1 of 5

Record Deletion

When can PKB records be deleted?

Kaleidoscope Consultants Limited | +44 (0) 20 3637 1111 | info@kaleidoscopeconsultants.com

East Side, Kings Cross, London, N1C 4AX, UK | The Black Church, St. Mary’s Place, Dublin, D07 P4AX, RoI | Calle Balmes 173, 4-2, Barcelona 08006, España

2 of 5

Deletion conditions

Deletion requestor

Patient Record

Patient Account

Result

Justification/notes

HCP viewed?

DS viewed?

Data subject request

Do not delete

Hold for medico-legal duty for eight years from last access

Data subject request

Delete

Assess on a case by case basis

Data subject request

Do not delete

Hold for medico-legal duty for eight years from last access

Data subject request

Delete

Assess on a case by case basis

Creator/single source requested – unshared record

Do not delete

Hold for medico-legal duty for eight years from last access

Creator/single source requested – unshared record

Do not delete

Record is in the control of the data subject

Creator/single source requested – unshared record

Do not delete

Hold for medico-legal duty for eight years from last access

Creator/single source requested – unshared record

Delete

Assess on a case by case basis

Creator/multiple source requested – shared record

Do not delete

Hold for medico-legal duty for eight years from last access

Creator/multiple source requested – shared record

Do not delete

Record in the control of the data subject

Creator/multiple source requested – shared record

Do not delete

Hold for medico-legal duty for eight years from last access

Creator/multiple source requested – shared record

Delete

Assess on a case by case basis

Court Order

Delete

3 of 5

Controller/Processor/Joint Controller

I am of the opinion that the legal basis for retention is unaffected by which organisation is the controller on the basis that:

  1. Where a controller, the controller must specify their lawful basis for processing and expected deletion. Deletion justification must be justified and documented (GDPR article 5(1)(e))
  2. Where a processor, data must be deleted on the instruction of the controller unless there is a separate duty to process, including retention (GDPR article 28(3)(g))
  3. Where joint controllers, each controller purpose, lawful basis and retention should be documented in the JCA
  4. Where the PKB data is in a Patient Account, the subject may request deletion and this will be implemented unless another legal duty applies, in which case the subject will be informed and the data will be deleted at the earliest opportunity
  5. Where the PKB data is in Patient Record, deletion requests will be handled as noted in the previous slide.

4 of 5

Definitions

  1. A patient record comprises data sourced from health and social care provider records and other records which may be accessed by Healthcare Professionals (HCPs) from single or multiple source organisations
  2. A patient account is created when the data subject has activated their access to their record and exercises control over who can see what of their data and may also contribute to their record

5 of 5

History

Version

Date

Author

Change

0.1

05/03/2021

David Stone

Created

0.2