Accessibility and language tool guide
Skip to content
Leeds Community Healthcare NHS Trust Logo
Careers Contact Us
  • Home
  • Our services (A to Z)
  • About us
    • Access to information
    • Equality and diversity
    • Research
    • Awards
    • Infection prevention and control
    • Clinical and medical education and training
    • Board of directors
    • Working in partnership
    • Safeguarding children and adults
    • Charity
    • Sustainability
  • News
  • Join our team
    • Why work for us?
    • Flexible staff
    • Newly qualified graduates
    • Vacancies
    • Apprenticeships
    • Working and living in Leeds
  • Patient experience and engagement
    • Compliments, comments and complaints
    • Your feedback and experience
    • Person-centred care
    • Get involved
    • Thinking about using a camera or other equipment to monitor someone’s care?
    • Help to access and attend your appointment
    • About Me project
  • Contact us
    • Plan your journey
    • Location finder
    • Press and media enquiries
Skip to content
Leeds Community Healthcare NHS Trust Logo
  • Home
  • Our services (A to Z)
  • About us
    • Access to information
    • Equality and diversity
    • Research
    • Awards
    • Infection prevention and control
    • Clinical and medical education and training
    • Board of directors
    • Working in partnership
    • Safeguarding children and adults
    • Charity
    • Sustainability
  • News
  • Join our team
    • Why work for us?
    • Flexible staff
    • Newly qualified graduates
    • Vacancies
    • Apprenticeships
    • Working and living in Leeds
  • Patient experience and engagement
    • Compliments, comments and complaints
    • Your feedback and experience
    • Person-centred care
    • Get involved
    • Thinking about using a camera or other equipment to monitor someone’s care?
    • Help to access and attend your appointment
    • About Me project
  • Contact us
    • Plan your journey
    • Location finder
    • Press and media enquiries
Leeds Community Healthcare NHS Trust Logo
/Policies and guidelines/Data protection policy

Data protection policy

Document control

  • Policy owner: Narissa Leyland, Head of information governance and data protection officer
  • Corporate lead: Executive director of finance and resources
  • Document version: V1
  • Document status: Final
  • Date approved by clinical and corporate policies group (CCPG): 19 March 2019
  • Date ratified by SMT: 27 March 2019
  • Date issued: 2 April 2019
  • Next review date: April 2022
  • Policy number: PL378

Executive summary

Leeds Community Healthcare is committed to ensuring the privacy of individuals are respected and that all personal data processed is handled appropriately and in accordance with the requirements of the General Data Protection Regulation (GDPR), the Data Protection Act 2018 (DPA2018) and all other data protection laws collectively known in this policy document as (Data Protection Legislation).

The trust has a legal obligation to comply with all appropriate legislation and guidance when processing personal data about patients, employees and other individuals.

Equality analysis

Leeds Community Healthcare NHS Trust’s vision is to provide the best possible care to every community. In support of the vision, with due regard to the Equality Act 2010 General Duty aims, Equality Analysis has been undertaken on this policy and any outcomes have been considered in the development of this policy.

Table of content

  1. Introduction
  2. Scope
  3. Definitions
  4. Responsibilities
  5. GDPR principles
  6. Accountability
  7. Lawful basis for processing
  8. Consent
  9. Individuals rights
  10. Data processors and contracts
  11. Documentation
  12. Data protection by design and default
  13. Data privacy impact assessment (DPIA)
  14. Data protection officer
  15. Personal data breaches
  16. International transfers
  17. Monitoring compliance and effectiveness
  18. Training needs
  19. Approval and ratification process
  20. Dissemination and implementation
  21. Review arrangements
  22. Associated documents
  23. References

1. Introduction

This policy is to set out the trusts’ commitment in how the organisation will comply with current Data Protection Legislation.

The trust will, through appropriate management, and strict application of criteria and controls:

  • observe fully conditions regarding the fair and lawful collection and use of information
  • meet its legal obligations to specify the purposes for which information is used
  • collect and process appropriate information to the extent that it is needed to fulfil operational needs or to comply with legal requirements
  • ensure the quality of information used
  • apply strict checks to determine the length of time information is held
  • ensure that the rights of people about whom information is held can be fully exercised under the Data Protection Act 2018
  • take appropriate technical and organisational security measures to safeguard personal information
  • ensure that personal information is not transferred abroad without suitable safeguards.

2. Scope

This policy must be followed by all staff who work for or on behalf of the Trust including those on temporary or honorary contracts, secondments, volunteers, students and any staff working on an individual contractor basis or who are employees for an organisation contracted to provide services.

The policy is applicable to all areas of the organisation and covers all aspects of information including (but not limited to):

  • Patient, client and service user information.
  • Personnel and staff information.
  • Organisational and business sensitive information.
  • Structured and unstructured record systems, paper and electronic.
  • Photographic images, digital, text or video recordings including CCTV.
  • All information systems purchased, developed and managed by (or) on behalf of, the organisation.
  • Information held on paper, mobile storage devices, computers, laptops, tablets, mobile phones and cameras.

The processing of all types of information, including (but not limited to):

  • Organisation, adoption or alteration of information.
  • Retrieval, consultation, storage or retention or use of information.
  • Disclosure, dissemination or otherwise making available information for clinical, operational or legal reasons.
  • Alignment, combination or linkage, blocking, erasing or destruction of information.
  • Failure to adhere to this policy may result in disciplinary action and where necessary referral to the appropriate regulatory bodies including the police and professional bodies.

3. Definitions

Data protection legislation refers to both the General Data Protection Regulations (2018) and the Data Protection Act 2018 where the following definitions apply.

Personal data means ‘any information relating to an identifiable person who can be directly or indirectly identified in particular by reference to an identifier’.

Special category data consists of personal data relating to:

  • ethnic origin
  • physical and mental health (including, for example, details of the reasons for an individual’s sick leave)
  • sexual preference
  • genetics
  • biometrics (where used for ID purposes)
  • religion or belief
  • political opinion
  • Trade Union membership

Greater protections are required when processing this data.

Processing means obtaining, recording, holding or adding to the information or data or carrying out any operation or set of operations on the information or data.

Data subject means an individual who is the subject of the personal data.

Data controller means a person who or organisations which (either alone or jointly or in common with other persons or organisations) determines the purposes for which, and the manner in which, any personal data is processed. In this case, this means the trust or nominated individuals acting on behalf of and with the authority of the trust.

Data processor means any person (other than a member of staff) or organisation that processes data on behalf of the trust.

4. Responsibilities

4.1 Chief executive

The individual with overall accountability for information governance within the trust is the accountable officer, the chief executive. The role provides assurance, through a Statement of Internal Controls, that all risks to the organisation, including those relating to information, are effectively managed and mitigated, on a day-to-day basis will be delegated to the head of information governance and data protection officer.

4.2 Senior information risk owner (SIRO)

The trust has appointed the executive director of finance and resources as the senior information risk owner (SIRO).

The SIRO is responsible for:

  • taking overall ownership of the trust’s information risk management approach
  • acting as champion for information risk on the board and provide written advice to the accounting officer on the content of the trust’s statement of internal control in regard to information risk
  • implementing and lead the NHS information governance risk assessment and management processes
  • advising the board on the effectiveness of information risk management across the trust.

4.3 Data protection officer

The trust has appointed the head of information governance and data protection officer (DPO).

This role is defined under the EU General Data Protection Regulation (GDPR) 2018. The regulation specifies the minimum duties or “tasks” to be performed by the DPO.

  • To inform and advise the trust, and their employees, of their obligations under the Regulation and other applicable laws and regulations.
  • To monitor compliance with the regulation and other applicable laws and regulations and with the relevant policies of the trust data controller, this includes assignment of responsibilities, awareness and training, and relevant audits.
  • To advise on the data protection impact assessment (DPIA) and monitor its performance, if requested.
  • To liaise with the Information Commissioner’s Office as required under the GDPR (Article 39(1) (a to e).
  • The DPO will be the contact point for the public as regards the regulation.

4.3 Information security manager

The trust has appointed head of information technology and the head of EPR.

The information security manager is responsible for the day to day operational effectiveness of the information security policy and its associated policies and processes of which the data protection policy is one.

  • Lead on the provision of expert advice to the organisation on all matters concerning information security, compliance with policies, setting standards and ensuring best practice.
  • Provide a central point of contact for information security.
  • Ensure the operational effectiveness of security controls and processes.
  • Ensure that staff are aware of their responsibilities and accountability for information security.
  • Be accountable to the SIRO and other bodies for information security across the trust.
  • Monitor potential and actual security breaches with appropriate expert security resource.

In carrying out these tasks the information security manager will work closely with the associate director of business intelligence, and the head of information governance (IG) and data protection officer (DPO).

4.4 Caldicott guardian

The trust has appointed the medical director as the Caldicott guardian.

The Caldicott guardian is responsible for ensuring the confidentiality of patient confidential data and ensuring it is shared appropriately and securely.

4.5 Managers

Managers within every business area are responsible for implementing and ensuring compliance with data protection procedures. This includes the requirement to take all reasonable steps to ensure compliance by third parties. Managers must
always contact the head of IG and DPO if:

  • they are unsure of the lawful basis which they are relying on to process personal data
  • they need to rely on consent for processing personal data
  • they need to prepare privacy notices or other transparency information they are unsure about the retention period
  • they are unsure on what basis to transfer personal data outside the European Economic Area (EEA)
  • they are engaging in a significant new, or change in, processing activity which is likely to require a data protection impact assessment
  • they plan to use personal data for purposes other than those for which it was originally collected
  • they plan to carry out activities involving automated processing including profiling or automated decision-making
  • they need help with any contracts or other areas in relation to sharing personal data with third parties (including our contractors)
  • they plan to share data with another organisation or person in a way which is new or could affect data subjects’ rights.

4.6 All staff

Everyone working for Leeds Community Healthcare or on behalf of Leeds Community Healthcare is responsible for ensuring that they understand and follow this policy and other procedures relating to the processing and use of personal data and support Leeds Community Healthcare in complying with data protection legislation, including undertaking Information Governance training on an annual basis.

5. GDPR principles

The GDPR sets out the main principles for organisations when processing data. In accordance with article 5 of the GDPR, the
trust must ensure that personal data is:

5.1 Lawfulness, transparency and fairness

5.1.1 Lawfulness

To process personal data and special category data lawfully, the trust must identify a legal basis for each data processing activity.

An annual data mapping exercise is undertaken across the trust which identifies all inbound and outbound flows of information and an appropriate condition under article 6 and article 9 of the GDPR is identified and documented.

5.1.2 Transparency and fairness

General information about how we process personal data as a controller (referred to as “fair processing information”) will be available on our website through privacy notices and other public-facing material.

5.2 Purpose limitation

The trust has clearly identified and documented the purposes for processing and included details of these purposes in our privacy information which we make available to both patients and our staff. All purposes are reviewed on an annual basis.

5.3 Data minimisation

The trust will only collect personal data required for specified purposes and ensure information we hold is periodically reviewed and removed when it is no longer required.

5.4 Accuracy

The trust will take reasonable steps to ensure the accuracy of personal data and will carefully consider any challenges to the accuracy of information. This will be achieved by ensuring:

  • appropriate processes are in place to check the accuracy of data
  • any mistakes are clearly identified as a mistake
  • all records will identify any matters of opinion, and where appropriate whose opinion it is and any relevant changes to the underlying facts
  • any challenges to the accuracy of personal data will be carefully considered when complying with an individual’s right to rectification

5.5 Storage limitation

We will ensure that personal data is not kept in an identifiable form for longer than is necessary. Due to our function as a public authority, the trust retains some personal data for long periods of time.

Details of all of our retention and disposal periods are set out in our records management policy.

5.6 Appropriate security

A key principle of the GDPR and Data Protection Act 2018 is that personal data must be processed securely by means of ‘appropriate technical and organisational measures’, this is the ‘security principle’. This will be achieved by ensuring:

  • A Network security policy (PL350) is in place and implemented across the trust
  • additional policies and controls are in place to enforce them
  • information security risk shall be adequately managed and risk assessments on IT systems and business processes shall be performed where appropriate
  • the requirements for confidentiality, integrity and availability for the personal data we process are understood.
  • appropriate information security controls are implemented to protect all IT facilities, technologies and services used to access, process and store the trust information
  • encryption and/or pseudonymisation are in place where it is appropriate to do so
  • access to personal data can be restored in the event of any incidents, such as by establishing an appropriate backup process
  • regular testing is conducted and reviews of our measures to ensure they remain effective, and act on the results of those tests where they highlight areas for improvement
  • measures are implemented that adhere to an approved code of conduct or certification mechanism when necessary
  • all relevant information security requirements of the trust shall be covered in agreements with any data processors, third-party partners or suppliers, and compliance against these is monitored.

6. Accountability

The trust is responsible for complying with the GDPR and DPA18 and must be able to demonstrate compliance by evidencing the steps taken to comply. This will be achieved by ensuring:

  • we take responsibility for complying with the GDPR and DPA 2018, at the highest management level and throughout our organisation
  • we keep evidence of the steps we take to comply with the GDPR and DPA 2018
  • appropriate technical and organisational measures are in place, which will be achieved by:
    • adopting and implementing data protection policies
    • taking a ‘data protection by design and default’ approach, putting appropriate data protection measures in place throughout the entire lifecycle of our processing operations
    • putting written contracts in place with organisations that process personal data on our behalf
    • maintaining documentation of our processing activities
    • implementing appropriate security measures
    • recording and, where necessary, reporting personal data breaches
    • carrying out data protection impact assessments (DPIA) for uses of Personal Data that are likely to result in high risk to individuals’ interests
    • appointing a data protection officer
    • adhering to relevant codes of conduct and signing up to certification schemes (where possible)
    • we review and update our accountability measures at appropriate intervals.

7. Lawful basis for processing

The trust must determine the lawful basis for processing before starting any collection of personal data. The lawful basis for processing are set out in Article 6 of the GDPR and at least one of these must apply whenever personal data is processed:

  1. Consent: the individual has given clear consent to process their personal data for a specific purpose.
  2. Contract: the processing is necessary for a contract with the individual, or because they have asked the trust to take specific steps before entering into a contract.
  3. Legal obligation: the processing is necessary to comply with the law (not including contractual obligations).
  4. Vital interests: the processing is necessary to protect someone’s life.
  5. Public task: the processing is necessary to perform a task in the public interest or for your official functions, and the task or function has a clear basis in law.
  6. Legitimate interests: the processing is necessary for the trust’s legitimate interests or the legitimate interests of a third party unless there is a good reason to protect the individual’s personal data which overrides those legitimate interests. (This cannot apply when the Trust is processing data to perform its official functions).

In order to process Special Categories Data, the Trust must also ensure that one of the following applies:

  1. The data subject has given explicit consent to the processing of those personal data for one or more specified purposes.
  2. Processing is necessary for the purposes of carrying out the obligations and exercising specific rights of the controller or of the data subject in the field of employment and social security and social protection.
  3. Processing is necessary to protect the vital interests of the data subject or of another natural person where the data subject is physically or legally incapable of giving consent.
  4. Processing relates to personal data which are manifestly made public by the data subject.
  5. Processing is necessary for the establishment, exercise or defence of legal claims or whenever courts are acting in their judicial capacity.
  6. Processing is necessary for reasons of substantial public interest, on the basis of EU or UK law which shall be proportionate to the aim pursued, respect the essence of the right to data protection and provide for suitable and specific
    measures to safeguard the fundamental rights and the interests of the data subject.
  7. Necessary for the purposes of preventative or occupational medicine, for assessing the working capacity of the employee, medical diagnosis, the provision of health or social care or treatment or management of health or social care systems and services on the basis of Union or Member State law or a contract with a health professional.
  8. Necessary for reasons of public interest in the area of public health, such as protecting against serious cross-border threats to health or ensuring high standards of healthcare and of medicinal products or medical devices.

These conditions must be read alongside the Data Protection Act 2018, which adds more specific conditions and safeguards:

  • Schedule 1 Part 1 contains specific conditions for the various employment, health and research purposes under Articles 9(2), (b), (g), (i) and (j).
  • Schedule 1 Part 2 contains specific ‘substantial public interest’ conditions for Article 9(2)(h).

The trust annually reviews the purposes of our processing activities, and selects and documents the most appropriate lawful basis for each activity to demonstrate compliance. This information is included in our privacy notices for both staff and
patients.

8. Consent

Where relying on consent as the legal basis for lawful sharing of personal information, ensure the quality of consent meets new requirements and that:

  • consent is active, and does not rely on silence, inactivity or pre-ticked boxes
  • consent to processing is distinguishable, clear, and is not “bundled” with other written agreements or declarations
  • data subjects are informed that they have the right to withdraw
  • there are simple methods for withdrawing consent, including methods using the same medium used to obtain consent in the first place
  • separate consents are obtained for distinct processing operations
  • consent is not relied on where there is a clear imbalance between the data subject and the controller (especially if the controller is a public authority).

9. Individuals rights

The trust will respect individuals’ rights when processing personal data. These are enshrined in the legislation as follows:

  1. The right to be informed
  2. The right of access
  3. The right to rectification
  4. The right to erasure
  5. The right to restrict processing
  6. The right to data portability
  7. The right to object
  8. Rights in relation to automated decision making and profiling.

The rights above depend upon the lawful basis for processing. For example, the right to erasure only applies where the lawful basis for processing is consent.

Where public task, legitimate interests, contractual basis or a legal requirement are used as the basis for processing, the right of rectification, restriction and the right to object are also limited to ensuring that the data is accurate before it can be processed.

The right to be informed is, however, a key right and applies in all circumstances (see transparency and fairness, section 5.1). The trust has an individuals rights and subject access request procedure in place to support.

10. Data processors and contracts

Where it uses a data processor, the trust is still responsible for data protection and liable for any data transferred.

The trust is also liable for the data processor’s compliance with the legislation and must only appoint processors who can provide sufficient guarantees that the requirements of the legislation will be met and the rights of data subjects protected. It must, therefore, ensure that there is an appropriate written contract with the data
processor. The contract is important so that both parties understand their responsibilities and liabilities.

Contracts will set out the subject matter and duration of the processing, the nature and purpose of the processing, the type of personal data and categories of data subject, and the obligations and rights of the controller and which must, as a
minimum set out the following:

  • only act on the written instructions of the trust
  • ensure that people processing the data are subject to a duty of confidence
  • take appropriate measures to ensure the security of processing
  • only engage sub-processors with the prior consent of the trust and under a written contract
  • assist the trust in providing subject access and allowing data subjects to exercise their rights under the GDPR
  • assist the trust in meeting its GDPR obligations in relation to the security of processing, the notification of personal data breaches and data protection impact assessments
  • delete or return all personal data to the controller as requested at the end of the contract
  • submit to audits and inspections, provide the controller with whatever information it needs to ensure that they are both meeting their Article 28 obligations, and tell the controller immediately if it is asked to do something infringing the GDPR or other data protection law of the EU or a Member State.

The trust will apply the approach set out in the Procurement Policy Note (PPN03/17) Changes to Data Protection Legislation and General Data Protection Regulation, published by Crown Commercial Service.

11. Documentation

The trust is required to maintain a record of its processing activities, covering areas such as processing purposes, data sharing and retention.

A data mapping review of all data processing activities across the trust will be undertaken on an annual basis facilitated by the Information Governance team. The review will identify all inbound and outbound flows of personal identifiable
information from each department and business unit, the purposes of the flow, what type of personal data is involved, who it is shared with, the lawful basis and whether an information sharing agreement has been established.

12. Data protection by design and default

The trust will ensure that privacy and data protection issues are considered at the design phase of any new system, service, product or process and that appropriate technical and organisational measures to implement the data protection principles and safeguard individual rights are in place. This will involve but not limited to:

  • only using data processors that provide sufficient guarantees of their technical and organisational measures for data protection by design
  • anticipating risks and privacy-invasive events before they occur, and take steps to prevent harm to individuals
  • making data protection an essential component of the core functionality of our processing systems and services.

13. Data privacy impact assessment (DPIA)

The GDPR introduces a new obligation to carry out a DPIA before carrying out types of processing likely to result in high risk to individuals’ interests.

The trust will consider if a full DPIA is necessary if the processing of personal data involves:

  • evaluation or scoring (including profiling and predicting)
  • automated decision making
  • systematic monitoring of data subjects, including in a publicly accessible area
  • sensitive data (special categories of data as defined in Article 9 and data regarding criminal offences)
  • data being processed on a large scale
  • matched or combined datasets
  • vulnerable individuals
  • transferring data outside the European Union
  • innovative technical or organisational solutions
  • preventing data subjects from exercising a right or using a service or a contract

As a minimum, a DPIA will include:

  • A description of the envisaged processing operations and the purposes of the processing
  • An assessment of :
    • the need for and proportionality of the processing
    • the risks to data subjects (as viewed from the perspective of data subjects) arising
  • A list of the measures envisaged to mitigate those risks and ensure compliance with the GDPR.

14. Data protection officer

The GDPR introduces a duty to appoint a Data Protection Officer (DPO) if you are a
public authority or body, or if you carry out certain types of processing activities.

The trust’s DPO is Narissa Leyland, who can be contacted via email dpo.lch@nhs.net or phone: 0113 220 8572

or at the following address:
Information Governance team
Leeds Community Healthcare
Stockdale House
Victoria Road
Leeds
LS6 1PF

15. Personal data breaches

It is a legal obligation to notify personal data breaches of the GDPR under Article 33 within 72 hours, to the ICO, unless it is unlikely to result in a risk to the rights and freedoms of individuals. Article 34 also makes it a legal obligation to communicate the breach to those affected without undue delay when it is likely to result in a high risk to individual’s rights and freedoms. It is also a contractual requirement of the standard NHS contract to notify incidents in accordance with this guidance. By notification, this may be an initial summary with very little detail known at the outset but a fuller report that might follow. There is no expectation that a full investigation will be carried out within 72 hours.

The trusts documents all data breaches even if they don’t need to be reported to the information commissioner.

The ‘Guide to the Notification of Data Security and Protection Incidents’ must be followed when a data breach has been detected. The guidance applies to all organisations operating in the health and social care sector. This guidance has been incorporated into the Personal Data Breach Management Procedure, which is aligned to the incident and serious incident policy.

16. International transfers

Current data protection laws impose restrictions on the transfer of personal data outside the European Union, to third countries or international organisations. These restrictions are in place to ensure that the level of protection of individuals afforded by the GDPR is not undermined.

17. Monitoring compliance and effectiveness

Minimum requirement to be monitored and audited Process for monitoring and audit Lead for the monitoring and audit process Frequency of monitoring and auditing Lead for reviewing results Lead for developing and reviewing action plan Lead for monitoring action plan
Compliance with the data security and protection toolkit Reporting to the IG group Head of information governance and data protection officer Quarterly Director of finance and resources Head of information governance and data protection officer IG group
Annual information governance audit Reporting to the Audit Committee Head of information governance and data protection officer Annually Director of finance and resources Head of information governance and data protection officer IG group

18. Training needs

All staff must adhere to the IG training requirements set out in the trust’s mandatory and statutory training policy.

19. Approval and ratification process

The policy has been approved by the IG group, clinical and corporate policy group and ratified by SMT on behalf of the board with oversight of the Audit Committee.

20. Dissemination and implementation

Dissemination of this policy will be via the clinical and corporate policy group and workforce policies to services and made available to staff via the IG intranet page.

21. Review arrangements

This policy will be reviewed in three years by the author or sooner if there is a local or national requirement then ratified by the SMT with oversight of the Audit Committee.

22. Associated documents

The policies and procedures in place to support the IG Framework are:

  • Confidentiality Code of Conduct, PL306
  • Records management policy, PL235
  • FOI procedure, IG004
  • Individual rights and subject access request procedure, IG003
  • Information handling guideline, GL083
  • Network security policy, PL350
  • Data protection impact assessment policy, PL374
  • Data protection impact assessment procedure, IG002
  • Data breach management procedure, IG005
  • Information asset procedure, IG001

23. References

  • General Data Protection Regulation 2018
  • Data Protection Act 2018
  • Human Rights Act 1998
  • Privacy and Electronic Communications Regulations 2003
  • A Manual for Caldicott Guardians (2017)
  • Department of Health, Confidentiality: NHS Code of Practice (2003)
  • Department of Health, Information: To Share or Not to Share (2013) (Caldicott 2)
  • Report on the Review of Patient-Identifiable Information (1997) (The Caldicott Report)
  • NHS Digital, Code of Practice on Confidential Information (2014)
survey icon

Tell us what you think

We would love to know what you think of our website and if there is anything we can improve.

Complete our survey and share your thoughts.

Leeds Community Healthcare NHS Trust Logo

Headquarters

Leeds Community Healthcare NHS Trust
White Rose Office Park, Building 3
Millshaw Park Lane
Leeds, LS11 0DL

Useful Links

  • News
  • Current vacancies
  • Contact us
  • Give feedback

Need to speak to someone urgently?

MindMate Website Logo MindWell Leeds Website Logo NHS 111 Logo
© 2026 Leeds Community Healthcare NHS Trust - Website by 6B
  • Accessibility statement
  • Privacy notice
  • Cookie policy
  • Terms and conditions
  • Policies and guidelines