{{org_field_logo}}

{{org_field_name}}

Registration Number: {{org_field_registration_no}}


National Data Opt-Out Policy

1. Purpose

The purpose of this policy is to set out how {{org_field_name}} complies with the National Data Opt-Out in England where confidential patient information is used or disclosed for purposes beyond an individual’s own care and treatment, such as research, planning, commissioning, approved audits or service evaluation.

{{org_field_name}} is committed to ensuring that people who use the service, and where appropriate their lawful representatives, are informed about how confidential patient information may be used and how national data opt-out choices can be made, checked or changed.

This policy supports compliance with the UK General Data Protection Regulation, the Data Protection Act 2018, the common law duty of confidentiality, the NHS National Data Opt-Out policy, DCB3058 Compliance with National Data Opt-Outs, the Health and Social Care Act 2008, the Health and Social Care Act 2008 (Regulated Activities) Regulations 2014, and CQC Regulation 17: Good governance. It also supports Regulation 9: Person-centred care by ensuring that people are given accessible information and that their choices are respected.

2. Scope

This policy applies to all staff, including permanent employees, temporary staff, agency workers, contractors, volunteers, senior managers and any person acting on behalf of {{org_field_name}} who may access, use, disclose or otherwise process confidential patient information.

This policy applies where {{org_field_name}} uses or discloses confidential patient information that originated within the health and adult social care system in England for purposes beyond an individual’s own care and treatment. This may include research, planning, commissioning, approved audits, service evaluation or other secondary uses.

The National Data Opt-Out does not apply to information used for an individual’s direct care, safeguarding, statutory reporting, public health requirements, legal obligations, anonymised information that no longer identifies an individual, or information used with the person’s explicit consent for a specific purpose.

This policy applies to both paper and electronic records and must be followed alongside the organisation’s confidentiality, data protection, records management, consent, information sharing and governance policies.

3. Related Policies

This policy should be read alongside:

4. Policy Details

4.1 Understanding the National Data Opt-Out

The National Data Opt-Out allows people to choose whether their confidential patient information can be used for research and planning purposes beyond their individual care and treatment. The choice applies across health and adult social care organisations in England where confidential patient information is used or disclosed for purposes beyond individual care.

The opt-out does not apply where information is used or shared for the person’s own care and treatment. It also does not apply where there is a legal requirement to share information, where information is needed for safeguarding or public health purposes, where the information has been anonymised in line with applicable guidance, or where the person has given explicit consent for a specific use.

{{org_field_name}} will respect national data opt-out choices whenever the organisation proposes to use or disclose confidential patient information for a purpose to which the National Data Opt-Out applies.

4.2 Definitions

For the purpose of this policy:

4.3 Organisational Responsibilities

The Data Protection Officer {{org_field_data_protection_officer_first_name}} {{org_field_data_protection_officer_last_name}} is responsible for advising on compliance with the National Data Opt-Out, UK GDPR, the Data Protection Act 2018, the common law duty of confidentiality and relevant NHS England guidance.

The Registered Manager {{org_field_registered_manager_first_name}} {{org_field_registered_manager_last_name}} is responsible for ensuring that this policy is implemented in day-to-day practice, that staff understand when the National Data Opt-Out may apply, and that appropriate records, audits and governance checks are completed.

{{org_field_name}} will maintain a clear record of any proposed use or disclosure of confidential patient information for purposes beyond individual care. This record will include the purpose of the disclosure, the lawful basis under data protection legislation, whether the National Data Opt-Out applies, whether any exemption applies, who approved the disclosure, how opt-outs were checked or applied, and what information was shared.

Where required, {{org_field_name}} will complete and maintain its Data Security and Protection Toolkit submission or any equivalent information governance assurance required for adult social care providers. Evidence of compliance will be retained and made available for internal audit, commissioning assurance or CQC inspection where appropriate.

4.4 Identifying When the National Data Opt-Out Applies

Before any confidential patient information is used or disclosed for a purpose other than the individual’s direct care, the staff member proposing the use or disclosure must complete an information sharing request or seek approval from the Data Protection Officer or Registered Manager.

The following questions must be considered and recorded before the information is used or shared:

Where the National Data Opt-Out applies, {{org_field_name}} will use the approved NHS England Digital process, such as the Check for National Data Opt-Outs Service through MESH or another compliant system, to ensure that records relating to people who have opted out are removed before the information is used or disclosed.

4.5 Respecting and Actioning Opt-Outs

Where the National Data Opt-Out applies, {{org_field_name}} will ensure that the record or records associated with any person who has opted out are removed from the relevant extract, report, dataset or disclosure before the information is used or shared.

Staff must not rely on verbal assurances, assumptions or informal checks when deciding whether an opt-out applies. All decisions must be based on the approved process set out in this policy and must be recorded.

Where confidential patient information relates to more than one person, staff must seek advice from the Data Protection Officer before any use or disclosure. If an opt-out applies to any identifiable person within the record and the opt-out is relevant to the proposed use, the record must not be disclosed unless an exemption applies or the information can be anonymised.

Staff must not use or disclose confidential patient information for research, planning, commissioning, service evaluation or similar purposes until approval has been obtained and the National Data Opt-Out position has been checked where required.

4.6 Informing People We Support

{{org_field_name}} will provide people who use the service, and where appropriate their representatives, with accessible information about how confidential patient information may be used and about the National Data Opt-Out. This information will be provided during admission, care planning, review meetings, and whenever a relevant data use or disclosure is being considered.

People will be informed that they can make, check or change their National Data Opt-Out choice by visiting the NHS “Your NHS Data Matters” service, using the NHS App where available, or using the alternative contact routes provided by the NHS. Staff may support people to access information, but must not make a choice on their behalf unless the person has capacity and has specifically requested practical support, or the staff member is supporting a legally authorised representative.

Staff must explain that choosing to opt out will not affect the person’s care, treatment or support from {{org_field_name}}.

The care record must show that information about the National Data Opt-Out has been offered or provided, the format used, any communication support provided, and any questions or concerns raised by the person or their representative. The care record must not be used as a substitute for the national opt-out system.

4.7 Capacity, Representatives and Proxy Decisions

Where a person may lack capacity to understand information about the National Data Opt-Out, staff must follow the Mental Capacity Act 2005 and the organisation’s Mental Capacity Act Policy. Staff must not assume that a person lacks capacity because of age, disability, dementia, communication needs or diagnosis.

Where the person has capacity, the decision about whether to set, change or remove a National Data Opt-Out is their own decision. Staff may provide accessible information and practical support but must not influence the person’s choice.

Where the person lacks capacity, staff must only involve a person who has lawful authority to act on the person’s behalf, such as a relevant attorney, deputy or other legally recognised representative. Any involvement of representatives must be recorded clearly, including the basis of their authority.

Staff must not make a National Data Opt-Out choice on behalf of a person who uses the service.

4.8 Accessible Information

Information about the National Data Opt-Out will be provided in a way that the person can understand. This may include large print, easy read, translated information, verbal explanation, communication aids, involvement of family or advocates where appropriate, or additional time for discussion.

Staff must check understanding as far as practicable and must record any reasonable adjustments or communication support provided. Where a person has substantial difficulty understanding, retaining or weighing up information, staff must consider whether advocacy, family involvement or a mental capacity assessment is required.

4.9 Training and Staff Competency

All staff must complete confidentiality, data protection and information governance training as part of induction and at least annually thereafter. Training will include the National Data Opt-Out, the difference between direct care and purposes beyond individual care, when to seek advice, how to identify confidential patient information, and how to escalate proposed data sharing.

Staff involved in audits, quality assurance, commissioning returns, research, service evaluation, data extraction or external reporting must receive additional role-specific guidance before handling confidential patient information for purposes beyond individual care.

Agency staff, temporary staff, volunteers and contractors must be made aware of their confidentiality responsibilities and must not access, use or disclose confidential patient information unless authorised to do so.

Competency will be checked through supervision, spot checks, audit findings, reflective learning, team meeting discussions and scenario-based questions. Failure to follow this policy may result in management action, retraining, disciplinary action or referral to relevant professional or regulatory bodies where appropriate.

4.10 Auditing and Monitoring

The Data Protection Officer and Registered Manager will monitor compliance with this policy through quarterly information governance audits and additional checks where a data sharing request, incident, complaint or concern has been identified.

Audits will include, where applicable:

Audit findings will be reported to the Registered Manager and senior management. Any shortfalls will be recorded in the service improvement plan, with named leads, timescales and evidence of completion. Records of audits and actions will be retained as evidence of compliance with CQC Regulation 17: Good governance.

4.11 Data Sharing Approval and Record Keeping

Staff must not disclose confidential patient information for research, planning, commissioning, service evaluation or other purposes beyond individual care without approval from the Data Protection Officer, Registered Manager or other authorised senior person.

A record must be kept of each approved disclosure, including:

Records must be accurate, complete, up to date and available for internal governance review, external audit, commissioner assurance or CQC inspection where appropriate.

4.12 When the National Data Opt-Out Does Not Apply

The National Data Opt-Out does not apply in every situation. It will not usually apply where:

Staff must seek advice from the Data Protection Officer before relying on an exemption.

4.13 Data Breaches and Incidents

Any actual or suspected failure to apply the National Data Opt-Out, unauthorised disclosure of confidential patient information, inappropriate access to records, loss of records, insecure transfer of information or failure to follow this policy must be reported immediately to the Registered Manager and Data Protection Officer.

The incident must be recorded and investigated in line with the organisation’s Data Breach and Incident Reporting Policy. The investigation must consider whether the incident is reportable to the Information Commissioner’s Office, affected individuals, commissioners, safeguarding bodies, CQC or any other relevant organisation.

Lessons learned must be recorded and shared with staff through supervision, team meetings, policy updates, retraining or service improvement actions.

4.14 Privacy Notice

{{org_field_name}} will ensure that its privacy notice explains clearly how personal information and confidential patient information are used, the purposes for which information may be shared, the lawful basis for processing, the person’s data protection rights, and how the National Data Opt-Out may apply.

The privacy notice will signpost people to the NHS “Your NHS Data Matters” information and will explain that opting out does not affect the care, treatment or support provided by {{org_field_name}}.

5. Policy Review

This policy will be reviewed at least annually, or sooner where there are changes to legislation, UK GDPR or Data Protection Act 2018 requirements, NHS England National Data Opt-Out guidance, DCB3058 compliance requirements, Data Security and Protection Toolkit expectations, CQC guidance, commissioning requirements, audit findings, incidents, complaints or changes to the way {{org_field_name}} uses or shares confidential patient information.

The review will be led by the Data Protection Officer in consultation with the Registered Manager and senior management. Any changes will be communicated to staff, and staff will be required to confirm that they have read and understood the updated policy.


Responsible Person: {{org_field_registered_manager_first_name}} {{org_field_registered_manager_last_name}}
Reviewed on:
{{last_update_date}}
Next Review Date:
{{next_review_date}}
Copyright © {{current_year}} – {{org_field_name}}. All rights reserved.

Leave a Reply

Your email address will not be published. Required fields are marked *