Data Sharing Audits
We carry out independent audits and where necessary post audit reviews to check that our customers are meeting the obligations in their Data Sharing Framework Contracts and Data Sharing Agreements. This helps to ensure that organisations abide by the terms and conditions set by NHS Digital and data is kept safe and secure.
Why data sharing audits are important
The audit team carries out data sharing audits to check that organisations meet the obligations in their contract and agreement. The team also confirm that organisations adhere to their own policies and procedures relating to data sharing and security.
Audits help assure us, and the public, that organisations are handling the data securely and are using it for the purposes for which it was provided. Audits also help organisations to improve and achieve good practice in how they operate.
Final audit reports are published here to aid transparency.
How audits are conducted
For further information on the audit process, please refer to our current Audit Guide.
How findings are classified
An audit report identifies findings where an organisation has not met specific elements of its contract or agreement, or where the audit team believes improvements can be made.
Each finding is given one of the following classifications:
Just because an agreement nonconformity is identified (an organisation is not complying with the contract or agreement), it does not mean there has been a breach of data protection law or that privacy or security of any data has been put at risk.
An overall risk score is also calculated, based on the findings, their classification and the type of data being shared. A report is then produced and provided to the organisation, these are also published on our website.
How audits are followed up
When findings are identified, the audit team works with the organisation to produce an action plan to show how the organisation will address the findings. Post audit reviews are then carried out to ensure the findings have been addressed satisfactorily. Each final post audit report is published here.
The data we collect and provide access to is only used to benefit health and social care in a legal, ethical and transparent manner. Where serious findings are identified, NHS Digital works with the organisation to rectify the problem and ensure that patient data is protected while also ensuring that the organisation can continue its work to achieve the benefits for health and care services.
NHS Digital takes its responsibility to safeguard data very seriously and where necessary can suspend access to data, but it is important that any action taken is proportionate.
Therefore any potential penalties, such as removal of access to data, are balanced with safeguarding against a potential negative impact to patient care. For example, if a CCG has to return all the data it holds, it would be unable to commission vital services for patients. Equally, ceasing access to data for a clinical trial would mean that the potential benefits of that trial for patient care and treatment would not be achieved since it could not be concluded.
However, if there is a significant breach of the data sharing agreement then NHS Digital may require that the data provided is destroyed. If appropriate, in relation to personal data breaches, we may report the organisation to the Information Commissioner’s Office (ICO).
Audits archive pre-2021
See our archive of independent audits and post audit reviews from January 2015 to December 2020.
Audit Guides
All our audits are conducted in line with the latest version of our audit guide. We update the guide periodically.
This table shows which version of the audit guide we followed when conducting previous data sharing audits.
Time period | Version |
---|---|
October 2016 to December 2017 | Audit guide version 1 |
January 2018 to 26 July 2019 | Audit guide version 2 |
29 July 2019 to March 2020 | Audit guide version 3 |
November 2020 to 9 June 2023 | Remote audit guide |
19 June 2023 to present | Audit guide version 4 |
To assist the data recipient with the audit process NHS Digital has also produced an Action Plan template.
Last edited: 25 March 2025 11:09 am