This page outlines the principles, policies and practices that guide how GP Alliance manages information ensuring it remains secure and well-governed and used ethically across all our practices. The videos below provide clear demonstrations of the processes and standards we follow at GP Alliance.
The content is organised into 5 key areas:
- Subject Access Requests
- Personal Data Breaches
- Cybersecurity
- Freedom Of Information
- Data Protection
Understanding Subject Access Requests
Subject Access Requests allow individuals to access the personal information we hold about them. Watch these videos to enhance your understanding.
Subject Access Request are important to understand because they ensure we handle personal data transparently and give individuals confidence in how their information is managed.
Personal Data Breaches
A personal data breach is any incident where personal information is compromised, whether through loss, unauthorised access or accidental disclosure. At GP Alliance, being aware of personal data breaches is essential to protecting individuals’ information and meeting our responsibilities.
The ICO’s Self-assessment for data breaches offers step by step guidance to help determine whether a data breach should be reported and how to assess its impact.
Journey of a personal data breach report
Information asset
Information assets are the key data, systems, and resources we rely on to deliver safe, effective patient care and they must be managed in line with our Information Governance standards.
Here you can build a more clearer and practical knowledge of information assets and how they are managed.
Introduction to risk management for SIRO And IAO workbook
Cybersecurity
Cybersecurity education plays a vital role in helping individuals navigate the digital world safely and responsibly. The instructional videos on this topic below provide clear guidance on how to protect personal information, recognise online threats and engage in appropriate digital behaviour.
Ransomware
Phishing
Social engineering
Messy files
Protecting NHS data
Be aware what you share
The The Caldicott Principles are a set of good practice guidelines for using and keeping safe people’s health and care data. The Caldicott Principles are a core part of cybersecurity in UK health and social care because they govern how confidential information is accessed, shared, protected and justified.
To further enhance your learning on cybersecurity, you may like to explore the accompanying e‑learning training and course materials, which serve as a curated collection of instructional resources designed to deepen and refine your understanding of cybersecurity.
Test your knowledge
Freedom Of Information
The following videos illustrate how freedom of information empowers the public and strengthens transparent governance.
What Is The Freedom Of Information Act?
What Does A Valid FOI Request Look Like And What Should I Do?
What’s the ICO’s role under FOI and EIR?
Data Protection
Safeguarding your personal information is a responsibility we take seriously. This section explains how we collect, use, store and protect your data when you interact with our website. You’ll also find details about your rights and how you can exercise them at any time.
Controllers Processors in GDPR
www.youtube.com/watch?v=lLhrMDGeyN0
To conclude your learning please review the staff handbook.
Here are some additional links to support your exploration into the topics covered above.