The Law and Caldicott Guardians
Introduction
Information governance is a core leadership responsibility in the emergency department (ED). Timely clinical care, safe handovers, quality improvement and research rely on lawful, proportionate handling of personal health data.
The Data Protection Act 2018 (implementing UK GDPR) sets the legal framework; within health and social care the Caldicott Guardian provides senior ethical and practical oversight. This section summarises the law, the role and duties of Caldicott Guardians, and concrete actions ED leaders should take.
Legal summary: Data Protection Act 2018 and individual rights
The Act (with UK GDPR) defines processing principles and individual rights that should drive ED practice. Key practical points:
- Core principles (high level): lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; accountability. Organisations must be able to demonstrate compliance under the Data Protection Act 2018.
- Individual rights include the right to be informed; access (subject access request, SAR); rectification; erasure (in limited circumstances); restriction of processing; portability; objection; and information about automated decision‑making.
- SAR timescales: organisations must respond to subject access requests within one calendar month; an additional two months may be allowed for complex or numerous requests (notify the requester within one month).
- Health data are "special category" data and require both a lawful basis for processing and an additional condition to legitimise...
Ready to master this topic for the FRCEM?