# Data protection at work

*UK GDPR for people who handle other people's information, and what to do in the first hour of a breach.*

## Production summary

- Modules to record: 2
- Total script: 1192 words, about 8 minutes of finished audio
- Voices: Amara (host) and Nadia (practice educator)
- Level: All staff

## Accreditation wording that must appear in the description

- **The CPD Certification Service** (planned): Application scheduled.

> Do not upgrade any of these words in a description or a thumbnail. Aligned is not accredited, and planned is not approved.


---

## The principles, and the first hour of a breach

**Runtime** about 4 minutes. **Words** 570. **Starts at** 00:00 in the full course recording.

### Learning outcomes to state on camera

- Apply the principles to a real sharing decision
- Identify special category data and the extra care it needs
- Act correctly in the first hour of a breach
- Handle a subject access request

### Script


`[CUE 1]` *Three principles as a three question filter applied to a real request.*

**AMARA**  [00:00]
Seven principles. I have been trained on them four times and could not list them.

**NADIA**  [00:06]
Then do not try. Three of them decide almost every real question, and the others are mostly the organisation's problem rather than yours.

**AMARA**  [00:15]
Which three?

**NADIA**  [00:16]
Purpose limitation: was it collected for this? Data minimisation: do I need all of it, or just this part? And integrity and confidentiality: is it secure in the way I am about to move it?


`[CUE 2]` *Special category data types, with everyday care examples beside each.*

**AMARA**  [00:30]
Give me a real example.

**NADIA**  [00:32]
A colleague asks you to send a resident's care plan to her personal email so she can read it at home. Run the three. Was it collected for that? No. Does she need all of it? Almost certainly not. Is personal email secure? No. Three noes in about four seconds.

**AMARA**  [00:52]
What is special category data?

**NADIA**  [00:54]
Health, race or ethnic origin, religion or belief, political opinions, trade union membership, genetic and biometric data, sex life and sexual orientation. It needs more protection.


`[CUE 3]` *Breach response order: contain, report, do not delete, do not cover.*

**AMARA**  [01:04]
In care, that is basically everything.

**NADIA**  [01:06]
It is, and that is exactly why people stop noticing. A diagnosis. A colleague's sickness reason. A dietary requirement that reveals a religion. All special category, all being discussed in corridors.

**AMARA**  [01:19]
Right. I have just emailed a care plan to the wrong person. What do I do?

**NADIA**  [01:25]
In order. Contain it, so recall the email. Then report it internally immediately. Manager or data protection lead.


`[CUE 4]` *72 hour ICO clock starting at organisational awareness.*

**AMARA**  [01:32]
Even if the recall worked?

**NADIA**  [01:34]
Even then, and this is the bit people get wrong out of embarrassment. Recalling an email does not mean it was not read. And the judgement about whether it is reportable is not yours to make, it belongs to the organisation.

**AMARA**  [01:51]
What is the rush?

**NADIA**  [01:52]
Seventy two hours to notify the ICO where it is reportable, and that clock starts when the organisation becomes aware. So every hour you spend hoping it will be fine is an hour eaten out of somebody else's deadline.


`[CUE 5]` *Everyday breaches: bus seat, open screen, personal phone, lift conversation.*

**AMARA**  [02:08]
Is there anything I must not do?

**NADIA**  [02:11]
Do not delete anything and do not try to cover it. That turns a mistake, which happens to everyone, into misconduct, which does not have to happen to anyone.

**AMARA**  [02:22]
What actually counts as a breach? It feels like a hacking word.

**NADIA**  [02:27]
Far broader. An email to the wrong recipient. A handover sheet left on a bus. A screen left open in a corridor. A photograph of a wound on a personal phone. A conversation in a lift.


`[CUE 6]` *Subject access request arriving informally in a corridor.*

**AMARA**  [02:42]
A conversation?

**NADIA**  [02:42]
Unauthorised disclosure of personal data. If you discuss a named resident's condition where visitors can hear, that is a disclosure. Nobody reports it and it is one of the most frequent.

**AMARA**  [02:55]
Last thing. Subject access requests.

**NADIA**  [02:57]
Anyone can ask what personal data you hold about them. It does not have to be in writing, does not have to use the words, and does not have to go to a particular person.

**AMARA**  [03:11]
So if a daughter asks me what is written about her mother?

**NADIA**  [03:16]
She may have just made one, and the clock may have started. Which is why every member of staff needs to recognise it and pass it on rather than answering it in a corridor.

**AMARA**  [03:29]
How long do we have?

**NADIA**  [03:31]
One month, extendable by two more for complex or numerous requests, provided you tell them inside the first month. Normally no fee. And redact other people's data within the record rather than withholding the whole thing, which is the usual overreaction.

### Sources for the on screen credit

- UK GDPR and Data Protection Act 2018, Information Commissioner's Office
- Personal data breaches: a guide, Information Commissioner's Office
- Right of access guidance, Information Commissioner's Office

---

## Access requests, retention and sharing with other organisations

**Runtime** about 4 minutes. **Words** 622. **Starts at** 03:48 in the full course recording.

### Learning outcomes to state on camera

- Handle a subject access request end to end, including redaction
- Apply a retention schedule and justify it
- Share data with another organisation lawfully
- Recognise when a DPIA is required

### Script


`[CUE 1]` *One month clock starting at receipt, with the extension conditions attached.*

**AMARA**  [03:48]
A daughter has asked for everything we hold about her mother. Where do I start?

**NADIA**  [03:54]
With the clock, because it has already started. One month from receipt. Extendable by two more if it is complex or there are several, but only if you tell her inside the first month and say why.

**AMARA**  [04:08]
Can I ask her to prove who she is?

**NADIA**  [04:12]
Yes, proportionately. And be careful here, because asking for excessive proof to buy time is itself a breach. The clock only pauses while you wait for identification you genuinely needed.

**AMARA**  [04:24]
Where do I search?


`[CUE 2]` *Data found in the official system, then in email, a notebook and a messaging group.*

**NADIA**  [04:26]
Everywhere the data actually lives, which is always more places than the official system. Email. Shared drives. Handover sheets. The manager's notebook. The messaging group the team uses.

**AMARA**  [04:37]
The messaging group is not official.

**NADIA**  [04:39]
It is still your data, and honestly, discovering it exists is often the more serious finding. A request has a way of surfacing every unofficial place information has been living.

**AMARA**  [04:51]
Can I tidy the records up first?

**NADIA**  [04:54]
No. And I want to be very precise about this one, because people do it instinctively and think they are being helpful.


`[CUE 3]` *Section 173 warning: tidying a record after a request is a criminal offence.*

**AMARA**  [05:03]
Go on.

**NADIA**  [05:04]
Amending or deleting a record because somebody has asked to see it is a criminal offence under section 173 of the Data Protection Act 2018. Routine deletion under a schedule you already had can carry on. Tidying, cannot.

**AMARA**  [05:19]
Redaction. There are other people mentioned throughout.

**NADIA**  [05:22]
Then redact the third party detail and disclose the rest. What you must not do is withhold the whole record because parts of it mention somebody else, which is the standard overreaction.

**AMARA**  [05:34]
Is it always redacted?


`[CUE 4]` *A black box over PDF text with the text copied out from underneath.*

**NADIA**  [05:36]
It is a balance, not a blanket rule. Another service user, yes. A professional acting in their working capacity, often not, because they were doing their job and their name is part of the account.

**AMARA**  [05:50]
How do I redact a PDF?

**NADIA**  [05:52]
Properly, and this catches organisations out expensively. A black box drawn over text is not redaction if the text is still underneath and can be copied out. Flatten the document, or redact on paper before scanning.

**AMARA**  [06:07]
Let us do retention. We keep everything, which feels safest.

**NADIA**  [06:11]
It feels safest and it is a breach. Storage limitation says no longer than necessary, and keeping everything forever also means any future incident is much larger than it needed to be.


`[CUE 5]` *Retention schedule applied, beside one that exists and is ignored.*

**AMARA**  [06:24]
But care records are needed years later.

**NADIA**  [06:26]
They are, and the periods are genuinely long for exactly that reason. The point is not to keep less than you should. It is to have a schedule, to be able to justify each period, and to actually apply it.

**AMARA**  [06:42]
What if we have a schedule and ignore it?

**NADIA**  [06:46]
That is worse than having none, because you have documented that you knew what you should have been doing and did not.

**AMARA**  [06:55]
Last thing. We are about to start sharing data with a local NHS team.


`[CUE 6]` *DPIA triggers with a care service ticking three of them.*

**NADIA**  [07:00]
Routine sharing wants a written data sharing agreement. What is shared, why, the lawful basis, how it is transferred, how long each side keeps it, and what happens if there is a breach.

**AMARA**  [07:14]
And urgent one off sharing?

**NADIA**  [07:16]
No agreement needed. Lawful basis, minimum necessary, and a record of what you shared, with whom, and why.

**AMARA**  [07:23]
Is there anything else I should have done and probably have not?

**NADIA**  [07:28]
A DPIA, almost certainly. It is required before processing likely to be high risk: large scale special category data, systematic monitoring, new technology, or processing about vulnerable people.

**AMARA**  [07:39]
That is us on at least three counts.

**NADIA**  [07:42]
It is most care services on at least three counts, and very few have ever done one. And note the word before. A DPIA written after the system went live is a document, not an assessment.

### Sources for the on screen credit

- Right of access detailed guidance, Information Commissioner's Office
- Data Protection Act 2018, section 173, legislation.gov.uk
- Records management code of practice for health and care, NHS England
- Data protection impact assessments, Information Commissioner's Office

---

*Copyright WAJD Group. Built by WAJD AI.*