Data protection laws and personal data Flashcards

1
Q

What is personal data?

A

Information relating to an identifiable natural person, who can be directly/indirectly identified by reference to an identifier

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Give 3 examples of identifiers?

A

Name, address, cultural identity

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What act was implemented in the UK to protect personal data?

A

General Data Protection Regulation (GDPR) implemented Data Protection Act 2018

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

How does the DPA 2018 state data should be processed?

A

Fairly and lawfully

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What right does the DPA 2018 give living people/their authorised representatives?

A

Right to apply for access to personal data irrespective of where data was produced

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

In what 2 situations does DPA 2018 not apply?

A

Deceased person

Data is anonymous

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Does DPA 2018 apply to NHS or private health records?

A

Both

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

How does DPA 2018 apply to employers?

A

Employers could hold info on employees’ mental, physical health

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Who developed the Caldicott principles?

A

Dame Fiona Caldicott

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is the purpose of the Caldicott principles?

A

Demonstrate how staff should handle their access to patient’s personal information

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is the role of the Caldicott Guardian?

A

Safeguarding and governing of use of personal data in the Trust

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

How many Caldicott principles are there?

A

8

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What do Caldicott principles state about decisions regarding sharing confidential info?

A

Must be justified

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What do Caldicott principles state about when to share confidential info?

A

Only when necessary

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What do Caldicott principles state about how much confidential info to share?

A

Minimum necessary amount

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What do Caldicott principles state about sharing info on a need-to-know basis?

A

Only tell others what they need to know at the time that need to know the info

17
Q

What do Caldicott principles state about staff responsibilities regarding sharing confidential info?

A

Staff should be aware of their responsibilities

18
Q

What do Caldicott principles state about the law?

A

Staff must comply with the law

19
Q

What do Caldicott principles state about balance between duties of sharing info and confidentiality?

A

Duty of sharing info for individual care is just as important as duty of confidentiality

20
Q

What do Caldicott principles state about informing patients and service users?

A

They should be informed about how their personal data is used

21
Q

If personal data is incorrect or incomplete, what can the data subject do?

A

They have the right to correct data

22
Q

If a patient’s personal records contain an incorrect clinical opinion, can the patient exercise their right to correct data?

A

No, incorrect clinical opinions can’t be removed/corrected but patient can add note stating that they disagree with the clinical opinion

23
Q

What right does a data subject have that allows them to request to remove personal data?

A

Right of erasure

24
Q

Why does a data subject’s right to erasure not apply to health records?

A

Healthcare professionals can refuse to comply if data is needed for processing eg. in public interest, or they have official authority

25
Q

Can children access their personal records?

A

Yes, if they have capacity

26
Q

Give 2 situations in which a patient can access their child’s personal records?

A

Child gives consent to parents

Child doesn’t have capacity, so patients are given access in child’s best interests

27
Q

Can divorced or separated parents access their child’s personal records if required?

A

Yes, they still have the same parental responsibility

28
Q

Generally, do deceased patients’ notes stay confidential?

A

Yes

29
Q

Give 2 examples of when deceased patients’ notes are shared?

A

Access to Health Records Act 1990 applied

Court-ordered

30
Q

What is the Access to Health Records Act 1990?

A

Permits access to deceased person’s records by others with claim arising from that patient’s death