Recording script
Data protection at work
- 2modules
- 1192words
- 8minutes when read
- 2voices
How to record this
Amara is the host. Curious, a little sceptical, asks the question the learner is actually thinking, and pushes back when something sounds unrealistic on a short staffed shift.
Nadia is the practice educator. Warm, direct, never condescending. Answers the awkward question rather than deflecting it.
Leave a beat of silence between speakers rather than overlapping. Timestamps assume 150 words per minute, which is a natural teaching pace. Cue numbers mark where each on screen graphic should land.
Wording that must not be upgraded
planned The CPD Certification Service
Application scheduled.
Do not promote any of these words in a video title, description or thumbnail. Aligned is not accredited, and planned is not approved.
1. The principles, and the first hour of a breach
About 4 minutes, 570 words. Starts at 00:00 in the full course recording.
Outcomes to state on camera
- Apply the principles to a real sharing decision
- Identify special category data and the extra care it needs
- Act correctly in the first hour of a breach
- Handle a subject access request
Script
Cue 1 Three principles as a three question filter applied to a real request.
AMARA 00:00 Seven principles. I have been trained on them four times and could not list them.
NADIA 00:06 Then do not try. Three of them decide almost every real question, and the others are mostly the organisation's problem rather than yours.
AMARA 00:15 Which three?
NADIA 00:16 Purpose limitation: was it collected for this? Data minimisation: do I need all of it, or just this part? And integrity and confidentiality: is it secure in the way I am about to move it?
Cue 2 Special category data types, with everyday care examples beside each.
AMARA 00:30 Give me a real example.
NADIA 00:32 A colleague asks you to send a resident's care plan to her personal email so she can read it at home. Run the three. Was it collected for that? No. Does she need all of it? Almost certainly not. Is personal email secure? No. Three noes in about four seconds.
AMARA 00:52 What is special category data?
NADIA 00:54 Health, race or ethnic origin, religion or belief, political opinions, trade union membership, genetic and biometric data, sex life and sexual orientation. It needs more protection.
Cue 3 Breach response order: contain, report, do not delete, do not cover.
AMARA 01:04 In care, that is basically everything.
NADIA 01:06 It is, and that is exactly why people stop noticing. A diagnosis. A colleague's sickness reason. A dietary requirement that reveals a religion. All special category, all being discussed in corridors.
AMARA 01:19 Right. I have just emailed a care plan to the wrong person. What do I do?
NADIA 01:25 In order. Contain it, so recall the email. Then report it internally immediately. Manager or data protection lead.
Cue 4 72 hour ICO clock starting at organisational awareness.
AMARA 01:32 Even if the recall worked?
NADIA 01:34 Even then, and this is the bit people get wrong out of embarrassment. Recalling an email does not mean it was not read. And the judgement about whether it is reportable is not yours to make, it belongs to the organisation.
AMARA 01:51 What is the rush?
NADIA 01:52 Seventy two hours to notify the ICO where it is reportable, and that clock starts when the organisation becomes aware. So every hour you spend hoping it will be fine is an hour eaten out of somebody else's deadline.
Cue 5 Everyday breaches: bus seat, open screen, personal phone, lift conversation.
AMARA 02:08 Is there anything I must not do?
NADIA 02:11 Do not delete anything and do not try to cover it. That turns a mistake, which happens to everyone, into misconduct, which does not have to happen to anyone.
AMARA 02:22 What actually counts as a breach? It feels like a hacking word.
NADIA 02:27 Far broader. An email to the wrong recipient. A handover sheet left on a bus. A screen left open in a corridor. A photograph of a wound on a personal phone. A conversation in a lift.
Cue 6 Subject access request arriving informally in a corridor.
AMARA 02:42 A conversation?
NADIA 02:42 Unauthorised disclosure of personal data. If you discuss a named resident's condition where visitors can hear, that is a disclosure. Nobody reports it and it is one of the most frequent.
AMARA 02:55 Last thing. Subject access requests.
NADIA 02:57 Anyone can ask what personal data you hold about them. It does not have to be in writing, does not have to use the words, and does not have to go to a particular person.
AMARA 03:11 So if a daughter asks me what is written about her mother?
NADIA 03:16 She may have just made one, and the clock may have started. Which is why every member of staff needs to recognise it and pass it on rather than answering it in a corridor.
AMARA 03:29 How long do we have?
NADIA 03:31 One month, extendable by two more for complex or numerous requests, provided you tell them inside the first month. Normally no fee. And redact other people's data within the record rather than withholding the whole thing, which is the usual overreaction.
Sources for the on screen credit
- UK GDPR and Data Protection Act 2018, Information Commissioner's Office
- Personal data breaches: a guide, Information Commissioner's Office
- Right of access guidance, Information Commissioner's Office
2. Access requests, retention and sharing with other organisations
About 4 minutes, 622 words. Starts at 03:48 in the full course recording.
Outcomes to state on camera
- Handle a subject access request end to end, including redaction
- Apply a retention schedule and justify it
- Share data with another organisation lawfully
- Recognise when a DPIA is required
Script
Cue 1 One month clock starting at receipt, with the extension conditions attached.
AMARA 03:48 A daughter has asked for everything we hold about her mother. Where do I start?
NADIA 03:54 With the clock, because it has already started. One month from receipt. Extendable by two more if it is complex or there are several, but only if you tell her inside the first month and say why.
AMARA 04:08 Can I ask her to prove who she is?
NADIA 04:12 Yes, proportionately. And be careful here, because asking for excessive proof to buy time is itself a breach. The clock only pauses while you wait for identification you genuinely needed.
AMARA 04:24 Where do I search?
Cue 2 Data found in the official system, then in email, a notebook and a messaging group.
NADIA 04:26 Everywhere the data actually lives, which is always more places than the official system. Email. Shared drives. Handover sheets. The manager's notebook. The messaging group the team uses.
AMARA 04:37 The messaging group is not official.
NADIA 04:39 It is still your data, and honestly, discovering it exists is often the more serious finding. A request has a way of surfacing every unofficial place information has been living.
AMARA 04:51 Can I tidy the records up first?
NADIA 04:54 No. And I want to be very precise about this one, because people do it instinctively and think they are being helpful.
Cue 3 Section 173 warning: tidying a record after a request is a criminal offence.
AMARA 05:03 Go on.
NADIA 05:04 Amending or deleting a record because somebody has asked to see it is a criminal offence under section 173 of the Data Protection Act 2018. Routine deletion under a schedule you already had can carry on. Tidying, cannot.
AMARA 05:19 Redaction. There are other people mentioned throughout.
NADIA 05:22 Then redact the third party detail and disclose the rest. What you must not do is withhold the whole record because parts of it mention somebody else, which is the standard overreaction.
AMARA 05:34 Is it always redacted?
Cue 4 A black box over PDF text with the text copied out from underneath.
NADIA 05:36 It is a balance, not a blanket rule. Another service user, yes. A professional acting in their working capacity, often not, because they were doing their job and their name is part of the account.
AMARA 05:50 How do I redact a PDF?
NADIA 05:52 Properly, and this catches organisations out expensively. A black box drawn over text is not redaction if the text is still underneath and can be copied out. Flatten the document, or redact on paper before scanning.
AMARA 06:07 Let us do retention. We keep everything, which feels safest.
NADIA 06:11 It feels safest and it is a breach. Storage limitation says no longer than necessary, and keeping everything forever also means any future incident is much larger than it needed to be.
Cue 5 Retention schedule applied, beside one that exists and is ignored.
AMARA 06:24 But care records are needed years later.
NADIA 06:26 They are, and the periods are genuinely long for exactly that reason. The point is not to keep less than you should. It is to have a schedule, to be able to justify each period, and to actually apply it.
AMARA 06:42 What if we have a schedule and ignore it?
NADIA 06:46 That is worse than having none, because you have documented that you knew what you should have been doing and did not.
AMARA 06:55 Last thing. We are about to start sharing data with a local NHS team.
Cue 6 DPIA triggers with a care service ticking three of them.
NADIA 07:00 Routine sharing wants a written data sharing agreement. What is shared, why, the lawful basis, how it is transferred, how long each side keeps it, and what happens if there is a breach.
AMARA 07:14 And urgent one off sharing?
NADIA 07:16 No agreement needed. Lawful basis, minimum necessary, and a record of what you shared, with whom, and why.
AMARA 07:23 Is there anything else I should have done and probably have not?
NADIA 07:28 A DPIA, almost certainly. It is required before processing likely to be high risk: large scale special category data, systematic monitoring, new technology, or processing about vulnerable people.
AMARA 07:39 That is us on at least three counts.
NADIA 07:42 It is most care services on at least three counts, and very few have ever done one. And note the word before. A DPIA written after the system went live is a document, not an assessment.
Sources for the on screen credit
- Right of access detailed guidance, Information Commissioner's Office
- Data Protection Act 2018, section 173, legislation.gov.uk
- Records management code of practice for health and care, NHS England
- Data protection impact assessments, Information Commissioner's Office