive System Access Does not include the flow of confidential data
Emergency Care Data Set (ECDS) Anonymised - ICO Code Compliant Sensitive System Access Does not include the flow of confidential data
Hospital Episode Statistics Admitted Patient Care (HES APC) Anonymised - ICO Code Compliant Sensitive System Access Does not include the flow of confidential data
Hospital Episode Statistics Critical Care (HES Critical Care) Anonymised - ICO Code Compliant Non-Sensitive System Access Does not include the flow of confidential data
Hospital Episode Statistics Outpatients (HES OP) Anonymised - ICO Code Compliant Sensitive System Access Does not include the flow of confidential data
Mental Health Services Data Set (MHSDS) Anonymised - ICO Code Compliant Sensitive System Access Does not include the flow of confidential data

Files released

Files released counts only files released externally by DARS. Access granted in NHS England's own systems, such as its Secure Data Environment, is not included.

No files recorded as released under this agreement.

Version history

The register lists each renewal of this agreement as a separate row. This site has 1 version.

DARS-NIC-755472-Y7C7F-v0.6 23 August 2024 to 22 August 2026
Title
NHSE UDAL - CQC
Commercial
No
Sublicensing
No
Datasets
6
Files released
0

Datasets: Community Services Data Set (CSDS); Emergency Care Data Set (ECDS); Hospital Episode Statistics Admitted Patient Care (HES APC); Hospital Episode Statistics Critical Care (HES Critical Care); Hospital Episode Statistics Outpatients (HES OP); Mental Health Services Data Set (MHSDS)

Register history

When this agreement appeared in, or was edited in, each monthly edition of the register. Built by comparing every edition this site holds.

Cite this page

NHS England (2026) Data Uses Register, September 2026 edition, agreement DARS-NIC-755472-Y7C7F, “NHSE UDAL - CQC”. Read via NHS Data Access Explorer (unofficial), https://healthdatauses.uk/agreements/dars-nic-755472-y7c7f/ (accessed [date]).

This address stays the same, but the page is rebuilt with each monthly edition, so the citation names the edition it shows. Every edition's data is kept in the facts store.

Source: datausesregister_september2026.xlsx, September 2026 edition of the NHS England Data Uses Register. Search that workbook for DARS-NIC-755472-Y7C7F to see the original rows.