About this privacy notice
This Privacy Notice explains how Stockport NHS Foundation Trust collects, uses, stores and shares personal information. It applies to patients, carers, visitors, members of the public and other people who use or interact with our services. It should be read alongside any more specific privacy notices we publish for particular services, projects, research studies or staff information.
Stockport NHS Foundation Trust is the controller for the personal information it uses for most Trust services. This means we decide why and how information is used and shared. We are registered with the Information Commissioner’s Office under registration number Z5059033.
Our main contact details are: Information Governance Team, Stockport NHS Foundation Trust, Stepping Hill Hospital, Poplar Grove, Stockport, SK2 7JE. Email: [email protected]. The Trust’s Data Protection Officer can be contacted through the Information Governance Team.
At Stockport NHS Foundation Trust, staff must only access your health and care records when they have a clear work reason to do so, such as providing or supporting your care or carrying out an approved Trust activity.
Accessing records out of curiosity, for personal reasons, or without a valid reason is not allowed and may lead to action being taken.
We protect your information through secure systems, access controls, staff confidentiality training, and audit logs that record who has accessed records and when.
We may carry out checks to help identify access that does not look right. If you are worried that someone may have looked at your records without a valid reason, please see section ‘How do I complain’.
See NHS England: Stopping unlawful access to records guidance for patients and service users – NHS England Digital
When you use our services, we collect information about you so that we can provide safe and effective care, manage our services, meet our legal duties and support the wider NHS and care system. We only use information where the law allows us to do so. We follow the UK GDPR, Data Protection Act 2018, the common law duty of confidentiality, Caldicott Principles, NHS England information governance guidance and other laws and standards that apply to health and care.
We use information in two main ways: to provide your individual care, and to support planning, improvement and approved research. Wherever possible, information used for planning and research is anonymised so that you cannot be identified.
We collect information directly from you when you are referred to us, attend appointments, receive treatment, contact us, make a complaint, request information, give feedback or use our digital services. We may also receive information from other organisations involved in your care, such as your GP, another NHS provider, social care, local authority services, carers or family members where this is relevant and lawful.
We may use information to:
- provide, coordinate and review your care and treatment
- manage appointments, referrals, letters, reminders and other communications
- record care in clinical and administrative systems, including electronic patient records
- support patient safety, clinical audit, incident investigations, complaints, safeguarding and learning
- plan, monitor and improve health and care services
- support approved health and care research, usually using anonymised information wherever possible
- meet legal, regulatory, reporting, public health and public interest duties
- prevent and detect fraud or crime and protect public funds
We collect and use information needed to provide healthcare and manage our services. Some of this information can identify you. Health and care information is classed as special category data and is protected by additional safeguards.
- Personal details such as name, address, date of birth, NHS number and contact details
- Health and care information such as symptoms, diagnoses, test results, treatment, medicines, allergies, care plans and clinical correspondence
- Appointments and referrals such as attendance, waiting list information, clinic letters and discharge information
- Information from other organisations involved in your care, such as your GP, other NHS services, local authorities, social care providers, carers or family members where relevant
- Equality, accessibility and communication needs where provided, to help us meet your needs and monitor fairness
- Images, recordings and CCTV where these are part of care, service delivery, safety, security or approved operational processes
- Feedback and survey responses such as Friends and Family Test feedback, complaints, compliments or other patient experience information
- Information about legal, safeguarding, incidents or complaints matters where this is relevant to your care, safety, service management or our legal duties
We process personal information under the UK General Data Protection Regulation, the Data Protection Act 2018, the common law duty of confidentiality and other laws that apply to health and care services. For most NHS care and service management activities, our lawful basis is usually Article 6(1)(e) public task and/or Article 6(1)(c) legal obligation. Where we use special category health and care information, this is usually under Article 9(2)(h), because it is necessary for the provision or management of health or social care systems and services.
In some situation’s we may rely on another lawful basis, such as legal obligation, vital interests, public interest, research purposes or your consent. Where we rely on consent, we will explain what you are being asked to agree to and how you can withdraw consent.
We also have a legal duty to keep confidential health and care information private. We may use or share confidential information where this is needed for your direct care, where you have given consent, where we are required or allowed by law to do so, where there is support from an appropriate legal route such as the Confidentiality Advisory Group, or where there is an overriding public interest such as preventing serious harm or serious crime.
The Data Use and Access Act 2025 updates UK data protection and privacy law. It changes parts of the UK GDPR, the Data Protection Act 2018 and PECR, but does not replace them. The Act covers areas such as scientific research, subject access requests, complaints, automated decision-making, recognised legitimate interests, and rules on cookies and storage technologies. We will keep our privacy information, policies, contracts, data sharing arrangements, information asset records and information governance processes under review as new requirements and guidance are introduced.
When you use our services, confidential patient information is collected to provide your care. Information may also be used for research and planning to help improve services. Wherever possible, we use anonymised information that does not identify you.
Stockport NHS Foundation Trust applies the National Data Opt-Out where confidential patient information is used or shared for purposes beyond your individual care, such as planning or approved research, unless an exemption applies. Your choice will not affect your individual care. You can also make a choice for someone else in some circumstances, such as for a child under the age of 13 or where you have legal authority to act for someone else.
If you do not want your confidential patient information to be used for research and planning, you can opt out securely online at www.nhs.uk/your-nhs-data-matters or by calling 0300 303 5678. You can change your choice at any time, including through the NHS App where available.
In some situations, information must be used or shared regardless of an opt-out choice—for example where it is needed for direct care, where there is a court order or statutory duty/power, where you have given explicit consent, or where sharing without consent has been authorised through an appropriate legal route (for example the Confidentiality Advisory Group).
If you need advice about the National Data Opt-Out, you can contact the Information Governance team at [email protected].
Further information available: National Data Opt-Out – NHS England Digital https://digital.nhs.uk/services/national-data-opt-out
Health and care information may be used across the NHS and wider health and care system for direct care, planning, service improvement and approved research. Most of the time, information used for planning and research is anonymised or de-identified so that you cannot be identified. Where identifiable information is needed, it will only be used where the law allows and appropriate approvals, safeguards and transparency arrangements are in place.
Research bodies and organisations may include university researchers, NHS researchers, medical royal colleges, pharmaceutical companies researching new treatments and other organisations involved in approved health and care research. Research projects must follow research governance requirements. Where the Trust is involved as a research site or sponsor, we will provide or signpost to appropriate research privacy information, including Health Research Authority transparency wording where relevant.
We may share relevant information where there is a lawful basis, a care need or another legal reason to do so. We share information on a need-to-know basis and only the minimum necessary information should be shared.
- Other NHS organisations, including hospitals, GP practices, community services and ambulance services
- Health and care partners, including social care, local authority partners, care homes, hospices and voluntary sector partners where they are involved in care
- Integrated Care Boards, NHS England, the Department of Health and Social Care and other national bodies where required for statutory, planning, reporting, assurance or national data services
- Regulators, auditors and organisations responsible for quality, safety, public health, fraud prevention or crime prevention
- Police, courts, safeguarding agencies, public inquiries or other organisations where required or permitted by law
- Approved research organisations, where the appropriate legal, ethical and governance approvals are in place
- IT, communications and other suppliers who process information on our behalf under strict contractual and security requirements
We do not provide confidential patient information for marketing or insurance purposes. We do not sell patient data. Where external suppliers process information for us, they can only use it for the agreed purpose and must meet confidentiality, security and data protection requirements.
We aim to keep personal information within the UK and do not routinely transfer information outside the UK. If a supplier or system involves processing outside the UK, we will make sure appropriate safeguards are in place so that information is protected to an equivalent standard.
We use a range of methods to communicate with you and support your involvement in your care. These may include text messages, emails, automated telephone calls, digital letters, patient portals and online questionnaires. We may contact you to provide appointment information, send reminders, invite you to complete a health assessment or ask for feedback about your experience.
These services may be supported by approved suppliers acting on the Trust’s behalf. We share only the information needed to provide each service, and invitations or messages may come directly from these suppliers.
Appointment reminders, digital letters and patient portals
We may send appointment reminders by text message or automated telephone call to help reduce missed appointments. We may also send digital copies of appointment letters by text message. Messages may include a secure link and a unique PIN so that you can access your letter safely.
You may also be able to access appointment details and letters through our patient portal and, where available, through the NHS App. You do not have to use the NHS App to view your appointment letters. Your information will only be visible through the NHS App’s connection to the portal if you choose to connect it.
If you wish to opt out of outpatient appointment reminder services, please contact the Appointment Booking Centre on 0161 419 1010.
Online health questionnaires and assessments
We may invite you to complete an online health questionnaire as part of your care, including before an appointment, operation or procedure. Questionnaires collect information about your health, medical history, medicines and any support you may need.
Your healthcare team reviews your answers to assess your needs and plan your care, including whether you need further appointments or investigations. Your responses form part of your health record.
You may receive an invitation or reminder by text message or email, with a link to complete your questionnaire. If you need help completing it or cannot use an online service, please contact the team caring for you to discuss support or an alternative way to complete your assessment.
Feedback about your care
We may invite you to provide feedback about your care and treatment, including through the Friends and Family Test. This gives you an opportunity to comment on your experience and helps us understand what is working well and where services can improve.
We may submit combined Friends and Family Test results to NHS England as required. These results do not usually identify individual patients.
Providing feedback is voluntary. If you wish to opt out of Friends and Family Test feedback messages, please contact the Patient Advice and Liaison Service (PALS) on 0161 419 5678. This will not affect your care.
We protect personal information using appropriate technical and organisational measures. This includes role-based access controls, staff confidentiality obligations, mandatory training, policies and procedures, audit and monitoring, secure systems, secure methods for sharing information and investigation of incidents where needed. Staff must only access information where they have a legitimate reason to do so.
Our approach is informed by NHS England information governance guidance, the Data Security and Protection Toolkit, the Records Management Code of Practice, the Trust’s retention schedule and data protection law. Information governance covers data protection, confidentiality, information security, records management and transparency.
We store personal information securely in approved Trust systems, including clinical, administrative and corporate systems. This may include electronic records, paper records, secure network drives, approved cloud-based systems and systems provided by third-party suppliers acting on our behalf. Where third parties store or process information for us, they must meet strict contractual, confidentiality, security and data protection requirements.
We keep health records and other information only for as long as we need to. Retention periods are set in line with the NHS Records Management Code of Practice, which also applies to adult social care, and the Trust’s records management and retention arrangements. Different types of records are kept for different periods depending on the record type, legal requirements, clinical need, audit requirements and business purpose.
When the retention period has ended, we will take appropriate action in line with the Records Management Code of Practice and Trust procedures. This may include securely destroying or deleting the information, archiving it where there is a lawful reason to keep it, or anonymising it so that it can no longer identify you.
- Secure disposal: paper records are disposed of using approved confidential waste processes, such as secure shredding. Electronic records, files and devices are deleted, wiped or destroyed using approved secure methods.
- Archiving: some records may be archived where this is required by law, NHS guidance, historical value, public interest or Trust records management arrangements.
- Anonymisation: where information is no longer needed in identifiable form, it may be anonymised so that it can be used for purposes such as service planning, audit, statistics or learning without identifying you.
It is important that the information we hold about you is accurate and up to date. If you think information in your record is incorrect, you can ask us to review it. If we agree that information is inaccurate, we will correct it. If we do not agree, we will add a note to your record explaining that you disagree with the information.
To tell us about a possible inaccuracy, please contact the Information Governance team at [email protected].
Data protection law gives you rights over your personal information. These rights depend on the lawful basis we rely on for using your information and they are not absolute. Exemptions may apply, for example where we must keep information to meet legal duties, provide safe healthcare, protect others, or manage legal claims.
- Right to be informed – to understand how and why we use your personal information.
- Right of access – to ask us for copies of your personal information, also known as a Subject Access Request.
- Right to rectification – to ask us to correct personal information you think is inaccurate, or complete information you think is incomplete.
- Right to erasure – to ask us to delete your personal information in certain circumstances.
- Right to restrict processing – to ask us to limit or change how your personal information is used in certain circumstances.
- Right to object – to object to how your personal information is used in certain circumstances.
- Right to data portability – to ask that we transfer personal information you gave us to another organisation, or to you, in certain circumstances.
- Rights related to automated decision-making and profiling – to be told about, challenge and request human involvement in certain decisions made solely by automated means where these have legal or similarly significant effects.
You do not usually need to pay a charge to use your rights. We usually respond within one month once we have the information we need to identify you, understand your request and locate the relevant records. If a request is complex, or if you make several requests, the law allows extra time in some circumstances, and we will explain this to you.
To request a copy of your health records, contact the Subject Access Request Team at Stockport NHS Foundation Trust, please contact:
Subject Access Request Team
Stockport NHS Foundation Trust.
Stepping Hill Hospital,
Stockport,
SK2 7JE.
Tel: 0161 419 5425.
Email: [email protected].
To exercise your rights, ask a question, or raise a concern about how information has been handled, contact the Information Governance team at [email protected].
You can also raise your concern or compliant using the Trusts PALS and complaints process – see our page Patient Advice and Liaison Service (PALS) – Stockport NHS Foundation Trust
If you remain unhappy after contacting the Trust, you can raise a concern with the Information Commissioner’s Office:
Information Commissioner’s Office (ICO)
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
Telephone: 0303 123 1113
Website: www.ico.org.uk
Online complaint form: www.ico.org.uk/make-a-complaint
The ICO is the UK’s independent regulator for data protection and will usually expect you to have raised the matter with the Trust first.
If we rely on your consent for a specific use of information, you can withdraw that consent at any time. Withdrawing consent will not affect anything we have already done based on your consent, but it will affect what we do from that point onwards.
Stockport NHS Foundation Trust may use artificial intelligence (AI), automation and other digital tools to help us provide safe, effective and efficient services.
- support healthcare services and clinical administration
- help staff prepare notes, actions and summaries
- support service planning, audit and improvement
- analyse information and prepare reports
- help protect our systems from cyber security risks
- support approved research and quality improvement work
AI means computer systems that can carry out tasks which usually need human intelligence, such as recognising patterns, summarising text or supporting decisions. In health and care, AI can help staff work more efficiently, but it does not replace professional judgement.
How we check AI is safe to use
Before we introduce an AI tool, we check whether it is suitable, safe and lawful. This includes looking at how information will be used, protected and monitored.
- complete a Data Protection Impact Assessment where required
- review information governance, confidentiality and privacy risks
- check cyber security and system safety
- complete clinical safety review where this applies
- check supplier assurances, contracts and data processing arrangements
- approve use through the Trust’s information governance processes
We expect AI systems and suppliers to meet UK data protection law, Information Commissioner’s Office guidance, NHS England Digital information governance guidance and the NHS Data Security and Protection Toolkit requirements.
How we protect your information
If AI uses personal information, we will:
- use only the information needed for the agreed purpose
- use anonymised, pseudonymised or de-identified information where possible
- keep information only for as long as needed
- support your data protection rights
Human review and responsibility
AI is used to support staff, not to replace them.
Trust staff remain responsible for checking AI outputs, using their professional judgement and making sure decisions are appropriate. Clinical decisions about your care will remain with trained health and care professionals, in discussion with you where this applies.
Decisions about you
We will not use AI to make significant decisions about patients, service users or staff without appropriate human involvement and safeguards where these are required by law, national guidance or Trust policy.
Our staff receive training and must follow Trust policies on confidentiality, data protection, information security and safe use of digital tools.
This statement explains how we may use AI. It should be read alongside our main Privacy Notices. Using AI does not change our responsibilities under data protection law or your rights over your personal information.
Automated decision-making means making a decision about a person by computer or system without human involvement. Profiling means using personal information to analyse or predict things about a person, such as their needs, risks or preferences.
We do not routinely use personal information to make decisions about patients or service users solely by automated means where the decision would have a legal or similarly significant effect. If this changes, or if a specific service uses automated decision-making or profiling, we will explain what information is used, why it is relevant, how the decision is made, the likely impact, and what rights you have to ask for human review or challenge the decision.
If you remain unhappy after contacting the Trust, you can raise a concern with the Information Commissioner’s Office. The ICO is the UK’s independent regulator for data protection and will usually expect you to have raised the matter with the Trust first.
If your complaint is about Trust services more generally, such as care, treatment, communication or appointments, please use the Trust’s complaints process. ( see our Contacts page: Contact us – Stockport NHS Foundation Trust)
We also have a separate Children’s Privacy Notice, aimed at children and younger people and tailored to their understanding.