Question to the Department of Health and Social Care:
To ask the Secretary of State for Health and Social Care, if he will publish his Department's contractual guidance on the (a) access and (b) use of big data collected by private companies contracted to the NHS.
The Department recently published the updated standard National Health Service Terms and Conditions which reflect the requirements of the General Data Protection Regulation (GDPR). The NHS Terms and Conditions require suppliers to the NHS to comply with the Procurement Policy Note 03/17 Changes to Data Protection Legislation and General Data Protection Regulation (PPN) published by the Government Crown Commercial Service. This PPN places an obligation on the contracting authority to take certain steps to ensure suppliers are compliant with GDPR (ensuring security of personal data) in existing contracts and for contracts awarded after 25 May 2018.