Scottish Vaccinations Privacy Notices
The way that vaccinations are delivered in Scotland changed in 2022. Responsibility for vaccine delivery moved from GPs to Territorial Health Boards in order to tailor them to meet the needs of local populations. Responsibility for all immunisation programmes and ad hoc vaccines will be fully transferred to Health Boards.
Your personal data is being used by NHS Education Scotland (NES) as the Data Controller responsible for the National Clinical Data Store (NCDS). NCDS is updated with information and events (such as your previous vaccinations or clinical treatments) from healthcare records maintained by GPs, specialist treatment centres and the Vaccination Management Tool (VMT) within NHS Scotland. You will find our contact details, together with those for our Data Protection officer (DPO) at the foot of this notice.
The purpose of processing is to support the delivery of vaccinations across Scotland.
Your personal data will be shared with the following organisations listed below in order to deliver vaccines across Scotland. National Services Scotland (NSS) is responsible for collecting a restricted subset of your NCDS patient record and making this available in a secure format to your local Health Board. Each local Health Board will use this data to make decisions about inviting you for vaccinations.
The set of personal data used contains information about your:
Lawful reasons for processing areas follows:
Sometimes, emergency legislation will be introduced to manage a pandemic, epidemic or other public health emergency, for example, Coronavirus (COVID-19) legislation - gov.scot (www.gov.scot) and Coronavirus Legislation. Where legislation is introduced to manage a public health emergency, your information may also be processed under:
After the data is requested by NSS from the National Clinical Data Store (NCDS) it is updated every 24 hours to ensure accuracy. This regular refresh of data is repeated daily for the duration of the vaccination programme, which is itself subject to review every 18 months. The data in the NCDS is retained in accordance with the Scottish Government Records Management Health and Social Care Scotland Code of Practice (Scotland) 2020 and in line with retention for GP records. This decision is based on the need to ensure that GPs and other clinicians have access to vaccination records over an extended period of time to ensure clinical safety.
Your personal data will remain in the UK at all times.
You have rights regarding how we process your personal data (for details about your rights and how to invoke them, see our privacy page at https://www.nes.scot.nhs.uk/legal-and-site-information/privacy/:
You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO) as the regulator in the UK. ICO address: Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF. Or visit ICO.org.uk
NES Address: NHS Education for Scotland, Westport 102, West Port, Edinburgh, EH3 9DN.
NES DPO contact email: foidp@nes.scot.nhs.uk(postal address as above for NES).