September 2023
University Hospitals of North Midlands (UHNM) is required to provide you with details on the type of personal information which we collect and process. In addition to any other privacy notice which we may have provided to you, this notice relates to the information collected and processed in relation to the FPPT.
The FPPT in ESR is commissioned by NHS England.
Contact: Nicola Hassall
Address: Ground Floor, Springfield, Royal Stoke, Newcastle Road, ST4 6QG
Phone Number 01782 676625
Email: nicola.hassall@uhnm.nhs.uk
The type of personal information we collect is in relation to the FPPT for board members and is described below, much of which is already collected and processed for other purposes than the FPPT:
- Name and position title
- Employment history – this includes details of all job titles, organisations, departments, dates, and role descriptions
- References
- Job description and person specification in previous role
- Date of medical clearance
- Qualifications
- Record of training and development in application/CV
- Training and development in the last year
- Appraisal, incorporating the completion of Leadership Competency Framework
- Record of any upheld, ongoing or discontinued disciplinary, complaint, grievance, adverse employee behaviour or whistleblowing findings
- DBS status
- Registration/revalidation status (where required)
- Insolvency check
- A search of the Companies House register to ensure that no board member is disqualified as a Director
- A search of the Charity Commission’s register of removed Trustees
- A check with the CQC, NHS England and relevant professional bodies where appropriate
- Social media check
- Employment tribunal judgement check
- Exit reference completed (where applicable)
- Annual self-attestation signed, including confirmation (as appropriate) that there have been no changes
Processing of this data is necessary on the lawful basis set out in Article 6(1)(e) UK GDPR as the foundation for the database. This is because it relates to the processing of personal data which is necessary for the performance of the FPPT which is carried out in the public interest and/or in the exercise of official authority vested in the controller.
For Care Quality Commission (CQC) registered providers, ensuring directors are fit and proper is a legal requirement for the purposes of the Health and Social Care Act 2008 (Regulated Activities) Regulations 2014, and organisations are required to make information available connected with compliance to the CQC.
How we get the personal information and why we have it
Most of the personal information we process is provided to us directly by you as part of your application form and recruitment to satisfy recruitment checks and the FPPT requirements. We may also receive personal information indirectly, from the following sources in the following scenarios:
- References when we have made a conditional offer to you
- Publicly accessible registers and websites for our FPPT
- Professional bodies for FPPT to test registration and or any other ‘fitness’ matters shared between organisations
- Regulatory bodies, eg CQC and NHS England
We use the information that you have given us to:
- conclude whether or not you are fit and proper to carry out the role of board director
- inform the regulators of our assessment outcome.
We may share this information with NHS England, CQC, future employers (particularly where they themselves are subject to the FPP requirements), and professional bodies.
Under the UK General Data Protection Regulation (UK GDPR), the lawful bases we rely on for processing this information are:
- We need it to perform a public task.
How we store your personal information
Your information is securely stored. We keep the ESR FPPT information including the board member reference, for a career long period. We will then dispose of your information in accordance with our policies and procedures regarding retention periods as set out in Policy DSP16 Information Lifecycle & Records Management and the Records Management: NHS Code of Practice.
Your data protection rights
Under data protection law, you have rights including:
- Your right of access – You have the right to ask us for copies of your personal information
- Your right to rectification – You have the right to ask us to rectify personal information you think is inaccurate. You also have the right to ask us to complete information you think is incomplete
- Your right to erasure – You have the right to ask us to erase your personal information in certain circumstances
- Your right to restriction of processing – You have the right to ask us to restrict the processing of your personal information in certain circumstances
- Your right to object to processing – You have the right to object to the processing of your personal information in certain circumstances
- Your right to data portability – You have the right to ask that we transfer the personal information you gave us to another organisation, or to you, in certain circumstances
- You are not required to pay any charge for exercising your rights. If you make a request, we have one month to respond to you
Please contact DSPUHNM@uhnm.nhs.uk
How to complain
If you have any concerns about our use of your personal information, you can make a complaint to us at DPOUHNM@uhnm.nhs.uk You can also complain to the Information Commissioner’s Officer (ICO) if you are unhappy with how we have used your data.
The ICO’s address
Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
Helpline number: 0303 123 1113 ICO website: https://www.ico.org.uk