Privacy Notice for Staff

Privacy Notice for Staff

This Privacy Notice explains how Royal Devon University Healthcare NHS Foundation Trust (the Trust) collects, uses and protects personal information about prospective, current and former staff.

It explains:

  • what information we collect and where it comes from
  • how and why we use it
  • the lawful bases we rely on
  • who we share it with
  • how long we keep it
  • how we keep it secure
  • your rights under data protection law

This notice applies to all staff, including employees, workers, students, volunteers and contractors.

From time to time, the Trust introduces new systems and technologies to support workforce management, planning, and service delivery across Devon through initiatives such as One Devon People Digital. Where new processing activities are introduced, we will provide additional, focussed privacy information in advance and give staff the opportunity to review the information and provide feedback before implementation.

Who we are

Royal Devon University Healthcare NHS Foundation Trust is an NHS Foundation Trust providing healthcare services across Devon.

The Trust employs more than 14,000 staff.

The Trust is registered with the Information Commissioner’s Office (ICO) to process personal and special category data under the Data Protection Act 2018. Our ICO registration number is Z5368894.

Further Information Governance information is available at: Information Governance page

Why we collect personal information about you

The Trust collects, stores and processes personal information about prospective, current and former staff to meet its legal obligations as an employer and to support effective workforce management, service delivery and organisational planning.

We recognise the need to treat staff personal data fairly and lawfully. No personal information held by us will be processed unless the requirements for fair and lawful processing can be met. Your information will never be sold for direct marketing purposes.

This includes, for example:

  • recruitment, onboarding and employment administration (including payroll, pensions, benefits and performance processes)
  • workforce management (including rostering, leave requests, shift planning and safe staffing)
  • workforce planning and reporting (including system-wide workforce initiatives such as One Devon People Digital)
  • equality, inclusion and diversity monitoring and reporting
  • health and safety management and occupational health support
  • information governance, system security and compliance (including monitoring and auditing access to records to protect confidentiality and detect inappropriate access)
  • prevention and detection of fraud, misconduct and unlawful acts

Personal data relating to HR investigations and grievance processes is collected and used to investigate concerns, resolve workplace issues, and support fair and lawful employment practices. The Trust processes this information in accordance with UK data protection legislation, ensuring it is handled confidentially, securely, and only for legitimate HR purposes. Processing is carried out under appropriate legal bases, including legal obligation, public task, and employment contract requirements. For more information see: HR Investigations and Grievance Process Privacy Notice

How we inform you about new uses of your personal data

Where the Trust introduces new systems or changes how staff data is used (including through programmes such as One Devon People Digital), we are committed to ensuring transparency.

Before implementation, we will provide focussed privacy information which explains:

  • what personal data will be processed
  • the purpose of the processing
  • who the data will be shared with
  • the lawful basis under UK GDPR
  • retention periods and safeguards

Staff will be given the opportunity to review this information and provide feedback via Trust engagement channels. Where appropriate, adjustments will be made before implementation.

What personal information we collect and how we obtain it

Personal information about you will largely be collected directly from you during recruitment and throughout your employment.

Personal information may also be collected from other sources where necessary and lawful, including references, professional regulators, occupational health providers, national checks (including DBS) and relevant NHS systems.

In order to carry out our activities and obligations as an employer, we may process information including:

  • Personal demographics (including gender, race, ethnicity, sexual orientation, and religion or belief)
  • Contact details (such as name, address, telephone numbers and emergency contact details)
  • Employment records (including professional membership, references, eligibility to work checks and security checks)
  • Bank details and payroll information
  • Pension details
  • Leave records (including sickness absence, special leave, family leave, study leave and other applicable leave)
  • Health information relevant to employment (including occupational health assessments, fitness to work information and workplace adjustments)
  • Information relating to health and safety
  • Trade union membership (where provided)
  • Trust governors / membership information (where relevant)
  • Offences (including alleged offences), criminal proceedings, outcomes and sentences where relevant and lawful
  • Employment Tribunal applications, complaints, accidents and incident details

What we do with your personal information

Your personal information is processed for purposes that include:

  • staff administration and management (including payroll, pensions and performance processes)
  • business management and planning
  • accounting and auditing
  • accounts and records management
  • education and training administration
  • staff benefits administration
  • equality, inclusion and diversity monitoring
  • health administration and services (including occupational health where relevant)
  • processing leave requests and supporting safe staffing levels
  • staff engagement, feedback and workforce experience surveys (including the NHS Staff Survey)
  • crime prevention and prosecution of offenders
  • sharing and matching of personal information for the National Fraud Initiative (where applicable)
  • cross referencing, access audit and investigative purposes
  • information and databank administration to generate insights into key workforce metrics (for example headcount, headcount by gender, employee age demographics, hiring timelines, termination reasons and attrition rates)

The Trust may use digital tools, including automated analytics and artificial intelligence (AI), to support workforce management, information security and compliance with legal and regulatory obligations. These tools are designed to assist authorised staff and managers by identifying patterns, trends or potential risks, rather than to replace human decision-making.

Examples of how automated analytics may be used include:

  • monitoring and auditing access to electronic patient and staff records to help detect potential inappropriate access
  • supporting workforce planning, rostering and reporting activities
  • analysing staff engagement or feedback data (such as survey results) to improve workforce experience
  • supporting information governance, fraud prevention and system security activities

Monitoring and audit of system access

As part of our responsibility to protect patient confidentiality and comply with legal and regulatory requirements, the Trust monitors and audits access to its systems. This monitoring is proportionate, targeted and restricted to authorised staff.

This includes the use of Patient Privacy Monitoring (PPM), which brings together audit information from clinical systems with workforce and access information to identify potential inappropriate access to patient records for review and investigation.

PPM may use information from:

  • audit logs from the Electronic Patient Record (Epic)
  • workforce information (HR data)
  • user and access information from Active Directory

PPM uses automated analysis to identify patterns and relationships that may indicate inappropriate access (for example where a member of staff accesses their own record). PPM does not analyse the detailed clinical content of records (such as diagnoses or test results), but may use contextual audit information such as the location of treatment within the Trust.

No decisions that have a legal or similarly significant effect on you (for example disciplinary outcomes) are made solely by automated means. All outputs are reviewed by authorised Information Governance staff and, where appropriate, Human Resources, and any action taken is based on human assessment and established Trust procedures.

Workforce systems

The Trust uses workforce management systems such as: ESR (the NHS Central Employee Staff Record system), rostering platforms, and a learning management system.   These systems help us manage staff records including pay purposes, rostering and shift planning, leave and sickness management and workforce planning.

Key system providers such as RLDatix (used for rostering and staff expenses) acts as a Data Processor, processing personal data only on the Trust’s instructions and for the purposes of delivering those services. The Trust remains with the Data Controller for this information.

What is our legal basis for processing your personal information?

We rely on different lawful bases depending on the purpose for which we use your personal information. The main lawful bases we rely on include:

  • Public task (Article 6(1)(e)) – processing necessary to carry out our duties as an NHS Trust
  • Legal obligation (Article 6(1)(c)) – processing required by law (for example HMRC reporting or UKVI requirements)
  • Contract (Article 6(1)(b)) – processing necessary to administer and perform your employment contract
  • Legitimate interests (Article 6(1)(f)) – in limited circumstances where appropriate (for example certain staff benefit or secondment administration), supported by an assessment

Where we process special category data (including health data and equality information), we rely on one or more of the following conditions as appropriate:

  • Employment and social security law (Article 9(2)(b))
  • Occupational health / health or social care management (Article 9(2)(h))
  • Substantial public interest (Article 9(2)(g)) where relevant, supported by Data Protection Act 2018 conditions

A summary of typical purposes and lawful bases is set out below:

Purpose of processing

Lawful basis (Article 6)

Special category condition (Article 9) (where applicable)

Recruitment, onboarding and pre-employment checks

6(1)(b) Contract

9(2)(b) Employment and social security law

Payroll, pensions and benefits administration

6(1)(b) Contract; 6(1)(c) Legal obligation

9(2)(b) Employment and social security law

Workforce management (including rostering, leave and deployment)

6(1)(b) Contract; 6(1)(e) Public task

9(2)(b) Employment and social security law

Equality monitoring and workforce analytics

6(1)(c) Legal obligation; 6(1)(e) Public task

9(2)(g) Substantial public interest

Occupational health and staff wellbeing

6(1)(b) Contract; 6(1)(e) Public task

9(2)(h) Health or social care management

Training, development and staff engagement (including surveys)

6(1)(e) Public task

9(2)(g) Substantial public interest (where applicable)

Information governance, system security and audit (including monitoring system access)

6(1)(e) Public task; 6(1)(c) Legal obligation

9(2)(g) Substantial public interest

Prevention and detection of fraud, misconduct or unlawful acts

6(1)(c) Legal obligation; 6(1)(e) Public task

9(2)(g) Substantial public interest

Investigations, disciplinary processes and professional conduct

6(1)(c) Legal obligation; 6(1)(e) Public task

9(2)(g) Substantial public interest

Compliance with legal and regulatory requirements

6(1)(c) Legal obligation

9(2)(g) Substantial public interest (where applicable)

Where we process criminal offence data (including DBS checks), this is processed in accordance with UK GDPR Article 10 and the Data Protection Act 2018, including Schedule 1 conditions (for example safeguarding and preventing or detecting unlawful acts) where applicable.

The Trust does not require explicit consent from employees to process personal data where an appropriate lawful basis applies. Consent will only be used in limited circumstances where it is appropriate and can be freely given.

It can be a disciplinary offence (including dismissal) and in some circumstances may be a criminal matter to inappropriately access records about patients or work colleagues.

Who we share your personal information with and why

We will not routinely disclose information about you without a valid reason. However, in order to enable effective staff administration, to protect confidentiality, and to comply with our obligations as an employer, we may share personal information with relevant organisations and service providers.

Key examples include:

National NHS workforce systems (ESR)

We share relevant information with the NHS Business Services Authority (NHSBSA) for maintaining employment records held on national systems including the NHS Electronic Staff Record (ESR).

Workforce management, rostering and communication systems

The Trust uses systems such as Loop and HealthRoster to support staff rostering, leave requests, shift planning and internal communication. RLDatix acts as a Data Processor for these services, processing data only on the Trust’s instructions. The Trust remains the Data Controller.

Staff engagement surveys

As an NHS employer, the Trust is required to participate in the annual NHS Staff Survey. We engage an independent contractor (IQVIA Ltd) to administer the survey on our behalf. Personal information is shared with the contractor solely for distributing the survey and analysing results.

One Devon People Digital

To support informed decision-making and enable a proactive approach to workforce management across Devon, the Trust may share employee data through One Devon People Digital arrangements. These arrangements support improved workforce processes across participating organisations, staff movement and collaboration, and operational efficiency. Technical integration services (for example Boomi) may be used to enable controlled data flows between systems. Only the minimum necessary data is shared and access is restricted to authorised personnel.

Patient Privacy Monitoring (PPM)

We use the PPM system to help detect potential inappropriate access to patient records. To support this, we share relevant audit and workforce/access information with Imprivata, who provides and operates the PPM solution as a Data Processor on behalf of the Trust.

The procurement contract is with Phoenix Software Ltd (as reseller/partner). Phoenix Software Ltd does not access the data. The solution is hosted using cloud infrastructure and is intended to store and process data within the UK. Access to the PPM outputs is restricted to authorised Information Governance staff and relevant investigation managers and HR for case management.

Other circumstances where we may share information

There are circumstances where we must or can share information about you to comply with or manage:

  • disciplinary and investigation processes (including referrals to professional bodies such as NMC or GMC)
  • legislative and statutory requirements
  • court orders
  • NHS Counter Fraud requirements
  • requests from police and other law enforcement agencies for the prevention and detection of serious crime and/or fraud (where lawful)

Any disclosures are made on a case-by-case basis, using the minimum personal data necessary for the specific purpose, and with appropriate security controls in place. Where possible, we will anonymise or pseudonymise information to protect confidentiality.

Epic and NHS Care Identity

If you access Epic using NHS Care Identity credentials, identity access and management services are managed by NHS England. NHS England is the controller for the personal information you provided to obtain and use your national digital identity for authentication. For this information, our role is a processor only and we act under NHS England instructions when verifying your identity.

NHS Care Identity Service information: NHS Care Identity Service

International transfers

Where personal data is transferred internationally outside the UK, we ensure appropriate safeguards are in place before the transfer (for example contractual safeguards and risk assessments).

For PPM, Imprivata is based in the United States. During development and implementation, limited processing may take place outside the UK with appropriate safeguards. Once the system is implemented, processing is intended to take place within the UK.

How we maintain your records (security and retention)

Your personal information is held in both paper and electronic forms. We hold and process your information in accordance with the UK General Data Protection Regulation and the Data Protection Act 2018.

We have measures in place to keep your personal data confidential and secure, including access controls and audit logs, and we limit access to those with a legitimate need to know.

We retain staff records in line with the NHS Records Management Code of Practice and National Archives requirements. Retention periods vary depending on the type of record and the purpose for which it is held.

Retention relating to monitoring and investigations

Where monitoring and audit systems are used, retention may differ depending on whether information forms part of an investigation.

What are your rights?

The UK General Data Protection Regulation and the Data Protection Act 2018 give you certain rights in relation to your personal information. These rights apply in different ways depending on the lawful basis and purpose of processing.

In addition, everyone working for the NHS must comply with the Common Law Duty of Confidentiality and various national and professional standards and requirements. We have a duty to maintain full and accurate records of your employment, keep records confidential and secure, and provide information in an accessible format.

Your rights include:

  • Request access to the personal data we hold about you (for example staff/personnel records)
  • Request correction of inaccurate or incomplete information
  • Request deletion of information where there is no need to continue processing and a retention period has passed (where applicable)
  • Request restriction of processing in some circumstances
  • Request transfer of your information between systems where applicable
  • Object to processing in some circumstances
  • Challenge decisions made without human intervention (automated decision making) where applicable

You also have the opportunity to raise questions or concerns about new or proposed uses of your personal data as part of staff engagement activities prior to the implementation of new systems or processing arrangements.

Use of email

Some services within the Trust may offer the option to communicate via email. We will use appropriate secure methods where available. However, email is not always the most secure method of communication. If you choose to communicate with us by email, please consider what information you include.

How to exercise your rights

If you wish to exercise your rights, including making a subject access request for your staff records, please contact the Trust Information Governance team.

Further information is available at: Access your personal data

Data Protection Officer

The Trust’s Data Protection Officer can be contacted at: rduh.dpo@nhs.net

For further details, see: Fair collection / privacy notice page

Information Commissioner’s Office (ICO)

The Information Commissioner’s Office (ICO) is the UK regulator for data protection. If you are not satisfied with our response or believe we are processing your personal data unlawfully, you can complain to the ICO.

ICO website: www.ico.org.uk

Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

Telephone: 0303 123 1113

Email: casework@ico.org.uk

Other Privacy Notices

Separate privacy notices are also available for:

Information Requesters Privacy Notice covers the information we collect when you request a disclosure from us.

HR Investigations and Grievance Process Privacy Notice covers information relating to Human Resources (HR) Investigations and the Grievance Process for the Trust

Occupation Health Privacy Notice covers the information relating to occupational health.

Patient Privacy Notice covers the information we hold about our patients and other individuals that may use our services as a healthcare provider

Devon Electronic Patient Record (EPR) Privacy Notice covers information relating to the Devon Electronic Patient Record (EPR).

We reserve the right to update this privacy notice at any time. The latest version will be published on our website.