Lack of transparency
A key concern with the proposed GPDPR was the lack of transparency in communicating to the public and GPs how the data extracting and sharing was to work. This was highlighted by the British Medical Association and the Royal College of General Practitioners and reiterated in a statement, from Elizabeth Denham, the then UK Information Commissioner (ICO). [4]
Although NHS Digital has said the Department of Health and Social Care and its executive agencies, NHS England, local authorities and research organisations may need to access the data, the limits on the range of other organisations which may look to access the data are unclear. “Appropriate requests” from organisations wishing to access the data will be scrutinised by NHS Digital’s Independent Group Advising on the Release of Data and decisions will be published on NHS Digital’s publicly-available Data Release Register. However, major concerns remain around access to data within the programme by “big tech” organisations who will likely see significant commercial benefits from accessing the highly sensitive information held on the database. Access to such data for research and social care purposes does not exclude data monetisation opportunities for third parties, yet data sharing restrictions seem to be weak in the face of the broad definitions of “health and care planning and research” purposes and the security parameters, which do not detail how to address the risks of re-identification of pseudonymised data.
It is now intended that NHS Digital will develop an engagement and communications campaign so that patients can be made aware of the scheme and in a better position to make informed choices. A DPIA reflecting the changes to the programme, and demonstrating how all risks and mitigation measures had been considered and addressed, will also be published before the data collection commences. This should help to answer many of the concerns and should go a long way in making the scheme more transparent to all. [5]
Data Security
Whilst NHS Digital has said that it will be using a secure system to collect and store the data there is little information about what security measures will be in place.
Data collected as part of the scheme will be pseudonymised when it is collected from GPs. The UK GDPR defines pseudonymisation as the processing of personal data in a way that means that it can no longer be attributed to the data subject. [6] This involves replacing personal data with pseudonyms which can only be re-identified using additional information, known as a key, which must be kept separate from the pseudonymised data. NHS Digital have said that any data which could be used to identify someone directly will be replaced with unique codes and then also securely encrypted. [7]
In particular, there are concerns that NHS Digital itself could re-identify the data using other data it already holds under its existing Personal Demographics Service which contains patients’ name, address, date of birth and NHS Number. Despite NHS Digital stating that data collected would not be sold or used solely for commercial purposes, there are concerns that if big tech platforms such as Google Amazon or Apple, private health providers or insurers are able to gain access to patient data through the scheme then they may be able to use this alongside other data they hold to identify patients and exploit the data for monetary gain to the cost of the NHS.
Again, the DPIA should provide further assurance as to what risks have been identified and how NHS Digital plans to deal with those to secure patient data.
Opting out
Under the existing framework, if patients did not want their data to be shared with NHS Digital, then they were required to actively opt-out rather than opting-in.
Patients can opt-out of their data being shared under GPDPR by registering a Type 1 Opt-out directly with their GP surgery or a National Data Opt-out (or both). A Type 1 Opt-out prohibits the uploading and extraction of a patient’s data whereas the National Data Opt-out only limits the ways that NHS Digital will be allowed to use confidential patient information for research and planning.
If patients did not opt-out, then their data was designed to be automatically shared with NHS Digital when the programme went live. There was a concern that many people, especially those members of society who do not have access to the internet, may not have been able to take advantage of this opt-out.
Additionally, there was a concern that although patients could opt-out after the programme had commenced, this would only prevent further data from being collected. It would not obligate NHS Digital to delete any data already collected, which by then would have been shared with multiple third parties.
The requirement now published for NHS Digital to ensure that an individual’s data can be erased once they have requested to opt out of the scheme should assist in alleviating these concerns to some extent. However, given that the scheme will remain subject to patient opt-out rather than an opt-in, the requirements for valid consent under the UK GDPR will not be met and NHS Digital must therefore rely on alternative bases for the lawful collection and sharing of data.
Lawful basis
NHS Digital will only be allowed to collect and share patient data if there is an applicable lawful basis for processing data as set out in the UK GDPR. Given that, as structured, patient consent is not appropriate, it must rely on another basis under Articles 6(1) and 9(2) of the UK GDPR.
Fortunately, there were valid grounds provided in legislation: The Health and Social Care Act 2012 (the Act) contains provisions allowing the Secretary of State for Health and Social care (the Secretary of State) to make directions to instruct NHS Digital to collect and analyse data to help the health service. On 6 April 2021, the Secretary of State sent the General Practice Data for Planning and Research Directions 2021 (the Directions) to NHS Digital, authorising it to collect and analyse pseudonymised data from GP practices. Following receipt of the Directions, NHS Digital sent a Data Provision Notice to GP practices who were then legally required to share patient data with NHS Digital on the basis of the Directions. This notice has subsequently been withdrawn, but is likely to be replaced once the necessary conditions to restart the scheme have been satisfied, as outlined below.
Once a new Data Provision Notice has been reissued, GPs will be able to rely on Article 6(1)(c) of the UK GDPR as the lawful basis for sharing of patient data with NHS Digital as they have a legal obligation under the Act, the Directions and the Notice to share the relevant patient data. [8]
NHS Digital will also rely on this basis to collect, analyse, publish and share patient data.
The UK GDPR also states that when special categories of personal data (which include health data) are being shared, then one of the specified conditions in Article 9 UK GDPR, must also be satisfied. [9]
NHS Digital have stated that the following Article 9 conditions will be relied on:
i. Article 9(2)(g): the sharing of patient data for reasons of substantial public interest, being the processing of patient data for planning and research purposes to improve health and care services.
ii. Article 9(2)(h): the sharing of patient data for the purposes of providing care and managing health and social care systems and services.
iii. Article 9(2)(i): necessary sharing for reasons of public interest in the area of public health.
iv. Article 9(2)(j): sharing for archiving, research purposes or for statistical purposes. [10]
Next steps
Following its launch on 12 May, the original go-live date for the GPDPR data extraction was originally set at 1 July 2021. However, in view of the widespread concerns raised, it has been paused until 31 March 2022, pending satisfaction of a number of conditions, the most important in terms of data privacy being that:
- patient awareness of the scheme must be increased through a campaign of engagement and communication; and
- patients must be able to delete their personal data if they choose to opt-out of sharing it with NHS Digital, even if after data has been uploaded.
Further communications from NHS Digital, since the scheme was first published, have helped to clarify and address some aspects of the concerns which have been raised but more needs to be done to ensure that the scheme is launched in compliance with data protection laws.