Information governance Flashcards
Personal vs sensitive
Health data that can be linked to measure
pathways and outcomes is often both
personal and sensitive. It is personal because
there is information that identifies individuals;
and it is sensitive because it is about aspects
of individual’s health and health care
treatments and services.
Information governance principles
Basic Principles:
* used fairly, lawfully and transparently.
* used for specified, explicit purposes.
* used in a way that is adequate, relevant and limited to only what is necessary.
* accurate and where necessary kept up to date.
* kept for no longer than is necessary.
* handled in a way that ensures appropriate security, including protection against unlawful or unauthorised processing, access, loss, destruction or damage
There is stronger legal protection for more sensitive information, such as:
race
ethnic background
political opinions
religious beliefs
trade union membership
genetics
biometrics (where used for identification)
health
sex life or orientation
data should be held on a secure machine with strong password protection
data access should be limited to identified named individuals who need access for achieving the work objectives. Those individuals should be trained in data protection principles