top of page
Search

They wrote it. You hold it. Is it still in scope of the SAR?

2 days ago
4 min read
An individual's right of access applies to the personal information that the organisation is processing. The fact that some of that information originated somewhere else does not, by itself, take it outside the scope of the request.
An individual's right of access applies to the personal information that the organisation is processing. The fact that some of that information originated somewhere else does not, by itself, take it outside the scope of the request.

We find that there is a surprisingly persistent misunderstanding when our customers respond to subject access requests:

“We didn't create that document, so we don't need to disclose it.”

But that isn't how subject access works because a patient's right of access applies to the personal information that the practice is processing - so that includes holding or viewing.


The fact that some of that information originated somewhere else does not, by itself, take it outside the scope of the request.

This means that, if a hospital consultant sends a letter to the GP practice and that letter is added to the patient's record, the practice should not remove it from a SAR simply because the hospital wrote it.


Similarly, a report from a community service, correspondence from another NHS provider, an investigation result received from secondary care or another externally-created document may all contain personal information that is now held and processed by the practice.


So our advice has always been that it is not about asking


“Who wrote this?”

But actually


“Are we processing personal information about this patient?”

The ICO describes the right of access as the right to obtain a copy of the personal information an organisation is processing and makes clear that organisations must carry out a reasonable and proportionate search for information within the scope of a request.


“But it's third-party information”

This is where another misunderstanding often creeps in because I sometimes hear information described as “third-party confidential” simply because it was supplied by another organisation.


It is critical to know that that is not what the third-party exemption means.


The exemption concerns information that is also the personal information of another individual.


Imagine, for example, that a patient's record contains:

“Patient's daughter telephoned and explained that she is struggling with her own mental health and is concerned about the patient's behaviour at home.”

Some of that information may be the patient's personal information, but some is also personal information about the daughter. The practice therefore needs to consider the rights of the other person and whether it would be reasonable to disclose their information.

That is a genuine third-party issue.


A hospital letter about the patient is not automatically a third-party issue merely because the hospital is a third party.



Withholding information needs a legal reason

The important principle is that information should not be removed from a SAR because it feels safer to leave it out, because another organisation created it, or because it has been labelled “confidential”.


There needs to be a proper legal basis for withholding the personal information.

For health records, that might include the specific serious harm provisions where disclosure would be likely to cause serious harm to the physical or mental health of the patient or another person. There may also be genuinely confidential information about another person, legal professional privilege or another statutory exemption depending on the circumstances.


But exemptions must be considered case by case. The ICO expressly warns against routinely or blanket-applying exemptions simply because information falls into a particular category.


So remember, “Another provider wrote it” is not a lawful reason to withhold the data.


What about information the practice can see in another provider's system?

This becomes more complicated where information sits in a shared record, SystmOne module or another provider's system but can still be viewed by the GP practice.


Sadly, there is not a national document providing a clear answer about which organisation is the controller for every part of that shared record.


There is also an important point that can get lost if we focus only on who originally entered the information.


If practice staff can access and view information about a patient, the practice is still processing that information in a meaningful sense. From the patient's perspective, that matters.


The right of access is not simply about obtaining copies of documents. It is also about understanding what an organisation knows about you and what personal information it is able to use when making decisions about you.


That is particularly important in healthcare, where there is an obvious imbalance of knowledge between the patient and the organisations providing their care. A patient may reasonably want to know not only what sits within the traditional GP record, but what other information is available to their GP when they open their clinical system.


That does not necessarily mean the practice should attempt to download and disclose an entire record maintained by another provider in a separate module.


My usual practical approach is:

  • disclose the relevant personal information that the practice actually holds within its own record;

  • where the practice can also access relevant information held or maintained by another provider, in a separate module, be transparent about that fact; and

  • Use your standard disclosure letter tempalte to explain that "the practice can also gain access to other modules within the system such as community providers and we advise that you reach out to other providers who have treated or supported you for a full picture"


That approach reflects an important purpose of the right of access: allowing people to understand the information organisations have available about them.


That small change in approach avoids two common mistakes: excluding information simply because it came from somewhere else, and misusing “third-party confidentiality” as a catch-all reason for withholding information.


A SAR isn't limited to the bits of the record your organisation wrote itself.


If the information is within the practice's responsibility, start from the position that the patient's personal information is in scope. Withhold it only where the law gives you a proper reason to do so.





Emma Cooper, Information Rights Nerd
Emma Cooper, Information Rights Nerd

 
 
 

Comments


00011-2939233035.png

DID YOU FIND THIS USEFUL?

Join our mailing list to get practical insights on ISO 27001, AI, and data protection; No fluff, just useful stuff.

You can unsubscribe at any time. You are welcome to read our Privacy Policy

bottom of page