Privacy Notice
Your right to be informed – how the Trust uses your personal information
Effective from date: 01 June 2026
Review date: Two-yearly
Summary
King’s College Hospital NHS Foundation Trust (the Trust) is responsible for the personal information it holds about you. It is known in Data Protection law as the data controller. This means we decide how and why your information is used and must keep it safe and lawful. Our data protection contact details have been provided under section 13 of this page.
This Privacy Notice explains how the Trust looks after your personal information so it can deliver the best possible care and services. Using information responsibly allows the Trust to provide safe, high quality treatment, ensure staff have the information they need, and continually improve NHS services for patients and communities.
Most personal information is used because the Trust is carrying out its role as an NHS organisation. This includes caring for patients, supporting education and training, planning services and carrying out approved research. Much of the information we hold is health related and sensitive, and it is treated with the highest levels of care, confidentiality and security.
Information is securely shared with professionals and organisations directly involved in your care, such as GPs, other hospitals, and social care services. This helps make sure your care is joined up, timely and safe. Shared clinical systems like Epic and the London Care Record allow authorised staff to see relevant information when they need it, with access carefully controlled, monitored and audited.
The Trust is committed to keeping your information secure, using only what is necessary, and keeping it only for as long as NHS rules require. You have clear rights over your information, including the right to access it, correct it and raise concerns. The Trust is open, transparent and committed to always respecting your privacy.
1: Introduction
This Privacy Notice explains how the Trust collects, uses, stores, shares, and protects the personal information of you, our patients.
The Trust provides healthcare services to adults and children. Where appropriate, children are supported to exercise their own rights as they become able to do so. In addition to delivering clinical care, we support education and training of healthcare professionals, health and care research, service planning, evaluation and improvement, and related support services.
To conduct these activities safely, lawfully, and effectively, we must process personal information about patients, carers, staff, volunteers, and members of the public. This includes both routine information and information that is sensitive or confidential in nature.
The Trust is the data controller for the personal information it holds. This means the Trust is legally responsible for deciding how and why personal data is processed and for making sure that it is managed in line with Data Protection law.
This Privacy Notice applies to information held in electronic systems, paper records, images, audio or visual recordings and other formats.
The Trust is committed to being open and transparent about how personal information is used and to always respecting your privacy rights.
2: Legal framework
The Trust processes personal data in accordance with all relevant Data Protection and confidentiality laws, including:
- UK General Data Protection Regulation (UK GDPR)
- Data Protection Act 2018
- Data (Use and Access) Act 2025
- The common law duty of confidentiality
- NHS and health and care law
These laws set out clear rules that the Trust must follow. They require us to:
- process personal information fairly and lawfully
- use information only for clear and legitimate purposes
- ensure information is accurate and up to date
- keep information secure
- retain information only for as long as necessary
The Trust is registered with the Information Commissioner’s Office (ICO), the independent authority responsible for overseeing Data Protection in the UK. Our registration number is Z4653019.
3: Lawful bases for processing
The Trust will only process your personal information where there is a lawful reason to do so. These lawful bases include:
Public task
Most of the information the Trust processes is used to perform its official duties as an NHS organisation. This includes delivering healthcare, ensuring patient safety, improving services, training staff, and supporting research in the public interest.
Legal obligation
In some cases, the Trust must process or share information to comply with the law. This may include safeguarding duties, public health reporting or responding to court orders.
Vital interests
Information may be used or shared where this is necessary to protect life, for example in a medical emergency.
Contract
Where the Trust has a contract with you, such as in employment or certain services, data may be processed to meet contractual obligations.
Legitimate interests
In limited circumstances, we may process personal information under legitimate interests, for example for administrative functions such as facilities management or fraud prevention. We do not normally rely on legitimate interests to process confidential patient information for healthcare purposes.
Data Protection consent
Consent is only used where appropriate, such as for optional services or communications. Your care and treatment are not usually dependent on giving consent for Data Protection purposes.
Clinical consent
Consent to medical examination, treatment or care is known as clinical consent. This is different from consent under Data Protection law. For most healthcare activities, personal information is processed under public task, not Data Protection consent. This means you cannot normally withdraw consent to stop information being used where it is necessary for your care, safety, or for the Trust to carry out its NHS duties.
More sensitive personal information
Much of the information we use about you is more sensitive data under Data Protection law (known as special category data). This includes information about your physical or mental health.
We process this information because it is necessary for:
- the provision of health or social care or treatment
- managing health or social care systems and services
- reasons of public interest around public health
These uses are permitted under Data Protection law and are subject to strict safeguards.
4: Information we collect
Patients and carers
The Trust holds records about your health, care, and treatment. This information may be collected directly from you or received from other organisations involved in your care.
This includes, but is not limited to:
- personal details such as name, address, date of birth, NHS number, and contact details
- information about appointments, admissions, referrals, and discharges
- clinical notes written by healthcare professionals
- diagnoses, treatment plans, and care pathways
- results of tests and investigations
- imaging such as x rays, scans, and clinical photographs
- medication information, allergies, and adverse reactions
- information provided by other NHS or health and care organisations
- details of carers, relatives or others involved in your care
We only collect information that is relevant and necessary for your care or for our NHS responsibilities.
Most records are held electronically, although some paper records are retained where required. Our main clinical system is called Epic.
It is important that the Trust holds accurate and up to date information. You are encouraged to check your details and inform staff of any changes.
5: How we use your information
The Trust uses personal information to support a wide range of activities, including:
- providing safe, effective, and timely care and treatment
- supporting continuity of care across different services and organisations
- ensuring staff involved in your care have appropriate information
- communicating with you about appointments, test results, and treatment
- monitoring, auditing, and improving the quality and safety of services
- investigating complaints, concerns, incidents, and legal claims
- educating and training healthcare professionals
- supporting authorised research and innovation
- managing and planning NHS services
- meeting public health responsibilities
- complying with legal, regulatory, and contractual obligations
Where information is used for purposes beyond your direct care, this is done under a clear legal basis and with protections in place.
Patient surveys and feedback
We may invite you to give feedback through surveys such as the Friends and Family Test or national patient surveys to help improve services. Limited contact details may be shared with approved survey providers. Taking part is voluntary and does not affect your care.
Vaccination programmes
For national vaccination programmes, limited personal and health information may be shared within the NHS to identify eligibility, invite you for vaccination, record vaccination status, and update your health record. This processing supports public health and is required by law.
Genomic services
If you are referred for genomic testing, relevant information may be shared with NHS Genomic Laboratory Hubs and partner organisations involved in providing these services. This supports diagnosis and treatment. The Trust and partners may act as joint data controllers.
All use of data follows NHS principles of data minimisation, meaning only the information needed for a specific purpose will be used.
6: Information sharing
The Trust shares information securely and lawfully and only where necessary.
Sharing for direct care
Information is shared with professionals and organisations involved in your care, including:
- GP practices
- other NHS trusts and hospitals
- community health services
- social care services
- approved partner organisations directly providing care
Epic inter‑Trust sharing
Our electronic patient record, Epic, is shared with partner NHS organisations. This allows staff directly involved in your care to access up‑to‑date information, supporting safe, coordinated care. Access is role‑based and audited, and relevant information may be shared where you receive care from more than one participating organisation.
London Care Record
The London Care Record allows authorised health and care professionals across London to securely view relevant information from your records to support your direct care, such as medications or allergies. Access is limited to those involved in your care and is logged and monitored. You can object to sharing through the London Care Record, although this may affect care in some situations.
To find out how to object and what this means for your care, you can:
- visit the Lewisham and Greenwich NHS Trust website
- email: [email protected]
- or speak to your care team
MyChart
MyChart is a secure app and website that gives you access to parts of your health record, helping you take more control of your care. It is part of our Epic patient record system and supports your care with our hospital and community services. It can be used on your mobile, tablet or computer to view test results and letters in one place, share information ahead of appointments, have video consultations, keep your details up to date, share your record with your GP, and support friends or family through proxy access. Full details are on our MyChart webpage.
If you use your NHS login to view and manage appointments or view and access MyChart, NHS England checks your identity. NHS England is responsible for the personal information you gave them to create your NHS login and confirm who you are, and they only use it for that purpose. When we use this information to verify your identity, we act on NHS England’s instructions. You can read the NHS login Privacy Notice and Terms and Conditions. This does not affect any information you give directly to us.
Sharing for other purposes
Information may also be shared with:
- regulatory and oversight bodies, including the Care Quality Commission, NHS England, the Department of Health and Social Care, and auditors where necessary to meet legal and regulatory duties
- public health authorities
- commissioners and planners of NHS services
- police or safeguarding organisations where legally required
Information is shared only when necessary, following the Caldicott Principles, which provide a framework for using and protecting confidential health and care information safely and appropriately.
Joint data controllers
When using shared systems or joint services, the Trust may act as a joint data controller with partner organisations. Clear agreements are in place to define responsibilities and protect your information.
Where we act as a joint data controller with another organisation, you may exercise your Data Protection rights with either organisation. We will work together to ensure your request is managed lawfully and promptly.
Anonymised and pseudonymised information
Where possible, information is anonymised (this means it is processed so individuals can no longer be identified) or pseudonymised (which means it is altered to remove direct identifiers but still re‑identifiable with a key) before being used for planning, reporting, or research purposes.
Caldicott guardian
The Trust’s Caldicott guardian provides senior clinical oversight to ensure confidential patient information is used lawfully, ethically and in line with the Caldicott principles.
7: Research and service planning
The Trust undertakes and supports health and care research to improve treatments, services, and patient outcomes.
All research uses of data follow NHS ethical standards and minimise the use of identifiable information wherever possible.
Identifiable information is only used where there is a clear legal basis.
Research publications never identify individuals.
We are committed to using information for research only where there is a clear legal basis, appropriate approvals, and strong safeguards in place.
National data opt out
You can choose whether your confidential patient information is used for research and planning beyond your individual care.
This does not affect your direct care or treatment.
The national data opt‑out does not apply to information used for your individual care, where disclosure is required by law, or where data has been anonymised so individuals cannot be identified.
To find out more or to set or change your preference, visit the NHS Digital national data opt-out webpage or call 0300 303 5678.
8: Communicating with you
The Trust aims to communicate with you in a clear, timely and convenient way.
Where appropriate, we use a digital-first approach, including:
- text messages
- secure patient portals
These use approved NHS systems. Your contact details are used to communicate about your care, appointments, and treatment. You can tell us if your contact details change.
You can tell the Trust if you have preferences about how you are contacted. However, there may be occasions where alternative methods are required to make sure important information is received.
Emails containing sensitive information may be encrypted unless you request otherwise.
Video appointments
In some circumstances, the Trust offers video appointments as an alternative to face-to-face care. These are treated the same as in-person consultations and use approved, encrypted NHS systems. If you have concerns about using video technology, you may request a face-to-face or telephone appointment.
9: Other processing activities
Staff, volunteers, and job applicants
The Trust processes personal and special category information for workforce purposes, including recruitment, employment administration, payroll, pensions, professional registration, training, wellbeing, and compliance with legal duties.
CCTV and security systems
CCTV, body-worn cameras, and related systems are used in some areas to help maintain safety, security and prevent crime. Recordings are retained for limited periods unless required for investigation or legal purposes. Signs are displayed in areas where CCTV or body‑worn cameras are in use.
Charitable and support services
Where applicable, personal information is used to manage donations, enquiries, newsletters, and communications in line with lawful bases and consent requirements.
10: Your rights
Under Data Protection law, you have rights including to:
- know how and why your personal data is collected and used
- easily request a copy of personal information held about you (often known as a subject access request)
- request that inaccurate or incomplete personal information be corrected
- control how your personal data is used in certain situations
- choose to object to specific uses of your personal data
- receive and reuse your electronic data across different services
- be protected from decisions made solely by automated systems
The Trust does not normally make decisions about you using fully automated processes without an appropriate member of staff being involved. If this ever applies, you will be informed and given the right to request an appropriate member of staff review and challenge the decision.
Some rights may not apply where information is processed as part of the Trust’s public task.
If you wish to make a subject access request, visit our Medical Records webpage. If you wish to exercise any of your other rights contact the Trust’s Information Governance team or Data Protection Officer using the details at the end of this notice.
Requests can be made verbally or in writing (by using our form, in email, or by letter). We may ask for information to help us identify the records you want.
Some rights may be limited where information is required for your care, to protect the rights of others, or where we are legally required to retain or use it. We will always explain our decision clearly if this applies.
With some exceptions, requests are responded to within one calendar month, but if this needs to be extended, you will be told at the earliest opportunity.
11: Keeping your information secure
The Trust has strong technical and organisational measures in place to protect personal information, including:
- secure IT systems
- computer access based on job roles
- audit logs and monitoring
- mandatory staff Data Protection training
- confidentiality clauses in contracts
- regular security reviews and inspections
Any personal data breaches are investigated and reported to the ICO where required.
12: Retention of records
The Trust keeps information only for as long as necessary and in line with the NHS Records Management Code of Practice.
13: Contact details
Data Protection Officer
If you have questions, concerns or wish to exercise your rights, you can contact our Data Protection Officer:
Data Protection Officer
King’s College Hospital NHS Foundation Trust
King’s College Hospital
Denmark Hill
London
SE5 9RS
- Email: [email protected]
We encourage you to raise any concerns with the Trust first so we can try to resolve them. If you remain dissatisfied, you have the right to complain to the Information Commissioner’s Office.
Information Commissioner’s Office (ICO)
If you are unhappy with how your information has been managed and remain dissatisfied with the Trust’s response, you can contact the ICO:
- Website: www.ico.org.uk
- Phone: 0303 123 1113