Patients and Visitors
South Tyneside NHS Foundation Trust (STFT) is an Acute Hospital and Community Services Trust that provides a range of acute inpatient and community based healthcare services for the people living in South Tyneside. It is also a provider of community health services for the people living within Gateshead and Sunderland areas.
For more information see our website http://www.stft.nhs.uk
STFT is a registered Data Controller. Information Commissioner Office (ICO) registration number Z7201380
This Privacy Notice explains how we use and share your information. We will continually review and update this Privacy Notice to reflect changes in our services and feedback from service users, as well as to comply with changes in the law.
Why do we hold information about you?
As a provider of healthcare services, we are legally required to hold information relating to the care we provide to you under the National Health Service Act 2006.
The information we hold about you is used to provide you with health and social care, for the management of the services that we provide to you, the management of the NHS and also for public health reasons.
We may also capture images of you within our CCTV systems (including Body worn cameras) which may be held for a period of up to 90 days and are held for the purposes of crime prevention and detection. Such images are deleted automatically after 90 days if not further required.
What information do you hold about me?
The information held about you will include:
Who can access my information?
Information about you will be accessed by employees of the Trust who are involved in providing direct care to you or who support the provision of direct care or the management of the Trusts services. This will include:
All staff, whether Clinical or Non-Clinical, have a legal duty to keep information about you confidential. They will only access your information when it is necessary to do so and will only disclose your information when authorised.
How do you store my information?
Your information will be stored by the Trust in the form of either;
How long will you keep my information?
NHS Trusts are required to keep your information for the periods of time set out in the ‘Records Management Code of Practice for Health and Social Care 2016’. This code of practice requires the Trust to keep your information for the following lengths of time:
Some information may be kept for longer than the above periods. Further information on the retention periods for healthcare records can be found here:
Who will you share my information with?
Your information will be shared internally between teams, eg shared with the Safeguarding Team if necessary and also externally, eg Police, Social Services, Education, your GP, etc. This is to ensure that adult and children’s safeguarding matters are managed appropriately. Access to identifiable information will be shared in some limited circumstances where it’s legally required for the safety of individuals concerned.
Your information will be shared, for the purposes of providing direct care, with other NHS and Non-NHS Provider organisations. These will include organisations such as other Acute Hospitals, Mental Health Hospitals, Community Healthcare providers, Local Authority Children’s Centres, General Practitioners and Ambulance Services. For Safety reasons information that is shared will always identify you however the Trust will endeavour to always ensure that you or your Next of Kin are aware of the information being shared and why.
Additionally, we may need to share your NHS number with Clinical Commissioning Groups (CCG) including the North of England Commissioning Support Unit, who process requests on behalf of the CCGs that we work with, for the purpose of having funding approved for certain procedures. No other patient identifier is included other than your NHS number during this process. This information is processed under Article 6(e): performance of a public task/ official functions and; Article 9(h) provision of health or social care or treatment. Without sharing this information we may be unable to offer you certain procedures or treatment that you have been referred to us for.
Your confidential healthcare Information will only be shared where there is a legal basis for doing so.
If you want to know who we have shared your information with you will need to make a Subject Access Request (SAR).
We may pass your information to an approved contractor for the purpose of contacting you in relation to the National Patient Survey Programme. You have the right to ask the Trust not to share your information for this purpose. If you wish to exercise this right, please contact the Data Protection Officer.
We will also share your anonymised information for the purposes of commissioning and managing healthcare, patient information may also be shared with other types of NHS organisations, such as the local Clinical Commissioning Group (CCG), and the Health & Social Care Information Centre (part of NHS England).
Sometimes we will also share your information in an anonymous format with organisations, such as universities, community safety units and research institutions. If your information is anonymous it means you cannot be identified.
In such cases, the shared data is made anonymous, wherever possible, by removing all patient-identifying details, unless the law requires the patient's identity to be included. In these circumstances we do not need your permission to share your anonymous information.
At any time you have the right to refuse/withdraw consent (opt out), in full or in part, to information sharing. The possible consequences and risks (ie, lack of joined up care, delay in treatment if information has to be sourced from elsewhere, medication complications; all leading to the possibility of difficulties in providing the best level of care) will be fully explained to you to allow you to make an informed decision.
If you do not want your personal information to be shared and used for purposes other than your care and treatment, then you should discuss your objections with the healthcare professional who is providing your care. This will not affect the care and treatment you receive.
Your records and research
We are a research active NHS Trust and there is the possibility that your records may be looked at by a Clinical Studies Officer at some point, who is not involved in your direct care. This is so that we can see if you are eligible to be invited to participate in approved research projects being run in the Trust that may be relevant to you.
Person-identifiable information may be used for essential NHS purposes, such as monitoring, research and auditing. This will only be done with your consent, unless the law requires information to be passed on to improve public health. The Information Commissioners Anonymisation Code of Practice will be used and further guidance is available in this Code of Practice.
How the NHS and care services use your information
South Tyneside NHS Foundation Trust is one of many organisations working in the health and care system to improve care for patients and the public.
Whenever you use a health or care service, such as attending Accident & Emergency or using Community Care services, important information about you is collected to help ensure you get the best possible care and treatment.
The information collected about you when you use these services can also be provided to other approved organisations, where there is a legal basis, to help with planning services, improving care provided, research into developing new treatments and preventing illness. All of these help to provide better health and care for you, your family and future generations. Confidential personal information about your health and care is only used in this way where allowed by law and would never be used for insurance or marketing purposes without your explicit consent.
You have a choice about whether you want your confidential patient information to be used in this way.
How can I access my information?
You can request access to the information that the Trust holds about you free of charge and you should do this by approaching a member of staff in the first instance. They will provide you with guidance on the Trust’s processes. Your request, once agreed with you, will be completed within 30 calendar days. However, if your records are extensive we may take longer to process your request but will inform you from the outset.
To submit a formal request, please contact:
Access to Records Team
Medical Records Department
South Tyneside NHS Foundation Trust
Or email: email@example.com
Information that you are entitled to:
As well as receiving a copy of the information that the Trust holds and processes you are also entitled to the following:
How do you make sure it is safe and secure?
We will use your information in a way that follows data protection laws and Trust policies and procedures.
Everyone working for the NHS is subject to the Common Law Duty of Confidence. Information provided in confidence will only be used for the purposes advised and consented to, unless it is required or permitted by the law.
All Trust staff are required to undertake mandatory Information Governance training, which covers how personal information should be processed.
We do not transfer personal information to a country outside of the European Union (EU) and this is checked on a yearly basis. If it is found that we intend to share information outside of the EU, appropriate and suitable safeguards will be put in place, which you will be told about.
How do you protect my privacy/confidentiality?
We protect your information by following data protection laws:
The GDPR 2016 and DPA 2018 are the laws that primarily determine how we can use your personal data. However, there are other laws that are followed if we need to process your information:
What rights do I have?
You have a number of rights in relation to the information we hold about you. Further information is contained in the leaflet Data Protection Individual Rights here as not all of these rights will apply to the information we hold about you.
These rights are:
1. The right to be informed
2. The right of access
3. The right of rectification
4. The right to erasure
5. the right to restrict processing
6. The right to data portability
7. The right to object
8. Rights in relation to automated decision making
Data Protection Officer
The Trust’s Data Protection Officer (DPO) is responsible for ensuring that the Trust complies with the Data Protection legislation. The DPO is the person to contact if you would like to know more about how we use your information, require information in any accessible format or language or if (for any reason) you do not wish to have your information used in any of the ways described. Their contact details are:
Data Protection Officer
Information Governance Department
South Tyneside District Hospital
Or email to firstname.lastname@example.org
The Caldicott Guardian is the person who makes the final decision on how, what, when and why personal information will be processed in/by the Trust.
South Tyneside Foundation Trust Caldicott Guardian is Dr Shaz Wahid, Medical Director.
For independent advice about data protection, privacy and information-sharing issues you can contact the Information Commissioner:
The Information Commissioner
Phone: 08456 30 60 60 or 01625 54 57 45