Provision of Non-Disclosure Measure Lists to NHS Greater and Clyde Protocol: Version 3.2 Authorisation

SCRA NHS Greater Glasgow and Clyde

Name : Paul Harkness Name: Robin Wright

Locality Reporter Manager for Caldicott Guardian for NHS Greater SCRA, Glasgow Glasgow and Clyde

Signature …………………. Signature ……………….

Date………………………… Date………………………

NHS GGC ND Monthly Lists Protocol V3 2.doc Page 1 of 9

Contents

Title Page

Authorisation 1

Version Control 2

Terms of Reference 3

Purpose 3

Process 3

Security 4

Information Handling Prerequisites 5

Information Handling Processes 6

Supporting Information 7

Appendix A - Data Handling Briefing Note 9

Version Control

Date Version Author File Ref. Comments Initials

30/10/13 3.0 JPH Transmission of ND Version 3 contains some further minor Lists Protocol changes

19/6/14 3.1 LMcN Transmission of ND Updates to reflect GSC Lists Protocol

19/8/14 3.2 JPH Transmission of ND Updates to e-mail addresses Lists Protocol

NHS GGC ND Monthly Lists Protocol V3 2.doc Page 2 of 9

Terms of Reference

A Non-Disclosure Measure is a special provision attached to a child’s case in instances when it is considered necessary to protect the whereabouts of a child, or relevant person with whom the child is residing, due to significant concerns about their safety. Breaches of Non-Disclosure Measures can have serious consequences for children and those who care for them.

This protocol is designed to act as a code of practice between the Scottish Children’s Reporter Administration (SCRA) and NHS Greater Glasgow and Clyde for the electronic transfer of Non-Disclosure Measure information.

Purpose

The purpose of SCRA sharing Non-Disclosure Measure information with the NHS Greater Glasgow and Clyde is to ensure that they are aware of which children have Non-Disclosure Measures and have processes in place to reduce the likelihood of a breach of a non-disclosure measure. This data sharing agreement focuses on the security aspects of the transfer and provides detail on the subsequent handling arrangements that are to be met. The purpose of the protocol is to ensure that practices are consistent with the Data Protection Act 1998.

Process

This is a one way information sharing agreement from SCRA to NHS Greater Glasgow and Clyde, and does not permit NHS Greater Glasgow and Clyde staff to share sensitive information electronically with SCRA.

Non-Disclosure Measure lists will be sent to NHS Greater Glasgow and Clyde by SCRA’s Data Management Team.

Only Non-Disclosure Measure fortnightly lists for the SCRA West Dumbarton, , Glasgow, East and localities are to be sent by SCRA to NHS Greater Glasgow and Clyde.

The SCRA Non-Disclosure Measure lists are issued fortnightly and any previous lists are to be destroyed by NHS Greater Glasgow and Clyde as confidential waste. Each list sent is to be accompanied by Data Handling Briefing Note to NHS Greater Glasgow and Clyde (Appendix A). The data handling briefing note provides explicit data handling requirements for NHS Greater Glasgow and Clyde to follow.

NHS GGC ND Monthly Lists Protocol V3 2.doc Page 3 of 9

Security

SCRA will only send the non-disclosure lists to a designated email account belonging to the nhs.net domain. SCRA are currently part of the Public Services Network (PSN) and will use their Government Secure Intranet (GSI) email account for data exchanges. These lists are not to be sent outside the GSi, PSN and nhs.net secure domains. SCRA will use the Government Classification Scheme (GCS) and information, which is shared, will carry a protective or handling marking.

The classification of the data is OFFICIAL and the protective marking to be used is OFFICIAL-SENSITIVE. The PERSONAL descriptor is added to the protective marking to indicate that the information relates to an identifiable individual so the documents are marked OFFICIAL-SENSITIVE PERSONAL. This protective marking is equivalent to the NHS Confidential marking used widely by the National Health Service (NHS). The non-disclosure lists are only to be circulated to those members of NHS Greater Glasgow and Clyde staff who have or are likely to have contact with the children listed.

NHS GGC ND Monthly Lists Protocol V3 2.doc Page 4 of 9

Information Handling Prerequisites

Common

Both SCRA and NHS Greater Glasgow and Clyde will handle these ND lists in accordance with the Data Protection Act 1998.

SCRA SCRA will send all emails in accordance with the Code of Connection of the secure domain they are operating from (either GSi or PSN).

SCRA will use a single designated email account to send ND lists to NHS Greater Glasgow and Clyde.

Only SCRA staff will have access to the designated email account on a ‘need to know’ basis.

All Non-Disclosure lists are to be classified as ‘OFFICIAL’ and marked “OFFICIAL-SENSITIVE PERSONAL” on each page of the list.

A ‘Data Handling Briefing Note’ will be incorporated within the body of the email when the ND list is sent.

SCRA is the Data Controller for this information in terms of the Data Protection Act 1998.

NHS Greater Glasgow and Clyde

Will use a single designated email account to receive ND lists from SCRA.

The designated email account will be checked for new ND lists on a fortnightly basis.

Will ensure that only selected members of their staff have access to the designated email account on a ‘need to know’ basis.

Will be responsible for the distribution of the non-disclosure information on a ‘need to know’ basis to prevent non-disclosure breaches from occurring.

All Non-Disclosure lists are to be handled in accordance with the ‘Data Handling Briefing Note’.

NHS Greater Glasgow and Clyde is the Data Processor for this information in terms of the Data Protection Act 1998.

NHS GGC ND Monthly Lists Protocol V3 2.doc Page 5 of 9

Information Handling Processes

1. An e-mail sent by SCRA’s Data Management Team will contain one Non-Disclosure Measure (ND) list supplied as an e-mail attachment with 5 pages covering each of the 5 local authorities served by Greater Glasgow and Clyde.

2. In respect of all ND fortnightly lists submitted electronically, the ‘Data Handling Briefing Note’ will be included in the body of the email when the ND lists ARE sent (Appendix A). The briefing note describes the data handling requirements that are to be applied by NHS Greater Glasgow and Clyde to the ND list supplied by SCRA.

3. Non-disclosure lists are supplied to NHS Greater Glasgow and Clyde for its use only. This information is only to be used by those staff who have or are likely to have contact with the children in the ND list. The ND lists (in whole or part) are not to be forwarded to anyone or any organisation outside the NHS Greater Glasgow and Clyde domain.

4. Each new fortnightly ND list replaces the previous fortnight’s ND list. Old ND lists must not to be retained and must be disposed of by NHS Greater Glasgow and Clyde in accordance with the ‘Data Handling Briefing Note’ (Appendix A).

5. In the event of a breach of a non-disclosure condition by NHS Greater Glasgow and Clyde, SCRA is to be informed immediately so the risks to the child(ren)/carers can be assessed and action taken to protect them, if necessary.

6. Current methods (Royal Mail Special Delivery, courier or hand-delivery) can be used as a contingency in the event that the email system(s) at either NHS Greater Glasgow and Clyde or SCRA are unavailable. Faxing of ND lists or information must never be used as a contingency method or for any other reason.

7. In the event of any problem associated with e-mail submission of ND lists, the other organisation must be notified. Key contacts for both technical and business issues are listed in the supporting information section.

8. SCRA and NHS Greater Glasgow and Clyde are responsible for monitoring the use of this protocol. Either party has the right to retract from the protocol at any time. Any withdrawal must be given in writing to the other party and a month’s notice must be provided.

9. The start date for using this protocol will be the date that both parties sign the protocol. The protocol will be reviewed annually by both parties.

NHS GGC ND Monthly Lists Protocol V3 2.doc Page 6 of 9

Supporting Information

NHS Greater Glasgow and Clyde Key Contacts – Business Issues

NHS [email protected] Designated Email Account [email protected]

Name Designation Telephone E-mail

Catherine Business 0141 201 [email protected]. Martin Manager 0667 uk

NHS Greater Glasgow and Clyde Key Contacts – Technical Issues

Name Designation Telephone E-mail Jonathan Head of 0141 278 Todd Information [email protected] 2806 Management

NHS GGC ND Monthly Lists Protocol V3 2.doc Page 7 of 9

SCRA’s Key Contacts – Business Issues

SCRA [email protected] Designated Email Account

Name Designation Telephone E-mail

Martin Data Analyst 0300 200 [email protected] Black 1611

SCRA’s Key Contacts – Technical Issues

Name Designation Telephone E-mail

Bruce IS Security & 0300 200 [email protected] Knight Technical 1596 Assurance Officer

Michelle ICT Support 0300 200 [email protected] Rice Officer 1551

NHS GGC ND Monthly Lists Protocol V3 2.doc Page 8 of 9

Appendix A: Data Handling Briefing Note

DATA HANDLING BRIEFING NOTE

The Non-Disclosure Order list supplied is classified as Official in accordance with the Government Security Classifications (GSC) and carries the protective marking Official: Sensitive-Personal. The data handling arrangements to be followed for these Non-Disclosure lists are:

Storage of hard copy documents Protected by one barrier e.g. a locked container such as a locked cupboard or locked filing cabinet.

Storage duration 2 weeks

Disposal of paper waste Shredded or disposed of as confidential waste. Kept secure when left unattended.

Disposal of Magnetic Media Securely destroy

Reuse of Media (hard drives etc) Triple rewrite using CESG approved software

Movement within NHS Greater Glasgow In a sealed envelope marked ‘NHS and Clyde using internal distribution Confidential’. system. A transit envelope may be used if sealed with a security label.

Movement of paper lists (as a By Royal Mail Special Delivery, by contingency method if email is not courier or by hand delivery in a sealed available) between SCRA and NHS envelope. Greater Glasgow and Clyde. Do not show protective marking on the envelope.

Use by NHS Greater Glasgow and Clyde Only to be used by those staff who have or likely to have contact with the children in the ND list.

Email To send to other nhs.net accounts within NHS Greater Glasgow and Clyde only

Internal Telephone network Can be used if a private secure network is in place.

Mobile, public telephones Not to be used.

Facsimile Machines Not to be used.

NHS GGC ND Monthly Lists Protocol V3 2.doc Page 9 of 9