Leicestershire Health Informatics Service (LHIS) is a hosted organisation of Leicestershire Partnership NHS Trust (LPT). We are committed to protecting personal data and handling information lawfully, securely, and transparently.
LHIS complies with:
- UK General Data Protection Regulation (UK GDPR)
- Data Protection Act 2018
- Privacy and Electronic Communications Regulations (where applicable)
Our Role
When delivering services:
- Our Customers act as the Data Controller.
- LHIS acts as the Data Processor, processing personal data on the Customer’s behalf and only in line with their documented instructions and applicable law.
In limited circumstances, LHIS or Leicestershire Partnership NHS Trust may act as a Controller where required by law.
How We Protect Data
We:
- Apply appropriate technical and organisational security measures
- Restrict access to authorised and trained personnel
- Require confidentiality commitments from staff
- Ensure any approved sub-processors meet equivalent data protection standards
Data Subject Rights
We support our Customers in meeting their obligations under UK GDPR, including responding to subject access requests and other individual rights.
Personal Data Breaches
If a personal data breach occurs, we notify the relevant Customer without undue delay and provide appropriate support.
International Transfers
We do not transfer personal data outside the UK without appropriate safeguards and required authorisation.
Registration Authority Services
Where we provide NHS Registration Authority services, we process identity information solely to verify staff before issuing NHS Smartcards. Information is uploaded to the Care Identity Service for audit purposes and is not retained longer than necessary.
For further information about how LHIS processes personal data, please contact Leicestershire Health Informatics Service, hosted by Leicestershire Partnership NHS Trust.
