VerbatimParliament, as it happens

NHS: Data Protection

Asked by James McMurdockIndependentDepartment of Health and Social CareTabled Answered 15 June 2026UIN 6079

The question

To ask the Secretary of State for Health and Social Care, what plans he has to require NHS bodies to conduct Data Protection Impact Assessments when ownership of contracted data processors changes.

Answered by Preet Kaur Gill

National Health Service organisations should be ensuring all relevant information governance requirements are met in relation to their processing of patient data, including completing Data Protection Impact Assessments (DPIA) where appropriate. Article 35(1) of UK General Data Protection Regulation requires a DPIA where processing is likely to result in a high risk to the rights and freedoms of individuals. DPIAs must be kept under review and should be updated where there is a substantial change to the nature, scope, context, or purpose of data processing.

There are no plans to introduce requirements relating to informing patients where the ownership of a company processing NHS data changes hands, beyond ensuring all required governance documents are updated to indicate the data processor.

Verbatim has judged this answer against the question that was actually asked — answered, partly answered, or evaded. Sign in to see the verdict →

Open this question in Verbatim →

Every written question, searchable

155,000 questions tabled since the election, with the answer each department gave — and the ones still unanswered, with the clock running. Free to search.

Search written questions →Read on Verbatim