Patient Privacy Notice

About this privacy notice

North Cheshire and Mersey NHS Foundation Trust is committed to protecting your privacy and making sure your personal information is used safely, fairly and lawfully.

This privacy notice explains:

  • what information we collect about you
  • how we use your information
  • who we may share your information with
  • how long we keep your information
  • your rights under data protection law
  • how to contact us about your information

View our Children's Privacy Notice.

Who we are

North Cheshire and Mersey NHS Foundation Trust is the data controller for the personal information described in this privacy notice. This means we are responsible for deciding how your information is collected, used, stored and protected.

Contact details

North Cheshire and Mersey NHS Foundation Trust
Executive Offices
Kendrick Wing
Warrington Hospital
Lovely Lane
Warrington
WA5 1QG

Data protection officer

The trust has appointed a data protection officer (DPO) who is responsible for monitoring compliance with data protection law and providing advice on data protection matters.

Email: ncm.dataprotection@nhs.net

If you have any questions about how we use your personal information, or if you want to exercise your information rights, please contact the data protection officer.

Information we collect

To provide healthcare services, we collect and keep records about you. These records may be held electronically, on paper or in other formats.

Information we collect may include:

  • your name, address and contact details
  • your date of birth and NHS number
  • next of kin and emergency contact details
  • information about your physical and mental health
  • clinical notes, diagnoses and treatment information
  • appointment and referral information
  • test results and imaging records
  • correspondence relating to your care
  • information needed to manage and improve NHS services

Our staff are trained to handle your information correctly and protect your privacy. We regularly monitor compliance with information governance standards and data protection law.

We do not collect your information for marketing purposes and we do not share it for marketing activities.

Where we get your information from

Information may come from:

  • you or someone acting on your behalf
  • GP practices
  • other NHS organisations
  • social care providers
  • local authorities
  • ambulance services
  • care homes and residential providers
  • family members or carers, where appropriate
  • national NHS systems and services
  • other organisations involved in your care and treatment

How we use your information

Information collected to provide your healthcare may also be used to:

  • make sure your care is safe and effective
  • assess your condition against recognised clinical standards
  • co-ordinate care between organisations involved in your support
  • monitor and improve the quality of services
  • prepare statistics and performance reports
  • support NHS planning and commissioning
  • support the education and training of healthcare professionals
  • support approved research
  • investigate complaints, incidents and claims
  • meet legal and regulatory requirements
  • protect the health and wellbeing of the wider population
  • prevent and detect fraud and other unlawful activity

Sometimes your care may be provided by a multidisciplinary team that includes staff from other health, social care, education or care organisations. Information may be shared where needed to provide safe and effective care.

Legal basis for processing

The trust processes personal information in line with UK data protection law.

Personal data

We process personal data under Article 6(1)(e) of the UK General Data Protection Regulation (UK GDPR). This allows us to process information when it is necessary for a task carried out in the public interest or under official authority.

Special category data

Health information is processed under Article 9(2)(h) of UK GDPR. This allows us to process information when it is necessary for healthcare, social care, medical diagnosis, treatment and the management of health and care services.

We may also process information where required by law, including for public health, safeguarding and regulatory purposes.

Who we share information with

Where appropriate and lawful, information may be shared with:

  • GP practices
  • NHS England
  • Integrated Care Boards (ICBs)
  • acute, community and mental health providers
  • ambulance services
  • local authorities
  • social care organisations
  • care homes
  • hospices and specialist providers
  • regulatory and inspection bodies
  • organisations providing services on behalf of the trust

We may also share information with organisations that provide services on behalf of the trust, such as IT suppliers. These organisations must meet strict contractual, confidentiality and security requirements.

Information is only shared when there is a lawful basis to do so and appropriate safeguards are in place.

Secure Data Environment (SDE)

Approved staff employed by the trust may access the Cheshire and Merseyside Secure Data Environment (SDE).

The SDE is a secure digital platform that supports approved analysis of health and care information for research, service planning and population health purposes.

Strong governance, security and confidentiality controls protect information held within the SDE.

Patients may have choices about how their information is used for some research and planning activities.

NHS Federated Data Platform (FDP)

North Cheshire and Mersey NHS Foundation Trust participates in the NHS Federated Data Platform (FDP), a national programme led by NHS England.

The FDP supports joined-up working across health and care services. It allows authorised NHS staff to bring together information already held in NHS systems to help plan, deliver and improve healthcare services.

Protecting your information

Using the FDP does not change how your information is protected.

All information used within the FDP remains subject to:

  • UK data protection legislation
  • NHS information governance requirements
  • national cyber security standards
  • strict access controls and security measures
  • local and national information security policies

The trust remains responsible for the personal information it uses.

Information made available through the FDP is only used for legitimate NHS purposes, including:

  • direct patient care
  • operational management
  • service planning
  • service improvement

Your information does not become the property of the platform supplier. 

Access is limited to authorised staff who need the information as part of their role.

The FDP provides a secure environment that connects existing NHS systems and helps staff deliver safe, effective and efficient healthcare.

Further information is available on the NHS England website: NHS Federated Data Platform.

Public interest and legal disclosures

There may be circumstances where information is shared in the public interest, including:

  • where a serious crime has been committed
  • where there is a risk to the public
  • to protect vulnerable children or adults
  • to safeguard staff or others from harm

We may also have a legal duty to share information, including for:

  • birth registrations
  • notification of certain infectious diseases
  • firearms injury reporting
  • court orders
  • approved medical research with the required legal approvals

National Data Opt-out

The NHS National Data Opt-out allows patients to choose whether their confidential patient information is used for research and planning purposes.

The National Data Opt-out does not usually apply when information is used for your care and treatment, or where there is a legal requirement to use or share information.

Find out more: Your NHS data matters.

How long we keep information

We keep personal information only for as long as necessary and in line with legal, regulatory, clinical and operational requirements.

The trust manages records in line with the NHS: Records Management Code of Practice for Health and Social Care.

This guidance sets minimum retention periods for NHS records. Different types of records are kept for different lengths of time depending on their purpose and legal requirements.

In some situations, records may need to be kept longer than normal NHS retention periods. This can happen if NHS England, the Department of Health and Social Care, public inquiries, legal proceedings, inquests or national investigations require records to be preserved as evidence.

Where this applies, records will be retained securely until formal notification is received that they can be destroyed.

When retention periods expire, records are reviewed and either securely destroyed or permanently preserved where required by law or for historical reasons.

Further information is available:

International transfers

The trust does not routinely transfer personal information outside the United Kingdom.

Where international transfers are required, appropriate legal and security safeguards will be in place to protect your information.

Your rights

Data protection law gives you rights over the personal information we hold about you.

These include:

  • the right to be informed about how your information is used
  • the right to access your information
  • the right to request correction of inaccurate information
  • the right to request restriction of processing in certain circumstances
  • the right to object to processing in certain circumstances
  • the right to request deletion of information where applicable
  • the right to data portability where applicable
  • the right to challenge decisions made solely by automated means

Not all rights apply in every situation and some are subject to legal exemptions. 

Accessing your records

You have the right to request access to information held about you.

For information on requesting copies of your personal information please visit our Data Protection and Accessing your medical records pages.

Complaints

If you are concerned about how your personal information has been used, please contact the trust's data protection officer first.

Email: ncm.dataprotection@nhs.net

You also have the right to complain to the Information Commissioner's Office (ICO).

Information Commissioner's Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF

Telephone: 0303 123 1113
Website: www.ico.org.uk

Review information

Last reviewed: 18 September 2026

Review frequency: Every 3 years, or sooner if there are significant changes to legislation, services or information processing activities.