
How we use your information
The page explains how Kent and Medway ICB collects, uses, and protects personal health data to plan services and meet legal privacy obligations.
Find out how we protect data on the Kent and Medway Care Record (KMCR), the electronic care record that links data held in different provider systems.
This privacy notice tells you about information we obtain, hold and use about you. It describes what we do with it, how we will look after it and who we share it with. It covers information we collect directly from you as well as information we may get from other individuals or organisations.
NHS Kent and Medway Integrated Care Board (ICB) is responsible for the planning and buying (also known as commissioning) of healthcare services in that ICS area, bringing the NHS together locally to improve population health and care.
We also monitor the performance and quality of these services. In general, we only use data that has been anonymised (identifiable details removed) or pseudonymised for these purposes. Please see our Information the ICB collects and how we use it section for more information about these definitions.
The ICB is a controller under the terms of the UK General Data Protection Regulations (GDPR)/Data Protection Act 2018 (the Act). This means we are legally responsible for ensuring all personal information we process, hold, obtain, record, use or share about you is carried out in compliance with data protection principles.
All controllers must register with the Information Commissioner's Office (ICO). Our ICO Data Protection Register number is ZB346663 and our entry can be found in the Data Protection Register on the Information Commissioner's Office website.
We are committed to protecting your privacy and will only process personal, confidential data in accordance with data protection legislation.
This includes ensuring the ICB complies with the UK General Data Protection Regulation (GDPR) and the Data Protection Act (DPA) 2018.
In addition, consideration will also be given to all applicable law concerning privacy, confidentiality, the processing and sharing of personal data including:
Further, everyone working for the NHS has a legal duty to keep information about you confidential and comply with the Common Law Duty of Confidentiality. The information we do hold about you is protected from unauthorised access. Under the NHS Confidentiality Code of Conduct, all our staff are required to protect your information, inform you of how your information will be used, and allow you to decide if and how your information can be shared.
The NHS Care Record Guarantee and NHS Constitution provide a commitment that all NHS organisations and those providing care on behalf of the NHS will use records about you in ways that respect your rights and promote your health and wellbeing.
All information we hold about you will be held securely and confidentially. We use administrative and technical controls to do this, such as issuing encrypted secure IT equipment to all staff. We use strict controls to make sure only authorised staff are able to see information that identifies you. Only a limited number of authorised staff have access to information that identifies you where it is appropriate to their role and is strictly on a need-to-know basis.
All of our staff, contractors and committee members receive appropriate and on-going data security awareness training to make sure they are aware of their personal responsibilities and have contractual obligations to uphold confidentiality, enforceable through disciplinary procedures.
Under the General Data Protection Regulations (GDPR) and Data Protection Act 2018, the ICB as a public authority must appoint a data protection officer (DPO). All ICBs must also appoint a Caldicott Guardian and Senior Information Risk Owner (SIRO).
The ICB's data protection officer is our Head of Information Governance, Dan Clement.
The DPO's minimum tasks are defined in Article 39 of the GDPR:
All NHS organisations are required to appoint a Caldicott Guardian to provide compliance with patient data confidentiality. The ICB's Caldicott Guardian is our Chief Nurse, Paul Lumsdon, who is responsible for protecting the confidentiality of patients' and service users' information and enabling appropriate information sharing.
The Caldicott Guardian plays a key role in making sure the ICB satisfies the highest possible standards for handling personal information.
Acting as the conscience of an organisation, the Caldicott Guardian supports work to enable information sharing where it is appropriate and advises on options for lawful and ethical processing of information.
In addition to the Caldicott Guardian, the ICB also has a SIRO who owns the ICB's overall information risk policy and risk assessment process. This involves making sure there are robust incident reporting processes for any information risks identified by the ICB. The ICB's SIRO is Mike Gilbert, Director of Corporate Services. The Deputy SIRO is Dan Clement, Head of Information Governance.
Your doctor and other health professionals caring for you, such as nurses or physiotherapists, keep records about your health and treatment, the care they have provided, or plan to provide to you, so they are able to provide you with the best possible care.
These records are called your health care record and may be stored in paper form or on an electronic system. They may include:
Your health care records are used for the following reasons:
The law provides some NHS bodies, such as NHS England (NHSE), the ability to collect and use unidentifiable patient data which they can then provide to help commissioners (ICBs) to design and acquire the combination of services that best suit the population they serve.
Data may be linked and anonymised by these bodies so it can be used to improve health care and development and monitor NHS performance. This is often referred to as a secondary use of data. Where data is used for these statistical purposes, rigorous measures are taken to ensure patients cannot be identified (please see our Information the ICB collects and how we use it section for more information regarding anonymisation).
For the majority of the ICB's work, we do not need to use personal/confidential data of individuals who live in our community, and this is our preferred way of working. It should be noted that information which cannot identify an individual is not covered by data protection law. There are different types of information collected and used across the ICB as follows;
Identifiable - information which contains personal details that identify individuals such as name, address, email address, NHS Number, full postcode, date of birth.
Pseudonymised - individual level information where individuals can be distinguished by using a coded reference, which does not reveal their 'real world' identity
Anonymised - data which is about you but from which you cannot be personally identified.
Aggregated - grouped information about individuals that has been combined to show general trends or values without identifying individuals
We use anonymised and aggregated data to plan health care services, including:
Use of pseudonymised (de-identified) Information
We use pseudonymised information in our role, including:
As an ICB, we do not routinely hold or have any access to medical records. The provider of your healthcare for example an Acute Trust, or GP would hold this information. However, we may need to hold some information about you, for example:
Full details on each data flow are included in the Record of Processing Activities (ROPA).
The GDPR/Data Protection Act 2018 provides the following rights for individuals depending on the legal basis for processing (as identified in the ROPA.):
Further information on these rights can be accessed on the ICO website.
If you would like to exercise any of your rights, please contact the Information Governance team in the first instance kmicb.ig@nhs.net
You should be aware that the ICB may not be able to comply with your requests in every circumstance, such as where the ICB has compelling legitimate grounds for the processing which override the interests, rights and freedoms in the right to object.
Please go to the subject access requests webpage for more information.
Confidential information can be used for improving health, care and services including:
However, The NHS Constitution states 'you have the right to request that your confidential information is not used beyond your own care and treatment and to have your objections considered'.
There are several forms of opt-outs available at different levels:
If you do not want personal confidential information that identifies you to be shared outside your GP practice you can register a 'Type 1 opt-out' with your GP practice. This prevents your personal confidential information from being used except for your direct health care needs and in particular circumstances required by law, such as a public health emergency like an outbreak of a pandemic disease. Patients are only able to register the opt-out at their GP practice and your records will be identified using a particular code that will stop your records from being shared outside of your GP Practice.
The NDOO was introduced on 25 May 2018 and replaces the previous 'type 2' opt-out.
NHS England (NHSE) collects information from a range of places where people receive care, such as hospitals and community services. The information collected about you when you use these services can then be used and shared with other organisations for purposes beyond your individual care, for instance to help with:
The NDOO out provides a facility for individuals to opt-out from the use of their data for research or planning purposes. For anyone who had an existing type 2 opt-out, it will have been automatically converted to a national data opt-out from 25 May 2018.
Objections will be respected, except in very limited circumstances such as:
You have the right to refuse/withdraw consent to information sharing at any time and your decision will not affect your individual care.
All NHS organisations in England must comply with the NDOO from 30 September 2020. Essentially this means that NHS Kent and Medway ICB must always check whether any purpose for which it uses or shares patients' personal information is one to which the NDOO applies. Where it is, the ICBs will need to identify those patients that have opted out and exclude their information from use.
For the majority of the ICB's work, we do not need to use personal/confidential data. The applicability of the NDOO is therefore limited for the data processing carried out by the ICB. However, in order to ensure we maintain compliance with the NDOO, NHS Kent and Medway ICB will continually monitor its uses of confidential patient data to make sure any to which the NDOO is likely to apply are identified as quickly as possible. This is done via the ICB's work on Information Asset review.
Please see our National Data Opt Out application to ICB data flows. This is a breakdown of when the ICB does use personal/confidential data and whether the NDOO is applied to that data processing.
To find out more or to register your choice to opt out, please visit NHS - your data matters. On this web page you will also:
Whenever you use health or care services important information about you is collected in a patient record for that service. Collecting this information helps to ensure you get the best possible care and treatment.
The information collected about you when you use these services can also be used and shared with other organisations for purposes beyond your individual care, for instance to help with:
All these uses help to provide better health and care for you, your family and future generations. However, the National Data Opt-Out (NDOO) was introduced on 25 May 2018 and allows patients to opt out of their confidential information being used beyond their direct care for certain research and planning purposes. All NHS organisations in England must comply with the National Data Opt-Out from 30 September 2020.
Essentially this means that NHS Kent and Medway ICB must always check whether any purpose for which it uses or shares patients' personal information is one to which the NDOO applies. Where it is, the ICBs will need to identify those patients that have opted out and exclude their information from use.
It should be noted that the NDOO does not apply in all circumstances of data sharing, e.g. where patients have explicitly consented to share their data, and the use of aggregated or anonymised data.
For the majority of the ICB's work, we do not need to use personal/confidential data. The applicability of the NDOO is therefore limited for the data processing carried out by the ICB.
Please see this National Data Opt Out application to ICB data flows. This is a breakdown of when the ICB does use personal/confidential data and whether the NDOO applied to that data processing.
Additionally, there is a type 1 opt out that prevents information being shared outside of a GP practice for purposes other than direct care. Some patients will have a type 1 opt-out registered with their GP practice, which indicates they do not want their confidential patient information leaving the practice for research and planning purposes. These existing type 1 opt-outs will continue to be respected until the Department of Health and Social Care conducts a consultation with the National Data Guardian on their removal: further information on the types of data opt out.
In order to ensure we maintain compliance with the NDOO, NHS Kent and Medway ICB will continually monitor its uses of confidential patient data to ensure that any to which the NDOO is likely to apply are identified as quickly as possible. This is done via the ICB's work on Information Asset review.
To find out more or to register your choice to opt out, please visit nhs.uk: your data matters. On this web page you will also:
Any information obtained by the ICB will be retained for as long as is necessary for the purpose we collected it for.
Records are kept in accordance with Data Protection Act 2018 principles and are maintained in line with the Records Management Code of Practice for Health and Social Care retention schedule which determines the length of time records should be kept.
Destruction of data will only happen following a review of the information at the end of its retention period. Where data has been identified for disposal we have the following responsibilities to:
This notice is not exhaustive, however, we are happy to provide any additional information or explanation needed.
Requests for this should be sent to the Data Protection Officer, Dan Clement at kmicb.dpo@nhs.net:
Kent and Medway ICB
Gail House,
Lower Stone Street,
Maidstone,
Kent
ME15 6NB
Telephone: 01634 335020
For independent advice about data protection, privacy and data-sharing issues, or to make a complaint about how your data is used and processed, you can contact:
The Information Commissioner
Wycliffe House, Water Lane,
Wilmslow, Cheshire SK9 5AF
Phone: 08456 30 60 60 or 01625 545745
ICO website
We will keep our privacy notice under regular review. This privacy notice was last reviewed in June 2025 .