529 – High Court rules on data protection and confidentiality issues in health case

2024-03-28 12:41:20

 

Last month, Mr Justice Julian Knowles gave judgment in YSL v Surrey and Borders Partnership NHS Foundation Trust [2024] EWHC 391 (KB). The case raised a wide range of data protection and confidentiality issues.

YSL was a patient of the Defendant, which was the data controller. YSL claimed that certain records and personal data were unlawfully disclosed to third parties; that some were inaccurate, and that the Defendant’s records retention policy whereby records are kept for 20 years is unlawful because it is disproportionate. He sought erasure of his entire patient records. The Claimant’s case was brought amongst other things under the UK GDPR and the Data Protection Act 2018.

Lawful basis for processing

YSL’s main allegations concerned, amongst other things, letters sent by two specialist doctors to his GP and to his family and/or school were without a lawful basis. The judge held that the Defendant had processed it in accordance with the data protection principles. These required the Defendant to satisfy at least one condition in Schedule 2 to the Data Protection Act. The relevant conditions that had been satisfied were:

  • functions of a public nature exercised in the public interest – the provision of health care and mental health services by a hospital trust such as the Defendant was plainly such a function;
  • the Defendant had a legitimate interest in processing YSL’s special category personal data including by disclosing it to those it reasonably believed ought to have it.

In addition to processing in accordance with data protection principles, there also had to be a lawful basis for processing. Article 6 of UK GDPR provides that processing shall be lawful only if and to the extent that certain conditions apply. The judge referred to sub-paragraphs (d) and (e) of Article 6 which provide:

  • processing is necessary in order to protect the vital interests of the data subject or of another natural person;
  • processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller.

The judge rejected vital interests (d) as a lawful basis for processing, referring to guidance from the Information Commissioner’s Office that “vital interests” generally only applies to matters of life and death. However, the judge accepted that (e) provided a lawful basis for processing. In doing so, he considered that section 8 of the Data Protection Act was relevant. In particular, section 8(e) refers to the processing of personal data that is necessary for the exercise of a function conferred on a person by an enactment or rule of law. The judge held that the provision of health care was obviously such a function.

Special categories of personal data

Article 9 of UK GDPR prohibits the processing of data concerning health. However, the prohibition does not apply in circumstances set out in Article 9(2). These circumstances include:

“(h) processing is necessary for the purposes of preventative or occupational medicine…medical diagnosis, the provision of health or social care or treatment or the management of health or social systems…or pursuant to a contract with a health professional;

(i) processing was necessary for reasons of public interest in the area of public health…”

Article 9(3) of UK GDPR provides:

“Personal data…may be processed for the purposes referred to in point (h)…when those data are processed by or under the responsibility of a professional subject to the obligation of professional secrecy under domestic law or rules established by national competent bodies or by another person also subject to an obligation of secrecy…”.

The judge found that points (h) and (i) applied, and the condition of secrecy was satisfied because of the common law duty of confidentiality imposed on medical professionals in respect of patient records and also because of the obligations of confidentiality imposed on any of the Defendant’s employees, arising from their contractual obligations (whether express or implied).

Right to erasure of records

As data controller, the Defendant could not continue to process YSL’s personal data unless the Defendant demonstrated compelling legitimate grounds for the processing which overrode YSL’s interests, rights, and freedoms as the data subject. The judge referred to important exceptions to YSL’s right to erasure. Article 17(3) of UK GDPR provides an exception where the processing was necessary for compliance with a legal obligation which requires processing…or for the performance of a task carried out in the public interest. Having regard to YSL’s particular health issues, the judge held that it was necessary for the Defendant to retain his medical data which was primarily being processed (ie, retained) for his potential benefit.

Article 8 EHCR and breach of privacy/confidentiality

YSL also claimed there was a breach of his right under Article 8 of the European Convention on Human Rights to a private life, and for breach of common law privacy/confidentiality. The judge held that the retention of records was justified because it served the legitimate interests of ensuring the efficient running of hospital services and also protected the rights of patients. The judge’s view was reinforced by regulation 17 of the Health and Social Care Act 2008 (Regulated Activities) Regulations 2014, which imposes an obligation on those providing health care to maintain securely an accurate, complete and contemporaneous record in respect of each service user.

As to the policy of retaining data for 20 years, the judge concluded that this period did not render the otherwise lawful retention of YSL’s medical records disproportionate and so unlawful as to breach UK GDPR.

Leave a Comment

Scroll to Top