What it covers
Why the information a GP practice holds is valuable, the types we protect, and the law and principles behind confidentiality. The everyday habits that keep it safe: your own login and smartcard, locked screens, spotting phishing and scam calls, social media, and sharing by phone, email and text. How to recognise subject access and Freedom of Information requests, and what to do the same day when a breach or near miss happens.
Who it is for
Everyone in a GP practice who sees patient or staff information: reception, administration, practice managers, HCAs, nurses, pharmacists, care coordinators, social prescribers, GPs, trainees, locums, students and volunteers.
By the end you will be able to
- Explain why patient information is valuable, and the types of information we protect.
- Apply data protection law, confidentiality and the Caldicott Principles in everyday work.
- Keep information confidential, accurate and available: logins, smartcards, screens, desks and devices.
- Recognise phishing, scam calls, malware and social media risks, and respond safely.
- Share information safely, and recognise and pass on subject access and Freedom of Information requests.
- Recognise a data breach or near miss, and report it the same day.
Modules
- Why patient information matters
- Your login, screen and smartcard
- Phishing, scams and social media
- Sharing information the right way
- When something goes wrong
Content mapped to the learning outcomes of the Core Skills Training Framework (England) v1.1: Information Governance and Data Security. Law named: Data Protection Act 2018 and the UK GDPR.
Sources
- Core Skills Training Framework (England) Statutory/Mandatory Subject Guide v1.1, June 2021 (Skills for Health), Information Governance and Data Security: Key Learning Outcomes (archived copy)
- UK GDPR, Article 4: definitions, including personal data, personal data breach and data concerning health
- UK GDPR, Article 5: principles relating to processing of personal data
- UK GDPR, Article 9: processing of special categories of personal data
- UK GDPR, Article 33: notification of a personal data breach to the Commissioner
- UK GDPR, Article 34: communication of a personal data breach to the data subject
- Data Protection Act 2018, section 170: unlawful obtaining etc of personal data
- Data Protection Act 2018, section 164A: complaints by data subjects to controllers (inserted by the Data (Use and Access) Act 2025)
- Computer Misuse Act 1990, section 1: unauthorised access to computer material
- Freedom of Information Act 2000, section 1: general right of access to information held by public authorities
- Freedom of Information Act 2000, section 8: request for information
- Freedom of Information Act 2000, Schedule 1, Part III, paragraph 43A: providers of primary medical services
- The Eight Caldicott Principles (National Data Guardian, 8 December 2020)
- Review of Data Security, Consent and Opt-Outs (National Data Guardian, 2016)
- Confidentiality: NHS Code of Practice (Department of Health, 2003)
- Data Security and Protection Toolkit (NHS England)
- Data Security and Protection Toolkit: overview and introductory guidance
- Data Security Standards: overall guide, the ten National Data Guardian standards
- Data Security and Protection Incident Reporting tool (Data Security and Protection Toolkit news)
- Information governance and data protection, GP good practice guidelines (NHS England, updated 11 March 2025)
- Smartcards and access controls, GP good practice guidelines (NHS England, updated 9 April 2025)
- GP mythbuster 41: Smartcards (Care Quality Commission)
- NHS mail, GP good practice guidelines (NHS England)
- Microsoft Teams and remote working, GP good practice guidelines (NHS England)
- Social media, GP good practice guidelines (NHS England, updated 4 April 2025)
- Subject access requests (SAR), GP good practice guidelines (NHS England, updated 13 March 2025)
- High quality patient records, GP good practice guidelines (NHS England)
- Texting, emailing and messaging patients and service users (NHS England information governance guidance, 21 January 2026, archived copy)
- Personal data breaches: a guide (Information Commissioner's Office)
- How do we recognise a subject access request (SAR)? (Information Commissioner's Office, updated 7 April 2026)
- What makes a valid request? Guide to managing an FOI request (Information Commissioner's Office)
- How to spot a scam email, text message or call (National Cyber Security Centre)
- Phishing attacks: defending your organisation (National Cyber Security Centre)
- Three random words (National Cyber Security Centre)
- Use a strong and separate password for your email (National Cyber Security Centre)
- Mitigating malware and ransomware attacks (National Cyber Security Centre)
- How to identify common cyber threats, NHSmail cyber security guide (NHSmail Support): the Report Phishing button and [email protected]
- Investigation: WannaCry cyber attack and the NHS (National Audit Office, 27 October 2017)
- Opt out of sharing your health records (NHS website, reviewed 6 June 2024)
- UK GDPR, Article 12A: meaning of applicable time period (inserted 5 February 2026 by section 76 of the Data (Use and Access) Act 2025)
- Freedom of Information Act 2000, section 10: time for compliance with request
- Data Protection Act 2018, section 173: alteration etc of personal data to prevent disclosure to data subject
- Right of access: how long do we have to comply? (Information Commissioner's Office subject access guidance)
- Guide to managing an FOI request: what are the timescales for responding? (Information Commissioner's Office)
- Incident reporting, Data Security and Protection Toolkit support (the 72 hour notification)
- Data protection officers, Article 37 UK GDPR, with section 7 Data Protection Act 2018 (public authority)
- The Data (Use and Access) Act 2025 (Commencement No. 9 and Transitional and Saving Provisions) Regulations 2026, SI 2026/1015, regulation 2: the Information Commissioner's office abolished and its functions transferred to the Information Commission on 30 September 2026
- ICO governance changes confirmed for 30 September 2026 (Information Commissioner's Office news, 15 September 2026): the Information Commission will continue to be known as the ICO
- Care Identity Service and NHS Spine users, terms and conditions (NHS England Digital, archived copy of 27 April 2025): no sharing of smartcards or passcodes; a breach may lead to disciplinary proceedings or criminal prosecution
- Data Security and Protection Toolkit 2026-27, version 9, released 1 September 2026 (DSPT news): GP practices still answer assertions numbered by the National Data Guardian standards; assertion 3.2.1 asks for at least 95% of staff trained in the last twelve months
GPAtlas is not accredited, verified or endorsed by Skills for Health or NHS England. Acceptance of this training is at the discretion of your employer, who remains responsible for confirming it meets local requirements. Your employer may require more frequent refreshers than the guidance period; the practice's own policy applies. Some pictures and films in our courses, and the film narration, are made with AI tools. We check every one for accuracy before we publish it.