4. Deciding to share personal data
4.1 Personal data sharing is not an automatic assumption and there must be:
5. Benefits of Information Sharing Agreements
5.1 Information Sharing Agreements provide the following benefits:
6. Data Protection Impact Assessments (DPIA’s)
6.1 It is good practice to carry out a data protection impact assessment before
entering any data sharing arrangement. This will assist in identifying and reducing
the privacy risks. A DPIA enables the Trust to systematically and thoroughly analyse
how a particular project or system will affect the privacy of the individuals involved
and identify and mitigate risks at an early stage.
6.2 A DPIA should be considered as part of any information sharing agreement.
7. Process
7.1 All ISA’s should be drafted using the Trust’s standard Information Sharing
Agreement Template and approved by the DPO (Appendix 1). The DPO should be
consulted when it is believed an ISA is required.
7.2 You must ensure when entering into any regular information sharing
arrangements that an Information Sharing Agreement is in place and that it states a
clear and lawful legal basis to allow the sharing to take place and it is agreed by all
parties and approved by the DPO.
8. Policy Review
8.1 This policy will be reviewed by the DPO. In addition, changes to legislation,
codes of practice or commissioner advice may trigger interim reviews.
9. Links with other Policies
9.1 This Information Sharing policy is linked to the Trusts:
APPENDIX 1
Construction Youth Trust Data Sharing Agreement
2. Partners
2.1 This agreement is between the following partners:
4. Process
4.1 This agreement has been formulated to facilitate the exchange of information
between partners. It is, however incumbent on all partners to recognise that any
information shared must be justified on the merits of each case.
5. Types of information to be shared
5.1 The following are the types of data that may be proportionate, relevant and
necessary to share between partners for the purposes listed below.
Data use under this agreement
the subject matter:
the lawful basis for sharing data:
the type of personal data purpose of the processing
6. Constraints on the information to be shared
6.1 The information shared must not be disclosed to any third party, other than
those partners signed up to this agreement, without the written consent of the Data
Subject(s).
6.2 All partners signed up to this agreement must store the information securely
and delete when it is no longer required for the purpose for which it is provided.
6.3 The Specific Personal information shared may only be shared for the purpose
of this agreement. This information must not be shared with other parties not signed
up to this agreement without the express permission of the data subject.
6.4 ‘Personal Data’ means any information relating to an identified or identifiable
natural person (‘data subject’); an identifiable natural person is one who can be
identified, directly or indirectly, in particular by reference to an identifier such as a
name, an identification number, location data, an online identifier or to one or more
factors specific to the physical, physiological, genetic, mental, economic, cultural or
social identity of that natural person.
7. Roles and responsibilities under this agreement
INSERT EACH PARTNERS ROLES AND RESPONSIBILITIES
Each Partner maintains responsibility for Freedom of Information Requests and
Subject Access Requests.
8. Review, retention & disposal
8.1 Partners to this agreement undertake that personal data shared will only be
used for the specific purpose for which it is requested. The recipient of the information
is required to keep it securely stored and will dispose of it when it is no longer required.
Partners may request a copy of information security policies when sensitive personal
data is to be shared.
8.2 The recipient will not release the information to any third party without obtaining
the express written authority of the partner who provided the information.
9. Signatures
9.1 By signing this agreement, all signatories accept responsibility for its execution
and agree to ensure that staff are trained so that requests for information and the
process of sharing itself is sufficient to meet the purpose of this agreement.
9.2 Signatories must also ensure that they comply with all the relevant legislation.
Organisation:
Name:
Signature:
Organisation:
Name:
Signature: