Controlled document information
Version number: v2.0
First published: July 2024
Date updated: July 2026
Next review date: July 2027
Policy prepared by: Board, Governance and Records Manager
Policy approved by: Senior Operational Team
Classification: OFFICIAL
Policy Number: HSSIB034
| Date | Author | Version | Page | Update |
|---|---|---|---|---|
| July 2024 | Board, Governance and Records Manager | v1.0 | Whole document |
First published as Information Governance and Data Compliance Strategy – now a first draft combined with draft Data Protection Policy. |
| July 2024 | Board, Governance and Records Manager | v1.1/v1.2 | See update section |
Draft Data Protection Policy added into the wording as discussed in SLT 16th May 2024. Paragraph 5 amended to refer to Section 7 rather than Section 6, Appendix A wording tweaked from ‘it is worth remembering’ to ‘It is important to note’ (as per comments from the NEDs). |
| Feb 2026 | Board, Governance and Records Manager | v1.3 | Whole document | Templar Update |
| Feb 2026 | Board, Governance and Records Manager | V1.4 | Whole document | Comments from Sarah Graham, Board, Governance and Records Manager |
| March 2026 | Board, Governance and Records Manager | V1.5 | Whole document |
Review by Templar, final comments from BGRM, comments from Finance and Resources Director. |
| June 2026 | Board, Governance and Records Manager | V1.6 | Whole document | Version presented to SOT for approval. |
| July 2026 | Board, Governance and Records Manager | V2.0 | Whole document |
Second final version approved by SOT in July 2026. NB: SOT noted that the policy should be reviewed in a year's time (rather than the normal two-year cycle) once the IMS has been implemented. |
1. Purpose
1.1 This Information Governance Policy provides the over-arching framework within which all information governance issues shall be conducted and managed.
1.2 The purpose of this Information Governance Policy is to protect all information assets to a consistently high standard and to define a clear set of accountabilities in ensuring that protection.
1.3 By promoting a culture of good practice around the processing of information at all levels, this policy aims to ensure that all information held by HSSIB is:
- Held securely and confidentially.
- Processed fairly and lawfully.
- Obtained for a specific purpose(s).
- Recorded accurately and reliably.
- Used effectively and ethically.
- Shared and disclosed appropriately and lawfully.
- Protected against unauthorised access.
2. Scope
2.1 This policy applies to all information obtained and processed within HSSIB, held electronically, in manual paper-based filing systems, and in other formats, relating (but not limited to):
- Patient information.
- Employee and personal information.
- Organisational, business, and operational information.
- Audit and reporting information.
- Commercial and contract details.
3. Applicability
3.1 This policy applies to all those working for HSSIB in whatever capacity, including employees, seconded staff, students, temporary workers, contractors, suppliers, Third Parties, and the HSSIB Board (hereafter referred to as ‘staff’). It also applies to Third Party providers who may hold or process information belonging to HSSIB.
4. Terminology
4.1 Information Governance: the structures, policies and practices used to ensure the confidentiality, integrity, availability, and security of the HSSIB’s information.
4.2 Confidentiality: ensuring that information is not made available or disclosed to unauthorised individuals or systems.
4.3 Integrity: ensuring that information should be accurate and complete and that only authorised individuals can alter, update and delete information.
4.4 Availability: information is accessible and usable upon demand by an authorised entity. Availability is in tension with the security of information - information needs to be made available for a business to function successfully and productively whilst also ensuring that only those who require it have access.
4.5 Information Asset: any form of information that has value to HSSIB and supports business outcomes.
5. Policy
5.1 This policy is supported by a set of information governance policies and related procedures which cover all aspects of information management at HSSIB. These policies are available on the HSSIB SharePoint area.
Legal and Regulatory Framework
5.2 There are a number of legal and regulatory obligations placed upon HSSIB for the security of personal and confidential information, these include:
- The Common Duty Law of Confidentiality
- The Public Records Act 1958
- The Access to Health Records Act 1990
- The Human Rights Act 1998
- The Freedom of Information Act 2000
- Regulation of Investigatory Powers Act 2000
- The Inquiries Act 2005
- The Data Protection Act 2018
- NHS England Records Management Code of Practice 2021 (updated Dec 2023)
- NHS Information Governance: Guidance on Legal and Professional Obligations
- UK General Data Protection Regulation 2021 (GDPR)
- Health and Care Act 2022
- The National Cyber Strategy 2022
- The Government Cyber Security Strategy 2022 – 2030
- The Online Safety Act 2023
- The Procurement Act 2023
- The Data Use and Access Act (2025)
- The Cyber Security and Resilience Bill (forthcoming)
Governance Framework at HSSIB
The HSSIB Board and the Senior Leadership Team (SLT) receive assurance that information governance is working effectively via various mechanisms:
- reporting to the SIRO / Deputy SIRO monthly
- reporting to the Board and Audit and Assurance Committee on a quarterly basis.
- reporting to the Senior Leadership Team monthly.
- management of the Strategic Risk Register (specifically strategic risk SR007)
Data Protection and Security Toolkit (DSPT)
As an NHS ALB, we also have a commitment to maintaining compliance with the Data Security and Protection Toolkit (DSPT) or Cyber Assessment Framework (CAF) as it is now known. HSSIB submit this on an annual basis.
Information Assets and Records Management
HSSIB maintains an Information Asset Register, and this is a tool for the ongoing management of HSSIB’s key information assets. The register is refreshed on an annual basis and Information Asset Owners are trained / updated every year on this important area.
Cyber Security
Governance of Cyber Security is a key aspect of information governance. Our Senior Information Risk Owner (SIRO) is the Finance and Resources Director, who also holds the portfolio for information governance at HSSIB. Information security management is vested in the Governance Team, and an incident register is kept, detailing any information incidents and the mitigations put in place against them.
Roles and Responsibilities
The Chief Executive Officer
5.3 Overall accountability for information governance lies with the Chief Executive Officer (CEO) as the Accountable Officer.
The CEO shall:
- Establish and maintain an effective document management system and the governance of information.
- Meet all statutory requirements.
- Adhere to guidance issues in respect of IG and procedural documents.
The Board
5.4 The responsibility for information governance, including data security and protection, rests with the Board.
HSSIB’s Board shall therefore ensure that:
- Information Governance is explicitly referenced within HSSIB’s Statement of Internal Controls.
- There is always one person with overall responsibility for the protection of personal data (the Caldicott Guardian).
- The Annual Report of HSSIB includes a Statement on information governance and Cyber Security.
- Contractual arrangements with Third Party Suppliers contain strengthened information governance requirements.
- Adequate training and support are provided to the individuals fulfilling the operational information governance roles and tasks set out in this policy.
- Clear lines of reporting and supervision are established for compliance with personal data protection.
- Regular checks are undertaken to monitor and assess the processing of personal data.
5.5 The Board is also responsible for setting the HSSIB’s Information Risk Appetite regarding information governance.
The Senior Information Risk Owner (SIRO)
5.6 HSSIB should appoint an Executive member of the Board as the Senior Information Risk Owner (SIRO). This position is currently held by the Finance and Resources Director. The Deputy SIRO role is held by the Deputy Director of Investigations.
5.7 The SIRO is accountable for information risk within HSSIB and advises the Board on the effectiveness of Information Risk Management across HSSIB, including the logging and monitoring of key information risks on the Strategic Risk Register.
The SIRO shall:
- Take overall risk ownership of HSSIB’s risk management and function as champion for Information Risk on the Board.
- Implement and lead risk management processes within HSSIB.
- Advise the Board on the effectiveness of information risk management across HSSIB.
- Understand how the strategic goals of HSSIB may be impacted by information risks, and how those risks may be managed.
- Through the Letter of Delegation, be accountable for the management and protection of all HSSIB’s information assets.
- Take overall ownership of information risk policies, and wider Risk Management Manual, and the other Information Governance Policies.
- Provide a focal point for managing information risks and incidents.
- Lead on Business Continuity in the context of information risk.
- Lead and foster a culture for protecting and using information and data.
- Sign off and take accountability for risk-based decisions and reviews in regards to the processing of personal data.
- Lead communications on information governance and security throughout HSSIB.
- Approve and appoint Information Asset Owners (IAOs)
- Receive training as necessary to ensure they remain effective in their role as SIRO.
The Caldicott Guardian
5.8 The Director of Investigations is the Caldicott Guardian for HSSIB. In the absence of our Director of Investigations, the CEO will deputise for this role.
The Caldicott Guardian shall:
- Ensure that HSSIB satisfies the highest practical standards for handling patient identifiable information.
- Facilitate and enable appropriate information sharing and make decisions on behalf of HSSIB following advice on options for lawful and ethical processing of information, in relation to disclosures.
- Represent and champion information governance requirements and issues at Board level.
- Ensure that confidentiality issues are appropriately reflected in organisational strategies, policies and working procedures for staff.
- Contribute to the arrangements, protocols, and procedures where confidential patient information may be shared with external bodies both within and outside the NHS.
- The Caldicott Guardian is required to be registered on the publicly available National Caldicott Guardian Register.
The Data Protection Officer
5.9 The Data Protection Officer (DPO) is responsible for ensuring that HSSIB and its constituent business areas remain compliant at all times with data protection, Privacy & Electronic Communications Regulations, Environmental Information Regulations, and associated legislation.
5.10 The Board, Governance and Records Manager is the Data Protection Officer (DPO) for HSSIB. In the absence of our BGRM, the Operations Manager will deputise for this role. The DPO reports to the SIRO but also can act independently of the SIRO and reports directly to the Board about data protection matters. These may include information governance risks to the organisation, privacy concerns or recommendations regarding data.
The DPO shall:
- Provide advice to HSSIB and its employees on compliance with obligations with data protection laws.
- Advise on when Data Protection Impact Assessments (DPIAs) are required.
- Monitor compliance and organisational policies in relation to data protection law. This includes the DPO ensuring that HSSIB staff receive data protection training as well as providing support to manage internal data protection activities e.g. internal audits.
- Co-operate with and be the first point of contact for the Information Commissioner’s Office.
- Be the first point of contact within HSSIB for all data protection matters. The DPO is not pressurised by HSSIB as to how to perform their tasks and is protected from disciplinary action when carrying out those tasks.
- Be available to be contacted directly by data subjects.
- Consider information risk when performing the above.
Information Asset Owners (IAOs)
5.11 IAOs are senior/responsible individuals who are the nominated owners of one or more identified information assets.
The role of the IAO is to:
- Lead and foster a culture that values, protects, and uses information for the benefit of patients and public.
- Know what information comprises or is associated with their asset(s) and understand the nature and justification of information flows to and from the asset.
- Know who has access to the asset, whether system or information, and why, and ensure access is monitored and compliant with policy.
- Understand and address risks to the asset and provide assurance to the SIRO.
- Ensure there is a legal basis for processing and for any disclosures, refer queries to the above to the Board, Governance and Records Manager on ig@hssib.org.uk
- Ensure all their information assets and Business Critical Information Assets are recorded on the Information Asset Register and protected according to their controls.
- Undertake specialist Information Asset Owner training as required.
5.12 These responsibilities shall be conferred in a Letter of Delegation from the SIRO who retains ultimate accountability for information handling across HSSIB.
Board, Governance and Records Manager
5.13 HSSIB have appointed an Information Governance Lead, the Board, Governance and Records Manager, to support the SIRO in ensuring the day-to-day operational effectiveness of the information governance policies including their management, accountability, compliance and assurance.
The Board, Governance and Records Manager shall:
- Provide expert advice and guidance to all staff on all aspects of information governance.
- Consult with and provide guidance to IAOs in the fulfilment of their information governance and Cyber Assessment Framework (CAF) duties, as directed by the SIRO.
- Manage the delivery of improvement plans to meet the DSPT assertions.
- Formulate, establish and promote this Information Governance Policy
- Review and audit all procedures relating to this policy where appropriate on an ad-hoc basis.
- Develop internal IG and records management (RM) policies and procedures.
- Investigate all information governance breaches, actual and suspected.
- Ensure that the approach to information handling is communicated to all staff and made available to the public regarding the safe sharing of personal confidential data.
- Develop information governance awareness and training programmes for all staff.
- Ensure compliance with information governance, information security, and other information related legislation.
- Ensure that line managers are aware of the requirements of this policy.
- Work with the Caldicott Guardian, SIRO and DPO functions to ensure organisational authority and awareness regarding issues relating to Data Protection, information governance, information risk or confidentiality concerns.
Line Managers
Line Managers shall:
- Implement good information governance and information security practice into normal day-to-day activity.
- Adhere to information governance and information security related policies and procedures.
- Ensure, with their IAO, that breaches and near misses relating to HSSIB’s information, data and/or systems are reported in accordance with the Information Incident Management Policy.
- Ensure that they, their reports and teams attend the required training regarding information security, handling and governance.
Staff
5.14 All members of staff and anyone working on behalf of HSSIB involved in the receipt, handling or sharing of information, including personally identifiable information, shall adhere to this policy to support the reputation of HSSIB and, where relevant, of their profession.
All Staff shall:
- Read HSSIB’s Acceptable Use Policy. Access to ICT systems shall not be granted until this has occurred.
- Adhere to this policy and all the associated Information Governance policies and procedures.
- Report information security incidents, as set out in the Information Incident Management Policy.
- Undertake the required information governance and security training for their role.
- Rescind access to information and any related equipment on completion of their role.
Third Parties
5.15 Risks to HSSIB’s information and information processing facilities shall be identified and managed prior to granting Third Party access.
5.16 All contracts shall contain appropriate information governance, Cyber Security and confidentiality clauses. This shall include a requirement to provide assurance to HSSIB regarding the secure handling of information held or processed on its behalf. Details are set out in the Third Party and Suppliers Policy.
Training
5.17 All staff must undertake the annual mandatory e-learning training on Information Governance, available on ESR.
5.18 New staff members will receive information governance training as part of their induction process.
6. Monitoring and Compliance
6.1 This policy will be reviewed every two years, or in response to significant changes due to security incidents, variations of law and/or changes to organisational infrastructure.
6.2 HSSIB policies apply to all forms of communication whether verbal, printed or online.
6.3 Non-compliance with policies may lead to disciplinary action in accordance with the HSSIB disciplinary procedure.
6.4 This policy is written and maintained by Board, Governance and Records Manager and approved by the SIRO and the SOT on behalf of the Board. Questions relating to its content or application should be addressed to the Information Governance team on ig@hssib.org.uk.
6.5 Every staff member at HSSIB undertakes the information governance mandatory training available in the ESR. This is done on an annual basis.
6.6 Every year information governance effectiveness at HSSIB is measured via the submission of the DSPT.
6.7 Every year a records management audit of the case management system is undertaken, and feedback / reporting is provided at the Senior Operational Team meeting.
6.8 Incident reporting is provided monthly to the Senior Leadership Team, and the SIRO meeting.
6.9 Governance and risk reporting is provided to the Board and the Audit and Risk Assurance Committee on a quarterly basis.
- Acceptable Use Policy
- Information Risk Management Policy (in the Risk Management Manual)
- Information Incident Management Policy
- Third Party and Suppliers Policy (coming soon)