Your information and how we use it

City Hospitals Sunderland is a registered Data Controller: Information Commissioner Office (ICO) registration number Z7637350.

This Privacy Notice explains how we use and share your information.We will continually review and update this Privacy Notice to reflect changes in our services and feedback from service users, as well as to comply with changes in the law.

Click to view an Easy Read Version of our Privacy Notice

Why do we hold information about you?

As a provider of healthcare services, we are legally required to hold information relating to the care we provide to you under the National Health Service Act 2006.

What information do you hold about me?

The information held about you will include:

  • Basic details about you, such as your name, date of birth, NHS Number
  • Contact details such as your address, telephone numbers, email address
  • Contact details of your ‘Next of Kin’, a close relative, friend or advocate
  • Contacts we have had with you; scheduled and unscheduled appointments
  • Details about your care; treatment and advice given and referrals made
  • Results of investigations, eg blood tests
  • Relevant information from people who care for you and know you well

How do you store my information?

Your information will be stored by the Trust in the form of either:

  • Paper based healthcare records, such as a medical file
  • Core electronic healthcare systems, such as the Trusts core Patient Care System or EMIS Community Healthcare System
  • Additional electronic based healthcare systems, such as the Radiology and Pathology systems
  • In other electronic formats

How long will you keep my information?

NHS Trusts are required to keep your information for the periods of time set out in the ‘Records Management Code of Practice for Health and Social Care 2016’. This code of practice requires the Trust to keep your information for the following lengths of time:

  • Adult healthcare records – for 8 years after your last contact with the service
  • Maternity records – for 25 years after your last contact with the service
  • Children’s healthcare records (including midwifery, health visiting, and school nursing - until the child reaches the age of 25 or 26 if they were 17 when treatment was concluded
  • Mental healthcare records – for 20 years after your last contact with the service or 8 years after you have died

Some information may be kept for longer than the above periods. Further information on the retention periods for healthcare records can be found in the Government's Records management code of practice for health and social care.

Who will you share my information with?

Your information will be shared internally between teams, i.e. shared with the Safeguarding Team if necessary and also externally, i.e. Police, Social Services, Education, your GP, etc. This is to ensure that adult and children’s safeguarding matters are managed appropriately. Access to identifiable information will be shared in some limited circumstances where it’s legally required for the safety of individuals concerned.

Your information will be shared, for the purposes of providing direct care, with other NHS and Non-NHS Provider organisations. These will include organisations such as other Acute Hospitals, Mental Health Hospitals, Community Healthcare providers, General Practitioners and Ambulance Services. For Safety reasons the information shared will always identify you however the Trust will endeavour to always ensure that you or your Next of Kin are aware of the information being shared and why.

Your confidential healthcare Information will only be shared where there is a legal basis for doing so.

  • When there is a Court Order
  • Where there is a legal requirement to provide the information
  • Where you have given explicit consent to share the information
  • Where information is being shared for a direct care purpose and you have been informed of the sharing
  • Where permission to share your information without consent has been authorised by the Confidentiality Advisory Group of the Health Research Authority (HRA CAG) under Section 251 of the 2006 NHS Act.

If you want to know who we have shared your information with you will need to make a Subject Access Request (SAR).

We will also share your anonymized information for the purposes of commissioning and managing healthcare; patient information may also be shared with other types of NHS organisations, such as the local Clinical Commissioning Group (CCG), and the Health & Social Care Information Centre (part of NHS England).

Sometimes we will also share your information in an anonymous format with organisations, such as universities, community safety units and research institutions. If your information is anonymous it means you cannot be identified.

In such cases, the shared data is made anonymous, wherever possible, by removing all patient-identifying details, unless the law requires the patient's identity to be included. In these circumstances we do not need your permission to share your anonymous information.

At any time you have the right to refuse/withdraw consent (opt out), in full or in part, to information sharing. The possible consequences and risks (ie, lack of joined up care, delay in treatment if information has to be sourced from elsewhere, medication complications; all leading to the possibility of difficulties in providing the best level of care) will be fully explained to you to allow you to make an informed decision.

If you do not want your personal information to be shared and used for purposes other than your care and treatment, then you should discuss your objections with the healthcare professional who is providing your care. This will not affect the care and treatment you receive.

Your records and research

We are a research active NHS Trust and there is the possibility that your records may be looked at by a Clinical Studies Officer at some point, who is not involved in your direct care. This is so that we can see if you are eligible to be invited to participate in approved research projects being run in the Trust that may be relevant to you.

Person-identifiable information may be used for essential NHS purposes, such as monitoring, research and auditing. This will only be done with your consent, unless the law requires information to be passed on to improve public health. The Information Commissioners Anonymisation Code of Practice will be used and further guidance is available in this Code of Practice.

How the NHS and care services use your information

City Hospitals Sunderland NHS Foundation Trust is one of many organisations working in the health and care system to improve care for patients and the public.

Whenever you use a health or care service, such as attending Accident & Emergency or using Community Care services, important information about you is collected to help ensure you get the best possible care and treatment.

The information collected about you when you use these services can also be provided to other approved organisations, where there is a legal basis, to help with planning services, improving care provided, research into developing new treatments and preventing illness. All of these help to provide better health and care for you, your family and future generations. Confidential personal information about your health and care is only used in this way where allowed by law and would never be used for insurance or marketing purposes without your explicit consent.

You have a choice about whether you want your confidential patient information to be used in this way.

How can I access my information?

How can I access my information?

You can request access to the information that the Trust holds about you free of charge and you should do this by approaching a member of staff in the first instance. They will provide you with guidance on the Trust’s processes. Your request, once agreed with you, will be completed within 30 calendar days. However, if your records are extensive we may take longer to process your request but will inform you from the outset.

To submit a formal request, please contact:

Enquiries Office
Medical Records Department
Sunderland Royal Hospital
Kayll Road

Phone: 0191 565 6256 Ext. 41151
Or email:


To obtain copies of X-rays please contact the Radiology Medicolegal Office on 0191 5699652.

Information that you are entitled to:

As well as receiving a copy of the information that the Trust holds and processes, you are also entitled to the following:
  • To be told whether any personal data is being processed
  • Given a description of the personal data, the reasons it is being processed, and whether it will be given to any other organisations or people
  • Given a copy of the personal data together with its source (where this is available)

Applications for accessing medical records/radiology information

Access to radiology imaging application form

Access to medical records application form

Access to deceased records application form

How do you make sure it is safe and secure?

We will use your information in a way that follows data protection laws and Trust policies and procedures.

Everyone working for the NHS is subject to the Common Law Duty of Confidence. Information provided in confidence will only be used for the purposes advised and consented to, unless it is required or permitted by the law.

All Trust staff are required to undertake mandatory Information Governance training, which covers how personal information should be processed.

We do not transfer personal information to a country outside of the European Union (EU) and this is checked on a yearly basis. If it is found that we intend to share information outside of the EU, appropriate and suitable safeguards will be put in place, which you will be told about.

How do you protect my privacy/confidentiality?

We protect your information by following data protection laws:

  • General Data Protection Regulation (GDPR) 2016
  • Data Protection Act (DPA) 2018

The GDPR 2016 and DPA 2018 are the laws that primarily determine how we can use your personal data. However, there are other laws that are followed if we need to process your information:

  • The Human Rights Act 1998
  • Freedom of Information Act 2000
  • Computer Misuse Act 1998
  • Audit Commission Act 1998
  • Regulation of Investigatory Powers Act 2016

What rights do I have?

You have a number of rights in relation to the information we hold about you. Further information is contained in the leaflet Data Protection Individual Rights as not all of these rights will apply to the information we hold about you.

These are:

  1. The right to be informed
  2. The right of access
  3. The right of rectification
  4. The right to erasure
  5. The right to restrict processing
  6. The right to data portability
  7. The right to object
  8. Rights in relation to automated decision making

Further information

Data Protection Officer

The Trust’s Data Protection Officer (DPO) is responsible for ensuring that the Trust complies with the GDPR. The DPO is the person to contact if you would like to know more about how we use your information, require information in any accessible format or language or if (for any reason) you do not wish to have your information used in any of the ways described. Their contact details are:

James Carroll
Data Protection Officer
Sunderland Royal Hospital
Kayall Road


Or email:

Caldicott Guardian

The Caldicott Guardian is the person who makes the final decision on how, what, when and why personal information will be processed in/by the Trust.

City Hospitals Sunderland NHS Foundation Trust Caldicott Guardian is Dr Ian Martin, Medical Director.

For independent advice about data protection, privacy and information-sharing issues you can contact the Information Commissioner's Office:

The Information Commissioner's Office
Wycliffe House
Water Lane

Phone: 08456 30 60 60 or 01625 545745

Sunderland Royal Hospital

Kayll Road, Sunderland, Tyne & Wear, SR4 7TP

Tel: 0191 565 6256

View on a map | Parking and directions

Sunderland Eye Infirmary

Queen Alexandra Road, Sunderland, Tyne & Wear, SR2 9HP

Tel: 0191 565 6256

View on a map | Parking and direction