The way we use patient data is changing: We aim to provide the highest quality care. To do this, we routinely collect information about you and the care you receive from us. Like other hospitals across England, we are changing how we share and use this data… Find out more

The Dudley Group NHS Foundation Trust Logo
Homepage|About our Trust|Privacy Notice
Flowers digital art

General Privacy Notice

This is the Trust’s main privacy notice. The sections below explain how the Trusts processes your personal information.

The Dudley Group NHS Foundation Trust (referred to in this notice as ‘The Trust’) is the main provider of hospital and adult community services to the populations of Dudley, significant parts of the Black Country, Sandwell borough and smaller, but growing, communities in South Staffordshire and Wyre Forest.

The Trust covers three hospital sites at Russells Hall Hospital, Guest Outpatient Centre in Dudley and Corbett Outpatient Centre in Stourbridge, providing a full range of secondary care services and some specialist services for the wider populations of the Black Country and West Midlands region. The Trust also provides specialist adult community-based care in patients’ homes and in more than 40 centres in the Dudley Metropolitan Borough Council community as well as other community-based services including two GP Practices. The Trust is also one of the four NHS Trusts which has created the Black Country Provider Collaborative. In addition, The Dudley Group NHS Foundation Trust and Sandwell and West Birmingham NHS Trust are working together through a Group model to support the delivery of high-quality, sustainable healthcare services for local populations.

The Trust has responsibility for ensuring that the personal information processed across these sites and services, which includes your personal and sensitive (special category) data is processed in accordance with applicable Data Protection Legislation including UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 (DPA 2018) and the Data (Use and Access) Act 2025 (DUAA).

The Trust’s Data Protection Registration reference number with the Information Commissioner’s Office is Z8909702.

The purpose of this Privacy Notice is to:

  • Inform you why we collect information about you
  • Inform you how we use your personal information
  • Explain who we share your personal information with
  • Explain how you can restrict the disclosure of information
  • Inform you about our communication services e.g. text messaging, patient portal
  • Explain how your personal information is used to improve the NHS as a whole
  • Explain how you can access information held within your health records

At the Trust we aim to provide you with safe and effective care to the highest standards. To do this our medical professionals caring for you will keep records about your health and the care you receive from the Trust. This may be stored electronically and in a paper form. This includes personal and special category data.

The Trust collects the following types of personal and special category data:

  • Personal information including your name, address, date of birth, NHS number, next of kin and contact details
  • Details of your hospital admissions or outpatient appointments
  • Records and reports about your health
  • Results of investigations, such as X-rays and laboratory tests
  • Relevant information from other health professionals, relatives, or carers
  • Ethnic origin
  • Religion

It is important that your personal details are accurate and up to date and we will often check with you at appointments or visits that these details are correct.

The staff caring for you need to collect and maintain information about your health, treatment, and care, so that you can be given the highest quality of health care.

We also collect data to help the NHS:

  • Prepare statistics on performance and health population
  • Audit the services
  • Monitor how we spend public money
  • Plan and manage the health services
  • Teach and train healthcare professionals
  • Conduct health research and development
  • Improve our existing services

We may also hold your information if you have contacted us with an enquiry or complaint.

If you think that any of the information, we hold about you is incorrect, please let us know as soon as possible.

Provide Healthcare

Your records are used to guide, monitor, and administer the care you receive to ensure your doctor, nurse or other healthcare professionals involved in your care has up-to-date information to assess your health and decide what care you need when you visit in the future. Data may be in hard copy and electronic form, in various Trust systems, dashboards, reports and may be discussed at various confidential meetings. This is not an exhaustive list as there are many ways in which the Trust will process your data to manage your care.

Management and Evaluation of Services

Health Records can also be used within service evaluation, audit and for teaching purposes; in these cases, we use anonymous information when possible. Service evaluation and audit is a way for the Trust to review the service’s effectiveness or efficiency through assessment of its aims, objectives, activities, outputs, outcomes, and costs. Where possible we will use anonymised information to complete the audits and evaluations.

Research

Some information we must share is used for statistical, research or audit purposes, and in these instances, we take strict measures to ensure that individual patients cannot be identified and where appropriate anonymisation and pseudonymisation techniques will be used to protect your identity. Where this is not possible, we will also ask for your consent to process your personal information for this purpose. Refer to the Trusts Research Privacy notice here.

Text messaging and appointment Reminders

The Trust provides appointment reminder services through third party providers. These reminders may also be sent via automated calls, text messages or emails. When you attend the Trust, you can confirm your contact details, including your mobile number and email address, to ensure we have the most up to date information.

Reminders will be sent to the mobile number, email address or landline you have provided and chosen as your preferred method of contact. If no mobile number is available, reminders may be issued via your landline. Should you wish to change your preferred mode of communication or if you do not wish to receive these reminders, please contact the Patient Management Centre on 01384 365100 so your contact details and preferences can be updated accordingly.

When collecting or transferring sensitive information such as health and personal details we use a variety of security technologies and procedures to help protect your personal information from unauthorised access, use or disclosure. However, any information we receive from you via a personal email address systems and any response we might transmit via email in return, cannot be guaranteed to be completely protected from access by unauthorised persons.

Patient Portals

Patient portals provide secure digital access to information such as appointment details, medical correspondence, letters and test results.

Digital appointment letters via Healthcare Communications

The Trust uses digital services to communicate with patients. A patient portal is available where patients can securely view their appointment letters online. More information is on our website, refer to the link here.

Technologies

The Trust may use approved digital technologies including artificial intelligence (AI) tools to support the delivery of healthcare services and Trust operations. Where these technologies process personal information, appropriate technical safeguards are in place to ensure compliance with data protection legislation.

As a data controller the Trust must establish and publish the lawful basis that is relied on for processing personal and special category data (sensitive data). The following provisions indicate the main processing legal basis that the Trust is relying on for processing activities.

Most of the processing we carry out is to deliver your care and is covered by the following legal provisions within GDPR.

  • Article 6(1)(a) the data subject has given consent to the processing of his or her personal data for one or more specific purposes.
  • Article 6(1)(e) the processing is necessary for you to perform a task in the public interest or for your official functions, and the task or function has a clear basis in law.

and

  • Article 9(2)(h) ‘…medical diagnosis, the provision of health or social care or treatment or the management of health or social care systems…’
  • Article 6(1)(d) is available in life-or-death situations but should not be necessary for health or social care organisations to use in the performance of its tasks. This might apply in a situation where an organisation needs to act to prevent harm being caused by a patient or service user, to someone who has no relationship with the organisation.

Statutory basis / Other relevant conditions:

  • Data Protection Act (DPA) 2018, UK General Data Protection Regulation (UK GDPR) and Data (Use and Access) Act 2025.
  • Common Law Duty of Confidentiality (CDLC)
  • Section 251 (NHS Act 2006)
  • NHS Trusts National Health Service and Community Care Act 1990
  • NHS England’s powers to commission health services under the NHS Act 2006 or to delegate such powers
  • 251B of the Health and Social Care Act 2012
  • Article 8 of the European Convention on Human Rights (ECHR)

We will ask you for your explicit consent to share your personal information unless there is another lawful basis to share the information, we are mandated by law, or the health and safety of others is at risk.

Yes, the Trust does share your information. We may need to share this information about you so we can all work together for your benefit. We will only ever use or pass on information about you if others involved in your care have a genuine need for it. We will only ever pass this information about you if one or more of the following applies:

  • Where there is a danger of harm to a child or vulnerable adult
  • To aid the prevention and detection of serious crime
  • There is a court order
  • We have your consent

We may share information about you with the following agencies to support the delivery of your care:

  • Other NHS Trusts (e.g., where your care and rehabilitation are to be continued elsewhere)
  • Department of Health and Social Care, other NHS bodies such as NHS England
  • Integrate Care Boards (ICB’s)
  • Integrated Care Systems (ICS)
  • General Practitioners (GP’s) in Dudley and out of areas if you are not from the Dudley region
  • Ambulance service such as West Midlands Ambulance Service
  • Other healthcare providers
  • Mental health services
  • Local authorities

We may also share your information, with your consent (where appropriate) and subject to strict sharing protocols about how it will be used with:

  • Education services
  • Voluntary sector providers
  • Private providers
  • The Police
  • Safeguarding Teams
  • Social Services
  • Voluntary services

We may also share your information with others that need to use records about you to carry out the following:

  • Check the quality of treatment of advice we have given you
  • Protect the health of the public
  • Manage health services
  • Help investigate any concerns or complaints you or your family have about your healthcare
  • Local and National NHS Surveys

If you are diagnosed with cancer or a condition that may lead to cancer, the team looking after you at the Trust will record information about you and the care you received. This applies to children and adults of all ages. This information is shared with the National Cancer Registry.

You have the right to opt out of cancer registration. This will not affect the care you receive from your healthcare team. Please discuss this option with your cancer treatment team.

In all circumstances where we need to share your information, we will only share it with those who are authorised to receive it. Anyone who receives information from us also has a legal duty to keep it confidential and secure.

Some partner organisations with which the Trust shares information include:

  • Dudley’s Action Heart Centre
  • Local councils e.g. Sandwell, Dudley, Walsall and Wolverhampton.
  • Black Country Healthcare NHS Foundation Trust
  • Black Country Alliance
  • Charity Organisations
  • Community Safety Partnerships and safeguarding teams
  • West Midlands Police
  • West Midlands Fire Service
  • West Midlands Ambulance Service
  • Dudley Community Partnership
  • Dudley Council for Voluntary Service (Dudley CVS)
  • Genomic Health UK Ltd
  • GP surgeries
  • National Probation Service
  • NHS Business Service Authority
  • Ophthalmic Diagnostic Services
  • Safeguarding Teams
  • The Black Country Alliance
  • Walsall Healthcare NHS Trust
  • Sandwell and West Birmingham Hospitals NHS Trust
  • The Royal Wolverhampton Hospitals NHS Trust
  • Other Neighbouring NHS Trusts

This list is not exhaustive. We will only share your information where it is necessary and proportionate to do so.

As part of the Group model between The Dudley Group NHS Foundation Trust and Sandwell and West Birmingham NHS Trust, personal information may also be shared between both the organisations where necessary to support the delivery of healthcare services, shared leadership responsibilities, joint services, workforce management, governance activities and operational functions. This supports the objective of Group model working and wider provider collaborative arrangements. Any sharing of information will only take place where there is a lawful basis to do so along with appropriate safeguards to protect confidentiality and security.

The Trust will collect data about you in several ways. The main method of collection is directly from yourself.

Face to face:

Most of the information we hold about you will be collected from you at the time you engage with us and our services. Any data provided will be used for the reasons listed in this notice and will only relevant data will be requested and recorded by the Trust.

Telephone calls:

The information you disclose over a telephone call may be recorded by the Trust either to support your care or as a record of the conversation that has taken place.

Virtual consultations:

The information you disclose during a virtual consultation with us may be recorded by the Trust or a third-party supplier who is supporting our provision in offering virtual appointments. This will be for the purposes of supporting your care or as a record of the consultation taking place.

Emails:

If you email the Trust, we may keep a record of your contact and your email address, and the information contained with that email. Emails that are not added to your medical record will be retained on the NHSmail system for up to 2 years. If deleted, they may remain recoverable for 30 days before being permanently removed.

CCTV:

The Trust has surveillance cameras (CCTV and body-worn cameras) on and around our premises for the purposes of crime prevention and detection, to assist in traffic management and to monitor operational and safety-related incidents. Images captured by CCTV will not be kept for longer than necessary and will be held securely. However, on occasions there may be a need to keep images for longer, for example where a crime is being investigated. The use of CCTV and any disclosure of images will be in accordance with the codes of practice issued by the Biometrics and Surveillance Camera Commissioner. Please note as the Trusts premises are managed through our PFI providers, we are not the data controller for this information. If you wish to request access to CCTV footage or have a query about CCTV, please contact the Trust’s Data Protection Officer at dgft.dpo@nhs.net. Where appropriate, your request will be forwarded to the relevant team for review and response.

Other organisation:

We may receive information from other organisations that are also required by law to share information with us about you, to help us have a full picture of your needs, provide you with care e.g., in relation to patient care transfer. This may be your GP or another NHS Organisation such as Social Care of the Local Authority.

Shared Care

The Shared Care Record is a way of bringing together all your separate records from the different organisations involved in your health and care. It’s confidential and different to anything you might have heard of before. It will also let health and social work professionals see relevant information about the care and treatment you’ve had across all services. For further information, please click here.

Under UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 (DPA 2018) and the Data (Use and Access) Act 2025 (DUAA) you have several rights in relation to your information. Below is a list of the rights you have and when they apply.

All rights requests should be responded to within 30 calendar days from date of receipt, but this time scale may be extended if the request is complex, in which case we will keep you notified.

Right to be informed

You have the right to be told how your personal information will be used. This privacy notice, and shorter summary statements used on our communications, are intended to be a clear and transparent description of how your data will be used.

Right of access

You have the right to request a copy of any information held by the Trust as well as any supplementary information. You may also be able to request a copy of data on behalf of another person e.g., a child or someone you have power of attorney for.

Right to rectification

If you believe your information may be inaccurate or incomplete you can make a request to have your information reviewed and corrected. Where there is a dispute between a data subject and a medical professional as to whether medical data is correct the Trust will retain the original but add an addendum to say it has been disputed.

Right to erasure

The right to erasure is also known as the ‘right to be forgotten’ introduces a right for you to have personal data erased. This right is not an absolute right within health care data only in exceptional circumstances will this be considered.

Right to object

Where we are relying on your consent to process data you have the right to object to processing which means that data should cease to be processed. In most cases we do not rely on consent as the legal basis for processing information. If your data is used for any other reason this right may apply but each request would be assessed on an individual basis.

Right to restrict processing

The right to restriction allows you to request the restriction or suppression your personal data. This right is linked with the right to rectify and the right to object and only applies if one of the following is met:

  • you contest the accuracy of your personal data, and the accuracy is being verified by the Trust;
  • the data has been unlawfully processed (i.e. in breach of the lawfulness requirement of the first principle of the GDPR) and you oppose erasure and requests restriction instead.
  • the personal data is no longer needed but we need to keep it to establish, exercise or defend a legal claim.

Right to data portability

The right to data portability allows you to obtain and reuse your personal data across different services without any hindrance to usability. The right to data portability is not an absolute right and generally does not apply to your health care information unless:

  • The processing is based on your consent or in the performance of a contract.
  • When processing is carried out by automated means.

Right related to automated decision-making including profiling

Profiling is automated processing of personal data to evaluate certain things about an individual. The Trust may use profiling techniques for health care planning purposes e.g., risk stratification of patients based on missed appointments.

All these rights are not always absolute and may depend on the circumstances, the type of information involved, the lawful basis for processing and whether any exemptions apply. The Trust will consider each request on a case-by-case basis and explain its decision where a right cannot be fully applied. Further information about your rights is available from the Information Commissioner’s Office here.

The Trust works in the health and care system to help improve care for patients and the public. Whenever you use a health or care service, such as attending urgent Care, Accident & Emergency or use Community Care services, important information about you is collected into a patient record for that service. Collecting this information helps to ensure you get the best possible care and treatment.

The information collected about you when you use these services can also be used and provided to other organisations for purposes beyond your individual care, for instance to help with:

  • improving the quality and standards of care provided
  • research into the development of new treatments
  • preventing illness and diseases
  • monitoring safety
  • planning services

This may only take place when there is a clear legal basis to use this information. All these uses help to provide better health and care for you, your family and future generations. Confidential patient information about your health and care is only used like this where allowed by law.

Most of the time, anonymised data is used for research and planning so that you cannot be identified in which case your confidential patient information isn’t needed.

However, you have a right to request that your personal confidential data is not used beyond direct care. If you are happy with this use of information you do not need to do anything. If you do choose to opt out your confidential patient information will still be used to support your individual care. This is called the National Data Opt-Out (NDOO). The National Data Opt-Out does not generally apply where information is being used to support your individual direct care, including where approved systems such as the NHS Federated Data Platform are used for direct care purposes.

To find out more or to register your choice to opt out, please visit www.nhs.uk/your-nhs-data-matters. On this web page you will:

  • See what is meant by confidential patient information
  • Find examples of when confidential patient information is used for individual care and examples of when it is used for purposes beyond individual care
  • Find out more about the benefits of sharing data
  • Understand more about who uses the data
  • Find out how your data is protected
  • Be able to access the system to view, set or change your opt-out setting
  • Find the contact telephone number if you want to know any more or to set/change your opt-out by phone
  • See the situations where the opt-out will not apply

You can also find out more about how patient information is used at:

You can change your mind about your choice at any time.

Data being used or shared for purposes beyond individual care does not include your data being shared with insurance companies or used for marketing purposes and data would only be used in this way with your specific agreement.

The Trust is currently compliant with the NDOO policy. The NDOO does not apply all the time.

For example: where explicit consent has been obtained from the patient for the specific purpose; to the disclosure of confidential patient information required for the monitoring and control of communicable disease and other risks to public health.

  • Where personal data is required under Section 259 of the Health and Social Care Act 2012 following a Direction from NHS England or the Secretary of State.
  • Where there is a legal requirement for the data disclosure that specifically sets aside the common law duty of confidentiality then the NDOO will not apply.
  • Data disclosure under Regulation 3 of the Control of Patient Information Regulations 2002 is exempt from the NDOO.
  • Data disclosure has Section 251 support obtained under regulation 2 or 5.

Please refer to the Trusts Research Privacy notice on how the Trust uses your personal data for research.

Everyone working for the NHS has a legal duty to keep information about you confidential and secure under the Data Protection Act 2018 and the Caldicott principles. We use the minimum amount of information required to inform the people who need to know to provide you care.

Anyone who receives information from us is also under a legal duty to do the same and our staff all have a confidentiality clause within their contract. Breaking these rules can result in staff members being dismissed.

The Trust IT Services are certified with ISO27001 Information Security Management standard accredited by BSI. This is an international standard and recognised within the commercial and public sector.

They are also Cyber Essentials certified. Cyber Essentials covers the ‘10 Steps to Cyber Security‘ published by the National Cyber Security Centre (NCSC). This is a scheme welcomed by the Information Commissioner.

We make every effort to check and test material at all stages of production. It is always wise for you to run an anti-virus programme on all material downloaded from the internet. We cannot accept any responsibility for any loss, disruption or damage to your data or your computer system that may occur while using material derived from this website.

Your information will not be sent outside of the United Kingdom or European Union where the laws do not protect your privacy to the same extent as the law in the United Kingdom. We will never sell any information about you to the external parties.

The Trust is required by law to protect the public funds it administers. It may share information provided to it with other bodies responsible for; auditing, or administering public funds, or where undertaking a public function, to prevent and detect fraud.

The Cabinet Office is responsible for carrying out data matching exercises.

Data matching involves comparing computer records held by one body against other computer records held by the same or another body to see how far they match. This is usually personal information. Computerised data matching allows potentially fraudulent claims and payments to be identified. Where a match is found it may indicate that there is an inconsistency which requires further investigation. No assumption can be made as to whether there is fraud, error, or other explanation until an investigation is carried out.

We participate in the Cabinet Office’s National Fraud Initiative: a data matching exercise to assist in the prevention and detection of fraud. We are required to provide particular sets of data to the Minister for the Cabinet Office for matching for each exercise, as detailed on the gov.uk website.

All our records are destroyed in accordance with the NHS Retention Schedule, which sets out the appropriate length of time each type of NHS records is retained. We do not keep your records for longer than necessary. All records are destroyed confidentially once their retention period has been met and the Trust has made the decision that the records are no longer required.

For more information, please see the Records Management Code of Practice by NHS England.

Through the NHS App.

You can access certain appointment details, letters and clinical information through the NHS App where this information is already available through our patient portals provided by Healthcare Communications and other Trust providers.

You do not have to access this information through the NHS App and can continue to access it directly through the patient portals. Information will only be accessible through the NHS App where you have completed the relevant access and consent steps within the App.

For this purpose, the Trust shares the NHS numbers of people registered with our patient portals with NHS England. This allows the NHS App to identify the information associated with you and make it available through the App

For more information, please visit the NHS App website.

The information available through the NHS App or Trusts patient portal may not represent your complete health record. If you would like access to information that is not available through the NHS App or patient portal, you can make a request as explained below.

By making a formal request:

You can request access to personal information held about you by the Trust. This is commonly known as a Subject Access Request. We will normally respond to your request within one calendar month of receiving it. We may extend this period by up to a further two months if your request is complex or if we have received a number of requests from you. If an extension is required, we will let you know when your request is handled.

The Health Records Access Team also handles applications relating to the health records of deceased people. Access to these records is governed by the Access to Health Records Act (1990). Applications may be made by the deceased person’s personal representative, executor or administrator, or by someone who has a claim arising from the person’s death.

For details of how to make a request, please visit our Accessing your medical records webpage.

If you have any questions or concerns regarding how your data is being processed, please contact our complaints team. The contact details are located here.

Please note the contact details for the Data Protection Officer for the Trust;

Data Protection Officer
Information Governance Team
South Block, 2nd Floor,
Russells Hall Hospital,
Pensnett Road,
Dudley, West Midlands
DY1 2HQ
Telephone: 01384 456 111 Ext: 1208
Email:
dgft.dpo@nhs.net

For a more detailed privacy notice for patients, please click here.

For a more detailed privacy notice for staff, please click here.

For a more detailed privacy notice for children, please click here.

For a more detailed privacy notice for research, please click here.

If you are looking for privacy notices of the GP surgeries that operate under the Trust, please visit the following links:

For High Oak GP Surgery privacy notice, please click here.

For Chapel Street Medical Centre privacy notice, please click here.

Alternative formats and languages

If you need this privacy notice in an alternative format, such as a printed or accessible version or require support understanding it in another language, please contact the Information Governance Team at dgft.info.gov@nhs.net. We will make reasonable efforts to meet your needs.

We may update our privacy notices from time to time. The latest version will always be available on Trusts website.

This notice was last updated in August 2026.