The purpose of this notice is to inform you of the type of information (including personal information) that the Integrated Care Board (ICB) holds; how that information is used; who we may share that information with; and how we keep it secure and confidential.
This notice applies to all information held by the ICB relating to individuals, whether you are a current or previous patient / service user. It covers information collected directly from you or receive from other individuals or organisations. The ICB also holds data from the closed ICB’s Suffolk and South East Essex ICB and Norfolk and Waveney ICB.
This notice is not exhaustive; however, we are happy to provide any additional information or explanation needed. Any requests for this should be sent to our Data Protection Officer.
We revise the Privacy Notice regularly to ensure that it continually provides transparent information about the use of your data. This notice was last reviewed in April 2026.
An Easy Read version of this privacy notice is also available.
Your data protection rights
NHS Norfolk and Suffolk ICB observes your rights, provided by the UK GDPR as detailed below. To enable the ICB to observe your rights it will be necessary to process your information in the administration of your request.
You are not required to pay any charge for exercising your rights. If you make a request, we have one month to respond to you.
Please contact us at: [email protected] if you wish to make a request.
National and Local Opt-Out if you don’t want your data shared
Information about your health and care helps us to improve your individual care, speed up diagnosis, plan your local services and research new treatments. The NHS is committed to keeping patient information safe and always being clear about how it is used.
There are different opt-outs available to you if you do not wish your data to be shared in an identifiable form.
| Type Opt outs | Description and purpose | How to Opt Out |
| Withdrawing consent Information given directly to the ICB | Where we have received information from you directly using your consent, you can withdraw this at any time. If there is an overriding legal obligation for us to hold or share your personal information. Meaning we cannot comply with your request, we will provide you with full details of the reason why. | You can withdraw your consent at any point by contacting the ICB contact details below. |
| Local Opt outs Information shared with the ICB for secondary use purposes | To help us manage the local health and social care system, the ICB may use anonymised or pseudonymised data that is shared with us by other health and social care services and ICS partner organisations. As this use of data is not for your direct care this is called secondary use of data. Risk stratification An example of this is Risk Stratification. This use allows us to provide the services that are needed, in the right areas, helping to promote good health and social care and reducing health inequalities. Further information on Risk Stratification is available within this notice Risk Stratification Research Your information is shared with the ICB and pseudonymised, and linked with other information within out Data Hub, once it is pseudonymised the ICB are allowed to use it for Commissioning purposes, planning and evaluation of services, research and evaluation of conditions. Data Hub Your pseudonymised information is used to help develop services and identify any health care needs you could benefit from. If you do not want your data used in this way you can opt-out | If you do not wish for your personal data to be used for Risk Stratification, or Research you can choose to exercise a local opt out by contacting the ICB as below. Address: NHS Norfolk & Waveney Integrated Care Board 8th Floor, County Hall Martineau Lane Norwich NR1 2DH Email address: [email protected] Telephone Number: 01603 595857 |
| Local Opt out Information shared between Health and Social Care organisations for direct care purposes | Shared Care Record Shared Care Record (ShCR) – Norfolk and Waveney ICS (improvinglivesnw.org.uk) The ICB facilitate a service call the Shared Care Record – where health organisations securely upload specific health data which can then be accessed securely by other health and social care providers. If you do not want your information shared in this way the ICB facilitate these opt outs. The ICB do not have access to your health information but can facilitate your opt out choice. | If you do not wish for your information to be accessed for the purpose of your direct care in this way, you may opt out by emailing: [email protected] with your: • Full Name, • Date of Birth and • NHS number. Please be aware that this may create clinical risks as health and care professionals will not see your records as easily. |
| The National Opt out – Research can be applied to Information provided to ICB from organisations that provide NHS services. | NHS England share your health information with the ICB to enable commissioning and planning of services to meet your needs (such as treatment and diagnosis codes, referral activity collected from organisations such as Hospitals) This information is pseudonymised. The information can also be used as part of research if you allow this. National Opt Out means that your information cannot be used for research but is still used in a pseudonymised format by the ICB for commissioning purposes. | You are able to opt out from the use of your personal data for research and planning purposes. This is known as the National Data Opt Out. See NHS pages for more information National Data Opt-Out – NHS England Digital. Your choice to opt-out will have no negative impact on your individual care. You can check or update your opt-out preference via the following link: https://www.nhs.uk/your-nhs-data-matters/manage-your-choice/ |
What information we hold and what we do with it
This is not an exhaustive list; the following pages provide key examples of the personal information ICB collects.
Our lawful Basis for processing personal information are Public Task and Explicit Consent
The General Data Protection Regulation definition for processing
Public Task
- Articles 6(1)(e) of GDPR: (e) Public task: the processing is necessary for you to perform a task in the public interest or for your official functions, and the task or function has a clear basis in law.
- Article 9(2)(h) of GDPR: (h) Health or social care (with a basis in law): (preventive or occupational medicine, for the assessment of the working capacity of the employee, medical diagnosis, the provision of health or social care or treatment or the management of health or social care systems and services)
Explicit Consent
- Articles 6(1)(a) the data subject has given consent to the processing of his or her personal data for one or more specific purposes.
- Article 9(2)(a) of GDPR: (a) Explicit consent: the data subject has given consent to the processing of his or her personal data for one or more specific purposes
Where the Common Law Duty of Confidentiality applies information is usually shared under Implied or Explicit Consent.
Purpose, Legal Basis and Processing Activities details for:
Care Service Activities Privacy Notice Commissioning and reporting Corporate Functions Privacy Notice Quality and Research Privacy NoticeFurther details
How we store your information and keep it safe
We are committed to protecting your privacy and will only process personal information in accordance with relevant legislations such as, UK GDPR and the Data Protection Act 2018, the common law duty of confidentiality, Data Use & Access Act 2025 and the Human Rights Act 1998.
NHS Norfolk and Suffolk ICB as a data controller is legally responsible for ensuring that all personal information is processed in accordance with data protection legislation, and that you can exercise your rights in respect of your information.
All staff have contractual obligations of confidentiality, enforceable through disciplinary procedures. All staff contractors and committee members will receive appropriate training on confidentiality of information and staff who have regular access to personal confidential data will have received additional specialist training.
We take relevant organisational and technical measures to make sure that the information we hold is secure – such as holding information in secure locations, restricting access to information to authorised personnel, protecting personal and confidential information held on equipment such as laptops with encryption and information is transferred safely and securely.
All data controllers must register their processing activities with the Information Commissioner’s Office (ICO).
Everyone working for the NHS has a legal obligation to keep information about you confidential. The NHS Constitution provide a commitment that all NHS organisations and those providing care under an NHS contract will use records about you in ways that respect your rights and promote your health and wellbeing.
The ICB works with our data processors, to ensure that information is held in secure locations with restricted access to authorised personnel only. We protect any personal information that is held on our systems with encryption so that it cannot be accessed by those who do not have permission to do so.
Retention and Destruction of records
In Health and Care, all organisations apply retention schedules in accordance with the NHS Records Management Code of Practice 2021 which determines the length of time records should be kept.
Use of Artificial Intelligence (AI)
We may use AI‑enabled systems to support the delivery of our services, including tools that analyse patterns, assist decision‑making, or help us improve the quality and safety of care. Where we use AI, we ensure that decisions affecting you are always subject to human oversight, and that appropriate safeguards are in place to protect your rights and freedoms.
We will only use your personal data in AI systems where we have a clear legal basis, a defined purpose, and where a Data Protection Impact Assessment has been completed. If AI involves automated processing that could have a significant effect on you, we will explain the logic involved, the significance and consequences of the processing, and your right to request human review, express your views, or challenge the outcome.
We do not use patient-identifiable data in publicly available generative AI tools, and we do not use AI to make solely automated decisions about your care.
If you have a concern or complaint on how we use your data
If you have any concerns about our use of your personal information or how we have processed your request, you can make a complaint to us at
Data Protection Officer (DPO)
Norfolk and Suffolk Integrated Care Board
Floor 8, County Hall
Martineau Lane
Norwich
NR1 2DH
Or Email the Data Protection Officer at: [email protected]
We will always endeavour to resolve the matter to your satisfaction. However, if you are not happy with the response, you can also complain to the Information Commissioners Office (ICO):
Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
Helpline number: 0303 123 1113
Make a complaint about how an organisation has used your personal information | ICO
ICO website: https://www.ico.org.uk