Data Protection Compliance

Home » Information Governance » IG services » Data Protection Compliance

decorative image

We understand the importance of ensuring that you can demonstrate robust compliance with the Accountability Principle of the Data Protection Act 2018.

Whether this is by way of evidencing and maintaining compliance with the NHS Data Security and Protection Toolkit (DSPT) or Cyber Assessment Framework (CAF), by supporting the achievement of standards such as ISO27001, or by working with you to ensure that a sound information governance (IG) framework is in place within your organisation, the NHS Midlands and Lancashire (ML) IG team will provide tailored support to meet your organisation’s needs.

NHS ML will work with you on anything from specific support in an area which requires review and improvement to a complete, fully managed, end-to-end IG service. We can even work with you to assess your current IG framework to identify any areas of improvement through our Data Protection Wellness Checks.

From working with you to develop policies, procedures and guidance, to supporting the development of assurance documentation such as Data Protection Impact Assessments (DPIAs) we will ensure your organisation meets all its legal data protection responsibilities. DPIAs should be completed whenever a new system, service, or process is implemented and personal data is processed.

Data Protection Compliance support includes:

  • Development or review of policies, procedures and guidance to meet the compliance needs of your organisation
  • Data Protection Impact Assessments – template documentation, implementation and project-specific support, working with the NHS ML Digital Clinical Safety team where applicable
  • Data sharing and contracts – ensuring that your organisation has appropriate documentation in place where personal data is shared with another party
  • Breach management – development and implementation of data breach management processes, training, breach assessments and investigations, root cause analyses and process reviews
  • Records of processing activity (ROPA) to ensure compliance with UK GDPR Article 30
  • Procurement support – supplier due diligence to ensure they have robust data protection measures in place and assessment of bid responses relating to data protection
  • Communications – briefings and newsletters focussing on relevant issues and themes based on queries received by the wider service as well as legislative, national or sector specific updates
  • Training to ensure your team fully understands their responsibilities around data protection and freedom of information, with bespoke sessions to address specific areas of development
  • Data protection officer – provision of a named data protection officer and supporting function
  • Information rights – advice or full management of freedom of information, environmental information rights, subject access requests, along with all other individual rights outlined in the Data Protection Act.

All of these services can be completey tailored to your organisation’s needs.

Contact us for more information on mlcsu.ig@nhs.net or 01782 916 875.

View all

How we can help health systems

Clinical redesign and provider collaboration

Redesigning how health and care works across England - placing people at the centre of their own health and care and utilising…

Learn more about Clinical redesign and provider collaboration
Clinical redesign and provider collaboration

Communications and engagement

Supporting ICSs with approaches to design and deliver effective communication, engagement and behavioural insights as a key enabler for system change and…

Learn more about Communications and engagement
Communications and engagement

Developing health systems

Acting as an independent and trusted partner within the system to facilitate working across stakeholders and integrate elements of the provider system…

Learn more about Developing health systems
Developing health systems

Digitally enabled transformation and IT

Digitising care and partnering with systems for the transformation of digitally enabled service delivery (and other supporting processes) across vision, planning and…

Learn more about Digitally enabled transformation and IT
Digitally enabled transformation and IT

Improving productivity and efficiency

We have a range of impactful solutions both across operational services and transformational programmes to support NHS systems to tackle some of…

Learn more about Improving productivity and efficiency
Improving productivity and efficiency

People solutions

Supporting systems to build a sustainable and integrated workforce, transforming systems, organisations and the workforce experience to improve resilience.

Learn more about People solutions
People solutions

Personalised healthcare commissioning services

Providing end-to-end funded care services, including patients as active partners in identifying their healthcare needs and then commissioning care to meet these.…

Learn more about Personalised healthcare commissioning services
Personalised healthcare commissioning services

PHM analytics and decision support

Applying intelligence-led understanding of the health of the population to support the redesign of care and improve patient and financial outcomes across…

Learn more about PHM analytics and decision support
PHM analytics and decision support

Place and primary care transformation

Supporting providers to work together at a place and neighbourhood level to manage common resources, integrate community teams, improve health and reduce…

Learn more about Place and primary care transformation
Place and primary care transformation
mlcsu