Patient privacy and data security is at the heart of what NWEH does. We operate robust information governance processes to ensure all personal data is handled in accordance with UK GDPR, the Data Protection Act, and NHS confidentiality and information governance requirements.
Access to data is strictly controlled, with appropriate technical and organisational safeguards in place to protect confidentiality, integrity, and availability. Our externally certified quality and information security management systems, supported by regular compliance reviews, help ensure that patient data remains secure throughout every research project and clinical trial.
Additionally, NWEH submits an annual assessment against the NHS England Data Security and Protection Toolkit (DSPT). In the context of clinical research, alignment with the DSPT helps provide confidence to NHS partners, sponsors, and stakeholders that patient data is managed securely throughout the research lifecycle. It complements broader quality and information security arrangements by reinforcing good governance, secure handling of confidential data, and continuous review of data protection practices.
Where required, NWEH also ensures compliance with the Common Law Duty of Confidentiality, obtaining support from the Confidentiality Advisory Group (CAG), alongside all relevant legal, ethical, and regulatory approvals.