Views:

Document History

Document replaces: Personal information policy v1.2

Replaced document archive location: KingsDocs

Reviews and updates

1. Introduction

A systematic approach to the management of employee records ensures that the Trust can control the quality and quantity of information generated; it can maintain that information in a manner that best serves its business needs; and it can dispose of the information efficiently. Personal data will be obtained for one or more specified purpose and shall not be used for a different purpose without an employee's prior consent (some exemptions exist - see appendix 2).

Personal information must be adequate, relevant, not excessive for the purpose and must be kept accurate and up to date.

Manual and electronic personnel records will be properly controlled, readily accessible and archived or destroyed in accordance with relevant Records management legislation (Public Records Act 1958 and 1967), National guidance NHS X Records Management Code of Practice 2021 rules and the Trust's statutory duties. Personal files should provide a clear comprehensive record of current and former employees' service record.

With the exception of excluded categories of information outlined in the Data Protection Legislation, e.g. references, employees have a right to access all information on their personal and electronic files.

2. Definitions and recording of personal demographic information

In the context of this policy, 'employees' is used to refer to current, former and prospective employees, honorary members of staff, agency staff, non-executive directors and students on work placements.

An 'employee record' is anything that contains information (in any media) about an employee.

The term 'manager' and 'line manager' is used in this policy to refer only to employees of the Trust with full management responsibilities (i.e. those who carry out employee relations processes. This term does not cover people whose role is purely supervisory or of a team leadership / team co-ordinator nature (e.g. those with basic rota/leave approvals or day to day task supervision). This term is not used to cover the Trust's Legal Services Department, who may require different access rights, pursuant with their legal professional privileges.

The term 'processing' is used in this policy to have the same meaning as it has within the UK Data Protection Act (incorporating both the EU and UK General Data Protection Regulations (GDPR)). This means the obtaining, recording or holding information or handling it in any way.

The term "personnel file", "HR file" or "personal file" (used herein) refers to information held both physically and/or electronically relating to an employee of King's College Hospital NHS Foundation Trust. These can be held in either local records and / or centrally held records.

A personnel file will usually contain:

Personal details (name, date of birth, employee number, emergency contact details, next of kin etc) Copy of identification documentation Confirmation that Disclosure and Barring Service check was returned satisfactorily (DBS - formerly Criminal Records Bureau - CRB) and right to work documentation Annual leave record (this may be held on a local file and not a central HR file) Sickness record (this will be held electronically on the rostering or payroll system) New starter forms References Job application/advert/job description at time of hire Interview and assessment paperwork Professional Registration and Qualification evidence Confirmation of occupational health clearance (note that detailed Occupational Health medical files are not held by HR but centrally within the Occupational Health department) Unconditional job offer letter For Executive and Non-Executive Director posts: Search of insolvency and bankruptcy register Search of disqualified directors register Declaration of fitness (signed and dated) Copies of formal correspondence between the Trust and employee, e.g. employee relations documentation (held on electronic file within HR)

All documents on personal files, including file notes and 'post-its', should have date and source information and should be organised in chronological order with the most recent documentation held at the front of the file.

The term "personnel information" in the context of this policy includes all information held about an individual inclusive of information stored on their personal file as well as any other information held by the Trust regarding them.

The Trust uses the TRAC recruitment system and Electronic Staff Record System (ESR) to enable, amongst other features, the recording and reporting of data to help the Trust demonstrate compliance with equality legislation. It also assists in comparing the experiences of staff in the Workforce Race Equality Standard (WRES) and Workforce Disability Equality Standard (WDES), and in determining action where necessary. The following disclosed 'Protected Characteristics' are recorded on ESR either directly or via transfer from the recruitment system TRAC. Candidates and employees have the option not to disclose and that status is then recorded in the system:

Note that Pregnancy & Maternity details are only recorded on ESR where there is an impact on employment: Pregnancy and maternity related absences are recorded. Employees receiving maternity pay are given an assignment status of 'Maternity & Adoption'. Where the nature of a person's job leads to a change of duties during pregnancy an appropriate reason for the change of assignment is recorded. For further information around privacy and what details are recorded in these national systems please see; Privacy - ESR Hub - NHS Electronic Staff Record; and Your ESR News -. 3. Purpose and Scope

This Policy has been developed in response to the Corporate Records Management legislation and guidance issued by NHS Employers. The guidance is based upon current legal requirements and professional best practice.

This policy covers all employee records. 4. Duties All members of staff have a responsibility not to accidentally or intentionally disclose information about employees through overheard conversations, mislaid documentation, e-mails, text messages and hard copies of correspondence sent to the wrong destination.

Information about employees is strictly private and confidential. Members of staff responsible for collecting, processing and storing information about employees have a 'duty of confidence' to ensure that the rules of confidentiality are rigorously exercised.

This 'duty of confidence' extends to students, trainees, apprentices, honorary, observers and temporary staff working in the Trust as well as members of staff.

Unauthorised communication of confidential information is a serious matter and can be grounds for dismissal in accordance with the Trust's Disciplinary Policy. All staff are responsible together with their line managers for ensuring they have completed Statutory and Mandatory Training around Information Governance and that this is maintained through their employment. 5. Personal Files 5.1 Storage of personal files

Personal files for staff joining the organisation before 1st October, 2013 including those staff who have transferred to the Trust with paper records at any time will be housed in secure record rooms located in the Human Resources Department. Staff joining the Trust from 1st October, 2013 onwards may have a full or skeleton paper record held in this location, with additional electronic records retained by the Trust's outsourced HR provider, Capita.

The electronic records stored by Capita are not single files held in one location but consist of electronic entries retained in their customer relationship management (CRM) system and the Trust's Greenlight system. Data is either stored locally within their network or at their West Malling data centre. The data centre is accredited to ISO27001 standards and their local servers are protected to the standard required by the NHS Information Governance Statement of Compatibility. This is set out in their Logica Connection Architecture (LCA) which was approved as part of them being granted a link to the Trust's secure N3 network. Access to their systems is controlled by multi layered password encrypted access (at least 2 layers) and password control is administered by their central IT team again to the standard set out by the NHS IG SOC. In the future, should Capita cease to provide HR services to the Trust, all files relating to Trust staff will be returned securely to the Human Resources Department for reintegration with legacy information.

5.2 Access to personal files

Access to personal files is restricted to authorised members of Human Resources team and the employee's direct line manager. Supervisors, Team Leaders and Team Co-ordinators not classed as line managers (see section 2 - Definitions) may not access an employee's personal file, whether it be a centrally or locally held one. Access to personal information will only be granted where it is wholly required by the individual as part of their legitimate management role. Where a supervisor wishes to add something to a personal file, this will be facilitated via the appropriate manager.

Investigating Officers may apply to the Divisional/Departmental HR Manager or Medical Workforce Manager for access to the personal file where they can demonstrate it is relevant and appropriate. Data held by Capita is restricted to members of the outsourced service function where that data needs to be accessed for day to day contracted activity on behalf of the Trust.

The member of staff removing a physical file from the designated record room is responsible for the safe keeping of the file. Whenever a file is removed, it must be kept in a secure place while not being used and returned to the record room as soon as possible. Any files that are removed by people outside the HR Administration team, or any files that are taken outside of the HR Administration department, will be logged centrally. This log file is held on the Human Resources secure shared drive. The person removing the file will be responsible for adding its location to the log held in the main HR Admin Office and will be responsible for updating the log once it is returned. Copies of an employee's electronic record will not need to be logged in the same way as the source data will not leave its storage location.

If HR staff forward the file(s) to other colleagues outside of the HR Department, this must also be recorded on the log. This includes the dissemination of electronic records.

Any locally held information should be restricted to the line manager.

5.3 Inspection of personal files by employees

Trust employees are entitled to see their personal file in the presence of a member of the Human Resources team. A trade union representative, friend or colleague can accompany employees.

Where part or an employee's entire file is electronic, this will be made available for viewing at a computer in a private location or copies of the file may be printed for the employee to view. This approach will also be applied to employee data retained by Capita, although employees can contact Capita directly on 0300 303 8609 to request direct access to their data. This activity will be placed in a log held in the main HR Admin Office.

An employee who wishes to see their personal file should send a written request to the HR Support officer in the Human Resources Department. Employees are required to provide proof of identity, e.g. Trust identity card or, in the case of former employees, a passport, driving licence etc. Where access to data held by Capita is required, Capita will require sight of a formal ID document, e.g. a passport or driving licence.

Trust employees are also entitled to see their secondary or local file in the presence of their manager. As above, a trade union representative or colleague can accompany employees.

No administration fee will be charged for viewing records, in line with the General Data Protection Regulation where copies of documentation are requested.

A member of the Human Resources team will ensure that information exempted by the relevant UK legislation such as Data Protection.

References provided by Trust managers will be withheld unless the author of the reference gives their explicit permission for the reference to be shown. References supplied by former employers will be withheld until the author of the reference gives their express permission for the reference to be shown.

If an employee considers that any information in the personal file is inaccurate, they are entitled to attach a correction note to the relevant document, however no documents may be removed from the file by the employee. This includes warnings that are placed on the employee's file which are no longer 'live' as these may still be relevant to the employment context.

5.4 Subject Access Requests/General Data Protection Regulation

The Trust will ensure that Subject Access requests are dealt with in line with legal requirements and Trust Policy including:

Assigning the request to a designated individual to manage That the request will be responded to in a reasonable timescale (the Trust will work to a schedule of a maximum of a calendar month for such requests relating to personnel information) That a response is provided in an appropriate format A quarterly report is produced for the Information Governance Steering Group summarising open alerts and those in breach of deadlines

The principles outlined in section 5.3 will also apply to the management of subject access requests, including the requirement to provide proof of identity or appropriate authorisation from the employee to release their records.

The Chief Executive has overall responsibility for the Trust's compliance with the Act. The Information Governance Steering Group (IGSG), chaired by the Senior Information Risk Owner has responsibility for monitoring compliance with Subject Access Requests.

The Trust will comply with written access requests by logging receipt of and sending an acknowledgement letter to the requester for all requests received by the Human Resources Department.

The Trust has the right to contact the requester to ask for additional information and/or clarification of the request if necessary.

Requests for copies of employee records in electronic or paper format will be logged by Human Resources and actioned.

As outlined in section 1, references are part of a list of excluded categories of information outlined in the Data Protection Legislation. These may only be released with approval from the individual who provided the reference and consideration should be given to the requester contacting the referee directly for this information.

5.5 Secondary Files

Secondary files on employees may be held by line managers at local level but should only contain information that is strictly necessary for the effective management of the subject of the file. Secondary files may contain, for example:

Telephone numbers and address Annual leave cards Performance appraisal records Attendance records and related correspondence Study leave applications Duty rosters Time sheets Meeting records, e.g. informal or formal HR meetings

Managers must ensure that secondary files are at all times kept in a secure, locked cabinet or in a secure electronic file accessible only to the line manager. As noted in section 2 (Definitions) and section 5.2 (Access to Personal Files), only line managers or managers in the individual's management chain may have access to these files. It is not appropriate for supervisors / team leaders / team co-ordinators who are not responsible for the full suite of employee management issues to view them.

When an employee leaves the Trust, all the documents contained within secondary files must be sent to HR (care of the HR Administrator) to be placed on the personal file. These will kept in accordance with the retention periods in appendix 1.

When an employee transfers to another department within the Trust, the secondary file should be transferred to the new departmental manager via the Central HR Team. The HR Business Partner will help facilitate this. If this information is not required by the new line manager it should be returned to the Human Resources Department. During the transfer, process strict care must be taken to ensure that the personal information of the transferring employee cannot be seen by unauthorised persons.

5.6 Other personnel records

Employee records are held by other departments, e.g., the Occupational Health Department, Day Nursery, etc. The principles outlined in the policy statement apply equally to records held in these areas, although access to these records and the process for obtaining them will vary from department to department. Please see appendix 2 for a list of exemptions which also apply to these records. Managers are not entitled to view the Occupational Health records of their employees as these are considered as medical records (see the Trust's Subject Access Policy for Health Records) by the occupational health department and are subject to the same regulations as hospital and GP medical notes in regard to access and confidentiality. Managers may however be sent Occupational Health Reports after an appointment with the employee's consent. Employees may request copies of their own Occupational Health records in line with the General Data Protection Regulation. Records may also be seen by Legal Services (subject to legal professional privileges) when required for use in legal matters relating to the Trust. 6.0 Electronic Records

The principles of good record management apply to employee records created and stored electronically. Access to records should be restricted to line managers, members of staff who have been delegated the administration of electronic personnel records (e.g. staff inputting e-Rostering information, ESR Self Service modules) and other authorised users. Computer users should ensure that if documents are not password protected, they log out or lock their computer before leaving their workstations. No records accessed should be saved to the local computer.

Access to these electronic records will be managed in accordance with the principles set out in this policy.

For further information regarding ESR, please see Appendix 3. 7.0 Transferring information about employees

7.1 General Rules

The general rules apply to the transfer of employee information.

- Where sensitive personal information is needed to construct a report or to inform a decision, the information provided will be restricted to the needs of the task and will not include unnecessary data items. - People requesting information must specify the data items (Individual data fields) they need. Where there is doubt, the person who is being asked to provide the data should get clarity on the need ensuring the requestor is authorised to access that level of data (including anyone they are going top share it with). . - All attachments which contain sensitive personal data must be password protected.

7.2 Conversations

Confidential information about employees should never be discussed in public areas where it might be overheard (e.g. virtual meetings such as Mircrosoft TEAMS, corridors, canteen, public transport, inter-hospital bus). Such discussions should always take place in appropriate areas such as meeting rooms with closed doors.

Where virtual meetings are used and recorded it must be made clear, before such a recording is due to start, that individuals have the right to object or leave the meeting. Care must be taken to ensure that any sharing of computer screens during virtual meetings does not disclose personal information to members of the meeting not entitled to view such information.

7.3 Written Information

Written information about employees should never be left where unauthorised persons could view it. Confidential information should also never be disclosed or 'discussed' in any virtual areas (such as social networking sites such as Facebook, Twitter and LinkedIn). Hard copy correspondence and other papers containing employee information should not be sent through the internal post unless placed in a sealed envelope marked private and confidential. If the sender wishes correspondence to be read only by the addressee, the envelope should be marked strictly addressee only.

7.4 Electronic Information

The NHS Electronic Staff Record (ESR), allows for limited data to be 'transferred' between Trusts by way of an Inter-Authority Transfer. Records transferring in this way will comply with the strict rules outlined by the Department of Health. 7.5 Telephone Enquiries about Employees

Permission should be sought from the employee before information is released to anyone other than members of staff who have authorised access to personal files. Alternatively the name and telephone number of the person requesting information can be given to the employee, thus enabling them to supply the information themselves.

7.6 Transmission of information by email

When transmitting information by email, the sender must be certain that information about employees is only sent to designated secure email accounts and only seen by the person authorised to receive it. Confidential e-mail messages should be encrypted and only NHS.Net should be used to transfer confidential information from King's. Personal email accounts such as Hotmail, Gmail and Yahoo! should not be used for sending work emails. There are a number of secure domains that afford the same level of protection as NHS.Net as follows: .x.gsi.gov.uk; .gsi.gov.uk; .gse.gov.uk; .gsx.gov.uk; .pnn.police.uk; .cjsm.net; .scn.gov.uk; .gcsx.gov.uk, .mod.uk. When sending emails to these addresses, the email will be encrypted and secure from sender to receiver.

When emails are sent from NHS.Net to other domains including personal email accounts, the message will not be encrypted. If a message needs to be sent from King's to a non-secure domain then written consent must be received from the subject of the email prior to transmission. This applies to sending emails to third parties, where consent must be sought from the subject of the communication.

When sending emails, you must ensure that the details of your recipient are correct before sending to prevent errors. Additional care must be taken with attachments to emails to ensure that personally identifiable data is encrypted and only sent to those relevant individuals entitled to view such information. Passwords to documents should be sent in a separate email.

7.7 Disclosure of personal information without explicit consent of the employee

In certain circumstances personal information may be disclosed to third parties without the explicit consent of employees (See appendix 2) 8.0 Recruitment and Selection

Personal information may be obtained during the recruitment process either electronically (e.g. through the ESR and E-Recruitment Systems), or manually (e.g. hard copy application forms). All data obtained in this way will meet the standards outlined above. Personal data obtained for monitoring purposes on "Part A" of the on-line and hard copy application forms will not be passed to the short-listing panel. All managers and administrators must ensure the confidentiality of this information is maintained. The E-Recruitment (TRAC) and associated Systems will record all shortlisting and appointment decisions. When an appointment is made, appointing managers/ administrators must send King's Recruitment Services an electronic copy of the job file via the Trust's Greenlight system on the Successful Candidate Form. Documents may also be emailed to KCH.CapitaRecruitment@nhs.net, with the email subject stating the vacancy reference number and the candidate's form number from Greenlight. The job file will contain: the application forms of unsuccessful candidates off-line shortlisting and interview notes copy of advert job description and person specification.

Unless prior permission is given, information about prospective employees at any stage of the recruitment and selection process will be restricted to the appointing managers, the members of staff to whom they delegate the administration of the process and members of the HR team. Job files are housed in either a secure record rooms located in the Human Resources Department or securely electronically at King's Recruitment Services (Capita) and then destroyed after 6 months. 9. Monitoring Compliance

Yearly audits will be carried out on the number of employee relations cases relating to breaches of confidentiality and this information will be cross referenced with the guidelines in this policy to ensure compliance. This audit will be presented to the Information Governance Steering Group. Responsibility for this monitoring lies with the Human Resources department.

Six-monthly audits of access to the Trust's personnel file room will also be conducted using details of security access to the storage location and reviewed by an appropriate member of the senior HR management team. Findings will be presented to the Information Governance Steering Group.

Any issues pertaining to this audit will be highlighted to the Chief People Officer and the Trust Data Protection Officer and / or ICT Security Manager as needed.

10. Associated documents

Disciplinary Policy and Procedure Freedom of Information policy Corporate Records Management Policy KCH Email Policy Subject Access Policy for Health Records Data Protection Policy 11. References

http://www.dh.gov.uk/en/Publicationsandstatistics/Publications/PublicationsPolicyAndGuidance/DH_4131747

General Data Protection Regulation

Freedom of Information Act 2000 Appendix 1: RETENTION AND DISPOSAL SCHEDULE - MINIMUM RETENTION PERIODS

Full retention schedules for all areas and other document types can be found in the Trust's Records Management Policy. All records above except job advertisements will be destroyed under confidential conditions at the end of their scheduled retention period.

*Only the name of an unsuccessful candidate should be submitted to Capita without any additional personally identifiable information attached. Interview notes and applications should be retained locally for 6 months and then securely destroyed.

Appendix 2: DISCLOSURE OF EMPLOYEE DATA TO THIRD PARTIES

In certain circumstances, employee data may be released to third parties without the explicit consent of the employee.

Where disclosure is required by law, permitted by implicit consent or recognised as being in the interests of the employee or general public (and this interest overrides the duty to maintain confidentiality), data can be released.

Examples of disclosure that do not require employee consent include:

Statutory requirements of powers, e.g. Inland Revenue returns, Sick Pay returns. Counter Fraud and Police investigations

Civil Legal proceedings, e.g. claims for damages, court orders in respect of maintenance.

Industrial Tribunals and other bodies established under employment law.

Other Health Authorities, Trusts, e.g. staff transfer forms, information regarding possible re-deployment.

Health Authority Management functions e.g. investigation of allegations of misconduct, authority appeal hearings.

Department of Health general auditors

Collection of statistics on all employees

Other disclosures in the interests of the employee or the general public, e.g. notification of a dangerous accident, previous convictions not deemed to be spent under the Rehabilitation of Offenders Act.

The employment of certain individuals by the NHS is public knowledge and the surname, forenames, occupational group and name of employing NHS hospital may be disclosed to third parties for the following:

Members of the medical and dental professions

Members of the nursing profession

Members of other professions include those supplementary to medicine

Members of the Executive Boards

Members of key public positions e.g. SIRO, Caldicott Guardian and Data Protection Oifficer

Some information about every role will also be a public record thse include salary band and job description (including personal specifications)

Appendix 3: Electronic Staff Record (ESR) Acceptable Use Protocol

The following information applies to users of the Electronic Staff Record (ESR) system. All users must comply with the Trust's ICT Security Policy when using ESR.

Terms and Conditions for use of Electronic Staff Record:

Access to the system will be authorised by the The Workforce Information Systems Manager or their delegated authority. Access to the ESR system will be through your smartcard and pin number, which will constitute your signature. You must not attempt to log into the system using another users credentials or disclose yours to another person You must ensure ESR and the data derived from the system is only used for the purpose of carrying out your work and access only the records relevant to your duties. It is the responsibility of all users to ensure that information entered into the system is accurate and appropriate and that information obtained from the system is safe and secure. All data accessed or processed by staff using the ESR system or information derived from it (e.g. in the form of report output) is to be treated as strictly confidential. You must not leave unattended a workstation logged onto ESR unless you have logged out or locked the workstation. You must report any actual or suspected breaches of confidentiality or of this AUP through the Adverse Incident Reporting Procedure, on Datix and via your line manager or to the Workforce Information Systems Manager. Confidentiality of staff records and manual data forms must be maintained at all times. Confidential material must be locked away if you need to leave it unattended. N.B. Improper use of the ESR system including failure to adhere to the standards of confidentiality or security may be regarded as gross misconduct and could result in withdrawal of the user's access and/or disciplinary action being taken, up to and including dismissal.

EQUALITY RISK ASSESSMENT FORM