| name | nhs-dpia |
| description | Use when drafting a Data Protection Impact Assessment (DPIA) for an NHS service that processes health data under UK GDPR. |
NHS DPIA — Data Protection Impact Assessment
This skill drafts DPIAs for NHS digital health services following ICO guidance and the NHS Data Security and Protection Toolkit.
When to Use
- Starting a new NHS service that processes personal or health data
- Adding a new data processing activity to an existing service
- Integrating with external NHS systems (PDS, GP Connect, etc.)
- Before any Alpha assessment — assessors will ask about data protection
ICO 8-Step DPIA Process
- Identify the need — Why is a DPIA required? (Art. 35 triggers: health data = special category)
- Describe the processing — What data, from whom, how collected, how stored, how shared
- Consultation — Who was consulted (clinicians, patients, IG team, Caldicott Guardian)
- Necessity and proportionality — Lawful basis (Art. 6), special category condition (Art. 9), data minimisation
- Identify risks — Risks to individuals' rights and freedoms
- Identify measures — Technical and organisational measures to mitigate each risk
- Sign off — DPO/IG lead approval
- Integrate outcomes — Feed measures into development backlog
UK GDPR — Key Articles for NHS
- Art. 6: Lawful basis — typically
6(1)(e) public task for NHS
- Art. 9: Special category condition — typically
9(2)(h) health/social care purposes
- Art. 35: DPIA required for high-risk processing (health data always qualifies)
- Art. 25: Data protection by design and default
NHS-Specific Considerations
- Caldicott Principles — justify each item of patient data
- NHS Data Security Standards (DSP Toolkit)
- Data flows to/from NHS Spine, PDS, GP Connect
- Data residency — Azure UK South/UK West only
- Retention periods — NHS Records Management Code of Practice
Output
The agent must create a new file at docs/dpia/dpia.md following the ICO 8-step structure described above. Do not edit this skill file — it is a reference, not a template to fill in.